CompTIA · PT0-003
CompTIA PenTest+ validates the skills required to plan, scope, and execute penetration testing engagements across network, web, cloud, and AI environments. It covers the full pentest lifecycle from reconnaissance and exploitation through post-exploitation, reporting, and communication of findings.
Practice Questions
699
≈ 7 practice exams
Duration
165 minutes
Passing Score
750/900
Difficulty
ProfessionalLast Updated
Mar 2026
PT0-003 weights Attacks and Exploits heaviest by a wide margin at 35 percent of the exam, followed by Reconnaissance and Enumeration at 21 percent, Vulnerability Discovery and Analysis at 17 percent, Post-exploitation and Lateral Movement at 14 percent, and Engagement Management at 13 percent. This practice bank of 699 questions is built to match that split, so exploitation and post-exploitation scenarios, over a third of the real exam, get matching depth.
On test day you face a maximum of 90 questions in 165 minutes, mixing multiple-choice with performance-based questions, and you need a scaled 750 on a 100 to 900 scale to pass. PT0-003 (V3) launched December 17, 2024, replacing the previous version with more emphasis on real exploitation technique over pure methodology recall. The performance-based questions simulate hands-on pentest tasks, so timed practice matters as much as knowing the terminology.
CompTIA recommends 3 to 4 years of experience in a penetration tester role, with Network+ and Security+ level knowledge as a foundation, though there is no formal prerequisite. CompTIA raised prices across its exam lineup around June 2026; check the official CompTIA store for the current voucher price before buying. The certification is valid for 3 years, renewed with 60 CEUs, CertMaster CE training, or retaking the current exam. Start with the 30 free questions to benchmark yourself, then work through the full 699-question bank until your accuracy holds steady across all five domains.
CompTIA PenTest+ (PT0-003) is a professional-level certification that validates the skills required to plan, scope, and execute penetration testing engagements across diverse environments including networks, web applications, cloud platforms, and AI systems. The certification demonstrates expertise across the full penetration testing lifecycle, from initial reconnaissance and vulnerability discovery through active exploitation, post-exploitation techniques, lateral movement, and comprehensive reporting. The PT0-003 version, launched December 17, 2024, represents the latest iteration of this credential and emphasizes modern attack surfaces and contemporary threat landscapes.
CompTIA PenTest+ is designed for security professionals with 3–4 years of hands-on experience in penetration testing or offensive security roles. Ideal candidates include penetration testers, ethical hackers, security analysts, vulnerability assessment specialists, and security consultants seeking to validate and advance their offensive security expertise. The certification is particularly valuable for professionals working in organizations requiring demonstrated competency in identifying and exploiting system vulnerabilities, as well as those pursuing careers in red team operations, bug bounty programs, or managed security services.
CompTIA recommends that candidates possess a minimum of 3–4 years of practical experience in a penetration testing role. Additionally, candidates should hold CompTIA Network+ and Security+ certifications or demonstrate equivalent knowledge in networking fundamentals, security concepts, and system administration. While formal prerequisites are not strictly enforced, candidates without this background may find the exam challenging, as it assumes proficiency with networking protocols, cryptography, operating systems, and security frameworks. Hands-on experience with penetration testing tools, vulnerability assessment platforms, and exploitation techniques is essential preparation.
The PT0-003 exam consists of a maximum of 90 questions combining multiple-choice and performance-based question types. The exam duration is 165 minutes (2 hours and 45 minutes), allowing approximately 1.8 minutes per question on average. The exam is delivered online through Pearson VUE testing centers worldwide and is available in English, French, Japanese, and Portuguese. Scoring is on a scale of 100–900, with a passing score of 750. The exam includes unscored pretest questions used for item analysis and future exam development. The previous version (PT0-002) retires on June 17, 2025, with PT0-003 estimated to remain current until approximately 2027.
Holding the CompTIA PenTest+ certification significantly enhances career prospects in the cybersecurity field. Penetration testers with this credential command competitive salaries, with median annual earnings around $110,540–$131,970 in the United States, representing 75–175% above the median national wage. The credential is increasingly featured in job postings across the industry and validates expertise required for roles such as Penetration Tester, Security Analyst, Red Team Specialist, and Vulnerability Assessment Specialist. The Bureau of Labor Statistics projects 32% growth in information security analyst positions through 2032, while the U.S. penetration testing market is expected to triple by 2028, indicating strong demand for certified professionals. PenTest+ has gained rapid adoption among employers and is recognized as a credible validation of offensive security skills, particularly in organizations requiring demonstrated competency in vulnerability identification and remediation. The certification positions holders for advancement into senior security roles, management positions, and specialized careers in bug bounty programs and managed security services.
