1.1 Current PT0-003 Exam Facts
Key Takeaways
CompTIA PenTest+ Version 3 uses series code PT0-003 and launched on December 17, 2024.
PT0-002 retired on June 17, 2025; PT0-003 is the only live PenTest+ series, with retirement usually three years after launch (estimated 2027).
The exam allows a maximum of 90 questions in 165 minutes, mixing multiple-choice and performance-based items, with a passing score of 750 on a 100-900 scale.
Official domain weights are Engagement Management 13%, Reconnaissance and Enumeration 21%, Vulnerability Discovery and Analysis 17%, Attacks and Exploits 35%, and Post-exploitation and Lateral Movement 14%.
CompTIA recommends 3-4 years in a penetration tester job role, with Network+ and Security+ or equivalent knowledge; those are recommendations, not mandatory prerequisites.
1.1 Current PT0-003 Exam Facts
Quick Answer: CompTIA PenTest+ Version 3 uses series code PT0-003. It launched on December 17, 2024. You face a maximum of 90 questions in 165 minutes and need a scaled score of 750 on a 100-900 scale. The previous exam, PT0-002, retired on June 17, 2025. CompTIA recommends 3-4 years in a penetration tester job role plus Network+ and Security+ or equivalent knowledge. Attacks and Exploits (35%) and Reconnaissance and Enumeration (21%) together are more than half the exam.
Computing Technology Industry Association (CompTIA) PenTest+ is CompTIA's vendor-neutral, intermediate credential for people who plan, execute, and report authorized penetration tests. It is not a product exam for one vendor's scanner, and it is not an entry-level vocabulary test. CompTIA designed Version 3 around the full engagement lifecycle: legal scoping, reconnaissance, vulnerability discovery, exploitation across modern attack surfaces, and post-exploitation work that includes persistence, lateral movement, and documentation. If you can only recite definitions, you are underprepared. If you can scope a test, find a path, prove impact, and write a finding the client can actually remediate, you are studying the right exam.
What PenTest+ Certifies
On the official PenTest+ product page, CompTIA groups PT0-003 skills into five job tasks. You plan and scope engagements while staying inside legal and ethical bounds, then produce reports with remediation recommendations. You perform active and passive reconnaissance and enumerate systems. You run vulnerability scans, analyze results, and validate findings instead of dumping raw tool output. You execute network, host-based, web application, and cloud-based attacks. After a foothold, you maintain persistence, move laterally, and document what you did so the client can fix it.
Version 3 also expects you to explain artificial intelligence (AI) attack ideas such as prompt injection and model manipulation—content that did not define the retired PT0-002 generation. Official domain summaries further call out identity and access management (IAM) misconfiguration, container escapes, metadata service attacks, SQL injection (SQLi), cross-site scripting (XSS), directory traversal, pass-the-hash, credential stuffing, and script modification in Python, PowerShell, and Bash. That mix is why PenTest+ sits between foundational security knowledge and specialist offensive credentials: it still tests planning and reporting, but the live exam is built for a tester who has a rules of engagement (RoE) document, a testing window, and a report deadline.
Who Should Sit PT0-003
CompTIA's recommended experience is 3-4 years in a penetration tester job role, with CompTIA Network+ and CompTIA Security+ or equivalent knowledge. That recommendation is not a gate. There is no mandatory prerequisite exam, no degree requirement, and no employer sponsorship rule. Candidates who already hold Security+ or Network+ usually spend less time on protocol and control vocabulary and more time on tooling, validation, and tradecraft.
The audience CompTIA names most often is people targeting penetration tester, vulnerability analyst, and security consultant work. If your day job already includes scanning, exploiting, or writing findings, PT0-003 is a structured way to prove that path. If you are coming from a defensive or generalist role, treat the recommendation seriously. The exam assumes you can reason about open-source intelligence (OSINT), Nmap service discovery, authenticated versus unauthenticated scanning, and exploit chains—not just the names of those techniques. Use this PenTest+ study guide as the syllabus and drill application with free practice at /practice/pentest-plus.
PT0-003 Versus Retired PT0-002
PT0-003 is Exam Version V3. It launched on December 17, 2024. PT0-002 retired on June 17, 2025. As of 2026, a new PenTest+ candidate should prepare only for PT0-003. CompTIA typically retires an exam series about three years after launch; for PT0-003 that window is estimated 2027. Do not sit a retired code, and do not study an old PT0-002 objective PDF as if it were current.
V3 keeps the penetration-testing story but modernizes the surfaces. Cloud, application programming interface (API), web, and AI content are first-class, not trivia at the end of a chapter. Scripting appears as a reconnaissance and enumeration skill, not as a separate programming exam. If your notes still treat "the pentest exam" as only on-premises Windows and a short Kali Linux tool list, they are behind Version 3. When an employer, job posting, or older blog still says PT0-002, translate that to PT0-003 before you buy a voucher.
