CompTIA Network Vulnerability Assessment Professional (CNVP)

CompTIA · Stackable · Professional

CompTIA · CompTIA Stackable Certifications

CompTIA Network Vulnerability Assessment Professional (CNVP)

StackableactiveProfessional
Official CompTIA source · comptia.org

Stackable · ● Active · Professional · CompTIA

Stackable credential — not a standalone exam. Awarded upon earning and maintaining both Security+ (SY0-701) and PenTest+ (PT0-002) simultaneously. No separate CNVP exam exists; achievement badge issued via Credly when prerequisites are met.


Exam facts

FieldValue
Cost$425 per exam (Security+); $425 per exam (PenTest+). Total: $850 for both exams.
DurationSecurity+: 90 minutes; PenTest+: 165 minutes (2 hours 45 minutes). Total study: ~300+ hours recommended.
QuestionsSecurity+: ~90 questions (multiple choice & multiple response); PenTest+: maximum 85 questions (multiple choice & performance-based).
PassingSecurity+: 750/900 scaled score; PenTest+: vendor-scaled; both required to hold CNVP badge.
FormatMultiple choice · Multiple response · Performance-based questions (PBQs)
DeliveryPearson VUE (online ProctorU or test center) · OnVUE
LanguagesEnglish (English-only delivery as of 2026)
Valid3 years from most recent passing date. Both certs must be held simultaneously.
RenewalContinuing Education (CE) credits or retake exams before expiration. CompTIA allows 40 CE credits per 3-year cycle; alternative: pass CySA+ to bundle into CNSP (broader stack).
PrerequisitesCompTIA recommends 2–5 years hands-on IT/security experience. No hard prerequisite, but practical networking and systems knowledge assumed.
ReleasedCNVP stackable badge introduced ~2019; refined 2023–2026. Individual exams (Security+ SY0-701, PenTest+ PT0-002) are current versions as of 2026.
RetiringNo retirement announced for Security+ or PenTest+ as of May 2026. Stackable badge status: Active.

Vendor source — CompTIA Stackable Certifications ↗

Security+ exam guide — CompTIA Security+ (SY0-701) ↗

PenTest+ exam guide — CompTIA PenTest+ (PT0-002) ↗

Stackable badge details — CNVP Digital Badge ↗


About

The CompTIA Network Vulnerability Assessment Professional (CNVP) is a stackable credential that recognizes professionals who have mastered both foundational security (Security+) and offensive penetration-testing skills (PenTest+). Unlike a standalone exam, CNVP is an achievement badge awarded by CompTIA when you hold both Security+ and PenTest+ certifications simultaneously. Earners demonstrate the ability to scan applications and systems to identify vulnerabilities, assess risk, and provide remediation guidance—a critical role in modern cybersecurity operations. The CNVP is designed for IT professionals and operations specialists with 2–5 years of hands-on experience.


Domain context — Security / Vulnerability Assessment

Penetration testing and vulnerability assessment are core practices in modern cybersecurity, sitting at the intersection of defensive security (assessment) and offensive tactics (testing). CNVP holders validate competency across threat identification, exploitation techniques, and security controls.

Read full deep dive — Security Domain →


Topics covered

Security+ (SY0-701) — Exam objectives

  • General Security Concepts (~13%) — Attack frameworks, threat actors, vulnerability management, incident response
  • Threats, Vulnerabilities, and Mitigations (~24%) — Types of attacks, malware, application/network exploits, mitigation techniques
  • Security Architecture (~21%) — CIA triad, cryptography, access control, identity/authentication
  • Security Operations (~16%) — Incident response, security monitoring, threat hunting, SOAR/SIEM
  • Governance, Risk, and Compliance (~16%) — Risk management, regulatory frameworks (HIPAA, PCI-DSS, SOC 2), policy

Source: CompTIA Security+ Exam Objectives ↗

PenTest+ (PT0-002) — Exam objectives

  • Penetration Testing Fundamentals (~12%) — Scope, rules of engagement, legal/ethical frameworks, tools overview
  • Reconnaissance (~13%) — Information gathering, passive/active scanning, enumeration techniques
  • Scanning and Enumeration (~14%) — Vulnerability scanning, exploitation frameworks, target profiling
  • Exploitation (~25%) — Web-application exploitation, network attacks, privilege escalation, post-exploitation
  • Post-Exploitation and Reporting (~16%) — Proof-of-concept development, evidence documentation, report writing, risk communication
  • Tools and Code Analysis (~20%) — Metasploit, Burp Suite, Python/Bash scripting, packet analysis

Source: CompTIA PenTest+ Exam Blueprint ↗


Common skills at Security / Vulnerability Assessment · Professional

Shared competencies across penetration testing and vulnerability assessment roles at the Professional level.

