Penetration testing study guide
Aligned to CompTIA PenTest+ PT0-003 public domain weights
675 practice questions
60 flashcards
Completely free

CompTIA PenTest+ Exam Prep

Practice engagement management, reconnaissance, enumeration, vulnerability analysis, controlled exploit validation, post-exploitation boundaries, and reporting with 675 original PenTest+ questions.

675 original questions
PT0-003 aligned
Authorized scenarios

Most popular

Start with free practice questions

Jump into a mixed set drawn from 675 free practice questions.

Free Practice Questions

Exam structure

Know the split before you start drilling

Engagement Management

13%

13 scored + 0 pretest

Reconnaissance and Enumeration

21%

21 scored + 0 pretest

Vulnerability Discovery and Analysis

17%

17 scored + 0 pretest

Attacks and Exploits

35%

35 scored + 0 pretest

Post-exploitation and Lateral Movement

14%

14 scored + 0 pretest

Current exam

PT0-003

The bank is aligned to the public PT0-003 domain structure.

Exam size

Max 90

PenTest+ uses multiple-choice and performance-based questions.

Testing time

165 minutes

Use timed mocks after engagement and validation drills are stable.

Passing score

750

CompTIA reports scores on a 100-900 scale.

Weighted mock

100 questions

The mock preserves the public 13/21/17/35/14 domain balance.

Practice bank

675 questions

The bank expands PenTest+ public domains into original scenario questions.

Start here

How to study for CompTIA PenTest+

Use this sequence for a clean PenTest+ pass.

1

1. Anchor authorization and scope

Know rules of engagement, exclusions, test windows, escalation, target selection, and communication before technical decisions.

2

2. Build recon and validation judgment

Practice passive versus active recon, enumeration, scanning safety, validation, false positives, and risk prioritization.

3

3. Finish with safe impact proof

Tie controlled validation, attack paths, post-exploitation boundaries, cleanup, and reporting to business risk.

About the exam

PenTest+ Exam structure

CompTIA PenTest+ PT0-003 prep with 675 original practice questions, domain-weighted mocks, ethical testing drills, flashcards, and topic recovery.

Issuer and path

CompTIA PenTest+ Exam Prep is administered through CompTIA. Check official resources before booking, retesting, or relying on a stale requirement.

Engagement Management

13%

13 scored + 0 pretest

Pre-engagement activities, scope, rules of engagement, legal authorization, compliance, communication, constraints, and post-engagement cleanup.

Reconnaissance and Enumeration

21%

21 scored + 0 pretest

Passive and active reconnaissance, target discovery, open-source intelligence, network enumeration, service identification, and tool selection.

Vulnerability Discovery and Analysis

17%

17 scored + 0 pretest

Vulnerability scanning, validation, prioritization, configuration review, web application testing concepts, and vulnerability analysis.

Attacks and Exploits

35%

35 scored + 0 pretest

Exploit selection, attack paths, social engineering constraints, web application attacks, network attacks, cloud, wireless, and validation of impact.

Post-exploitation and Lateral Movement

14%

14 scored + 0 pretest

Post-exploitation objectives, privilege context, pivoting concepts, persistence risks, cleanup, documentation, and reporting evidence.

Before you schedule

Confirm the PenTest+ exam code, voucher dates, testing option, ID requirements, system test for online delivery, and retake policy before booking.

Official Outline Coverage Map

Coverage is mapped to official outline item counts so content depth can be checked without hard-coding a single exam.

Official outline
TopicOfficial outline itemsYour questionsYour flashcardsConfidence
Scope, Authorization and Rules of Engagement138810
Priority
Passive, Active Reconnaissance and Enumeration2114210
Strong
Scanning, Validation and Vulnerability Prioritization1711510
Priority
Web, Network, Cloud and Exploit Validation1812110
Priority
Attack Chaining, Impact Control and Safety1711510
Strong
Post-exploitation, Lateral Movement, Cleanup and Reporting149410
Strong

How to use this guide

How to study for CompTIA PenTest+

Treat each PenTest+ item as an authorized-assessment decision: confirm scope, select safe evidence, validate risk, stop at the right point, and report remediation.

