SecuSparkSecuSpark
Practice TestsFlashcardsFeaturesPricingBlogChangelogAbout
Start Free

Practice Tests

  • Security+ Practice Test
  • A+ Practice Test
  • Network+ Practice Test
  • CySA+ Practice Test
  • PenTest+ Practice Test
  • SecAI+ Practice Test
  • Claude Architect Practice Test

Free Tools

  • Port Number Lookup
  • CompTIA Acronym Finder
  • Subnet Calculator
  • Exam Cost Calculator
  • Salary Calculator by City
  • Security+ PBQ Simulator

Guides

  • Security+ Certification Guide
  • Certification Overlap
  • Exam Objectives
  • Acronym Glossary
  • Salaries by Region
  • Solutions
  • FAQ
  • All Study Guides

Company

  • About
  • Features
  • Pricing
  • Changelog
  • Free Tools

© 2026 SecuSpark. CompTIA, Security+, A+, Network+, CySA+, PenTest+, and SecAI+ are registered trademarks of CompTIA, Inc. SecuSpark is not affiliated with, endorsed by, or sponsored by CompTIA, Inc.

PrivacyTermsCookies
SecuSparkSecuSpark
Practice TestsFlashcardsFeaturesPricingBlogChangelogAbout
Start Free
  1. Home
  2. Exam Objectives
  3. CompTIA PenTest+ PT0-003 Exam Objectives

PenTest+ PT0-003

CompTIA PenTest+ PT0-003 Exam Objectives

The PenTest+ PT0-003 exam covers the full penetration-testing lifecycle across five domains. Attacks and Exploits is the single heaviest at 35%, but Engagement Management — scoping, rules of engagement, and the remediation advice in the report — is what separates a professional pentester from a script runner.

5 domains|552 questions| 100–150 hours
Practice PenTest+ Free

3 practice exams free — no signup needed

PT0-003 Domains & Weights

1.0Engagement Management

13%

Pre-engagement activities, scoping and rules of engagement, legal and ethical boundaries, collaboration with the client, and writing the report with remediation recommendations.

2.0Reconnaissance and Enumeration

21%

Passive and active information gathering, OSINT, host and service discovery, and enumeration of networks, web applications, cloud assets, and users.

3.0Vulnerability Discovery and Analysis

17%

Selecting and running vulnerability scans, static and dynamic application analysis, and validating and prioritizing findings.

4.0Attacks and Exploits

35%

The largest domain: network, wireless, application, cloud, mobile, IoT, and social-engineering attacks, plus the scripting and tooling that run them.

5.0Post-exploitation and Lateral Movement

14%

Persistence, privilege escalation, lateral movement, data exfiltration, staging, and cleaning up after the engagement.

PenTest+ Objectives FAQ

How many domains are on the PenTest+ PT0-003 exam?

Five: Engagement Management (13%), Reconnaissance and Enumeration (21%), Vulnerability Discovery and Analysis (17%), Attacks and Exploits (35%), and Post-exploitation and Lateral Movement (14%). PT0-003 replaced PT0-002's Planning and Scoping / Tools and Code Analysis domains when it launched in December 2024.

Which PenTest+ domain is weighted the most?

Attacks and Exploits at 35%. It's the technical core of the exam, but Engagement Management (13%) covers scoping, rules of engagement, and the report — the part real engagements are judged on, so don't skip it.

Practice PenTest+ by Domain

552 questions across 25 exams, weighted to match the PT0-003 domains above. 3 free — no signup.

Start Free Practice Test

Related Resources

PenTest+ Practice Test·All Exam Objectives·All Practice Tests