Skip to content
CompTIA Security+ and PenTest+

CompTIA PenTest+ PT0-003 study guide: objectives and how to prepare

A PenTest+ PT0-003 study guide: the five official domains and weights, what each covers, a 12-week plan weighted to the exam, and lab exercises.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 8 min read

PenTest+ PT0-003 has five domains, and one of them, Attacks and Exploits, carries 35% of the weight on its own. A good study plan follows those weights, spends real time in a lab, and treats the reporting and engagement-management material as seriously as the hacking, because the exam does.

This guide sets out the official objectives, what each domain actually asks of you, and a 12-week plan built around them. Every exam fact here comes from CompTIA’s PenTest+ page and the official exam objectives document; download the objectives yourself before you start, because they are the syllabus.

PT0-003 at a glance

Item Detail (per CompTIA)
Exam code PT0-003
Questions Maximum of 90, multiple-choice and performance-based
Length 165 minutes
Passing score 750 on a scale of 100–900
Recommended experience 3–4 years in a penetration tester job role, with Network+ and Security+ or equivalent knowledge
Launched 17 December 2024 (PT0-002 retired 17 June 2025)

“Recommended” is not “required”: you can sit the exam without that experience. But read it as a signal. This exam assumes you’ve done the work, not just read about it. Check CompTIA’s exam page for the current price.

The five PT0-003 domains and weights

Domain Weight What it really tests
1.0 Engagement Management 13% Scoping, rules of engagement, legal paperwork, frameworks, reporting and remediation advice
2.0 Reconnaissance and Enumeration 21% OSINT, scanning, enumeration, modifying scripts, choosing recon tools
3.0 Vulnerability Discovery and Analysis 17% Scan types, interpreting results, false positives, physical security
4.0 Attacks and Exploits 35% Network, authentication, host, web, cloud, wireless, social engineering, specialised systems, scripting
5.0 Post-exploitation and Lateral Movement 14% Persistence, pivoting and lateral movement, staging and exfiltration, cleanup

If you studied for the older PT0-002, notice the restructure: reporting is now folded into Engagement Management, and the tools and code analysis material is spread across the domains where you’d actually use it.

What each domain covers, and how to study it

Domain 1: Engagement Management (13%)

The objectives cover pre-engagement activities (scope, rules of engagement, agreement types such as NDA, MSA and SoW, authorisation letters, shared responsibility in cloud), collaboration and communication, testing frameworks, report components and remediation recommendations.

The frameworks list is specific, so learn what each one is for: OSSTMM, CREST, PTES, MITRE ATT&CK, OWASP Top 10, OWASP MASVS, the Purdue model, and the threat-modelling frameworks DREAD, STRIDE and OCTAVE. Expect scenario questions like “the client wants X, which framework fits?”

How to study it: write a one-page rules of engagement for a fictional client, “Acme Fintech”, including scope (IP ranges, domains, exclusions), testing window and escalation contacts. Then write a report finding with an executive summary, technical detail and remediation. Learn to score findings with CVSS from FIRST, since risk scoring appears in both Domain 1 and Domain 4.

Domain 2: Reconnaissance and Enumeration (21%)

Active and passive recon, OSINT (social media, job boards, code repositories, DNS, certificate transparency logs), enumeration of hosts, services, shares, users, directories and secrets, and modifying Bash, Python and PowerShell scripts. The named tools include Nmap with NSE, theHarvester, Amass, Recon-ng, Maltego, Shodan, Censys, WHOIS, dig and Wireshark.

How to study it: practise enumeration until you can read output quickly. For example, in your lab:

$ nmap -p 445 --script smb-enum-shares 10.10.20.20
Nmap scan report for 10.10.20.20
Host is up (0.00052s latency).

PORT    STATE SERVICE
445/tcp open  microsoft-ds

Host script results:
| smb-enum-shares:
|   account_used: guest
|   \\10.10.20.20\IPC$:
|     Type: STYPE_IPC_HIDDEN
|     Comment: IPC Service (Samba 4.15.13-Ubuntu)
|     Anonymous access: READ/WRITE
|   \\10.10.20.20\finance:
|     Type: STYPE_DISKTREE
|     Comment: Finance team share
|     Path: C:\srv\finance
|_    Anonymous access: READ

The exam-style question is never “what command lists shares?” alone. It’s “given this output, what’s the most significant finding and what do you do next?” Here: a finance share readable without credentials, so you’d document it and enumerate its contents within scope.

For scripting, you won’t write programs from scratch, but you must read a short script, spot what it does and fix or adapt it: loops, conditionals, string handling, and libraries.

Legal note: only test systems you own or have written permission to test. All examples here are from our own lab.

Domain 3: Vulnerability Discovery and Analysis (17%)

Scan types (authenticated vs unauthenticated, network, host, container, application: SAST, DAST, IAST, SCA), secrets scanning, wireless and ICS considerations, interpreting results (true and false positives, false negatives, scan completeness), choosing public exploits, and physical security concepts such as tailgating, badge cloning and USB drops. Named tools include Nessus, OpenVAS, Nikto, Trivy, Grype, TruffleHog, BloodHound and kube-hunter.

How to study it: run one scanner against a lab target, then manually confirm three findings and disprove one. That habit of validating rather than pasting scanner output is exactly what this domain tests.

