CompTIA PenTest+ (PT0-003) Full-Length Practice Test
Ninety questions under the full 165-minute clock. Ten independent PT0-003 practice tests use the same five-domain blueprint and return an estimated 100–900 practice score against the 750 benchmark.
- 90 questions / 165 min
- Estimated 100–900 score
- 750 benchmark
- 10 choose-TWO questions
- 5 PT0-003 domains
Choose one test, five, or the complete set
Every option uses the same 90-question format, the same 165-minute window and the same fixed PT0-003 blueprint. The difference is how many fresh papers you get.
One test
90 questions
One complete 165-minute practice run
- 90 questions across all five PT0-003 domains
- 80 single-answer and 10 choose-TWO questions
- Estimated 100–900 practice score
- An explanation for every question
All 10 tests
900 questions
Ten separate full-length PT0-003 papers
- 900 questions across the complete set
- 100 choose-TWO questions across ten tests
- Same 12 / 19 / 15 / 31 / 13 domain allocation every time
- Same 20 easy / 42 medium / 28 hard difficulty mix
- Fresh paper each time you want a new benchmark
Five tests
450 questions
Five complete 165-minute practice runs
- 450 PT0-003 questions
- 50 choose-TWO questions across the pack
- Same five-domain blueprint in every test
- Five separate papers for spaced practice
What CompTIA currently sets on PenTest+ PT0-003
PT0-003 launched on 17 December 2024 and is the current PenTest+ exam. The older PT0-002 exam retired on 17 June 2025.
| Exam code | PT0-003 |
| Launched | 17 December 2024 |
| Questions | Maximum of 90 |
| Duration | 165 minutes |
| Passing score | 750 on a 100–900 scale |
| Question types | Multiple-choice and performance-based |
| Recommended experience | 3–4 years in a penetration tester role, with Network+ and Security+ knowledge or equivalent |
| U.S. exam voucher | $439 |
| Certification cycle | 3 years; 60 CEUs for renewal |
Written to the PT0-003 objectives
PT0-003 is an end-to-end penetration-testing exam. The current outline starts with engagement management, moves through reconnaissance and vulnerability analysis, then puts its biggest share into attacks and exploits before finishing with post-exploitation and lateral movement.
The ten practice tests use that same structure. Each paper fixes the domain allocation at 12 / 19 / 15 / 31 / 13 questions, so a later result is comparable with an earlier one instead of being pushed around by a different blueprint.
The questions are original and written to the current objectives. They focus on authorized testing decisions: scope, evidence, technique selection, safe validation, exploitation, cleanup and reporting.
One hundred and sixty-five minutes of applied decisions
PenTest+ is not a tool-name quiz. A good question gives you a target, evidence and an engagement constraint, then makes you choose the action that fits the current phase.
How it’s built
- 90 questions in a 165-minute practice window
- 80 single-answer questions
- 10 choose-TWO questions, scored all-or-nothing
- 20 easy, 42 medium and 28 hard questions
- No negative marking in the practice engine
- Same blueprint across all ten tests
Under the clock
- About 1 minute 50 seconds per question on average
- Scenario-led questions make you find the deciding constraint first
- Evidence can include scan output, logs, web requests and short scripts
- Scope and rules of engagement can make a technically possible action wrong
- Cloud, API, web, network, wireless and post-exploitation scenarios all appear
What comes back
- Estimated practice score on the 100–900 scale
- 750 used as the pass benchmark
- An explanation on every question
- The reason the correct choice fits the evidence
- Why the strongest alternative loses on scope, phase or technical detail
Every test follows the same five-domain blueprint
Attacks and Exploits is the largest domain at 35%. The fixed 90-question practice form converts CompTIA’s published weights into a repeatable 12 / 19 / 15 / 31 / 13 question split.
| PT0-003 domain | CompTIA weight | Questions per practice test |
|---|---|---|
| 1.0 Engagement Management | 13% | 12 |
| 2.0 Reconnaissance and Enumeration | 21% | 19 |
| 3.0 Vulnerability Discovery and Analysis | 17% | 15 |
| 4.0 Attacks and Exploits | 35% | 31 |
| 5.0 Post-exploitation and Lateral Movement | 14% | 13 |
All 10 CompTIA PenTest+ PT0-003 full-length practice tests
Each test has 90 questions, a 165-minute practice window, ten choose-TWO questions and the same five-domain allocation.
