CompTIA A+ Certification Guide for Beginners
·10 min read
What CompTIA A+ covers, how the 220-1201 and 220-1202 exams work, and a step-by-step plan to earn the certification as a complete beginner.
Continue readingA complete CompTIA PenTest+ preparation roadmap: PT0-003 objectives, hands-on lab practice, study phases and the resources that actually move you forward.

Preparing for CompTIA PenTest+ is different from preparing for most multiple-choice certifications, because the exam is built around a job you may not yet have done professionally: running a penetration test from scoping through to the final report. Reading alone will not get you there. The candidates who pass comfortably are the ones who pair the official objectives with regular hands-on lab time, then use practice questions to find the gaps between what they can do and what the exam actually asks.
This guide gives you the full preparation roadmap: confirming you are starting from the right baseline, understanding what you are walking into, a three-pillar study method, a phased plan you can adapt to your own timeline, and the resources worth your money. It deliberately stays out of two neighbouring debates — how PenTest+ stacks up against CEH or OSCP, and whether the certification is worth it for your career — because those are separate questions from the one you are asking now: how do I prepare well?
One version note before anything else. As of 2026, the current exam is PT0-003, which launched on 17 December 2024. The previous version, PT0-002, retired on 17 June 2025 — so if you are searching for "PT0-002 prep", check any book, course or notes you already own against the PT0-003 objectives before relying on them. Older material is not worthless, but it was written for a retired exam.
A short honest audit before you spend money on a voucher. CompTIA enforces no prerequisites for PenTest+ — anyone can book it — but the recommended profile is three to four years in a penetration-testing role, with knowledge equivalent to CompTIA Network+ and Security+. Most successful self-taught candidates are not literally four-year professionals, but they do arrive with solid fundamentals.
You are in a good position to begin if you can say yes to most of these:
If several of those made you wince, it is usually faster overall to shore up the foundation first than to fight through PenTest+ material you cannot anchor to anything. Security+ is the natural stepping stone; our CompTIA Security+ certification guide explains what that exam covers if you need to take a step back before stepping forward.
You do not need the exam's full biography to prepare — our CompTIA PenTest+ certification guide covers the exam itself, its cost and its positioning in depth — but four facts should shape your study plan from day one:
Delivery is through Pearson VUE, either at a test centre or online via OnVUE proctoring, so you can decide late in your preparation which environment suits you.
Every effective PenTest+ study plan rests on the same three pillars. Candidates who fail usually over-invested in one and neglected another.
Print the PT0-003 objectives and treat each bullet as a checklist item with three possible states: can explain it, can do it, neither. The exam's structure follows the arc of a real engagement — from planning and scoping an engagement under proper authorisation, through reconnaissance and identifying weaknesses, to exploitation and post-test analysis and reporting — so as you work through the document, keep asking where each line item sits in that arc. An objective about scope documents is testing whether you could run a legal, well-bounded engagement; an objective about a tool is testing whether you would know when to reach for it and how to read its output.
This translation step matters because PenTest+ questions are scenario-heavy. You will rarely be asked "what does this flag do?" in isolation; you are more likely to be given an engagement context and asked what a professional tester should do next.
This is the pillar that separates PenTest+ from purely theoretical exams, and it is non-negotiable. You need an environment where you can legally attack machines. Good options include:
What you practise matters more than where. Structure lab sessions around engagement phases rather than random exploitation: one session on network and service discovery, one on vulnerability identification and validation, one on gaining and expanding access, one on documenting what you did and what it means. Keep notes as if a client were paying for them — the reporting and communication side of penetration testing is a genuine part of the job and of the exam, and it is the part lab-only learners most often skip.
A hard ethical line while you practise: only ever test systems you own or have explicit written authorisation to test. That is not just exam-adjacent advice — understanding authorisation and rules of engagement is itself examinable material, and testing without permission is illegal in most jurisdictions.
Practice questions are study aids, not a shortcut — their job is to test your understanding of the objectives and expose weak areas while it is still cheap to fix them. Used well, they answer three questions reading cannot: Can you apply concepts inside a scenario? Can you hold pace for a 165-minute sitting? And which objective areas quietly never stuck?
