CompTIA PenTest+
CompTIA
Complete guide to passing the CompTIA PenTest+ exam on your first attempt.
$392
~65%
3 years
Global
CompTIA
$80k-$125k
Are you ready for CompTIA PenTest+?
Loading quiz...
Complete Overview
CompTIA PenTest+ is a vendor-neutral penetration testing certification that tests whether you can scope an engagement legally, find and validate vulnerabilities, exploit them across networks, hosts, web applications, and cloud, and write the findings up so someone can act on them. It is aimed at penetration testers and security consultants with roughly three to four years in the role, and the voucher is bought through the CompTIA store rather than from a published price list, so confirm the current figure at checkout before budgeting.
The current version is V3, exam code PT0-003, which launched on 17 December 2024. The previous version, PT0-002, retired on 17 June 2025. CompTIA retires exam versions roughly three years after launch, which puts the estimated retirement of PT0-003 in 2027. The exam is a maximum of 90 questions in 165 minutes, mixing multiple-choice with performance-based questions, and you need 750 on a scale of 100 to 900 to pass.
The PT0-003 blueprint has five domains. Attacks and exploits is the heaviest at 35 percent, followed by reconnaissance and enumeration at 21 percent, vulnerability discovery and analysis at 17 percent, post-exploitation and lateral movement at 14 percent, and engagement management at 13 percent. That last domain is where legal authorization, rules of engagement, stakeholder communication, and report writing live, and it is routinely the domain that technical candidates lose points on.
V3 broadened the attack surface the exam covers. Cloud-based attacks now include container escapes, metadata service attacks, and IAM misconfiguration. There is an explicit objective on AI attacks covering prompt injection and model manipulation. Script modification appears under reconnaissance, which means you are expected to read and adjust Python, PowerShell, and Bash rather than only recognize what a script does. The tooling named in CompTIA's own objectives summary includes Nmap, Wireshark, Shodan, Nessus, Nikto, and OpenVAS.
CompTIA recommends Network+ and Security+ or equivalent knowledge plus three to four years in a penetration tester job role. None of that is enforced. Anyone can buy a voucher and sit the exam. Languages available are English, French, Japanese, and Portuguese.
PenTest+ is valid for three years and renews through the CompTIA Continuing Education program, which requires 60 CEUs for PenTest+ V3 or a single qualifying activity such as passing a higher-level CompTIA exam. If you renew by uploading CEUs, CompTIA charges a $150 CE fee across the three-year period. The certification is frequently taken as a structured precursor to fully hands-on offensive certifications, because it covers methodology, scoping, and reporting that purely practical exams assume you already know.
Why Get CompTIA PenTest+ Certified?
Attacks and exploits carries 35 percent of the PT0-003 blueprint, 14 points clear of the next heaviest domain. Passing evidences breadth across network, authentication, host, web application, and cloud attack techniques rather than one specialism.
Engagement management is 13 percent of the exam in its own right: authorization letters, rules of engagement, mandatory reporting, escalation paths, peer review, and report structure. That is the contractual half of consultancy work, tested directly.
The salary band associated with PenTest+ holders runs $80k to $125k, above the CySA+ band and reflecting the consulting and contract structure of most offensive security work.
V3 added cloud-based attacks covering container escapes, metadata service attacks, and IAM misconfiguration, plus an AI attacks objective covering prompt injection and model manipulation. Those are the two attack surfaces clients are asking about that older certifications do not test.
Earning PenTest+ automatically renews eligible lower-level CompTIA certifications, so a single exam covers three years of renewal on Security+ and Network+ as well.
The performance-based questions require working with tool output, command syntax, and scenario-driven testing decisions rather than recognizing tool names.
Renewal requires 60 CEUs across three years with a $150 CE fee, or a single qualifying activity such as earning a higher CompTIA certification, which waives the fee entirely.
Exam Format & Structure
Duration
165 minutes
Questions
Maximum of 90 questions
Passing Score
750 on a scale of 100 to 900
Question Types
- Multiple-choice questions
- Performance-based questions requiring work with tool output, command syntax, and scenario-driven testing decisions
Delivery Method
Computer-based at a Pearson VUE test centre or online through Pearson OnVUE remote proctoring. CompTIA charges the same voucher price for both.
