PenTest+ is a branching path towards the offensive side in CompTIA's certification roadmap. If Security+ teaches you to understand the overall security landscape, PenTest+ teaches you to perform a penetration test from start to finish — including the part many technical people tend to avoid: writing reports and remediation proposals.
What is PenTest+?
CompTIA PenTest+ is a mid-level certification for penetration testing and vulnerability assessment. It is the offensive (red team) counterpart to CySA+ in the CompTIA roadmap, and sits above Security+.
The current version is PT0-003, released on December 17, 2024. The previous version (PT0-002) retired on June 17, 2025. Typically, CompTIA retires an exam about three years after its release — for PT0-003, this is estimated to be around 2027.
This means you have plenty of time and are not under pressure like with the transitioning Security+ series.
Exam Details
| Category | Information |
|---|---|
| Exam Code | PT0-003 |
| Release Date | 17/12/2024 |
| Number of Questions | Maximum 90 questions |
| Time Limit | 165 minutes |
| Question Types | Multiple-choice + performance-based questions (PBQ) |
| Passing Score | 750 on a scale of 100–900 |
| Recommended Experience | 3–4 years in a pentester role, with Network+ and Security+ foundation |
| Languages | English, French, Japanese, Portuguese |
Note the 165 minutes — significantly longer than Security+. This is not generosity: PBQs in PenTest+ are much more substantial, and you will need every minute.
Regarding the "3–4 years recommended experience": this is a recommendation, not a mandatory condition. Many people pass with less experience, provided they have done enough lab practice. But if you've never touched a pentesting tool, that number is a warning worth heeding.
Five Domains and Their Weight
| Domain | Weight | Content |
|---|---|---|
| 1. Engagement Management | 13% | Planning, scoping, legal aspects, reporting, client communication |
| 2. Reconnaissance and Enumeration | 21% | Passive and active information gathering, network scanning, service enumeration |
| 3. Vulnerability Discovery and Analysis | 17% | Vulnerability identification, scan result analysis, prioritization |
| 4. Attacks and Exploits | 35% | Network, web application, wireless, cloud exploitation, social engineering |
| 5. Post-exploitation and Lateral Movement | 14% | Maintaining access, lateral movement, privilege escalation, clearing tracks |
Domain 4 accounts for 35% — more than one-third of the exam. This is undeniably the core focus.
But don't neglect Domain 1. Many technical learners disregard the project management aspect of penetration testing — scoping, contracts, rules of engagement, reporting — because they feel it's not "hacking." It accounts for 13%, and more importantly: this is precisely what distinguishes a professional pentester from someone who just knows how to use tools. Clients pay for reports, not for shells.
How PenTest+ Differs from Security+
If you already have Security+, the biggest difference is not in the difficulty of the questions but in the type of competence being tested.
Security+ asks what you know. PenTest+ asks what you can do. PenTest+ questions often describe a specific testing scenario and ask which tool, which parameters, and why.
A practical consequence: rote learning won't save you in PenTest+. You might remember that nmap is a network scanning tool, but the exam will ask what type of scan yields what information — and if you've never typed the actual command, you'll be guessing.
Details about this difference, along with advice from those who have taken the exam, can be found in the article PenTest+ PT0-003 Exam Experience.
PenTest+ vs. CEH and OSCP
| PenTest+ | CEH | OSCP | |
|---|---|---|---|
| Organization | CompTIA | EC-Council | Offensive Security |
| Exam Format | Multiple-choice + PBQ, 165 minutes | Multiple-choice (Practical version has separate lab) | 24-hour hands-on lab |
| Focus | Full testing lifecycle, including reporting | Knowledge and attack tools | Practical exploitation, pure skills |
| Exam Difficulty | Medium | Medium | High |
| Cost | Medium | High | High |
Choose PenTest+ if: you want a widely recognized certification that covers both process and reporting, without having to undergo a 24-hour lab exam.
Choose CEH if: your target employer specifically requires CEH — this happens quite often in some organizations in Vietnam.
Choose OSCP if: you're aiming for a hands-on pentester position and are willing to invest hundreds of hours in labs.
Many people pursue both PenTest+ and OSCP. That order makes sense: PenTest+ builds the mindset and process framework, while OSCP hones the hands-on skills.
Who Should Study PenTest+?
Suitable if:
- You already have Security+ or equivalent knowledge and want to specialize in offensive security.
- You are working in SOC, system administration, or network administration and want to understand the attacker's perspective.
- You work for a security service provider and need a certification for your company's capabilities profile.
- You want a recognized pentest certification without a 24-hour lab exam.
Not yet suitable if:
- You lack a foundation in networking and operating systems. Please revisit Security+ first.
- You want to work in defensive security. CySA+ is a closer fit.
- You have never set up a lab or used pentest tools. It's not impossible, but preparation time will be twice as long.
Value of the Certification
PenTest+ is approved under the U.S. Department of Defense's DoD 8140 framework for relevant positions. In Vietnam, this has an indirect but real impact: FDI enterprises, companies providing services to international clients, and organizations adopting international standards all reference this list when writing job requirements.
The certification is valid for 3 years, renewable through CompTIA's CE program. And as mentioned in the Security+ renewal article: if you hold Security+, passing PenTest+ will automatically renew your Security+. Two birds with one stone.
How Long Does It Take to Study?
- Already a pentester or red teamer: 6–8 weeks
- Have Security+ and sysadmin/network experience: 10–14 weeks
- Have an IT background but no security experience: 4–6 months, including lab setup time
This assumes you practice in parallel with theoretical study. If you only read books, double the time and still be prepared to fail.
A detailed roadmap is available in the article 12-week PenTest+ Study Roadmap.
Where to Start?
- Download the PT0-003 objectives from the official CompTIA website — free and the most important resource you have.
- Assess how many tools from that list you can already use.
- Set up a lab environment, or use pre-built labs to save configuration time.
Related products at Security365:
- CompTIA PenTest+ Online Course (PT0-003) — includes genuine CertMaster Perform — 5,490,000₫ (original price 8,000,000₫). Taught in Vietnamese, covering 5 domains, with genuine practice materials.
- Genuine CompTIA PenTest+ PT0-003 CertMaster Perform — 2,250,000₫ (original price 4,500,000₫), if you self-study and only need the lab component.
- Exam Voucher PT0-003 with exam insurance — free 01 retest — 7,500,000₫ (original price 9,500,000₫).
See also: PT0-003 Exam Experience from a test-taker · Already have Security+, what's next: PenTest+ or CySA+? · PenTest+ vs. CEH vs. OSCP