CompTIA PenTest+ (PT0-003) Practice Test
Use the free 20-question sets to find the part of PT0-003 that is costing you marks. Each test runs on a roughly 37-minute clock, matching the exam's average pace. When you need a full dress rehearsal, the 90-question tests run for the complete 165 minutes.
Mixed-set PenTest+ practice tests
Five 20-question sets spread across all five PT0-003 domains. Attacks and Exploits carries 35% of the official blueprint, so it appears more often than any other domain.
Domain-wise PT0-003 practice tests
Once a mixed set shows the weak spot, isolate it. Each domain test gives you 20 questions from one part of the PT0-003 blueprint.
Twenty questions finds the gap.
Ninety questions tests the whole run.
A short set is useful for diagnosis. It does not make you manage 165 minutes across engagement rules, recon, vulnerability analysis, exploitation and post-exploitation in one attempt. Use the full-length tests when pacing and decision quality need to hold together from question 1 to question 90.
| Free tests on this page | Full-length tests | |
|---|---|---|
| Questions | 20 | 90 |
| Time limit | About 37 minutes | 165 minutes |
| Coverage | Mixed sample or one domain | All five domains at a fixed 12 / 19 / 15 / 31 / 13 split |
| Score you get | Percentage correct | Estimated 100–900 practice score against 750 |
| Per-domain view | — | Five-domain performance view |
| Choose-TWO | — | 10 per test, scored all-or-nothing |
| Exam conditions | Timed short set | Full 165-minute timed paper |
| Review | On-screen result and review | Explanation on every question |
| Number available | 10 free tests | 10 full-length tests · 900 questions |
| Price | Free | From $2₹99£1.47€1.70 a test |
How to use these tests
Use the short tests to learn where the problem is. Save the full-length papers for the point where you need to prove that the whole workflow still holds under a 165-minute clock.
Benchmark
Take two mixed sets before another revision pass. Look for the domain that keeps producing wrong answers, not just the headline score.
Start with Practice Test 1 →Drill the weak domain
Move into the matching domain test. For most candidates, Attacks and Exploits deserves extra time simply because it is 35% of PT0-003.
Practice Attacks and Exploits →Dress rehearsal
When the domain gaps are under control, move to 90 questions and stay under the full 165-minute clock. That exposes pacing problems a short set cannot.
Get full-length tests →About the CompTIA PenTest+ (PT0-003) exam
PT0-003 is the current PenTest+ exam. It launched on 17 December 2024, and PT0-002 retired on 17 June 2025.
What PenTest+ measures
CompTIA PenTest+ covers the full authorized penetration-testing workflow: engagement management, reconnaissance, vulnerability discovery, attacks and exploits, then post-exploitation and lateral movement. The official objectives put the biggest share on Attacks and Exploits at 35%, but the exam still expects you to respect scope, evidence and engagement rules before taking technical action.
PT0-003 includes multiple-choice and performance-based questions. CompTIA recommends three to four years in a penetration tester job role before attempting it.
Exam format
Exam code: PT0-003.
Questions: Maximum of 90.
Duration: 165 minutes.
Question types: Multiple-choice and performance-based.
Passing score: 750 on a 100–900 scale.
U.S. voucher price: $439.
Experience, renewal and retakes
Recommended experience: 3–4 years in a penetration tester role. Network+ and Security+ knowledge or equivalent is a useful foundation.
Formal prerequisites: None.
Certification cycle: Three years.
Continuing education: 60 CEUs over the three-year cycle.
Retakes: No required wait between the first and second attempt. Before the third and later attempts, wait at least 14 calendar days from the previous attempt.
PenTest+ PT0-003 domain weights
These are the percentages in CompTIA's PT0-003 Exam Objectives Version 3.0. Attacks and Exploits alone accounts for more than one-third of the exam.
| Domain | Topic | Weight | Questions in a 90-question full-length test |
|---|---|---|---|
| 1.0 | Engagement Management | 13% | 12 |
| 2.0 | Reconnaissance and Enumeration | 21% | 19 |
| 3.0 | Vulnerability Discovery and Analysis | 17% | 15 |
| 4.0 | Attacks and Exploits | 35% | 31 |
| 5.0 | Post-exploitation and Lateral Movement | 14% | 13 |
How the practice tests are built
Scenario first. PenTest+ rarely rewards pure tool-name recall. A strong PT0-003 question gives you an engagement constraint, evidence and a phase of the test, then asks for the action that fits all three.
