CompTIA PenTest+

CompTIA · PT0-003 · Associate

CompTIA · Offensive Security

CompTIA PenTest+

PT0-003activeAssociate
Official CompTIA source · comptia.org

PT0-003 · ● Active · Associate · CompTIA

CompTIA's mid-level offensive security certification. Launched December 17, 2024; PT0-002 retired June 17, 2025. PT0-003 emphasizes cloud exploitation, API security, AI/ML attack surface, and modern post-exploitation techniques alongside foundational penetration testing methodology.


Exam facts

FieldValue
CostUSD $404 (exam voucher; regional pricing varies)
Duration165 minutes
Questions90 maximum (mix of multiple-choice + performance-based; not all scored)
Passing750 on a scale of 100–900
FormatMultiple choice + Performance-Based Questions (PBQs); simulated penetration testing environments
DeliveryPearson VUE (in-person testing centers) and OnVUE (proctored online)
LanguagesEnglish
Valid3 years
Renewal60 continuing education units (CEUs) via approved activities, or retake exam; cost ~USD $100–$200
PrerequisitesCompTIA Security+ assumed knowledge; 3–4 years hands-on penetration testing/security testing experience recommended
ReleasedDecember 17, 2024
RetiringN/A (PT0-002 retired June 17, 2025)

Vendor source — CompTIA PenTest+ Certification ↗
Official exam guide — PT0-003 Exam Objectives ↗
DoD Approval — DoD 8140 Approved; aligns with NICE Framework


About

CompTIA PenTest+ is an intermediate offensive security certification focused on structured penetration testing methodology within legal, contractual scope boundaries. Unlike entry-level certs (Security+), PenTest+ requires demonstrated hands-on exploitation, privilege escalation, lateral movement, and professional reporting. The December 2024 refresh (PT0-003) added explicit coverage of cloud-native attacks (AWS/Azure/GCP IAM misconfig, serverless), API security testing (REST/GraphQL, authentication bypass), and AI/ML attack surface (adversarial inputs, prompt injection)—reflecting 2024–2026 attacker evolution. Typical candidate: SOC analyst moving into active testing, IT security professional seeking credible offensive credential, or junior red team operator.


Domain context — Security & Cybersecurity

Offensive security testing at the Associate level—positioned between foundational defensive certifications (Security+) and advanced practical credentials (OSCP, OSEP). PenTest+ validates hands-on ability to discover and exploit vulnerabilities under contract and rules of engagement.

Read full deep dive — Security Domain →


Topics covered

PT0-003 Exam Blueprint — 5 domains with weighted distribution:

  • Domain 1: Engagement Management (13%) — Planning, scoping, rules of engagement (ROE), legal/regulatory compliance (NDA, contract terms), report writing, stakeholder communication
  • Domain 2: Reconnaissance & Enumeration (21%) — Passive OSINT (search engines, DNS, WHOIS, certificate transparency logs), active scanning (Nmap, Masscan), vulnerability discovery, enumeration tools (Shodan, DNS enumeration, network mapping)
  • Domain 3: Vulnerability Discovery & Analysis (17%) — Manual vulnerability testing, automated scanners (Nessus, Qualys, OpenVAS, Burp Suite), vulnerability classification, prioritization, assessment methodology
  • Domain 4: Attacks & Exploits (35%) — Exploitation frameworks (Metasploit), payload delivery, cloud exploitation (AWS, Azure, GCP IAM misconfiguration), API testing (REST/GraphQL fuzzing, authentication bypass), AI/ML attack techniques (adversarial inputs, prompt injection), privilege escalation (Windows, Linux), lateral movement
  • Domain 5: Post-Exploitation & Lateral Movement (14%) — Persistence mechanisms, Windows/Linux privilege escalation, credential harvesting, data exfiltration, covering tracks, lateral movement techniques (pass-the-hash, credential spraying)

Source: CompTIA PenTest+ Exam Objectives ↗


Common skills at Security · Associate

Shared content for the Security domain at Associate level — not specific to this cert.

