PT0-003 · ● Active · Associate · CompTIA
CompTIA's mid-level offensive security certification. Launched December 17, 2024; PT0-002 retired June 17, 2025. PT0-003 emphasizes cloud exploitation, API security, AI/ML attack surface, and modern post-exploitation techniques alongside foundational penetration testing methodology.
Exam facts
| Field | Value |
|---|---|
| Cost | USD $404 (exam voucher; regional pricing varies) |
| Duration | 165 minutes |
| Questions | 90 maximum (mix of multiple-choice + performance-based; not all scored) |
| Passing | 750 on a scale of 100–900 |
| Format | Multiple choice + Performance-Based Questions (PBQs); simulated penetration testing environments |
| Delivery | Pearson VUE (in-person testing centers) and OnVUE (proctored online) |
| Languages | English |
| Valid | 3 years |
| Renewal | 60 continuing education units (CEUs) via approved activities, or retake exam; cost ~USD $100–$200 |
| Prerequisites | CompTIA Security+ assumed knowledge; 3–4 years hands-on penetration testing/security testing experience recommended |
| Released | December 17, 2024 |
| Retiring | N/A (PT0-002 retired June 17, 2025) |
Vendor source — CompTIA PenTest+ Certification ↗
Official exam guide — PT0-003 Exam Objectives ↗
DoD Approval — DoD 8140 Approved; aligns with NICE Framework
About
CompTIA PenTest+ is an intermediate offensive security certification focused on structured penetration testing methodology within legal, contractual scope boundaries. Unlike entry-level certs (Security+), PenTest+ requires demonstrated hands-on exploitation, privilege escalation, lateral movement, and professional reporting. The December 2024 refresh (PT0-003) added explicit coverage of cloud-native attacks (AWS/Azure/GCP IAM misconfig, serverless), API security testing (REST/GraphQL, authentication bypass), and AI/ML attack surface (adversarial inputs, prompt injection)—reflecting 2024–2026 attacker evolution. Typical candidate: SOC analyst moving into active testing, IT security professional seeking credible offensive credential, or junior red team operator.
Domain context — Security & Cybersecurity
Offensive security testing at the Associate level—positioned between foundational defensive certifications (Security+) and advanced practical credentials (OSCP, OSEP). PenTest+ validates hands-on ability to discover and exploit vulnerabilities under contract and rules of engagement.
Read full deep dive — Security Domain →
Topics covered
PT0-003 Exam Blueprint — 5 domains with weighted distribution:
- Domain 1: Engagement Management (13%) — Planning, scoping, rules of engagement (ROE), legal/regulatory compliance (NDA, contract terms), report writing, stakeholder communication
- Domain 2: Reconnaissance & Enumeration (21%) — Passive OSINT (search engines, DNS, WHOIS, certificate transparency logs), active scanning (Nmap, Masscan), vulnerability discovery, enumeration tools (Shodan, DNS enumeration, network mapping)
- Domain 3: Vulnerability Discovery & Analysis (17%) — Manual vulnerability testing, automated scanners (Nessus, Qualys, OpenVAS, Burp Suite), vulnerability classification, prioritization, assessment methodology
- Domain 4: Attacks & Exploits (35%) — Exploitation frameworks (Metasploit), payload delivery, cloud exploitation (AWS, Azure, GCP IAM misconfiguration), API testing (REST/GraphQL fuzzing, authentication bypass), AI/ML attack techniques (adversarial inputs, prompt injection), privilege escalation (Windows, Linux), lateral movement
- Domain 5: Post-Exploitation & Lateral Movement (14%) — Persistence mechanisms, Windows/Linux privilege escalation, credential harvesting, data exfiltration, covering tracks, lateral movement techniques (pass-the-hash, credential spraying)
Source: CompTIA PenTest+ Exam Objectives ↗
Common skills at Security · Associate
Shared content for the Security domain at Associate level — not specific to this cert.
