CompTIA · PT0-003 (V3)

CompTIA PenTest+

PenTest+

CompTIA PenTest+ (PT0-003) is the hands-on certification for penetration testers and vulnerability analysts — the credential that proves you can scope an engagement, find weaknesses, and exploit them legally and ethically. It leans heavily on performance-based simulations, so memorizing definitions is not enough: you have to apply real tools and techniques under a hard 165-minute clock. Because PenTest+ is approved under the DoD 8140 cyber workforce framework and often appears as a hiring or pay-bump requirement, a single failed attempt can stall a security offer. This page breaks down exactly what the exam tests, how it is delivered, and how to get it done right the first time.

165 minutes
Up to 90 Questions
750 to pass (100–900)
Center or Online (OnVUE)

Pay Only After You Pass

No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.

Exam Spec Sheet

Provider CompTIA
Exam code PT0-003 (V3)
Format Multiple-choice + performance-based
Duration 165 minutes
Questions Up to 90
Scoring 100–900 · 750 to pass
Fee ~$425 USD
Proctoring Pearson VUE / OnVUE
Validity 3 years (renew via CE)
Languages English, French, Japanese, Portuguese
See PenTest+ Help Options

EXAM FORMAT

How CompTIA PenTest+ (PT0-003) is built — at a glance

90

Questions (max)

Up to 90 items mixing standard multiple-choice with interactive performance-based questions, delivered linearly — PenTest+ is not computer-adaptive, so every item counts toward the same scaled score.

165

Minutes

A single timed block of 2 hours 45 minutes with no scheduled breaks. PBQ simulations eat time fast, so most candidates triage them and bank the multiple-choice questions first.

750

Passing Score

Scored 100–900; you need a scaled 750. It is pass/fail — there is no honors or distinction tier, and you see a domain breakdown immediately after.

Performance-based questions (PBQs)

PenTest+ is built around hands-on PBQs: you read Nmap or scanner output, choose and sequence the right tools, complete command-line tasks, or match attack techniques to scenarios. These simulations are weighted heavily and are the reason PenTest+ is considered tougher than a pure multiple-choice exam — recall alone will not carry you.

How scoring works

CompTIA reports a single scaled score from 100 to 900, with 750 required to pass. Because the score is scaled, you cannot map it directly to a percentage correct — harder items and PBQs carry more weight. There is no penalty for guessing, so you should answer every question. Results appear on screen the moment you finish.

WHAT'S TESTED

Five PT0-003 domains — bars show each domain's official weight on the exam

4

Attacks & Exploits

35%

The largest domain: network, wireless, application, cloud, IoT, and social-engineering attacks. Choosing exploits, modifying payloads, and chaining techniques against a target.

2

Reconnaissance & Enumeration

21%

Active and passive recon, OSINT, network and service enumeration, and the scripting and tooling used to map an attack surface before you touch it.

3

Vulnerability Discovery & Analysis

17%

Running and reading vulnerability scans, validating findings, prioritizing by risk, and analyzing weaknesses across hosts, applications, and cloud assets.

5

Post-exploitation & Lateral Movement

14%

Maintaining access, privilege escalation, pivoting, lateral movement, and cleaning up artifacts once a foothold is established.

1

Engagement Management

13%

Scoping, rules of engagement, legal and compliance constraints, and the reporting and communication that turn findings into a deliverable for the client.

Attacks & Exploits alone is a third of the exam, so it is where most prep time should go — but Engagement Management is where many technically strong candidates lose points, because scoping, legality, and reporting feel less exciting than exploitation. The performance-based questions can pull from any of the five domains.

DELIVERY & PROCTORING

Two ways to sit the exam — and what to expect on test day

At a Pearson VUE test center

You sit the exam in a quiet, monitored room at a Pearson VUE center. Staff verify two forms of ID, store your belongings in a locker, and watch the room throughout. You get an on-screen environment with the same PBQ simulations as the online version. This is the most common route for candidates who want zero connectivity risk during a 165-minute exam.

Online, proctored via Pearson OnVUE

You take the exam from a private room using Pearson OnVUE remote proctoring. Before it unlocks you run a system check, photograph your ID, and complete a 360° room scan. A live proctor monitors you on webcam for the entire session. You need a reliable connection, a clear desk, and no second monitor, phone, or notes within reach.

ID & identity check

A valid, unexpired government photo ID with a name that matches your CompTIA and Pearson VUE registration exactly. The proctor captures a photo before the exam unlocks; test centers usually require two IDs.

Environment scan

For OnVUE: a clear desk, no second monitor, no phone, no notes, and a full webcam scan of the room. No one else may enter, and you must stay alone for the full session.

During the exam

Stay in frame and on-camera the whole time. There are no scheduled breaks. Talking aloud, looking off-screen, leaving your seat, or losing connection can pause or flag the session.