1. Confirm permission

Verify scope, targets, exclusions, test window, escalation, and client rules before action.

2. Gather and validate evidence

Use appropriate recon, enumeration, scanning, and validation methods under approved constraints.

3. Prove risk safely

Show impact with least disruption, data minimization, and clear stop conditions.

4. Clean up and report

Remove artifacts, document findings, translate risk, and recommend remediation and retesting.

Scope, Authorization and Rules of Engagement
Engagement

Scope, Authorization and Rules of Engagement

PenTest+ starts with legal authorization, scope definition, rules of engagement, exclusions, test windows, escalation, targets, and stakeholder communication.

Key rules

Rule 1

A penetration test must begin with explicit authorization, scope, constraints, and communication paths.

Exam cue: Verify authorization, target scope, constraints, test window, and escalation path.

Rule 2

Rules of engagement protect the client, tester, and production environment by setting boundaries before testing.

Exam cue: Use rules of engagement before touching systems.

Rule 3

Scope decisions should address targets, exclusions, timing, data handling, evidence, and escalation.

Exam cue: Document exclusions and client-approved boundaries.

Common traps

Testing a target because it appears related but is not in scope.

Prevention: Avoid answers that exceed scope, skip authorization, use destructive proof, collect unnecessary sensitive data, or leave artifacts behind.

Starting active testing before authorization is documented.

Prevention: Avoid answers that exceed scope, skip authorization, use destructive proof, collect unnecessary sensitive data, or leave artifacts behind.

Skipping escalation instructions for production-impacting findings.

Prevention: Avoid answers that exceed scope, skip authorization, use destructive proof, collect unnecessary sensitive data, or leave artifacts behind.

Memory anchors

Authorization

Authorization documents permission to test defined systems under agreed conditions.

Rules of Engagement

Rules of engagement define scope, timing, methods, communication, escalation, and constraints.

Scope Definition

Scope definition identifies included targets, excluded systems, assumptions, and testing boundaries.

Testing Window

A testing window limits when activity may occur to reduce operational disruption.

Escalation Process

An escalation process tells testers who to contact when risk, outage, or sensitive findings arise.

NDA

A nondisclosure agreement protects confidential engagement information.

Statement of Work

A statement of work defines services, deliverables, scope, timeline, and responsibilities.

Target Selection

Target selection identifies authorized systems, networks, applications, or users for testing.

Exclusion

An exclusion is an explicitly out-of-scope system, technique, time, or data category.

Communication Plan

A communication plan defines status cadence, contacts, emergency channels, and expected updates.

Next best moves

Quick check-up

Use a short quiz to confirm the rule pattern is actually sticking.

Check-up Questions

1-2 question checkpoint

During kickoff a client verbally approves testing an additional subnet that is not listed in the signed statement of work. What should the tester do before scanning it?

Which document primarily establishes the deliverables, timeline, and responsibilities for a specific penetration test engagement?

Answer all questions to submit.

Next step personalized recommendations

Open another topic next

Official resources

Verify the details with the official sources

Use these links for eligibility, scheduling, handbook rules, and issuer updates. Our guide helps you study; official sources tell you what the testing partner currently requires.

FAQ

Common PenTest+ questions

Is this the official CompTIA PenTest+ exam?

No. These are original practice questions aligned to public PenTest+ PT0-003 domains. They are not copied from secure exam material.

What should I study first?

Start with scope, authorization, rules of engagement, recon boundaries, evidence handling, and vulnerability validation before attack-path scenarios.

Does this teach unauthorized hacking?

No. The content is framed around authorized assessments, risk validation, safety boundaries, communication, cleanup, and remediation.

Why are there 675 questions?

The larger bank supports repeated domain drills without memorizing a small set of prompts.

How should I use the 675 questions?

Use engagement and recon drills first, then vulnerability and exploit-validation drills, then full mocks to practice scope-safe decisions.

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.