Exam Domains & Topics
Everything that surrounds the technical work: defining rules of engagement and testing windows, securing authorization letters, meeting mandatory reporting and regulatory obligations, working with stakeholders through peer review and escalation paths, and producing a report with an executive summary, findings, and remediation recommendations. Small in weight, decisive in whether a real engagement survives legal review.
Key Topics to Master:
- Planning and scoping, including target selection and testing windows
- Rules of engagement and what falls outside authorized scope
- Authorization letters, permission to test, and third-party approvals
- Legal and ethical compliance and mandatory reporting obligations
- Stakeholder alignment, peer review, and escalation paths
- Articulating risk to non-technical audiences
- Report structure: executive summary, findings, evidence, and remediation recommendations
- Client acceptance, retesting, and engagement closure
Gathering information before and during an engagement, both passively through open-source intelligence and actively through scanning and enumeration. This domain also carries the script modification objective, which expects you to adjust Python, PowerShell, and Bash rather than only recognize what a script does when you read it.
Key Topics to Master:
- Passive reconnaissance and open-source intelligence collection
- Active reconnaissance, network sniffing, and protocol scanning
- DNS enumeration, service discovery, and directory enumeration
- Nmap scan types, timing options, and output formats
- Wireshark traffic analysis for reconnaissance purposes
- Shodan and other internet-wide scan data sources
- Modifying Python, PowerShell, and Bash scripts for reconnaissance tasks
- Enumerating cloud assets and exposed services
Running the right kind of scan, then doing the harder part: validating what comes back. Covers authenticated and unauthenticated scanning, static and dynamic application security testing, troubleshooting scanner configuration, and separating a genuine finding from a false positive before it reaches a client report.
Key Topics to Master:
- Authenticated versus unauthenticated vulnerability scanning
- Static application security testing and dynamic application security testing
- Nessus, Nikto, and OpenVAS configuration and output
- Validating findings and manually confirming exploitability
- Identifying and eliminating false positives
- Troubleshooting scan configuration and coverage gaps
- Prioritizing findings for the engagement report
- Scanning constraints in production and regulated environments
The largest domain by a wide margin. Covers network attacks, authentication attacks, host-based attacks, web application attacks, cloud-based attacks, and a new objective on attacks against AI systems. Expect scenario questions that hand you a foothold and ask which technique moves you forward, not which technique is theoretically strongest.
Key Topics to Master:
- Network attacks including VLAN hopping, on-path attacks, and service exploitation
- Authentication attacks including brute force, pass-the-hash, and credential stuffing
- Host-based attacks including privilege escalation, process injection, and credential dumping
- Web application attacks including SQL injection, cross-site scripting, and directory traversal
- Cloud-based attacks including container escapes, metadata service attacks, and IAM misconfiguration
- AI attacks including prompt injection and model manipulation
- Wireless and physical attack vectors
- Social engineering techniques within an authorized scope
- Selecting the appropriate tool for each attack class
What happens after the first shell. Covers establishing persistence, moving laterally through an environment, cleaning up artefacts so the client is not left with tester-created exposure, and documenting the attack narrative that ties the individual findings into a story a defender can act on.