WHO SHOULD TAKE THIS

PenTest+ is built for hands-on offensive security roles

  • Penetration testers and red-team members
  • Vulnerability analysts and security assessors
  • SOC analysts moving from defense into offense
  • DoD 8140 cyber-workforce personnel needing an approved cert
  • Security+ or CySA+ holders building an offensive specialization

PREREQUISITES & DIFFICULTY

No mandatory prerequisite — but the bar is hands-on

  • No required prerequisite — open to anyone who registers
  • CompTIA recommends Network+, Security+, and 3–4 years of hands-on security experience
  • Comfort with the Linux command line, scripting, and common tools (Nmap, Metasploit, Burp Suite)
  • Working knowledge of networking, web apps, and cloud attack surfaces

Difficulty: PenTest+ sits at the intermediate level and is widely rated harder than Security+ because of the performance-based questions and the breadth of tooling. Candidates without real pen-testing reps tend to struggle with the PBQs and time management — exactly the pressure points our help is designed to remove.

HOW EXAM ASSIST HELPS YOU PASS PENTEST+

PenTest+ is a hands-on, time-boxed exam standing between you and a security role, pay bump, or 8140 requirement. Exam Assist pairs you with a vetted penetration-testing specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: Exam Assist handles the sitting end to end, and you settle only after the verified result.

1

Share your exam details

Tell us your exam version (PT0-003), delivery method (test center or OnVUE), target date, and where you are in your prep. Takes a couple of minutes over WhatsApp, Telegram, or Discord.

2

Get an honest feasibility answer

We review your timeline and goal and tell you plainly whether it is realistic — before any money is discussed. If it is not a fit, we say so.

3

The sitting is handled

Exam Assist handles the sitting end to end. You are matched with a PenTest+ specialist who maps the work around the five domains, the PBQ format, and the OnVUE environment — discreetly and confidentially.

4

Settle after the verified result

You only pay once your passing result is confirmed. No verified pass, nothing owed.

Ready to lock in your PenTest+ pass?

See the full pay-after-you-pass CompTIA service, how matching works, and what the arrangement covers.

Explore the CompTIA Service

FREQUENTLY ASKED

Straight answers about CompTIA PenTest+ (PT0-003)

What score do you need to pass CompTIA PenTest+ (PT0-003)? +
PenTest+ is scored on a scaled 100–900 range, and you need 750 to pass. Unlike a percentage grade, the scaled score weights harder questions and the performance-based simulations more heavily, so there is no single fixed percentage of correct answers that guarantees a pass. You get a pass or fail result and a domain-by-domain breakdown immediately after the exam.
What is the difference between PT0-002 and PT0-003? +
PT0-003 is the current version of CompTIA PenTest+, launched in December 2024; the older PT0-002 retired in June 2025. PT0-003 reorganizes the content into five domains — Engagement Management, Reconnaissance and Enumeration, Vulnerability Discovery and Analysis, Attacks and Exploits, and Post-exploitation and Lateral Movement — with more emphasis on modern tooling, scripting, and cloud, IoT, and web-application attack surfaces. If you register today you take PT0-003.
Can I take CompTIA PenTest+ online from home? +
Yes. CompTIA delivers PenTest+ both at Pearson VUE test centers and as an online, remotely proctored exam through Pearson OnVUE. The online option requires a private room, a webcam, a stable internet connection, a clear workspace, and a government-ID check plus a room scan before the exam unlocks. A live proctor monitors you for the full 165 minutes.
How many questions are on the PenTest+ exam and what types are they? +
PenTest+ PT0-003 has a maximum of 90 questions delivered in 165 minutes. It mixes standard multiple-choice questions with performance-based questions (PBQs) — interactive simulations where you analyze scan output, sequence an attack, or work in a command-line-style environment. The PBQs are the part most candidates underestimate, because they test hands-on application rather than memorized definitions.
How long is CompTIA PenTest+ valid and how do I renew it? +
PenTest+ is valid for three years from the date you pass. You renew it through CompTIA's Continuing Education (CE) program by earning 60 continuing education units within that three-year cycle — through training, higher-level CompTIA certifications, industry activities, or qualifying work experience — and paying the annual CE fee.
Do I pay Exam Assist before or after I see my PenTest+ result? +
You settle only after your verified passing result is confirmed. There is no upfront fee — you share your exam details, receive an honest feasibility answer, and decide before any money changes hands. We advertise a guaranteed pass with money back if you do not pass; we offer a transparent, results-first arrangement.
EXAM HELP SERVICE PenTest+ Exam Help: Pay After You Pass We handle the sitting end to end. Pass guaranteed — settle only after the result posts. View Service

KEEP EXPLORING

Service, a guide, and sibling CompTIA exams

YOUR PENTEST+ PASS, HANDLED

Get expert CompTIA PenTest+ help with no upfront fee — you settle only after your verified passing result. Honest feasibility answer first, results-first arrangement always.

OR CHAT WITH US