About the PenTest+ exam and these practice tests
The PT0-003 exam
How many questions are on the CompTIA PenTest+ PT0-003 exam?
CompTIA lists a maximum of 90 questions in 165 minutes. The live exam uses multiple-choice and performance-based questions.
What score do I need to pass PenTest+?
The passing score is 750 on a 100–900 scale. It is a scaled score, not a statement that you need a fixed raw percentage correct.
Is PT0-003 the current PenTest+ exam?
Yes. PT0-003 launched on 17 December 2024. The previous PT0-002 exam retired on 17 June 2025.
What experience does CompTIA recommend?
CompTIA recommends three to four years in a penetration tester job role, with Network+ and Security+ knowledge or equivalent experience.
How much does the PenTest+ exam cost?
The current U.S. list price for a PenTest+ exam voucher is $439.
If I fail, when can I retake the exam?
There is no required waiting period between the first and second attempt. Before the third attempt and every later attempt, CompTIA requires at least 14 calendar days from the previous attempt.
How long is the PenTest+ certification valid?
PenTest+ is valid for three years. Renewal through CompTIA’s continuing education programme requires 60 CEUs during the three-year cycle.
These practice tests
How many questions are in each full-length practice test?
Each practice test contains 90 questions with a 165-minute practice window. Five tests contain 450 questions, and all ten contain 900.
What answer formats are included?
Each test contains 80 single-answer questions and 10 choose-TWO questions. Both required answers must be selected for a choose-TWO item to score.
Do these tests use the same question types as the live exam?
The live exam includes multiple-choice and performance-based questions. These practice tests use 90 selected-response questions: 80 single-answer and 10 choose-TWO.
How is the practice score shown?
The result engine returns an estimated score on the 100–900 scale and uses 750 as the practice benchmark. The scale is there to keep the target familiar; it does not reproduce CompTIA’s undisclosed weighting formula.
Are the ten tests built to the same difficulty and domain mix?
Yes. Every test uses 12 / 19 / 15 / 31 / 13 questions across the five domains and the same 20 easy / 42 medium / 28 hard difficulty mix.
Does every question include an explanation?
Yes. Each question includes a learner-facing explanation that covers why the correct choice fits and why the strongest alternative misses the evidence, scope or phase.
Is this a subscription?
No. Choose one test, five tests or all ten and pay once for that purchase.
What are the pack prices?
One test costs $2₹99£1.47€1.70. Five tests cost $5₹299£3.67€4.27, and all ten cost $9₹499£6.60€7.69.
Ten practice tests. 900 questions.
$9₹499£6.60€7.69
Use the short study sessions for learning. Use a 165-minute paper to find out whether the decisions still hold together when the clock is running.
Authors
-
Security Practice Test Editorial Team is the expert content team at SecurityPracticeTest.com dedicated to producing authoritative cybersecurity certification exam-prep resources. We create comprehensive practice tests, study materials, and exam-focused content for top security certifications including CompTIA Security+, SecurityX, PenTest+, CISSP, CCSP, SSCP, Certified in Cybersecurity (CC), CGRC, CISM, SC-900, SC-200, AZ-500, AWS Certified Security - Specialty, Professional Cloud Security Engineer, OSCP+, GIAC certifications, CREST certifications, Check Point, Cisco, Fortinet, and Palo Alto Networks exams. Our content is developed through careful review of official exam objectives, cybersecurity knowledge domains, and practical job-relevant concepts to help learners build confidence, strengthen understanding, and prepare effectively for certification success.
-
Sudhanshu Thakur: ReviewerEnterprise Technology and Digital Transformation Professional with 18+ years of experience in enterprise software, SaaS, industrial automation, and business consulting. Formerly associated with Rockwell Automation, Tech Mahindra, Emerson, ABB, L&T Infotech, and Hewlett Packard Enterprise.