  • SIEM & Log Analysis — Splunk, ELK, Microsoft Sentinel; parsing security logs, alert triage, timeline reconstruction
  • Threat Hunting — Proactive detection, MITRE ATT&CK framework, indicator of compromise (IOC) correlation, behavioral analysis
  • Vulnerability Management — Scanning, prioritization, remediation tracking, metrics and reporting
  • Incident Response — First response, containment, eradication, recovery, post-incident review
  • MITRE ATT&CK & TTPs — Adversary tactics, techniques, procedures; threat actor profiling, defensive mapping
  • Active Directory Security — Domain structure, trust relationships, Kerberos weaknesses, privilege escalation vectors

Recommended courses at Security · Associate

ProviderTitleCostURL
Udemy (Jason Dion)CompTIA PenTest+ (PT0-003) Full Course & Practice ExamUSD $15–$60
Udemy (Jason Dion)CompTIA PenTest+ (PT0-003) 6 Practice ExamsUSD $15–$60
Dion Training DirectCompTIA PenTest+ (PT0-003) Complete Course, Labs, & Practice ExamsUSD $299–$599
CBT NuggetsCompTIA PenTest+ (PT0-003)USD $30–$50/mo
PluralsightCompTIA PenTest+ (PT0-003) PathUSD $30/mo or $299/yr
Coursera (Packt)CompTIA PenTest+ (PT0-003) by PacktFree audit / USD $49–$99 paid
TryHackMeCompTIA PenTest+ Learning PathFree (limited) / USD $20/mo
HackTheBox AcademyPenetration Testing Labs + Structured PathsFree (limited) / Premium

Course-selection rule: Each course above is specifically for PT0-003 (not generic pentesting). Jason Dion Udemy courses are the most widely recommended for affordability + depth. Hands-on labs (TryHackMe, HackTheBox) are essential alongside lectures.


Practice exams

ProviderTitleCostURL
CertMaster (Official CompTIA)CertMaster Practice for PenTest+ PT0-003USD $99–$149
CertMaster (Official CompTIA)CertMaster Perform (Live Lab Simulations)USD $149–$199
MeasureUpPT0-003 Practice Test (221 questions)USD $89–$199
MeasureUpPT0-003 CertKit (Full Study Bundle)USD $179–$299
Jason Dion (Udemy)CompTIA PenTest+ (PT0-003) 6 Practice ExamsUSD $15–$60
ExamTopicsPT0-003 Q&A CommunityFree to read / paid to submit

Books

TitleAuthorPublisherYearISBNURL
Pearson CompTIA PenTest+ Cert Guide (PT0-003)Omar SantosPearson IT Certification2025 (forthcoming)TBD
CompTIA PenTest+ Study Guide (PT0-002)Dr. Mike Chapple, David SeidlSybex / John Wiley & Sons2021978-1119823810
The Web Application Hacker's Handbook (2nd Edition)Dafydd Stuttard, Marcus PintoWiley2011978-1118026472

Book rule: Pearson PT0-003 edition is forthcoming (as of May 2026); the PT0-002 study guides overlap 70–80% of content. The Web Application Hacker's Handbook is essential reference for web app pentesting but not exam-specific.


Typical job titles at Security · Associate

Junior Penetration Tester · Vulnerability Assessment Analyst · Red Team Apprentice · Cybersecurity Analyst (Offensive) · Security Consultant (Entry)

(Job titles drawn from current job-board postings listing PenTest+ as required or preferred; roles typically require 1–3 years prior IT/security experience.)


Salary

RegionRangeSource
USD$107K–$191K (25th–75th percentile; avg $142K for Junior Pentester)Glassdoor (2026) ↗ · ZipRecruiter ↗ · PayScale ↗
ZARR450K–R900K (estimated; limited public data — consult local recruiters)Pnet · PayScale ZA · CareerJunction
GBP£30K–£55K (entry to mid-level; London higher)IT Jobs Watch · Hays
EUR€40K–€65K (DE/FR/NL average)Glassdoor EU · LinkedIn Salary
AUDA$85K–A$140KGlassdoor AU · PayScale AU

Salary rule: PT0-003 holders with 0–2 years experience typically earn entry-level rates above; mid-level (3–5 years) $115K–$160K; senior $145K+. Regional variation and specialization (cloud, web app, red team) significantly impact compensation.


Skills validated

Cert-specific — what PT0-003 actually tests, distinct from "Common skills" above.

