PenTest+
CompTIA PenTest+ (PT0-003) is the hands-on certification for penetration testers and vulnerability analysts — the credential that proves you can scope an engagement, find weaknesses, and exploit them legally and ethically. It leans heavily on performance-based simulations, so memorizing definitions is not enough: you have to apply real tools and techniques under a hard 165-minute clock. Because PenTest+ is approved under the DoD 8140 cyber workforce framework and often appears as a hiring or pay-bump requirement, a single failed attempt can stall a security offer. This page breaks down exactly what the exam tests, how it is delivered, and how to get it done right the first time.
Pay Only After You Pass
No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.
How CompTIA PenTest+ (PT0-003) is built — at a glance
90
Up to 90 items mixing standard multiple-choice with interactive performance-based questions, delivered linearly — PenTest+ is not computer-adaptive, so every item counts toward the same scaled score.
165
A single timed block of 2 hours 45 minutes with no scheduled breaks. PBQ simulations eat time fast, so most candidates triage them and bank the multiple-choice questions first.
750
Scored 100–900; you need a scaled 750. It is pass/fail — there is no honors or distinction tier, and you see a domain breakdown immediately after.
PenTest+ is built around hands-on PBQs: you read Nmap or scanner output, choose and sequence the right tools, complete command-line tasks, or match attack techniques to scenarios. These simulations are weighted heavily and are the reason PenTest+ is considered tougher than a pure multiple-choice exam — recall alone will not carry you.
CompTIA reports a single scaled score from 100 to 900, with 750 required to pass. Because the score is scaled, you cannot map it directly to a percentage correct — harder items and PBQs carry more weight. There is no penalty for guessing, so you should answer every question. Results appear on screen the moment you finish.
Five PT0-003 domains — bars show each domain's official weight on the exam
The largest domain: network, wireless, application, cloud, IoT, and social-engineering attacks. Choosing exploits, modifying payloads, and chaining techniques against a target.
Active and passive recon, OSINT, network and service enumeration, and the scripting and tooling used to map an attack surface before you touch it.
Running and reading vulnerability scans, validating findings, prioritizing by risk, and analyzing weaknesses across hosts, applications, and cloud assets.
Maintaining access, privilege escalation, pivoting, lateral movement, and cleaning up artifacts once a foothold is established.
Scoping, rules of engagement, legal and compliance constraints, and the reporting and communication that turn findings into a deliverable for the client.
Attacks & Exploits alone is a third of the exam, so it is where most prep time should go — but Engagement Management is where many technically strong candidates lose points, because scoping, legality, and reporting feel less exciting than exploitation. The performance-based questions can pull from any of the five domains.
Two ways to sit the exam — and what to expect on test day
You sit the exam in a quiet, monitored room at a Pearson VUE center. Staff verify two forms of ID, store your belongings in a locker, and watch the room throughout. You get an on-screen environment with the same PBQ simulations as the online version. This is the most common route for candidates who want zero connectivity risk during a 165-minute exam.
You take the exam from a private room using Pearson OnVUE remote proctoring. Before it unlocks you run a system check, photograph your ID, and complete a 360° room scan. A live proctor monitors you on webcam for the entire session. You need a reliable connection, a clear desk, and no second monitor, phone, or notes within reach.
A valid, unexpired government photo ID with a name that matches your CompTIA and Pearson VUE registration exactly. The proctor captures a photo before the exam unlocks; test centers usually require two IDs.
For OnVUE: a clear desk, no second monitor, no phone, no notes, and a full webcam scan of the room. No one else may enter, and you must stay alone for the full session.
Stay in frame and on-camera the whole time. There are no scheduled breaks. Talking aloud, looking off-screen, leaving your seat, or losing connection can pause or flag the session.
PenTest+ is built for hands-on offensive security roles
No mandatory prerequisite — but the bar is hands-on
Difficulty: PenTest+ sits at the intermediate level and is widely rated harder than Security+ because of the performance-based questions and the breadth of tooling. Candidates without real pen-testing reps tend to struggle with the PBQs and time management — exactly the pressure points our help is designed to remove.
PenTest+ is a hands-on, time-boxed exam standing between you and a security role, pay bump, or 8140 requirement. Exam Assist pairs you with a vetted penetration-testing specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: Exam Assist handles the sitting end to end, and you settle only after the verified result.
Tell us your exam version (PT0-003), delivery method (test center or OnVUE), target date, and where you are in your prep. Takes a couple of minutes over WhatsApp, Telegram, or Discord.
We review your timeline and goal and tell you plainly whether it is realistic — before any money is discussed. If it is not a fit, we say so.
Exam Assist handles the sitting end to end. You are matched with a PenTest+ specialist who maps the work around the five domains, the PBQ format, and the OnVUE environment — discreetly and confidentially.
You only pay once your passing result is confirmed. No verified pass, nothing owed.
See the full pay-after-you-pass CompTIA service, how matching works, and what the arrangement covers.
Straight answers about CompTIA PenTest+ (PT0-003)
Service, a guide, and sibling CompTIA exams
Pair with a vetted CompTIA specialist on a results-first arrangement. No upfront fee — settle only after a verified passing result.
Explore the service Get StartedShare your PT0-003 details and target date to get an honest feasibility answer before anything is owed.
Start now GuideBuild the security foundation CompTIA recommends before PenTest+ — domains, study plan, and exam-day strategy.
Read the guide CySA+The defensive counterpart to PenTest+ — threat detection, monitoring, and incident response for blue-team analysts.
View exam Security+The baseline security cert CompTIA recommends before PenTest+ — core concepts every pen tester is expected to know.
View exam CASP+ / SecurityXCompTIA's advanced security architecture and engineering credential — a natural next step after PenTest+.
View examGet expert CompTIA PenTest+ help with no upfront fee — you settle only after your verified passing result. Honest feasibility answer first, results-first arrangement always.