HomeRoadmaps › CompTIA PenTest+ PT0-003
Current CompTIA PenTest+ V3

CompTIA PenTest+ V3 PT0-003 Roadmap

Prepare across engagement management, reconnaissance, vulnerability analysis, attacks and exploits, and post-exploitation by treating authorization, minimum impact, evidence, remediation, retest, and complete cleanup as one controlled lifecycle.

PT0-003165 minutesMaximum 90 questionsMultiple-choice and performance-based5 domains
Authorization and exam scope: CompTIA lists PT0-003 V3 as 165 minutes with a maximum of 90 multiple-choice and performance-based questions. PrepKloud's 50 questions are an independent proportional study set—not a claim about the live count or mix. Every lab is restricted to isolated owned targets under explicit written authorization with synthetic data and harmless proofs. Verify the official PenTest+ page and official PT0-003 objectives.

Exact 50-question proportional allocation

Engagement management · 13% · 7Authorization, scope, rules, legal and ethical constraints, collaboration, escalation, evidence, reports, and retest.
Reconnaissance and enumeration · 21% · 10Passive and active discovery, DNS, services, directories, certificates, cloud inventory, packet evidence, and bounded scripts.
Vulnerability discovery and analysis · 17% · 9Network, host, application, source, dependency, image, configuration, validation, coverage, priority, and retest.
Attacks and exploits · 35% · 17Safe defensive validation of network, identity, host, web, API, cloud, container, and AI control failures.
Post-exploitation and lateral movement · 14% · 7Canary-based impact, excessive privilege, segmentation, attack narratives, remediation, visible simulation, and cleanup.
1

Engagement authority and safe range design

Weeks 1–2: make authorization a technical control, not a paragraph forgotten after kickoff.

  • Define parties, owned targets, accounts or tenants, methods, payload classes, dates, windows, rates, exclusions, and third parties.
  • Set service-health monitoring, emergency contacts, stop conditions, rollback authority, evidence rules, retention, cost limits, and cleanup acceptance.
  • Translate signed scope into machine-enforced target, identity, endpoint, protocol, and method allowlists.
  • Use private reserved addressing, denied public and production routes, disposable snapshots, synthetic identities, and inert canary data.
  • Plan immediate critical-finding escalation and mandatory-reporting consultation through named legal and engagement contacts.
  • Protect evidence through provenance, encryption, need-to-know access, redaction, transfer records, and scheduled deletion.
  • Practice executive and technical report structures and retest criteria before the first probe.
  • Complete all 7 Engagement management questions.
2

Reconnaissance, enumeration, and coverage

Weeks 3–4: build an accurate attack-surface map without confusing discovery with permission.

  • Distinguish passive approved metadata from direct active interaction with a target.
  • Validate ownership and freshness for registration, certificate, archive, and public-like range fixtures.
  • Start active discovery at safe rates, observe health, respect exclusions, and expand only within the rules of engagement.
  • Enumerate DNS, certificates, protocols, routes, applications, APIs, synthetic directories, and read-only cloud inventories.
  • Do not identify services by port alone; correlate protocol behavior, certificate, banner, response, and owner records.
  • Bind scripts to exact target and account identifiers with dry runs, timeouts, concurrency limits, errors, and audit logs.
  • Minimize packet collection by interface, filter, field, duration, access, and retention.
  • Complete all 10 Reconnaissance and enumeration questions.
3

Vulnerability discovery and safe validation

Weeks 5–6: combine complementary methods and distinguish presence, reachability, exploitability, and impact.

  • Use bounded authenticated and unauthenticated host scanning plus source, dependency, image, configuration, application, and API analysis.
  • Verify credentials, privileges, platform support, policies, target reachability, and successful checks before interpreting clean results.
  • Reconcile duplicate findings while preserving original evidence and tool versions.
  • Validate version findings with vendor advisories, package provenance, configuration, and non-destructive checks.
  • Prioritize validation by reachability, exploitability, controls, target value, business impact, and operational safety.
  • Use synthetic objects, inert files, canary endpoints, and safe policy evidence instead of real data or harmful payloads.
  • During retest, verify the deployed version, root condition, alternative paths, regressions, and service health.
  • Complete all 9 Vulnerability discovery and analysis questions.
4

Attacks, exploits, and bounded attack paths

Weeks 7–8: understand exploit classes through defensive proof, remediation, and detection—not uncontrolled payload execution.

