1.1 Current PT0-003 Exam Facts
Key Takeaways
- CompTIA PenTest+ Version 3 uses series code PT0-003 and launched on December 17, 2024.
- PT0-002 retired on June 17, 2025; PT0-003 is the only live PenTest+ series, with retirement usually three years after launch (estimated 2027).
- The exam allows a maximum of 90 questions in 165 minutes, mixing multiple-choice and performance-based items, with a passing score of 750 on a 100-900 scale.
- Official domain weights are Engagement Management 13%, Reconnaissance and Enumeration 21%, Vulnerability Discovery and Analysis 17%, Attacks and Exploits 35%, and Post-exploitation and Lateral Movement 14%.
- CompTIA recommends 3-4 years in a penetration tester job role, with Network+ and Security+ or equivalent knowledge; those are recommendations, not mandatory prerequisites.
1.1 Current PT0-003 Exam Facts
Quick Answer: CompTIA PenTest+ Version 3 uses series code PT0-003. It launched on December 17, 2024. You face a maximum of 90 questions in 165 minutes and need a scaled score of 750 on a 100-900 scale. The previous exam, PT0-002, retired on June 17, 2025. CompTIA recommends 3-4 years in a penetration tester job role plus Network+ and Security+ or equivalent knowledge. Attacks and Exploits (35%) and Reconnaissance and Enumeration (21%) together are more than half the exam.
Computing Technology Industry Association (CompTIA) PenTest+ is CompTIA's vendor-neutral, intermediate credential for people who plan, execute, and report authorized penetration tests. It is not a product exam for one vendor's scanner, and it is not an entry-level vocabulary test. CompTIA designed Version 3 around the full engagement lifecycle: legal scoping, reconnaissance, vulnerability discovery, exploitation across modern attack surfaces, and post-exploitation work that includes persistence, lateral movement, and documentation. If you can only recite definitions, you are underprepared. If you can scope a test, find a path, prove impact, and write a finding the client can actually remediate, you are studying the right exam.
What PenTest+ Certifies
On the official PenTest+ product page, CompTIA groups PT0-003 skills into five job tasks. You plan and scope engagements while staying inside legal and ethical bounds, then produce reports with remediation recommendations. You perform active and passive reconnaissance and enumerate systems. You run vulnerability scans, analyze results, and validate findings instead of dumping raw tool output. You execute network, host-based, web application, and cloud-based attacks. After a foothold, you maintain persistence, move laterally, and document what you did so the client can fix it.
Version 3 also expects you to explain artificial intelligence (AI) attack ideas such as prompt injection and model manipulation—content that did not define the retired PT0-002 generation. Official domain summaries further call out identity and access management (IAM) misconfiguration, container escapes, metadata service attacks, SQL injection (SQLi), cross-site scripting (XSS), directory traversal, pass-the-hash, credential stuffing, and script modification in Python, PowerShell, and Bash. That mix is why PenTest+ sits between foundational security knowledge and specialist offensive credentials: it still tests planning and reporting, but the live exam is built for a tester who has a rules of engagement (RoE) document, a testing window, and a report deadline.
Who Should Sit PT0-003
PT0-003 Versus Retired PT0-002
PT0-003 is Exam Version V3. It launched on December 17, 2024. PT0-002 retired on June 17, 2025. As of 2026, a new PenTest+ candidate should prepare only for PT0-003. CompTIA typically retires an exam series about three years after launch; for PT0-003 that window is estimated 2027. Do not sit a retired code, and do not study an old PT0-002 objective PDF as if it were current.
V3 keeps the penetration-testing story but modernizes the surfaces. Cloud, application programming interface (API), web, and AI content are first-class, not trivia at the end of a chapter. Scripting appears as a reconnaissance and enumeration skill, not as a separate programming exam. If your notes still treat "the pentest exam" as only on-premises Windows and a short Kali Linux tool list, they are behind Version 3. When an employer, job posting, or older blog still says PT0-002, translate that to PT0-003 before you buy a voucher.
