Exampractice
IT & Networking

PenTest+ Exam Preparation Guide

A complete CompTIA PenTest+ preparation roadmap: PT0-003 objectives, hands-on lab practice, study phases and the resources that actually move you forward.

Liam Anderson · 11 min read
Desk showing printed CompTIA PenTest+ exam objectives beside a laptop terminal and a home-lab network diagram

Preparing for CompTIA PenTest+ is different from preparing for most multiple-choice certifications, because the exam is built around a job you may not yet have done professionally: running a penetration test from scoping through to the final report. Reading alone will not get you there. The candidates who pass comfortably are the ones who pair the official objectives with regular hands-on lab time, then use practice questions to find the gaps between what they can do and what the exam actually asks.

This guide gives you the full preparation roadmap: confirming you are starting from the right baseline, understanding what you are walking into, a three-pillar study method, a phased plan you can adapt to your own timeline, and the resources worth your money. It deliberately stays out of two neighbouring debates — how PenTest+ stacks up against CEH or OSCP, and whether the certification is worth it for your career — because those are separate questions from the one you are asking now: how do I prepare well?

One version note before anything else. As of 2026, the current exam is PT0-003, which launched on 17 December 2024. The previous version, PT0-002, retired on 17 June 2025 — so if you are searching for "PT0-002 prep", check any book, course or notes you already own against the PT0-003 objectives before relying on them. Older material is not worthless, but it was written for a retired exam.

Are you ready to start preparing?

A short honest audit before you spend money on a voucher. CompTIA enforces no prerequisites for PenTest+ — anyone can book it — but the recommended profile is three to four years in a penetration-testing role, with knowledge equivalent to CompTIA Network+ and Security+. Most successful self-taught candidates are not literally four-year professionals, but they do arrive with solid fundamentals.

You are in a good position to begin if you can say yes to most of these:

  • You understand networking well enough to explain what happens during a TCP handshake, what common ports map to which services, and how subnets and routing shape what a scanner can see.
  • You know core security concepts — authentication versus authorisation, common attack categories, basic cryptography — at roughly Security+ level.
  • You are comfortable at a command line (both Linux and Windows), even if you still look up flags.
  • You can read simple scripts, even if you cannot yet write them fluently.

If several of those made you wince, it is usually faster overall to shore up the foundation first than to fight through PenTest+ material you cannot anchor to anything. Security+ is the natural stepping stone; our CompTIA Security+ certification guide explains what that exam covers if you need to take a step back before stepping forward.

Know exactly what you are preparing for

You do not need the exam's full biography to prepare — our CompTIA PenTest+ certification guide covers the exam itself, its cost and its positioning in depth — but four facts should shape your study plan from day one:

  1. Format. PT0-003 presents a maximum of 90 questions in 165 minutes, mixing multiple-choice questions with performance-based questions (PBQs) that simulate hands-on tasks. That is a long sitting, and the PBQs are where unprepared candidates burn time.
  2. Scoring. You need 750 on a scale of 100–900. That is a scaled score, not a percentage — you cannot translate it into "I need to get X questions right", so aim to be strong everywhere rather than gaming a margin.
  3. Cost of failure. The exam costs US $439 at retail as listed by CompTIA's authorised resellers in June 2026 (prices vary by country, and legitimate discounted vouchers exist). There is no free retake unless you bought a retake bundle: fail, and the next attempt is another full-price voucher. You can retake immediately once, but from the third attempt onward CompTIA imposes a 14-day wait. Preparing thoroughly is cheaper than re-booking.
  4. The objectives document is the syllabus. CompTIA publishes the complete PT0-003 exam objectives as a free download on comptia.org. Everything examinable is in that document. Download it before you buy anything else, and confirm the current domain list and weightings there rather than trusting third-party summaries — including old PT0-002 breakdowns still circulating online.

Delivery is through Pearson VUE, either at a test centre or online via OnVUE proctoring, so you can decide late in your preparation which environment suits you.

The three pillars of PenTest+ preparation

Every effective PenTest+ study plan rests on the same three pillars. Candidates who fail usually over-invested in one and neglected another.