Key Topics to Master:
- Establishing and maintaining persistence
- Lateral movement techniques across Windows and Linux estates
- Pivoting, tunnelling, and port forwarding
- Credential reuse and privilege escalation chains
- Artefact cleanup and returning systems to their pre-test state
- Building an attack narrative from discrete findings
- Evidence capture and screenshotting for the report
- Remediation recommendations tied to each stage of the chain
Recommended Study Plan
- 1Download the PT0-003 exam objectives from the CompTIA PenTest+ page and build a tracker with one row per objective
- 2Sit one full-length practice exam cold to identify which of the five domains is weakest
- 3Build a lab: Kali Linux plus a deliberately vulnerable target set such as Metasploitable and a Windows domain controller
- 4Buy the voucher only once you have a target date, since a CompTIA voucher expires 12 months after issue and cannot be extended
- 5Read CompTIA's objectives summary for engagement management so you know that 13 percent of the exam is not technical
- 1Write a mock rules of engagement document with testing windows, target list, and out-of-scope assets
- 2Draft an authorization letter and list every party whose approval a cloud-hosted target would need
- 3Study mandatory reporting obligations and where a tester must stop and escalate
- 4Write a one-page executive summary from a sample finding, then the technical section for the same finding
- 5Review the PTES and OWASP Testing Guide methodology structures against CompTIA's engagement management objectives
- 1Run a full OSINT pass on a domain you own using WHOIS, certificate transparency logs, and Shodan
- 2Practise DNS enumeration including zone transfer attempts, subdomain brute forcing, and reverse lookups
- 3Document what each passive technique reveals and what it costs in detectability
- 4Capture and read traffic in Wireshark, identifying protocols and hosts without filters first
- 5Build a target profile document in the format you would attach to a report
- 1Drill Nmap until you can write the command for SYN scan, version detection, OS detection, UDP scan, and script scan from memory
- 2Compare Nmap timing templates against detection likelihood and note which you would use in a stealth engagement
- 3Enumerate SMB, SNMP, LDAP, and web directories against lab targets and record the artefacts each produces
- 4Modify a Python and a Bash reconnaissance script to change output format and target range
- 5Take a Reconnaissance and Enumeration domain quiz and rework everything missed
- 1Run Nessus Essentials and OpenVAS against the same lab target and compare which findings each reports
- 2Run Nikto against a web target and manually verify three findings before accepting them
- 3Practise separating false positives from real findings and write the justification you would give a client
- 4Study the difference between SAST and DAST and where each belongs in a testing programme
- 5Build a findings table with severity, evidence, and remediation for five validated issues
- 1Practise on-path attacks, VLAN hopping concepts, and service exploitation in an isolated lab
- 2Run password attacks with Hydra and Hashcat and learn where each fits
- 3Practise pass-the-hash and credential stuffing scenarios against a lab Windows environment
- 4Study Kerberos attack paths including Kerberoasting and AS-REP roasting
- 5Work through Hack The Box Academy modules covering Active Directory enumeration and attack
- 1Complete the PortSwigger Web Security Academy labs on SQL injection, XSS, and path traversal
- 2Practise using Burp Suite Community for request interception, repeater, and intruder workflows
- 3Study authentication and session management flaws and how to demonstrate them safely
- 4Map each web attack you practise to the corresponding OWASP Testing Guide section
- 5Write up one web finding fully, with reproduction steps and remediation advice
- 1Study container escape techniques and the misconfigurations that permit them
- 2Practise cloud instance metadata service abuse in a lab or study the documented attack paths in detail
- 3Review IAM misconfiguration patterns: over-permissive roles, wildcard policies, and privilege escalation chains
- 4Cover the AI attacks objective specifically: prompt injection and model manipulation
- 5Take an Attacks and Exploits domain quiz, since this domain alone is 35 percent of the exam
- 1Practise privilege escalation on both Linux and Windows targets using enumeration scripts and manual checks
- 2Set up pivoting and port forwarding through a compromised host in your lab
- 3Practise persistence techniques and then practise removing every artefact you created
- 4Write an attack narrative that chains reconnaissance through to domain compromise in one readable page
- 5Study process injection and credential dumping detection so you can explain the defensive side
- 1Write a complete mock penetration test report with executive summary, methodology, findings, and remediation
- 2Do every performance-based question in CertMaster Practice at least twice
- 3Practise command syntax recall without autocomplete, since the exam gives you no shell
- 4Rehearse the digital whiteboard, which replaces scratch paper on the online exam
- 5Rework the engagement management objectives, which technical candidates consistently underprepare
- 1Sit two timed 165-minute practice exams on separate days with no interruptions
- 2Track pace against the 90-item maximum, which allows under two minutes per question
- 3Trace every missed item back to a specific PT0-003 objective and restudy that objective only
- 4Run the OnVUE system test if testing online and confirm your connection clears CompTIA's 6 Mbps download and 2 Mbps upload minimum
- 5Confirm both forms of ID match the name on your CompTIA account exactly
- 1Reread the full PT0-003 objectives document and confirm you can explain every bullet in one sentence
- 2Review the five domain weights and spend remaining time proportionally, with the most on Attacks and Exploits
- 3Rebuild your Nmap, Hydra, and Hashcat command cheat sheet from memory, then check it
- 4Sleep properly the two nights before rather than cramming, since the exam rewards pattern recognition under time pressure
- 5Sit the exam and take the preliminary result screen note mentally, since photographing it is prohibited
Ready to pass CompTIA PenTest+?