- SIEM & Log Analysis — Splunk, ELK, Microsoft Sentinel; parsing security logs, alert triage, timeline reconstruction
- Threat Hunting — Proactive detection, MITRE ATT&CK framework, indicator of compromise (IOC) correlation, behavioral analysis
- Vulnerability Management — Scanning, prioritization, remediation tracking, metrics and reporting
- Incident Response — First response, containment, eradication, recovery, post-incident review
- MITRE ATT&CK & TTPs — Adversary tactics, techniques, procedures; threat actor profiling, defensive mapping
- Active Directory Security — Domain structure, trust relationships, Kerberos weaknesses, privilege escalation vectors
Recommended courses at Security · Associate
| Provider | Title | Cost | URL |
|---|---|---|---|
| Udemy (Jason Dion) | CompTIA PenTest+ (PT0-003) Full Course & Practice Exam | USD $15–$60 | ↗ |
| Udemy (Jason Dion) | CompTIA PenTest+ (PT0-003) 6 Practice Exams | USD $15–$60 | ↗ |
| Dion Training Direct | CompTIA PenTest+ (PT0-003) Complete Course, Labs, & Practice Exams | USD $299–$599 | ↗ |
| CBT Nuggets | CompTIA PenTest+ (PT0-003) | USD $30–$50/mo | ↗ |
| Pluralsight | CompTIA PenTest+ (PT0-003) Path | USD $30/mo or $299/yr | ↗ |
| Coursera (Packt) | CompTIA PenTest+ (PT0-003) by Packt | Free audit / USD $49–$99 paid | ↗ |
| TryHackMe | CompTIA PenTest+ Learning Path | Free (limited) / USD $20/mo | ↗ |
| HackTheBox Academy | Penetration Testing Labs + Structured Paths | Free (limited) / Premium | ↗ |
Course-selection rule: Each course above is specifically for PT0-003 (not generic pentesting). Jason Dion Udemy courses are the most widely recommended for affordability + depth. Hands-on labs (TryHackMe, HackTheBox) are essential alongside lectures.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| CertMaster (Official CompTIA) | CertMaster Practice for PenTest+ PT0-003 | USD $99–$149 | ↗ |
| CertMaster (Official CompTIA) | CertMaster Perform (Live Lab Simulations) | USD $149–$199 | ↗ |
| MeasureUp | PT0-003 Practice Test (221 questions) | USD $89–$199 | ↗ |
| MeasureUp | PT0-003 CertKit (Full Study Bundle) | USD $179–$299 | ↗ |
| Jason Dion (Udemy) | CompTIA PenTest+ (PT0-003) 6 Practice Exams | USD $15–$60 | ↗ |
| ExamTopics | PT0-003 Q&A Community | Free to read / paid to submit | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| Pearson CompTIA PenTest+ Cert Guide (PT0-003) | Omar Santos | Pearson IT Certification | 2025 (forthcoming) | TBD | ↗ |
| CompTIA PenTest+ Study Guide (PT0-002) | Dr. Mike Chapple, David Seidl | Sybex / John Wiley & Sons | 2021 | 978-1119823810 | ↗ |
| The Web Application Hacker's Handbook (2nd Edition) | Dafydd Stuttard, Marcus Pinto | Wiley | 2011 | 978-1118026472 | ↗ |
Book rule: Pearson PT0-003 edition is forthcoming (as of May 2026); the PT0-002 study guides overlap 70–80% of content. The Web Application Hacker's Handbook is essential reference for web app pentesting but not exam-specific.
Typical job titles at Security · Associate
Junior Penetration Tester · Vulnerability Assessment Analyst · Red Team Apprentice · Cybersecurity Analyst (Offensive) · Security Consultant (Entry)
(Job titles drawn from current job-board postings listing PenTest+ as required or preferred; roles typically require 1–3 years prior IT/security experience.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $107K–$191K (25th–75th percentile; avg $142K for Junior Pentester) | Glassdoor (2026) ↗ · ZipRecruiter ↗ · PayScale ↗ |
| ZAR | R450K–R900K (estimated; limited public data — consult local recruiters) | Pnet · PayScale ZA · CareerJunction |
| GBP | £30K–£55K (entry to mid-level; London higher) | IT Jobs Watch · Hays |
| EUR | €40K–€65K (DE/FR/NL average) | Glassdoor EU · LinkedIn Salary |
| AUD | A$85K–A$140K | Glassdoor AU · PayScale AU |
Salary rule: PT0-003 holders with 0–2 years experience typically earn entry-level rates above; mid-level (3–5 years) $115K–$160K; senior $145K+. Regional variation and specialization (cloud, web app, red team) significantly impact compensation.
Skills validated
Cert-specific — what PT0-003 actually tests, distinct from "Common skills" above.