Work them in two modes. Early on, use untimed sets in study mode, reviewing every explanation — including for questions you got right, since a correct guess is a gap wearing a disguise. Later, run full-length timed simulations under exam conditions. After each one, sort your errors by objective area and send the worst areas back to Pillars 1 and 2. What you should never do is loop the same question bank until you recognise the answers; memorised answers collapse the moment the real exam rephrases a scenario. ExamPractice offers free sample CompTIA PenTest+ practice questions, with fuller question sets and a timed practice-test simulation available to subscribers — check any question source you use against the current PT0-003 objectives, as material written for PT0-002 may not cover everything the live exam does.
There is no official CompTIA figure for how long PenTest+ preparation takes, and any guide promising one is inventing it. What follows is a sequence, not a schedule — most candidates spread it over roughly two to four months depending on experience and weekly hours, but let your checklist state, not the calendar, decide when you move on.
Download the PT0-003 objectives, build your three-state checklist, and skim your chosen primary resource end to end without trying to master anything. The goal is a mental map of the whole exam and an honest list of your weakest areas. Set up your lab environment now, while motivation is high — lab setup friction later in the plan is a common reason hands-on practice quietly disappears.
Work through the engagement lifecycle in order, pairing every study block with lab time in the same area. Study scoping and pre-engagement material, then draft a mock scope document for your own lab. Study reconnaissance, then enumerate your lab network and compare what you found against what you know is there. Study exploitation concepts, then attempt them against your vulnerable targets. Interleave short question sets in study mode to check retention as you go.
Two habits pay off disproportionately in this phase. First, keep a personal command-and-tool journal — your own notes on what you ran, why, and what the output meant will beat any purchased cheat sheet. Second, practise explaining findings in writing at a level a non-technical manager could follow, because clear communication of results is part of what the exam models.
Now shift from learning to rehearsal. Run full-length timed practice tests, review them by objective area, and target your remaining weak domains with focused lab-and-study loops. Revisit your checklist: anything still marked neither gets priority; anything at can explain it that the objectives frame as a hands-on task needs lab reps until it reaches can do it. Rehearse PBQ-style thinking by talking yourself through multi-step tasks in your lab without notes.
Book the exam only when your timed simulations are consistently strong across all areas rather than carried by one or two. In the final week, stop learning new material. Re-read your own notes, re-run a light lab session to keep commands fresh, decide between test centre and OnVUE, and check in for online proctoring requirements early if you go that route.
The best resource stack for PenTest+ is small and used thoroughly, not large and skimmed. A sensible combination:
Be sceptical of anything still marketed for PT0-002 without a PT0-003 update, and of anything promising "real exam questions" — those claims signal a vendor to avoid, not a shortcut. You can browse other security certifications' materials on the CompTIA exams hub if you are mapping what comes after this exam.
PT0-003 is the only live version. PT0-002 retired on 17 June 2025, so PT0-003 — launched 17 December 2024 — is the exam you will book. Study materials written for PT0-002 should be cross-checked against the PT0-003 objectives before you rely on them.
No prerequisite is enforced. CompTIA recommends knowledge equivalent to Network+ and Security+ plus three to four years of penetration-testing experience, but these are recommendations. If your fundamentals are shaky, earning Security+ first is often the faster route overall.
Yes. CompTIA exams are delivered through Pearson VUE, and PenTest+ can be sat either at a test centre or online via OnVUE proctoring. If you choose online delivery, run the system test early and prepare a compliant testing space.
PenTest+ is valid for three years and renews through CompTIA's continuing education (CE) programme — via qualifying activities, or by passing the latest exam version or a higher-level CompTIA certification, which renews lower certifications automatically. Check the exact CE unit requirement for PenTest+ on CompTIA's renewal pages, as it differs by certification.
If you take one action after reading this, make it the free one: download the official PT0-003 objectives from comptia.org and turn them into your checklist. Every other decision — which course, which lab, when to book — gets easier once you can see the whole exam on paper and know honestly which parts you can already do. From there, follow the three pillars, keep your lab time sacred, and let timed practice results tell you when you are ready. And if you have covered the objectives and want a benchmark before booking, a timed run through the practice test simulation will show you which engagement phases still need another pass.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·10 min read
What CompTIA A+ covers, how the 220-1201 and 220-1202 exams work, and a step-by-step plan to earn the certification as a complete beginner.
Continue reading·10 min read
What CompTIA Network+ covers, how the N10-009 exam works, who should take it and a practical preparation plan — everything in one guide.
Continue reading·9 min read
What CompTIA Security+ is, the SY0-701 exam format and cost, who the certification suits, and a practical five-step route to earning and keeping it.
Continue reading