Get 500+ practice questions, video walkthroughs, and a pass guarantee.
Best Study Resources
CompTIA PenTest+ (PT0-003) exam objectives
Official blueprintThe authoritative objective list with the five domain weights. Every question you practise should map back to a line in this document, especially in engagement management where third-party material is thin.
Free
CompTIA CertMaster Perform
Official eLearning with labsCompTIA's most complete PenTest+ product, combining instruction with labs in both simulated and live virtual machine environments. CompTIA estimates 30 to 60 hours to complete.
Paid, often bundled with a voucher
CompTIA CertMaster Practice
Official practice engineTimed practice exams, objective quizzes, and per-objective mastery scoring, estimated at 10 to 20 hours. The mastery scores tell you which of the five domains still needs work.
Paid, often bundled
CompTIA PenTest+ Study Guide (Sybex)
BookMike Chapple and David Seidl's exam guide, the most widely used third-party text for PenTest+. Confirm you have the PT0-003 edition, since the PT0-002 edition lacks the cloud and AI attack content.
Around $50 print
PortSwigger Web Security Academy
Free interactive labsThe best free resource for the web application attacks portion of Domain 4, with working labs for SQL injection, cross-site scripting, path traversal, and authentication flaws. Built by the Burp Suite team.
Free
Hack The Box Academy
Hands-on training platformGuided modules on enumeration, Active Directory attack paths, privilege escalation, and pivoting. Closer to the exam's post-exploitation and lateral movement domain than any book.
Free tier plus paid modules
TryHackMe offensive pathways
Hands-on training platformBrowser-based rooms covering reconnaissance, exploitation, and privilege escalation with guided walkthroughs. Useful early when you need structure more than difficulty.
Free tier plus paid subscription
Metasploit Unleashed
Free courseOffensive Security's free Metasploit training covering module structure, payload selection, and post-exploitation. Directly relevant to the attacks and exploits and post-exploitation domains.
Free
Nmap reference guide
Official documentationNmap is named explicitly in CompTIA's reconnaissance tooling objective, and the exam expects flag-level knowledge. Reading the reference guide beats memorizing a cheat sheet you did not build.
Free
OWASP Web Security Testing Guide
Free methodology referenceThe structured web testing methodology CompTIA references in its objectives. Use it to organize your web application practice into a repeatable process rather than a list of tricks.
Free
Common Mistakes to Avoid
Studying PT0-002 material for a PT0-003 exam. The older version retired on 17 June 2025 and does not cover container escapes, cloud metadata service attacks, IAM misconfiguration, or the AI attacks objective covering prompt injection and model manipulation.
Check the edition of every book and course against the PT0-003 code before buying. If a resource does not mention cloud attacks or AI attacks in its table of contents, it predates the current blueprint.
Skipping engagement management because it feels like paperwork. It is 13 percent of the exam, roughly a dozen questions, and it covers authorization letters, mandatory reporting, escalation, and report structure that most self-taught testers have never had to produce.
Write an actual rules of engagement document and an actual mock report. The questions are scenario framed and reward someone who has thought about who signs what and who gets told when a critical finding appears mid-engagement.
Preparing as though PenTest+ were a practical hands-on exam. It is not a machine-compromise exam. It is 165 minutes of multiple-choice and performance-based questions, so unlimited lab time without command-level recall leaves you slow on syntax questions.
Keep the lab work, but add recall drills. Write out Nmap, Hydra, Hashcat, and Metasploit command syntax from memory on paper, then verify. The exam gives you no shell, no autocomplete, and no man pages.
Treating the script modification objective as read-only. CompTIA's objective says modification, and questions can show you a Python, PowerShell, or Bash script and ask which line to change to alter behaviour.
Take three short reconnaissance scripts in each language and change the target range, the output format, and the error handling. You need to recognize loop structure, variable assignment, and argument parsing under time pressure, not write code from scratch.
Underweighting cloud attacks because your lab is on-premises. Cloud-based attacks are named explicitly within the 35 percent attacks and exploits domain, and container escapes plus metadata service abuse plus IAM misconfiguration is a lot of distinct content.
Use a free tier cloud account or a purpose-built vulnerable cloud lab to practise the documented attack paths. If you cannot run them, at minimum study the mechanics of instance metadata abuse and wildcard IAM policy escalation until you can explain each one out loud.