Pillar 1: The objectives, translated into skills

Print the PT0-003 objectives and treat each bullet as a checklist item with three possible states: can explain it, can do it, neither. The exam's structure follows the arc of a real engagement — from planning and scoping an engagement under proper authorisation, through reconnaissance and identifying weaknesses, to exploitation and post-test analysis and reporting — so as you work through the document, keep asking where each line item sits in that arc. An objective about scope documents is testing whether you could run a legal, well-bounded engagement; an objective about a tool is testing whether you would know when to reach for it and how to read its output.

This translation step matters because PenTest+ questions are scenario-heavy. You will rarely be asked "what does this flag do?" in isolation; you are more likely to be given an engagement context and asked what a professional tester should do next.

Pillar 2: Hands-on lab practice

This is the pillar that separates PenTest+ from purely theoretical exams, and it is non-negotiable. You need an environment where you can legally attack machines. Good options include:

  • A home lab: a virtualisation setup on your own hardware running deliberately vulnerable virtual machines alongside an attack box. Even a modest machine can host a two-VM lab.
  • Hosted lab platforms: browser-based environments with guided attack paths, useful if your hardware is limited.
  • Deliberately vulnerable applications and VMs: community-maintained targets built specifically for practice.

What you practise matters more than where. Structure lab sessions around engagement phases rather than random exploitation: one session on network and service discovery, one on vulnerability identification and validation, one on gaining and expanding access, one on documenting what you did and what it means. Keep notes as if a client were paying for them — the reporting and communication side of penetration testing is a genuine part of the job and of the exam, and it is the part lab-only learners most often skip.

A hard ethical line while you practise: only ever test systems you own or have explicit written authorisation to test. That is not just exam-adjacent advice — understanding authorisation and rules of engagement is itself examinable material, and testing without permission is illegal in most jurisdictions.

Pillar 3: Practice questions as a diagnostic

Practice questions are study aids, not a shortcut — their job is to test your understanding of the objectives and expose weak areas while it is still cheap to fix them. Used well, they answer three questions reading cannot: Can you apply concepts inside a scenario? Can you hold pace for a 165-minute sitting? And which objective areas quietly never stuck?

Work them in two modes. Early on, use untimed sets in study mode, reviewing every explanation — including for questions you got right, since a correct guess is a gap wearing a disguise. Later, run full-length timed simulations under exam conditions. After each one, sort your errors by objective area and send the worst areas back to Pillars 1 and 2. What you should never do is loop the same question bank until you recognise the answers; memorised answers collapse the moment the real exam rephrases a scenario. ExamPractice offers free sample CompTIA PenTest+ practice questions, with fuller question sets and a timed practice-test simulation available to subscribers — check any question source you use against the current PT0-003 objectives, as material written for PT0-002 may not cover everything the live exam does.

A phased preparation roadmap

There is no official CompTIA figure for how long PenTest+ preparation takes, and any guide promising one is inventing it. What follows is a sequence, not a schedule — most candidates spread it over roughly two to four months depending on experience and weekly hours, but let your checklist state, not the calendar, decide when you move on.

Phase 1 — Map the ground

Download the PT0-003 objectives, build your three-state checklist, and skim your chosen primary resource end to end without trying to master anything. The goal is a mental map of the whole exam and an honest list of your weakest areas. Set up your lab environment now, while motivation is high — lab setup friction later in the plan is a common reason hands-on practice quietly disappears.

Phase 2 — Deep study, phase by phase

Work through the engagement lifecycle in order, pairing every study block with lab time in the same area. Study scoping and pre-engagement material, then draft a mock scope document for your own lab. Study reconnaissance, then enumerate your lab network and compare what you found against what you know is there. Study exploitation concepts, then attempt them against your vulnerable targets. Interleave short question sets in study mode to check retention as you go.

Two habits pay off disproportionately in this phase. First, keep a personal command-and-tool journal — your own notes on what you ran, why, and what the output meant will beat any purchased cheat sheet. Second, practise explaining findings in writing at a level a non-technical manager could follow, because clear communication of results is part of what the exam models.