5 sample questions with answers and explanations. The full bank has 699 questions, enough for 7 full-length practice exams.
Preview — answers shown1. A penetration tester at Litware needs to enumerate valid email addresses on a target mail server. Which SMTP commands can be used for this purpose? (Select three!)
Multiple correct answersExplanation
VRFY verifies if a specific username exists on the system and returns a confirmation or rejection. EXPN expands mailing lists to reveal member email addresses. RCPT TO can confirm valid recipient addresses based on server responses during a simulated message transaction. EHLO and HELO are used for initial SMTP session identification, while DATA begins the message body transmission phase. Modern servers often restrict VRFY and EXPN to prevent enumeration, but RCPT TO responses can still be used for user enumeration.
2. You need to perform DNS reconnaissance on adatum.com to identify mail servers, nameservers, and IPv6 addresses. Which DNS record types should you query? (Select three!)
Multiple correct answersExplanation
MX records identify mail servers, NS records identify authoritative nameservers, and AAAA records contain IPv6 addresses. PTR records are used for reverse DNS lookups, CNAME records are aliases, and A records contain IPv4 addresses — none of these match the three requested record types.
3. During a penetration test of Tailspin Toys' Linux infrastructure, you discover a web application vulnerable to command injection. Which of the following metacharacters would allow you to chain commands for exploitation? (Select three!)
Multiple correct answersExplanation
The semicolon (;) executes commands sequentially regardless of whether the preceding command succeeds or fails, making it ideal for command injection. The double ampersand (&&) executes the second command only if the first command exits successfully, useful when conditional execution is acceptable. The pipe (|) redirects the standard output of the first command as input to the second command and executes both regardless of exit status. The percent sign (%) is used for environment variable expansion in Windows CMD but is not a standard command chaining metacharacter in Linux shells. The hash (#) begins comments in shell scripts, causing everything after it to be ignored and preventing further command execution. The at sign (@) is not a standard command chaining metacharacter in Linux.
4. You are enumerating Contoso's mail server on port 25 and want to verify whether specific email addresses exist before launching a phishing campaign. Which SMTP commands can be used for user enumeration? (Select two!)
Multiple correct answersExplanation
VRFY (verify) confirms whether a specific email address or username exists on the server. EXPN (expand) reveals the members of a mailing list, which can expose valid usernames. HELO is a greeting command, while RCPT TO and MAIL FROM are standard email transaction commands not designed for direct user enumeration.
5. A tester is analyzing different denial of service attacks for a red team engagement. Which attack maintains connections by sending partial HTTP requests slowly to exhaust server resources? (Select one!)
Explanation
Slowloris is an application-layer denial of service attack that sends legitimate HTTP requests but very slowly, keeping connections open by periodically sending partial request headers. This exhausts the web server's connection pool as it waits for complete requests that never arrive, preventing legitimate users from establishing new connections. SYN flood attacks exploit the TCP three-way handshake by sending SYN packets without completing the handshake, operating at the transport layer. UDP amplification attacks use protocols with amplification factors to overwhelm targets with response traffic. Smurf attacks use ICMP echo requests with spoofed source addresses to create broadcast storms.
A maximum of 90 questions in 165 minutes, mixing multiple-choice with performance-based questions.
A scaled 750 on a 100 to 900 scale.
CompTIA does not publish exam pricing directly on its certification page; check the official CompTIA store or a Pearson VUE checkout for the current price before buying, since CompTIA raised prices across its lineup around June 2026.
Attacks and Exploits (35%), Reconnaissance and Enumeration (21%), Vulnerability Discovery and Analysis (17%), Post-exploitation and Lateral Movement (14%), and Engagement Management (13%).
None formal. CompTIA recommends 3 to 4 years of experience in a penetration tester role, with Network+ and Security+ level knowledge.
December 17, 2024 (version 3 of the exam), with more emphasis on hands-on exploitation technique than the prior version.
Yes, after 3 years. Renew with 60 CEUs, CertMaster CE training, or by retaking the current exam.
CompTIA does not publish an official pass rate. The performance-based questions simulating hands-on pentest tasks are usually what trips up candidates who’ve only studied methodology, not practiced technique.
CompTIA DataSys+ (DS0-001)
DS0-001 · 700 questions
CompTIA Linux+ (XK0-006)
XK0-006 · 699 questions
CompTIA Network+ (N10-009)
N10-009 · 699 questions
CompTIA Project+ (PK0-005)
PK0-005 · 696 questions
CompTIA SecAI+ Certification (CY0-001)
CY0-001 · 600 questions
CompTIA Security+ (SY0-701)
SY0-701 · 700 questions
$17.99
One-time access to this exam