  • Threat modeling and risk quantification
  • Vulnerability scanning and remediation prioritization
  • Exploitation technique execution (SQLi, XSS, command injection, privilege escalation)
  • Network-traffic analysis and protocol exploitation
  • Web-application security assessment (OWASP Top 10)
  • Post-exploitation persistence and lateral movement
  • Secure reporting and executive communication
  • Legal and ethical boundary testing (scope, ROE, compliance)

Recommended courses at Security / Vulnerability Assessment · Professional

ProviderTitleCostURL
CompTIA Official (A Cloud Guru / Linux Academy)CompTIA Security+ (SY0-701) + PenTest+ (PT0-002) bundle$500–$800
Professor MesserCompTIA Security+ SY0-701 video seriesFree (YouTube)
Professor MesserCompTIA PenTest+ PT0-002 video seriesFree (YouTube)
Udemy (Jason Dion)CompTIA Security+ (SY0-701) Complete Course and Exam$15–$45
Udemy (Jason Dion)CompTIA PenTest+ (PT0-002) Complete Course$15–$45
TCM SecurityPractical Ethical Hacking (hands-on lab)$99–$199
PluralsightCompTIA Security+ Path$399/year
CBT NuggetsCompTIA PenTest+ Certification (Video + Labs)$399–$599
INE (Offensive Security)Introduction to Penetration Testing (EN101)$249–$499

Course-selection rule: Link courses explicitly tied to SY0-701 and PT0-002, not generic "security" content. Hands-on labs (TCM, INE) highly recommended given the practical nature of PenTest+.


Practice exams

ProviderTitleCostURL
CompTIA Official (via partner)CompTIA Security+ SY0-701 practice exam$95–$125
Boson ExSim-MaxCompTIA Security+ (SY0-701) practice exams (90-day access)$99
Boson ExSim-MaxCompTIA PenTest+ (PT0-002) practice exams$99
WhizlabsCompTIA Security+ (SY0-701) practice tests$49–$79
WhizlabsCompTIA PenTest+ (PT0-002) practice tests$49–$79
MeasureUpCompTIA Security+ (SY0-701) official practice exam$119
MeasureUpCompTIA PenTest+ (PT0-002) official practice exam$119

Books

TitleAuthorPublisherYearISBNURL
CompTIA Security+ Study Guide (Exam SY0-701)Mike Chapple, James Michael StewartSybex (Wiley)2024978-1-119-90620-7
CompTIA PenTest+ Study Guide (Exam PT0-002)Jon Hill, Clinton FosterSybex (Wiley)2023978-1-119-90688-6
The Web Application Hacker's Handbook: Finding and Exploiting Security FlawsStuttard & PintoWiley2011978-1-118-02635-8
Penetration Testing: A Hands-On Introduction to HackingGeorgia WeidmanNo Starch Press2014978-1-593-27564-7
The Hacker Playbook 3: Practical Guide to Penetration TestingPeter KimCreateSpace2018978-1-980901-15-3

Typical job titles at Security / Vulnerability Assessment · Professional

Penetration Tester · Vulnerability Assessor · Security Analyst · Application Security Engineer · Network Security Analyst · Security Consultant · Offensive Security Specialist · Red Team Operator

(Job titles drawn from current job-board postings that list Security+ and PenTest+ as required or strongly preferred.)


Salary

RegionRangeSource
USD$119,000 – $154,000PayScale ↗ · Glassdoor ↗ · Indeed ↗
ZARR483,918 – R851,221PayScale ZA ↗ · SalaryExpert ZA ↗ · Glassdoor ZA ↗
GBP£36,430 – £60,000PayScale UK ↗ · IT Jobs Watch ↗ · Glassdoor UK ↗

Salary rule: Ranges reflect roles requiring Security+ and PenTest+ or equivalent offensive/defensive certifications. Senior penetration testers and vulnerability assessors (7+ years) can exceed these ranges significantly. Regional variation reflects cost of living and demand; UK and ZA data sparser than USD due to smaller certified pool.


Skills validated

Distinct technical competencies this credential combination validates.

  • Nmap / Nessus / OpenVAS vulnerability scanning and reporting
  • Metasploit Framework exploitation and post-exploitation
  • Burp Suite web-application penetration testing
  • SQLi, XSS, command injection, directory traversal exploitation
  • Network reconnaissance (DNS enumeration, port scanning, service fingerprinting)
  • Windows and Linux privilege escalation techniques
  • Active Directory exploitation and lateral movement
  • Payload generation and encoding (evasion, obfuscation)
  • Python and Bash scripting for security automation
  • Cryptographic concepts and their weaknesses
  • Wireless network testing (WPA/WPA2 cracking)
  • OWASP Top 10 vulnerability identification and remediation
  • Firewall evasion and IDS/IPS bypass
  • Post-exploitation reporting and risk communication
  • Legal and ethical compliance in authorized testing (scope, ROE, NDA)

Related certifications


Sources


Last verified: 2026-05-01 Parent ecosystem: CompTIA Stackable Certifications Parent domain: Security / Vulnerability Assessment Vendor overview: CompTIA Overview

Rate this cert
Was this helpful?
Comments ()
0/2000