Start Your Free Practice Test
Enter your details, then choose a 25-question Quick Test or the full 50-question, 90-minute practice test.
Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Check your readiness for the CompTIA PenTest+ (PT0-003) exam with 50 exam-style questions across all five domains, each with an instant explanation. Free to take, with a 90-minute timer that matches the pace of the real exam, and retake it as often as you want.
New to PenTest+? Learn more about the certification →
Enter your details, then choose a 25-question Quick Test or the full 50-question, 90-minute practice test.
This free CompTIA PenTest+ practice test checks your readiness for the PT0-003 exam with 50 exam-style questions across all five domains, each with an explanation for every answer choice, on a 90-minute timer. Built by Training Camp and drawn from the same objectives we teach in our CompTIA PenTest+ Boot Camp. If you are new to the certification, start with what is PenTest+.
The PT0-003 exam has five weighted domains: Engagement Management (13%), Reconnaissance and Enumeration (21%), Vulnerability Discovery and Analysis (17%), Attacks and Exploits (35%), and Post-exploitation and Lateral Movement (14%). You get 165 minutes for a maximum of 90 questions, which are a mix of multiple choice and performance-based items, and you need a scaled score of 750 on a scale of 100 to 900 to pass. PT0-003 is the current version, launched in December 2024.
PenTest+ sits at the intermediate level. There are no formal prerequisites, but CompTIA recommends Network+ and Security+ or equivalent knowledge along with three to four years of hands-on penetration testing or related experience. The certification is valid for three years and can be renewed through continuing education.
Take it once without notes to get an honest baseline, then read the explanation for every answer, including the ones you got right. The incorrect-choice explanations are where the distinctions the exam likes to test (SAST versus DAST, pass-the-hash versus pass-the-ticket, CVSS versus EPSS) get spelled out. Study your weakest domain and retake the test in a week. Every scenario here is framed as an authorized engagement with a signed scope, which mirrors how the exam expects you to think: the rules of engagement come first, and the right next step is always the one that stays inside scope.
Domains Covered · PT0-003
Scoping, rules of engagement, agreements, methodologies, reporting, and remediation guidance.
Passive and active recon, OSINT, DNS, enumeration techniques, scripting, and the right tools.
Scan types, authenticated scanning, output analysis, exploit selection, and physical security.
Network, authentication, host, web, cloud, wireless, social engineering, and specialized attacks.
Persistence, lateral movement, pivoting, staging and exfiltration, and cleanup.
Four questions from the bank, one per domain, with the reasoning behind every answer. The full test has 50.
A client requires that one legacy system never be tested during an authorized assessment. Which of the following sections of the rules of engagement records this requirement?
Correct. Exclusions in the rules of engagement list the systems, addresses or techniques that are off limits for the engagement. A system that must never be tested is recorded there.
A tester reviews an authorized target's certificate transparency logs and public DNS records without sending any packets to the client's systems. Which of the following BEST describes this activity?
Correct. Passive reconnaissance gathers information from public sources such as search engines, DNS records and certificate transparency logs, so the target never sees traffic from the tester.
Which of the following application security testing approaches examines source code for flaws without running the application?
Correct. Static application security testing (SAST) analyzes source code or compiled binaries without executing them, which is why it is often described as white-box or code review testing.
A tester needs to prioritize confirmed vulnerabilities by how likely each one is to be exploited in the near term. Which of the following metrics should the tester use?
Correct. The Exploit Prediction Scoring System (EPSS) estimates the probability that a vulnerability will be exploited in the wild within the next 30 days, which is exactly the likelihood question being asked.
Every one of the 50 questions works this way: an explanation for the right answer and for the one you picked, so a wrong answer teaches you something. Questions last reviewed against the current CompTIA PenTest+ (PT0-003) objectives.
Quick answers about the test, the CompTIA PenTest+ (PT0-003) exam, and how to prepare.
Yes. Training Camp's CompTIA PenTest+ (PT0-003) practice test is free to take. You get 50 exam-style questions across all five domains, with a written explanation for every answer choice.
It is 50 multiple-choice scenario questions drawn from all five PT0-003 domains, with an instant explanation after each answer and a 90-minute timer. You can retake it as often as you want. Treat it as a readiness check rather than a substitute for full preparation.
The PT0-003 exam has a maximum of 90 questions and gives you 165 minutes. The questions are a mix of multiple choice and performance-based items, where you complete a hands-on style task rather than pick a single answer.
You need a scaled score of 750 on a scale of 100 to 900. CompTIA reports one overall scaled score, so a strong domain can offset a weaker one. There is no separate bar to clear in each domain.
The five domains are Engagement Management (13%), Reconnaissance and Enumeration (21%), Vulnerability Discovery and Analysis (17%), Attacks and Exploits (35%), and Post-exploitation and Lateral Movement (14%). Attacks and Exploits is the largest, so most of your study time belongs there.
There are no formal prerequisites. CompTIA recommends CompTIA Network+ and CompTIA Security+ or equivalent knowledge along with three to four years of hands-on penetration testing or related experience, which makes it an intermediate rather than an entry-level certification.
PenTest+ is valid for three years from the date you pass. You renew it through CompTIA's continuing education program, by earning credits or a higher-level certification, rather than by retaking the exam.
Start with the PT0-003 exam objectives and learn each attack, tool and reporting step at the level the objectives name, then use practice questions like these to find your weak domains. If you want a structured path with an instructor and hands-on labs, our CompTIA PenTest+ Boot Camp covers all five domains.