The blueprint matters. Mixed sets spread questions across the five official domains. The full-length papers go further and keep the same fixed 12 / 19 / 15 / 31 / 13 allocation every time, so one score can be compared with the next.
The clock changes the problem. A 20-question set gives you about 37 minutes at the exam's average pace. A full-length paper gives you the complete 165-minute window. Use both. They answer different questions about your readiness.
Know the workflow. Scope before attack. Gather evidence before exploitation. Clean up and report when the engagement requires it. PT0-003 tests technical ability inside professional constraints.
PenTest+ preparation tips
Study strategy
Give Domain 4 the time its weight deserves. Attacks and Exploits is 35% of PT0-003. Network, authentication, web, wireless and cloud attack decisions need to feel familiar before exam day.
Do not study exploitation in isolation. Engagement rules can make a technically valid action wrong. Recon and vulnerability evidence decide what you should attack, and reporting decides what the engagement produces.
Read tool output, not just tool lists. Practise interpreting short Nmap results, web responses, vulnerability findings and scripts. PT0-003 is much easier when the evidence is familiar at a glance.
Test-taking strategy
Watch the qualifier. BEST, FIRST and NEXT change the question. Two options can be technically possible while only one belongs in the current phase.
Use the 165 minutes deliberately. The average is about 1 minute 50 seconds per question. If one item starts consuming several minutes, mark the decision point and move.
Let scope beat cleverness. When an answer would exceed authorization, create unnecessary impact or skip required evidence, it should lose even if the technique itself would work.
Frequently asked questions
CompTIA lists a maximum of 90 questions in 165 minutes. The exam includes multiple-choice and performance-based questions.
The passing score is 750 on a 100–900 scale. It is a scaled score, not a fixed raw percentage.
Yes. PT0-003 launched on 17 December 2024. PT0-002 retired on 17 June 2025.
The current U.S. list price for a PenTest+ exam voucher is $439.
There is no required waiting period between the first and second attempt. Before the third attempt and every later attempt, CompTIA requires at least 14 calendar days from the previous attempt.
PenTest+ is valid for three years. CompTIA's continuing education path requires 60 CEUs during that three-year cycle.
Yes. The full-length PT0-003 practice tests contain 90 questions each with a 165-minute practice window. Every test has 80 single-answer questions and 10 choose-TWO questions, uses the same five-domain allocation, and returns an estimated 100–900 practice score against the 750 benchmark. There are 10 full-length tests, 900 questions in total, from $2₹99£1.47€1.70 per test.
Yes. The five mixed sets and five domain tests on this page are free. Each contains 20 questions.
CompTIA recommends three to four years in a penetration tester job role. Network+ and Security+ knowledge or equivalent experience gives you the networking and security foundation PT0-003 assumes.
Start with the domain your mixed-set results show is weakest. If you do not have a baseline yet, Domain 4, Attacks and Exploits, deserves the most study time because it carries 35% of the exam.
Start short. Go full-length when pacing matters.
Use a free 20-question set to find the weak domain. When you are ready to test the whole PT0-003 blueprint under the complete 165-minute clock, move to a 90-question practice test.
Exam details reflect CompTIA's PT0-003 Exam Objectives Version 3.0 and current certification policies as reviewed in September 2026.
Authors
-
Security Practice Test Editorial Team is the expert content team at SecurityPracticeTest.com dedicated to producing authoritative cybersecurity certification exam-prep resources. We create comprehensive practice tests, study materials, and exam-focused content for top security certifications including CompTIA Security+, SecurityX, PenTest+, CISSP, CCSP, SSCP, Certified in Cybersecurity (CC), CGRC, CISM, SC-900, SC-200, AZ-500, AWS Certified Security - Specialty, Professional Cloud Security Engineer, OSCP+, GIAC certifications, CREST certifications, Check Point, Cisco, Fortinet, and Palo Alto Networks exams. Our content is developed through careful review of official exam objectives, cybersecurity knowledge domains, and practical job-relevant concepts to help learners build confidence, strengthen understanding, and prepare effectively for certification success.
-
Sudhanshu Thakur: ReviewerEnterprise Technology and Digital Transformation Professional with 18+ years of experience in enterprise software, SaaS, industrial automation, and business consulting. Formerly associated with Rockwell Automation, Tech Mahindra, Emerson, ABB, L&T Infotech, and Hewlett Packard Enterprise.