How to Pass the CompTIA PenTest+ PT0-003 in 2026: Format, Cost, Domains and Study Plan

What the PT0-003 tests, what it costs, why the PBQs catch people out and a seven week study plan weighted to the exam domains.

What the CompTIA PenTest+ PT0-003 is and who it is for

PenTest+ is CompTIA’s intermediate penetration testing certification. It validates that you can plan, scope and run an engagement across networks, cloud environments, web applications, IoT and hybrid environments, through the full lifecycle from planning and reconnaissance to exploitation, post exploitation and reporting. The current version is V3, exam code PT0-003.

PT0-003 launched on 17 December 2024 and replaced PT0-002, which retired on 17 June 2025. The new version added AI based attacks, more cloud and API exploitation, and newer post exploitation techniques, so material written for the old exam can miss what is tested today.

CompTIA recommends three to four years in a penetration testing role, plus Network+ and Security+ or equivalent knowledge. In practice it suits working testers who want a recognised credential, security analysts moving towards offensive work, and anyone whose employer or contract names PenTest+ as a requirement.

CompTIA PenTest+ PT0-003 at a glance

Item Detail
Exam code PT0-003
Questions Up to 90, including performance based questions
Time allowed 165 minutes
Passing score 750 on a scale of 900
Exam fee US$439 per voucher
Languages English, French, Japanese and Portuguese
Where you sit it Pearson VUE testing centres or online proctored
Certification valid for 3 years

What is on the exam

Five domains, weighted as below. More than half of the exam sits in two of them.

Engagement management (13%). The professional side of testing: scoping, rules of engagement, legal and compliance considerations, communication with the client during the test, and the structure of a final report and its findings. Small weight, but the exam expects you to know it.

Reconnaissance and enumeration (21%). Gathering information about a target, passively and actively. Open source intelligence, DNS and network discovery, service and host enumeration, and reading the output of the tools that do it. Many questions show you scan results and ask what they mean.

Vulnerability discovery and analysis (17%). Turning what you found into a prioritised list of weaknesses. Running and interpreting vulnerability scans, validating results, dealing with false positives and deciding which findings are worth exploiting.

Attacks and exploits (35%). The largest domain by a wide margin. Network, wireless, web application, cloud, API, mobile, IoT and social engineering attacks, plus the AI based attack coverage added in this version. Expect questions that show tool output or code and ask you to choose the next step.

Post exploitation and lateral movement (14%). What you do once you are in: maintaining access, escalating privileges, moving between systems, collecting evidence and cleaning up in line with the engagement scope.

Why people fail it

The performance based questions are the main reason. A PBQ hands you tool output, a script or a network scenario and asks you to interpret it and make a testing decision against the clock. The exam gives you 165 minutes for up to 90 questions, which sounds generous until you have spent ten minutes on a single simulation. Candidates who have only practised multiple choice find the PBQs slow, and the slowness costs marks elsewhere.

The second reason is that knowing the tools is not the same as knowing the exam. Working testers who use Nmap and Metasploit daily still fail, because CompTIA’s scenarios ask what the exam expects you to do next, in CompTIA’s framing, rather than what you would do at work. Learning that framing takes practice questions with explanations, not more lab time.

The third is the weighting. Attacks and exploits is 35% and reconnaissance and enumeration is 21%. Together those two domains are 56% of the exam. Equal time per domain spends most of your effort on the smaller half of the marks. And because PT0-003 is recent, older material can leave out the AI, cloud and API content this version added.

A study plan that fits the exam

Seven weeks, split by domain weight. Attacks and exploits gets two full weeks because that is where the marks are.

  1. Week 1: engagement management. Scoping, rules of engagement, legal boundaries and report structure. Try the free PenTest+ practice questions to see how CompTIA writes a scenario.
  2. Week 2: reconnaissance and enumeration. Passive and active recon, OSINT, DNS, network and service discovery. Practise reading scan output until you can describe a host from a result block without looking anything up.
  3. Week 3: reconnaissance finishes, vulnerability discovery begins. Finish enumeration in the first half of the week, then move to vulnerability scanning, validation and prioritisation.
  4. Week 4: attacks and exploits, part one. Network, wireless and web application attacks. Start the attacks section of the PT0-003 practice question pack and read the explanation for every wrong option, because that is where the CompTIA framing lives.
  5. Week 5: attacks and exploits, part two. Cloud, API, mobile, IoT, social engineering and the AI based attacks added in this version. Keep working the pack questions for this domain: at 35% it deserves the repetition.
  6. Week 6: post exploitation and lateral movement. Persistence, privilege escalation, lateral movement, evidence collection and cleanup. Then a mixed set of questions across all five domains.
  7. Week 7: timed runs. Use the questions only PDF for full sittings under the 165 minute limit. Review by domain, go back to whatever scored lowest, and stop learning new material a few days before the exam.

On exam day

You sit PT0-003 at a Pearson VUE testing centre or online with a proctor. If you test online, check the room, webcam and desk rules on the vendor page well before the day, and run the system check on the machine you will use. If you test at a centre, bring the identification your booking confirmation asks for and arrive early.

You have 165 minutes for up to 90 questions, including PBQs. Decide your pacing before you start: move through the multiple choice items steadily, flag any long PBQ if the interface lets you, and return to it with the time you have banked. The passing score is 750 on a scale of 900, and the scale is not a straight percentage, so do not try to work out your mark during the exam. Answer everything and move on.

The exam is offered in English, French, Japanese and Portuguese. Book the language you studied in.

Frequently asked questions

How long is the PT0-003 exam and how many questions does it have?

Up to 90 questions, including performance based questions, in 165 minutes. The passing score is 750 on a scale of 900 and the exam fee is US$439 per voucher.

What happens if I fail? Can I retake it?

Yes, but each attempt needs a new voucher at the full fee, currently US$439. CompTIA publishes its retake policy on its website, including any waiting period between attempts, so check the current rules before you rebook. The practice pack is refunded if you fail, but the voucher is not, so treat your first attempt as the one that counts and do your timed practice before it.

Is the practice question pack enough on its own?

No. It is 344 practice questions, MCQs and PBQs, with an explanation for every answer and every wrong option, mapped to the PT0-003 objectives. That makes it a good test of what you know and a good way to learn CompTIA’s framing, but it is not a course and it does not replace hands on tool experience or a study guide for the underlying material. Use it to find gaps and to rehearse the question formats, alongside whatever you use to learn the content.

When you are ready to practise, get the 344 question PT0-003 pack for US$39, pass or your money back.