  • Study server-side object and function authorization, parameterized queries, context encoding, canonical paths, upload controls, sessions, and server-side fetch restrictions.
  • Assess cloud metadata, workload identity, effective policy, egress, secrets, container privilege, mounts, capabilities, and runtime isolation.
  • Evaluate identity defenses with synthetic accounts, MFA, breached-password screening, recovery, rate controls, and session revocation.
  • Treat AI retrieval content as untrusted data; expose no secrets or unrestricted tools and enforce policy outside the model.
  • Reject destructive public proof-of-concept behavior; use code review, vendor evidence, safe indicators, or reviewed inert rewrites.
  • Use designated canaries to validate segmentation and privilege without collecting credentials or unrelated files.
  • Keep monitoring enabled and activity visible. Do not practice stealth, evasion, destructive payloads, real-target testing, or durable persistence.
  • Complete all 17 Attacks and exploits questions.
5

Post-exploitation reporting, remediation, and cleanup

Weeks 9–10+: show how a path matters, then break it and prove the range is gone.

  • Build source-linked narratives of prerequisites, control gaps, minimum proofs, impact, detections, remediation, limitations, and cleanup.
  • Separate demonstrated access from possible next steps and avoid claims of total compromise from one path.
  • Replace standing administrative reach with tiering, just-in-time identities, hardened origins, restricted management paths, and session monitoring.
  • Simulate persistence only when pre-approved through a visible, expiring, reversible marker; remove it immediately after observation.
  • Complete the hybrid test, web/API/AI lab, and segmentation/identity path project.
  • Retest original and adjacent paths, required business flows, detections, service health, and rollback.
  • Review 40 cards and all 50 questions, explaining authorization, evidence, minimum impact, and cleanup in every answer.
  • Attest that no identity, token, file, task, process, rule, listener, route, snapshot, schedule, raw artifact, or charge remains.

Three deep authorized projects

Authorized Hybrid Penetration TestFull lifecycle across network, web, API, identity, and cloud-like controls with inert proofs and retest.
Web, API, and AI AssessmentOwned container stack, layered discovery, defensive application validation, AI boundaries, regression, and deletion.
Segmentation and Identity PathsSynthetic identities, canary access, visible simulation, JIT remediation, detection validation, and teardown.

All learning surfaces

Official sources

Frequently asked questions

What is the current PenTest+ exam code?

The current CompTIA PenTest+ V3 exam is PT0-003.

How long is PT0-003 and which formats can appear?

CompTIA lists 165 minutes and a maximum of 90 questions, including multiple-choice and performance-based questions.

What are the official domain weights?

Engagement management 13%, Reconnaissance and enumeration 21%, Vulnerability discovery and analysis 17%, Attacks and exploits 35%, and Post-exploitation and lateral movement 14%.

How are the 50 practice questions allocated?

Using the requested exact proportional allocation: 7, 10, 9, 17, and 7 across the five domains, split 25 and 25.

Are the projects safe and authorized?

Yes. They require isolated owned environments, written scope, synthetic identities and data, inert canaries, visible reversible activity, monitoring, and verified cleanup. They prohibit credential theft, stealth and evasion, real targets, destructive payloads, and durable persistence.

Are the materials exam dumps?

No. They are independently authored educational scenarios based on CompTIA's public current page and objectives, without live, recalled, leaked, or proprietary items.

Independence, authorization, and safety: PrepKloud is independent and not affiliated with or endorsed by CompTIA. CompTIA and related marks belong to CompTIA. No activity authorizes testing outside an isolated owned range. No pass guarantee or exact live exam count or mix is claimed.

Practice the full authorized lifecycle

Start with signed scope, gather minimum evidence, remediate and retest, and prove cleanup.

Start questionsReview cardsOpen projectsRead guide