Current Logistics
Confirm every number below against CompTIA's PenTest+ product page when you schedule. CompTIA's PenTest+ product page does not list a dollar price. Candidates purchase a voucher from the CompTIA Store and must confirm the current regional price. CompTIA requires paying the exam price each attempt and does not offer free retakes.
| Fact | Official PT0-003 detail |
|---|---|
| Exam version | V3 |
| Series code | PT0-003 |
| Launch date | December 17, 2024 |
| Previous exam retirement | PT0-002 retired June 17, 2025 |
| PT0-003 retirement | Usually three years after launch (estimated 2027) |
| Number of questions | Maximum of 90, including multiple-choice and performance-based questions |
| Length of test | 165 minutes |
| Passing score | 750 (scale of 100-900) |
| Recommended experience | 3-4 years as a penetration tester, plus Network+ and Security+ or equivalent |
| Languages | English, French, Japanese, and Portuguese |
| Delivery | Pearson VUE test centers or Pearson OnVUE online proctoring |
| Price | Purchase a voucher from the CompTIA Store; confirm the current regional price |
CompTIA does not publish a public PenTest+ pass-rate percentage. Ignore recycled blog claims that treat an unofficial estimate as a CompTIA statistic. Your cut score is 750 on the published 100-900 scale, not a public industry pass rate.
The Five Domains and Why Two of Them Dominate Study Time
Use the official weights from CompTIA's product page and the PT0-003 Exam Objectives v3.0 PDF. Domain 5 is 14%. A February 2025 CompTIA blog listed 11% for that domain, but 13 + 21 + 17 + 35 + 11 = 97. Do not use 11%. Use 14% from the product page and objectives PDF.
| Domain | Weight | What it rewards |
|---|---|---|
| Engagement Management | 13% | Planning, scoping, legal and ethical compliance, collaboration, reports |
| Reconnaissance and Enumeration | 21% | Active and passive recon, enumeration, recon tools, script modification |
| Vulnerability Discovery and Analysis | 17% | Scans including static application security testing (SAST) and dynamic application security testing (DAST), result analysis, discovery tools |
| Attacks and Exploits | 35% | Network, authentication, host, web, cloud, and AI attacks |
| Post-exploitation and Lateral Movement | 14% | Persistence, lateral movement, documentation |
Attacks and Exploits at 35% is the largest slice. Reconnaissance and Enumeration at 21% is second. Together they are 56% of the exam. Add Vulnerability Discovery and Analysis at 17% and you are looking at 73% of scored weight in the find-it-and-prove-it half of the job. That is why study time should not be split evenly five ways.
Spend enough time on Engagement Management to avoid cheap misses on authorization letters, RoE, testing windows, mandatory reporting, stakeholder communication, and report structure. Then invest the majority of lab hours in recon, validation, and exploitation. Domain 5 still matters: persistence, lateral movement, artifact cleanup, and attack narratives are how testers turn a foothold into a complete finding. Do not skip reporting just because it is not 35% of the blueprint.
Do not confuse a practice bank's size with the live exam. CompTIA's maximum of 90 is the real-test cap. Our practice inventory is a study tool, not the official question count. Keep the study guide and free PT0-003 practice mapped to these five weights rather than to an older PT0-002 outline.
Languages, Launch Window, and What To Do Next
PT0-003 is offered in English, French, Japanese, and Portuguese. Confirm language availability when you schedule; not every Pearson VUE site or OnVUE slot offers every language at every hour. Create a CompTIA account, buy a voucher from the CompTIA Store at the price shown for your region, then schedule through Pearson VUE. CompTIA's online-testing guidance states there is no published price difference between a test-center seat and OnVUE for the same exam.
This section's job is the facts you should be able to quote: the code is PT0-003, the clock is 165 minutes, the cap is 90 items, the cut score is 750, the live series replaced PT0-002 on June 17, 2025, and two domains—Attacks and Exploits plus Reconnaissance and Enumeration—should dominate your calendar. Format, performance-based questions (PBQs), scoring mechanics, and retakes are the next section.
What is the current CompTIA PenTest+ exam series code for Version 3?
PT0-003, the Version 3 series that launched on December 17, 2024
PT0-002, which remains the live PenTest+ series through 2027
PT0-001, which CompTIA relaunched as the current penetration testing exam
PEN-003, CompTIA's published code for the PenTest+ performance exam
Which PT0-003 domain carries the largest official weight on CompTIA's product page and Exam Objectives v3.0 PDF?
Engagement Management at 13 percent
Reconnaissance and Enumeration at 21 percent
Attacks and Exploits at 35 percent
Post-exploitation and Lateral Movement at 11 percent
What experience does CompTIA recommend before sitting PenTest+ PT0-003?
No experience, because PenTest+ is published as an entry-level exam with no recommended background
One year of help-desk work plus a mandatory A+ certification before you may schedule
Mandatory passage of Security+ before Pearson VUE will allow you to purchase a PT0-003 voucher
Three to four years in a penetration tester job role, with Network+ and Security+ or equivalent knowledge
Sections you finish are checked off in the contents.