Reconnaissance & Information Gathering
- Passive OSINT (search engines, DNS lookups, WHOIS, certificate transparency logs, social media harvesting)
- Active enumeration (Nmap, Masscan, port scanning, service fingerprinting)
- Network mapping, asset discovery, subdomain enumeration
- DNS reconnaissance, DNS zone transfer attempts
Vulnerability Discovery & Assessment
- Manual vulnerability testing (authentication bypass, authorization flaws)
- Automated scanners (Nessus, Qualys, OpenVAS, Burp Suite Community/Pro)
- Vulnerability classification (CVSS scoring, severity prioritization)
- Vulnerability life-cycle management, remediation tracking
Exploitation Frameworks & Techniques
- Metasploit Framework — module selection, payload generation, multi-handler setup
- Burp Suite — intruder, repeater, scanner, proxy configuration
- Custom exploitation scripts (Python, Bash)
- Payload encoding, obfuscation, evasion tactics
Privilege Escalation (Windows & Linux)
- Windows: UAC bypass, token impersonation, DLL injection, kernel exploits, service misconfiguration
- Linux: SUID binary exploits, kernel vulnerabilities, sudo misconfig, capability abuse
Post-Exploitation & Lateral Movement
- Credential harvesting (mimikatz, plaintext searches, credential manager)
- Lateral movement (pass-the-hash, pass-the-ticket, credential spraying)
- Persistence (registry persistence, scheduled tasks, service creation, backdoors)
- Data exfiltration (stealth techniques, compression, encoding)
Advanced Techniques (PT0-003 focus)
- Cloud Exploitation: AWS S3 enumeration, IAM policy analysis, EC2 metadata bypass, Lambda code injection; Azure managed identities, Key Vault leakage; GCP service account compromise
- API Testing: REST/GraphQL fuzzing, authentication/authorization bypass, rate limit evasion, API key leakage, XML external entity (XXE) injection
- AI/ML Attack Surface: Adversarial input injection, prompt injection against LLMs, model evasion, training data poisoning concepts
Tooling Proficiency
- Scanning: Nmap, Masscan, Shodan queries, theHarvester, Recon-ng
- Exploitation: Metasploit, Burp Suite, custom Python/Bash scripts
- Post-Exploitation: Mimikatz, linpeas, BloodHound, Empire, Cobalt Strike (red-team environments)
- Credential Cracking: Hashcat, John the Ripper
- Network: Wireshark, netcat, tcpdump
Reporting & Communication
- Written penetration test reports (executive summary, technical findings, risk rating, remediation recommendations)
- Stakeholder communication (explaining technical findings to non-technical clients)
- Legal/regulatory context (NDA, ROE scope, liability, compliance frameworks: PCI-DSS, HIPAA, GDPR, NIST)
Related certifications
- Replaces: PT0-002 (officially retired June 17, 2025)
- Stacks with: CompTIA Security+ SY0-701 ↗ (foundational prerequisite)
- Prerequisite for: OSCP, OSEP (OffSec pathway); GPEN (SANS pathway)
- Equivalents at Associate level: eJPT (eLearnSecurity Junior Penetration Tester) ↗ · CEH (EC-Council Certified Ethical Hacker, entry level) ↗
- Advanced alternatives: OSCP (Offensive Security Certified Professional) ↗ · GPEN (GIAC Penetration Tester) ↗ · OSEP (Offensive Security Web Expert) ↗
- Vendor overview: CompTIA Vendor Overview →
- Role roadmap: Penetration Tester / Red Team Operator →
Sources
- CompTIA PenTest+ Certification Official Page
- CompTIA PenTest+ PT0-003 Exam Objectives
- Glassdoor Junior Penetration Tester Salary 2026
- ZipRecruiter Penetration Tester Salary
- Udemy — Jason Dion PenTest+ PT0-003 Course
- Dion Training Solutions PenTest+ PT0-003
- CompTIA CertMaster Practice PT0-003
- MeasureUp PT0-003 Practice Test
- Coursera Packt PenTest+ Course
- TryHackMe PenTest+ Learning Path
- HackTheBox Academy
Last verified: 2026-05-01
Parent ecosystem: Offensive Security →
Parent domain: Security & Cybersecurity →
Vendor overview: CompTIA →
Role roadmap: Penetration Tester / Red Team →
Exam preparation summary
Timeline: 12–16 weeks (assuming 10–15 hrs/week study)
Phase 1 (Weeks 1–2): Foundation
- Read full PT0-003 exam blueprint
- Review Security+ knowledge (if gaps exist)
- Set up lab environment (VirtualBox, Kali Linux, Windows target)
Phase 2 (Weeks 3–6): Core content
- Complete paid course (Udemy Jason Dion or CBT Nuggets) — 6–8 hrs/week
- Parallel hands-on labs (TryHackMe, HackTheBox) — 2–3 hrs/week
- Take notes per domain; build flashcards for tools/commands
Phase 3 (Weeks 7–10): Deep practice
- Hands-on labs with real tools: Nmap, Burp Suite, Metasploit, Hashcat
- Exploit vulnerable machines (DVWA, Juice Shop, WebGoat)
- Practice AWS/Azure cloud pentesting (free tier + credits)
Phase 4 (Weeks 11–14): Practice exams
- Take 2–3 full-length practice exams (MeasureUp, CertMaster, Udemy)
- Review weak domains; re-read materials for failing topics
Phase 5 (Weeks 15–16): Final review
- Flashcard drill-through; mock exams in Certification Mode
- Rest and exam-day prep
Exam day: Arrive 15–30 min early; bring two forms of ID (one with photo); read PBQ instructions carefully; manage ~1.8 min/question average; flag hard questions for later review.