Domain 4: Attacks and Exploits (35%)

The heavyweight. Ten objectives:

  1. Prioritising and preparing attacks (CVSS, CVE, CWE, EPSS, attack paths)
  2. Network attacks (default credentials, on-path, relay, VLAN hopping, packet crafting)
  3. Authentication attacks (pass-the-hash and pass-the-ticket, Kerberos attacks, password spraying, credential stuffing, MFA fatigue, SAML and OIDC attacks)
  4. Host-based attacks (privilege escalation, credential dumping, shell and kiosk escape, process injection)
  5. Web application attacks (SQL and command injection, XSS, SSRF, CSRF, IDOR, file inclusion, deserialisation, JWT manipulation, API abuse)
  6. Cloud attacks (metadata service, IAM misconfigurations, exposed storage, container escape, supply chain)
  7. Wireless attacks (evil twin, deauthentication, WPS PIN attacks)
  8. Social engineering (phishing, vishing, smishing, impersonation, credential harvesting)
  9. Specialised systems (mobile, OT, Bluetooth, NFC, RFID, and AI attacks such as prompt injection and model manipulation)
  10. Scripting to automate attacks, plus breach-and-attack simulation tools such as Caldera and Atomic Red Team

How to study it: you cannot cover all of this in depth, so prioritise by what you can practise. Web attacks map neatly onto PortSwigger’s free Web Security Academy and the OWASP Top 10. For directory discovery and IDOR, a lab session looks like:

$ gobuster dir -u http://10.10.20.15 -w /usr/share/wordlists/dirb/common.txt -q
/admin                (Status: 301) [Size: 312] [--> http://10.10.20.15/admin/]
/backup               (Status: 403) [Size: 277]
/index.php            (Status: 200) [Size: 4120]
/robots.txt           (Status: 200) [Size: 46]

For authentication attacks, practise offline password cracking on hashes from your own lab, for example NTLM hashes with hashcat -m 1000 hashes.txt wordlist.txt, and understand why spraying one password across many accounts avoids lockouts that brute force triggers.

For the tool-heavy objectives, build a table: tool, what it does, which objective it belongs to, one example command. The exam expects you to pick the right tool for a scenario, not recite its flags.

Domain 5: Post-exploitation and Lateral Movement (14%)

Persistence (scheduled tasks, cron, services, registry keys, new accounts, C2 frameworks), lateral movement (pivoting, relays, SMB, RDP, WinRM, WMI, SSH, tools such as Impacket, CrackMapExec, sshuttle and Proxychains), staging and exfiltration (covert channels over DNS, ICMP or HTTPS, steganography, cloud storage), and cleanup: removing persistence, tester-created accounts and tools, and reverting changes.

How to study it: map each technique to the MITRE ATT&CK lateral movement tactic and its neighbours, and for each one note how a defender would spot it. Don’t skip cleanup: questions about restoring a client environment are easy marks if you’ve thought about them, and a professional obligation either way.

A 12-week PT0-003 study plan

This assumes about ten hours a week and a working knowledge of networking and Security+-level concepts. If you don’t have that yet, start with our Security+ SY0-701 study guide.

Week Focus Output by end of week
1 Read the objectives; build the lab (attacker VM plus 2–3 targets on an isolated network) Lab running; objectives checklist printed
2 Domain 1: scoping, RoE, agreements, frameworks One-page RoE for “Acme Fintech”
3–4 Domain 2: OSINT, Nmap and NSE, enumeration, script reading Enumeration notes for every lab host
5 Domain 3: scanning, validation, physical security Scan results with false positives identified
6–9 Domain 4: web (2 weeks), network and authentication (1 week), host, cloud, wireless, social engineering and specialised systems (1 week) Exploited lab targets with evidence; tool table complete
10 Domain 5: persistence, pivoting, exfiltration concepts, cleanup One full attack chain documented end to end
11 Reporting and remediation (back to Domain 1); full report on one lab target A professional report
12 Timed practice, PBQ drills, weak-area review Ready to book

Notice that Domain 4 gets four weeks, close to its 35% share. Performance-based questions deserve their own preparation, which we cover in PenTest+ PT0-003 PBQs and practice.

Common questions candidates ask online

If you’ve read forum threads about PT0-003, you’ll have seen the same questions come up repeatedly. Straight answers:

  • “Can I pass without real pentesting experience?” People do, but the exam assumes practical familiarity. Lab hours are the substitute for job experience, and there’s no shortcut around them.
  • “Is PT0-003 harder than PT0-002?” It’s broader. Cloud, AI, specialised systems and modern authentication attacks feature more explicitly. Compare the two objectives documents yourself rather than relying on anyone’s impression.
  • “Do I need to memorise tool flags?” Mostly you need to know what a tool is for and recognise its output. Knowing the common Nmap options well is still worth it.
  • “Should I use dump sites?” No. CompTIA’s objectives document states that candidates who use unauthorised “brain dump” material can have certifications revoked. They also leave you unable to do the job.

How PenTest+ fits your career

PenTest+ is an exam-based certification that shows broad knowledge of the penetration testing process, including the parts beginners neglect such as scoping and reporting. It doesn’t replace hands-on skill, and no certification guarantees a job. Paired with lab work and a solid report you can show, it’s a credible signal. For the full career picture, see how to become a penetration tester from scratch.

Questions

How many questions are on PenTest+ PT0-003?

A maximum of 90, a mix of multiple-choice and performance-based questions, in 165 minutes, according to [CompTIA](https://www.comptia.org/en-us/certifications/pentest/).

What is the passing score for PT0-003?

750 on a scale of 100–900, per CompTIA's exam page.

Which PT0-003 domain is the biggest?

Attacks and Exploits, at 35%. Reconnaissance and Enumeration is next at 21%.

How long should I study for PenTest+?

It depends on your starting point. With Security+-level knowledge and about ten hours a week, the 12-week plan above is realistic for many people; with less background, allow longer.

Do I need Security+ before PenTest+?

It isn't a formal prerequisite. CompTIA recommends Network+ and Security+ or equivalent knowledge, and the exam assumes it.