Choosing the theoretically most powerful attack rather than the appropriate one. PenTest+ questions embed scope, authorization, and stakeholder constraints, so the strongest technique is often the wrong answer because it falls outside the rules of engagement.
Read every scenario for scope boundaries before reading the options. If the scenario mentions a testing window, an out-of-scope system, or a production constraint, that detail is there to eliminate answers.
Ignoring artefact cleanup. Post-exploitation and lateral movement is 14 percent, and CompTIA names cleaning up artefacts as an explicit activity alongside persistence and lateral movement.
In every lab session, log what you created and remove it before you finish. Build the habit, then learn the exam answers about which artefacts a tester is obliged to remove and which must be documented instead.
Booking the retake immediately without checking the waiting rule. CompTIA requires no wait between the first and second attempt, but at least 14 calendar days before the third attempt and every attempt after that.
If you fail the first attempt, retake within two to three weeks while the material is fresh. Budget a full-price voucher, because CompTIA offers no free retests or retake discounts, or buy a bundle with Retake Assurance before your first attempt.
Assuming PenTest+ alone qualifies you for a senior offensive role. CompTIA recommends three to four years in a penetration tester job role as the target audience, and the certification validates methodology rather than proving you can compromise an unfamiliar network unaided.
Pair the certification with a public evidence trail: a lab writeup portfolio, a CTF record, or a documented mock engagement report. Hiring managers for offensive roles read the report you wrote before they read the certificate.
Exam Day Tips
- 1
Bring two forms of valid original identification, with the first and last name on both matching your CompTIA account exactly. Photocopies and digital IDs are refused at check-in.
- 2
Check-in opens 30 minutes before the appointment, and CompTIA turns you away if you are more than 15 minutes late.
- 3
No command reference sheets, no Nmap flag cheat sheet, no notes. The workspace must be completely clear, so anything you have not memorized by check-in is gone for the next 165 minutes.
- 4
Use the built-in digital whiteboard for working through subnet ranges, port lists, and attack chains. There is no physical scratch paper, so practise with the whiteboard before exam day.
- 5
Run the OnVUE system test days ahead if you test online. CompTIA requires at least 6 Mbps download and 2 Mbps upload, one display only with any second monitor disconnected, and a private network rather than a corporate connection or VPN.
- 6
Expect a room scan before you start. Clear desk, closed door, walled room, nobody else present, no second monitor connected, and your phone and any drink beyond arm's reach, since CompTIA bars food and beverages from the testing space.
- 7
Pace against 90 questions in 165 minutes, which is under two minutes each. Flag performance-based questions that stall and bank the multiple-choice points first.
- 8
Read every scenario for scope and authorization language before reading the answer options. On PenTest+ specifically, the constraint sentence is usually what eliminates two of the four choices.
- 9
Do not photograph or screenshot any part of the exam, including the score screen. CompTIA treats this as a violation that can invalidate the score and revoke the certification.
- 10
Raise technical problems through the Contact Proctor option while the exam is running. Proctors will not answer content questions, and CompTIA states they cannot pause the exam, add time, or repair your equipment.
Career Paths & Salary Ranges
Penetration tester
Executes scoped engagements against networks, applications, and cloud environments, then writes the findings up. The role the exam is built around, and CompTIA names it directly as the target job role for PT0-003.
Lower to middle of the $80k-$125k PenTest+ band
Security consultant
Runs client-facing assessments where scoping, communication, and report quality matter as much as exploitation. The 13 percent engagement management domain maps directly onto this work.
Middle to upper part of the $80k-$125k PenTest+ band
Red team operator
Runs longer adversary emulation engagements focused on persistence, lateral movement, and evading detection. The post-exploitation and lateral movement domain is the foundation, though most red team hiring expects further specialist credentials.
Upper part of the $80k-$125k PenTest+ band
Application security engineer
Tests and fixes web applications and APIs, working with development teams on secure design. Builds on the web application attacks objectives plus the SAST and DAST content in vulnerability discovery.
Middle to upper part of the $80k-$125k PenTest+ band
Vulnerability analyst
Runs and validates scanning programmes, separates real findings from false positives, and drives remediation. The vulnerability discovery and analysis domain covers this directly and it is a common entry point into offensive work.