Current Logistics
Confirm every number below against CompTIA's PenTest+ product page when you schedule. CompTIA's PenTest+ product page does not list a dollar price. Candidates purchase a voucher from the CompTIA Store and must confirm the current regional price. CompTIA requires paying the exam price each attempt and does not offer free retakes.
| Fact | Official PT0-003 detail |
|---|---|
| Exam version | V3 |
| Series code | PT0-003 |
| Launch date | December 17, 2024 |
| Previous exam retirement | PT0-002 retired June 17, 2025 |
| PT0-003 retirement | Usually three years after launch (estimated 2027) |
| Number of questions | Maximum of 90, including multiple-choice and performance-based questions |
| Length of test | 165 minutes |
| Passing score | 750 (scale of 100-900) |
| Recommended experience | 3-4 years as a penetration tester, plus Network+ and Security+ or equivalent |
| Languages | English, French, Japanese, and Portuguese |
| Delivery | Pearson VUE test centers or Pearson OnVUE online proctoring |
| Price | Purchase a voucher from the CompTIA Store; confirm the current regional price |
CompTIA does not publish a public PenTest+ pass-rate percentage. Ignore recycled blog claims that treat an unofficial estimate as a CompTIA statistic. Your cut score is 750 on the published 100-900 scale, not a public industry pass rate.
The Five Domains and Why Two of Them Dominate Study Time
Use the official weights from CompTIA's product page and the PT0-003 Exam Objectives v3.0 PDF. Domain 5 is 14%. A February 2025 CompTIA blog listed 11% for that domain, but 13 + 21 + 17 + 35 + 11 = 97. Do not use 11%. Use 14% from the product page and objectives PDF.
| Domain | Weight | What it rewards |
|---|---|---|
| Engagement Management | 13% | Planning, scoping, legal and ethical compliance, collaboration, reports |
| Reconnaissance and Enumeration | 21% | Active and passive recon, enumeration, recon tools, script modification |
| Vulnerability Discovery and Analysis | 17% | Scans including static application security testing (SAST) and dynamic application security testing (DAST), result analysis, discovery tools |
| Attacks and Exploits | 35% | Network, authentication, host, web, cloud, and AI attacks |
| Post-exploitation and Lateral Movement | 14% | Persistence, lateral movement, documentation |
Attacks and Exploits at 35% is the largest slice. Reconnaissance and Enumeration at 21% is second. Together they are 56% of the exam. Add Vulnerability Discovery and Analysis at 17% and you are looking at 73% of scored weight in the find-it-and-prove-it half of the job. That is why study time should not be split evenly five ways.
Spend enough time on Engagement Management to avoid cheap misses on authorization letters, RoE, testing windows, mandatory reporting, stakeholder communication, and report structure. Then invest the majority of lab hours in recon, validation, and exploitation. Domain 5 still matters: persistence, lateral movement, artifact cleanup, and attack narratives are how testers turn a foothold into a complete finding. Do not skip reporting just because it is not 35% of the blueprint.
Languages, Launch Window, and What To Do Next
PT0-003 is offered in English, French, Japanese, and Portuguese. Confirm language availability when you schedule; not every Pearson VUE site or OnVUE slot offers every language at every hour. Create a CompTIA account, buy a voucher from the CompTIA Store at the price shown for your region, then schedule through Pearson VUE. CompTIA's online-testing guidance states there is no published price difference between a test-center seat and OnVUE for the same exam.
This section's job is the facts you should be able to quote: the code is PT0-003, the clock is 165 minutes, the cap is 90 items, the cut score is 750, the live series replaced PT0-002 on June 17, 2025, and two domains—Attacks and Exploits plus Reconnaissance and Enumeration—should dominate your calendar. Format, performance-based questions (PBQs), scoring mechanics, and retakes are the next section.
What is the current CompTIA PenTest+ exam series code for Version 3?
Which PT0-003 domain carries the largest official weight on CompTIA's product page and Exam Objectives v3.0 PDF?
What experience does CompTIA recommend before sitting PenTest+ PT0-003?