Reconnaissance & Information Gathering

  • Passive OSINT (search engines, DNS lookups, WHOIS, certificate transparency logs, social media harvesting)
  • Active enumeration (Nmap, Masscan, port scanning, service fingerprinting)
  • Network mapping, asset discovery, subdomain enumeration
  • DNS reconnaissance, DNS zone transfer attempts

Vulnerability Discovery & Assessment

  • Manual vulnerability testing (authentication bypass, authorization flaws)
  • Automated scanners (Nessus, Qualys, OpenVAS, Burp Suite Community/Pro)
  • Vulnerability classification (CVSS scoring, severity prioritization)
  • Vulnerability life-cycle management, remediation tracking

Exploitation Frameworks & Techniques

  • Metasploit Framework — module selection, payload generation, multi-handler setup
  • Burp Suite — intruder, repeater, scanner, proxy configuration
  • Custom exploitation scripts (Python, Bash)
  • Payload encoding, obfuscation, evasion tactics

Privilege Escalation (Windows & Linux)

  • Windows: UAC bypass, token impersonation, DLL injection, kernel exploits, service misconfiguration
  • Linux: SUID binary exploits, kernel vulnerabilities, sudo misconfig, capability abuse

Post-Exploitation & Lateral Movement

  • Credential harvesting (mimikatz, plaintext searches, credential manager)
  • Lateral movement (pass-the-hash, pass-the-ticket, credential spraying)
  • Persistence (registry persistence, scheduled tasks, service creation, backdoors)
  • Data exfiltration (stealth techniques, compression, encoding)

Advanced Techniques (PT0-003 focus)

  • Cloud Exploitation: AWS S3 enumeration, IAM policy analysis, EC2 metadata bypass, Lambda code injection; Azure managed identities, Key Vault leakage; GCP service account compromise
  • API Testing: REST/GraphQL fuzzing, authentication/authorization bypass, rate limit evasion, API key leakage, XML external entity (XXE) injection
  • AI/ML Attack Surface: Adversarial input injection, prompt injection against LLMs, model evasion, training data poisoning concepts

Tooling Proficiency

  • Scanning: Nmap, Masscan, Shodan queries, theHarvester, Recon-ng
  • Exploitation: Metasploit, Burp Suite, custom Python/Bash scripts
  • Post-Exploitation: Mimikatz, linpeas, BloodHound, Empire, Cobalt Strike (red-team environments)
  • Credential Cracking: Hashcat, John the Ripper
  • Network: Wireshark, netcat, tcpdump

Reporting & Communication

  • Written penetration test reports (executive summary, technical findings, risk rating, remediation recommendations)
  • Stakeholder communication (explaining technical findings to non-technical clients)
  • Legal/regulatory context (NDA, ROE scope, liability, compliance frameworks: PCI-DSS, HIPAA, GDPR, NIST)

Related certifications


Sources


Last verified: 2026-05-01
Parent ecosystem: Offensive Security →
Parent domain: Security & Cybersecurity →
Vendor overview: CompTIA →
Role roadmap: Penetration Tester / Red Team →


Exam preparation summary

Timeline: 12–16 weeks (assuming 10–15 hrs/week study)

Phase 1 (Weeks 1–2): Foundation

  • Read full PT0-003 exam blueprint
  • Review Security+ knowledge (if gaps exist)
  • Set up lab environment (VirtualBox, Kali Linux, Windows target)

Phase 2 (Weeks 3–6): Core content

  • Complete paid course (Udemy Jason Dion or CBT Nuggets) — 6–8 hrs/week
  • Parallel hands-on labs (TryHackMe, HackTheBox) — 2–3 hrs/week
  • Take notes per domain; build flashcards for tools/commands

Phase 3 (Weeks 7–10): Deep practice

  • Hands-on labs with real tools: Nmap, Burp Suite, Metasploit, Hashcat
  • Exploit vulnerable machines (DVWA, Juice Shop, WebGoat)
  • Practice AWS/Azure cloud pentesting (free tier + credits)

Phase 4 (Weeks 11–14): Practice exams

  • Take 2–3 full-length practice exams (MeasureUp, CertMaster, Udemy)
  • Review weak domains; re-read materials for failing topics

Phase 5 (Weeks 15–16): Final review

  • Flashcard drill-through; mock exams in Certification Mode
  • Rest and exam-day prep

Exam day: Arrive 15–30 min early; bring two forms of ID (one with photo); read PBQ instructions carefully; manage ~1.8 min/question average; flag hard questions for later review.


Roles that use this certification

1 career-path guide on this site put this exam in the sequence.

Rate this cert
Was this helpful?
Comments ()
0/2000