Lower to middle of the $80k-$125k PenTest+ band
Cloud security engineer
Assesses and hardens cloud estates against the attack paths the exam covers: container escapes, metadata service abuse, and IAM misconfiguration. The V3 cloud additions make PenTest+ more relevant to this path than earlier versions were.
Upper part of the $80k-$125k PenTest+ band
Prerequisites & Requirements
- No enforced prerequisites. CompTIA lets anyone buy a PenTest+ voucher and sit the exam without proving prior certification or experience.
- CompTIA recommends CompTIA Network+ and CompTIA Security+ or equivalent knowledge before attempting the exam.
- CompTIA recommends three to four years of experience in a penetration tester job role.
- Practical comfort with a Linux command line, scripting in at least one of Python, PowerShell, or Bash, and reading raw tool output matters more than any prior certificate, because the performance-based questions assume all three.
- An isolated lab environment is effectively required for preparation, since roughly half the blueprint covers techniques you cannot legally practise on systems you do not own or have written authorization to test.
Frequently Asked Questions
How much does the CompTIA PenTest+ exam cost?
CompTIA sells the PenTest+ voucher through its own store and shows the price at checkout rather than on the exam page, so confirm the current figure there before budgeting. For comparison, CompTIA published $425 as the United States retail price for the CySA+ V4 voucher, which sits at the same level in the CompTIA cybersecurity pathway. There is no price difference between test centre and online delivery. Bundles combining a voucher with CertMaster Perform, Learn, or Practice reduce the total against buying separately, and actively registered students at four-year United States institutions can verify through SheerID for 35 to 55 percent off store products.
What happens if I fail the PenTest+ exam?
You can retake it immediately, because CompTIA requires no waiting period between the first and second attempt. Before the third attempt and any subsequent attempt, you must wait at least 14 calendar days from the date of your last attempt. Every attempt requires a full-price voucher, since CompTIA offers no free retests or retake discounts. Your score report shows results by domain, which is worth using: a fail driven by engagement management needs completely different remediation than a fail driven by attacks and exploits.
What is the passing score for PenTest+ and how is it calculated?
You need 750 on a scale of 100 to 900. The scale is not a percentage, so 750 does not correspond to 83 percent correct. CompTIA does not publish how many raw items you need or how many points a performance-based question carries relative to a multiple-choice item. The practical consequence is that you cannot calculate a safety margin, so target consistent scores comfortably above passing on official practice tests instead of trying to estimate the cut point.
How long does it take to get PenTest+ results?
Immediately. A preliminary pass or fail appears on screen the moment you finish, whether you test at a Pearson VUE centre or online. If you pass, the score report directs you to log in to your CompTIA account to request the wallet ID card and official certificate, and your digital badge becomes available from there. You are not permitted to photograph or screenshot the results screen.
What identification do I need on exam day?
Two forms of valid identification. The first and last name used to register for the exam must match the first and last name on both IDs, and both must be originals rather than photocopies. Candidates aged 17 and under present a single form of ID, for which a school ID is acceptable, and need guardian authorization for each testing event with the guardian present at check-in showing their own government-issued ID.
Can I use a calculator, notes, or a command reference during the exam?
No. Your workspace must be completely clear of books, paper, pens, and notes, and no second monitor or additional computer may be connected. Online candidates get a built-in digital whiteboard for scratch work in place of paper. This matters more on PenTest+ than on most exams because command syntax questions reward recall you cannot look up during the 165 minutes.
How does online proctoring work for PenTest+?
Online delivery runs through Pearson OnVUE. Download the software in advance, run a system test, and check in through a process that photographs you and your workspace and requires a room scan you must pass before starting. You must be alone in a walled room with a closed door for the whole session. A proctor monitors by camera and issues warnings if your eyes wander from the screen. You may chat with the proctor about technical difficulties but not about exam content, and any technical issue must be raised while the exam is running.
Are accommodations available for PenTest+?
Yes, on a case-by-case basis. CompTIA directs candidates to request accommodations from Pearson VUE, and accommodations for online proctored exams are assessed individually. CompTIA also notes that for online exams, time accommodations can be handled by closing the browser to stop the clock and resuming when ready, provided you remain within the allotted window and the exam time has not been fully consumed.
How long is PenTest+ valid and how do I renew it?