Phase 3 — Integrate and simulate

Now shift from learning to rehearsal. Run full-length timed practice tests, review them by objective area, and target your remaining weak domains with focused lab-and-study loops. Revisit your checklist: anything still marked neither gets priority; anything at can explain it that the objectives frame as a hands-on task needs lab reps until it reaches can do it. Rehearse PBQ-style thinking by talking yourself through multi-step tasks in your lab without notes.

Phase 4 — Book and taper

Book the exam only when your timed simulations are consistently strong across all areas rather than carried by one or two. In the final week, stop learning new material. Re-read your own notes, re-run a light lab session to keep commands fresh, decide between test centre and OnVUE, and check in for online proctoring requirements early if you go that route.

Choosing your resources

The best resource stack for PenTest+ is small and used thoroughly, not large and skimmed. A sensible combination:

  • The official PT0-003 objectives — free, authoritative, and the spine of everything above.
  • One primary study resource — a current PT0-003-aligned book or video course. One is enough; a second primary resource mostly duplicates the first.
  • A lab environment — see Pillar 2. If budget is tight, prioritise lab access over a second course; PenTest+ rewards doing.
  • A question bank with explanations — for the diagnostic loop in Pillar 3. Explanations are the feature that matters; a bank that only marks right/wrong teaches little.
  • Your own notes — the cheapest resource and, by exam week, the most valuable.

Be sceptical of anything still marketed for PT0-002 without a PT0-003 update, and of anything promising "real exam questions" — those claims signal a vendor to avoid, not a shortcut. You can browse other security certifications' materials on the CompTIA exams hub if you are mapping what comes after this exam.

Common preparation mistakes

  • All theory, no terminal. The most common failure pattern. If more than about two-thirds of your study time is passive reading or watching, rebalance toward the lab.
  • All exploitation, no engagement discipline. The inverse failure: candidates who love the hacking and skip scoping, legal, and reporting material because it feels dry. It is examinable, and it is the part that distinguishes a professional tester from a hobbyist.
  • Studying to old domain breakdowns. PT0-002 summaries are everywhere online. Verify everything against the official PT0-003 objectives document.
  • Memorising question banks. Recognising answers is not competence, and the exam's scenario phrasing will expose the difference.
  • Booking on a deadline instead of a signal. A calendar date is not evidence of readiness; consistent timed-simulation performance across all objective areas is.
  • Ignoring the retake economics. At $439 a sitting with no free retake by default, one extra fortnight of preparation is almost always cheaper than one extra attempt.

Frequently asked questions

Is PT0-002 still available, or do I have to take PT0-003?

PT0-003 is the only live version. PT0-002 retired on 17 June 2025, so PT0-003 — launched 17 December 2024 — is the exam you will book. Study materials written for PT0-002 should be cross-checked against the PT0-003 objectives before you rely on them.

Do I need Security+ before PenTest+?

No prerequisite is enforced. CompTIA recommends knowledge equivalent to Network+ and Security+ plus three to four years of penetration-testing experience, but these are recommendations. If your fundamentals are shaky, earning Security+ first is often the faster route overall.

Can I take PenTest+ from home?

Yes. CompTIA exams are delivered through Pearson VUE, and PenTest+ can be sat either at a test centre or online via OnVUE proctoring. If you choose online delivery, run the system test early and prepare a compliant testing space.

How does renewal work after I pass?

PenTest+ is valid for three years and renews through CompTIA's continuing education (CE) programme — via qualifying activities, or by passing the latest exam version or a higher-level CompTIA certification, which renews lower certifications automatically. Check the exact CE unit requirement for PenTest+ on CompTIA's renewal pages, as it differs by certification.

Your first move

If you take one action after reading this, make it the free one: download the official PT0-003 objectives from comptia.org and turn them into your checklist. Every other decision — which course, which lab, when to book — gets easier once you can see the whole exam on paper and know honestly which parts you can already do. From there, follow the three pillars, keep your lab time sacred, and let timed practice results tell you when you are ready. And if you have covered the objectives and want a benchmark before booking, a timed run through the practice test simulation will show you which engagement phases still need another pass.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like