Three years from the date you pass. Renewal runs through the CompTIA Continuing Education program. PenTest+ V3 requires 60 CEUs across the three-year cycle if you renew by uploading activities, and CompTIA charges a $150 CE fee for that route across the three-year period, payable using CE tokens sold at $25 and $50. Alternatively you can renew with a single qualifying activity such as completing CompTIA CertMaster CE, earning a higher-level CompTIA certification, earning a qualifying non-CompTIA industry certification, or passing the latest release of the PenTest+ exam. The single-activity routes that involve a higher CompTIA certification waive the CE fee.
Does PenTest+ renew my Security+?
Yes, where PenTest+ sits above it in the CompTIA cybersecurity pathway. Earning a higher-level CompTIA certification automatically renews eligible lower-level ones, and you only pay CE fees for your highest-level certification. CompTIA does flag one exception: the fee waiver does not apply when the higher-level certification does not fully renew the lower-level one, so check your certification dashboard rather than assuming.
How does PenTest+ compare to CySA+?
PenTest+ is offensive and CySA+ is defensive. PenTest+ covers scoping, reconnaissance, exploitation, post-exploitation, and reporting on a penetration test; CySA+ covers detection, vulnerability management, incident response, and reporting inside a SOC. Both sit at the same intermediate level in CompTIA's pathway, both recommend Network+ and Security+ first, both run 165 minutes, both pass at 750 on a 100 to 900 scale, and both are valid three years with 60 CEUs to renew. PenTest+ allows a maximum of 90 questions against CySA+ at a maximum of 85.
How does PenTest+ compare to more practical offensive certifications?
PenTest+ tests methodology through multiple-choice and performance-based questions in a 165-minute proctored session, while fully practical offensive exams require compromising live machines over many hours and submitting a report. The trade-off is coverage against depth: PenTest+ covers scoping, legal authorization, reporting, cloud, and AI attack surfaces that hands-on exams often assume, while a practical exam proves you can actually break into an unfamiliar network. Many candidates take PenTest+ first for the methodology and reporting structure, then move to a practical exam.
Which exam version should I take and when does the current one retire?
Take PT0-003, which launched on 17 December 2024 and is the only version currently available. The previous version, PT0-002, retired on 17 June 2025. CompTIA retires exam versions roughly three years after launch and gives an estimated 2027 retirement for PT0-003, so anyone studying now should be working from PT0-003 material and should watch CompTIA's certification page for a confirmed retirement date before booking far ahead.
How long is a CompTIA exam voucher valid?
Twelve months from the date you receive it, and CompTIA states the expiration date cannot be extended under any circumstances. A voucher may be used for any version of the certification exam provided you sit it before expiry. You must reschedule an appointment at least 24 hours before the scheduled time, and if you bought a bundle with Retake Assurance, the retake only activates after you have taken and not passed the exam.
Can I retake PenTest+ after passing it, to refresh the certification?
Not under the same exam code. CompTIA's retake policy prevents you from retaking an exam you have already passed using the same code without prior consent, so you would wait for a new series. This is why passing the latest release of your CompTIA exam counts as a renewal activity: when a successor to PT0-003 appears, existing holders can sit it to renew. A test found to violate the retake policy is invalidated and the candidate may be suspended, with repeat violators permanently banned from the program.
How much study time does PenTest+ need?
CompTIA's own product duration estimates give the clearest anchor: CertMaster Perform at 30 to 60 hours, CertMaster Learn at 25 to 40 hours, CertMaster Practice at 10 to 20 hours, and CertMaster Labs at 15 to 25 hours. Those assume a candidate near the recommended three to four years of penetration testing experience. Without that background, plan on considerably more, and weight the extra time towards hands-on lab work in the attacks and exploits domain, which is 35 percent of the exam on its own.
Do I need my own lab to prepare for PenTest+?
Effectively yes. Roughly half the blueprint covers techniques that are illegal to practise against systems you do not own or have written authorization to test, so you need an isolated environment. A workable setup is Kali Linux plus deliberately vulnerable targets, a small Windows domain for Active Directory attack paths, and either free-tier cloud resources or a purpose-built vulnerable cloud lab for the container, metadata service, and IAM objectives. Platforms such as Hack The Box Academy, TryHackMe, and PortSwigger's Web Security Academy provide legal targets without you building everything yourself.
Pass CompTIA PenTest+, Guaranteed
94% pass rate on first attempt
One-time • Lifetime access