Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Free Practice Test

Free PenTest+ Practice Test 2026 (PT0-003)

Check your readiness for the CompTIA PenTest+ (PT0-003) exam with 50 exam-style questions across all five domains, each with an instant explanation. Free to take, with a 90-minute timer that matches the pace of the real exam, and retake it as often as you want.

25 or 50 Questions 90-Minute Timer 5 PT0-003 Domains Every Answer Explained New Sample Each Retake

New to PenTest+? Learn more about the certification →

Start Your Free Practice Test

Enter your details, then choose a 25-question Quick Test or the full 50-question, 90-minute practice test.

First Name
Last Name
Phone
About This Test

Free CompTIA PenTest+ (PT0-003) Practice Test

This free CompTIA PenTest+ practice test checks your readiness for the PT0-003 exam with 50 exam-style questions across all five domains, each with an explanation for every answer choice, on a 90-minute timer. Built by Training Camp and drawn from the same objectives we teach in our CompTIA PenTest+ Boot Camp. If you are new to the certification, start with what is PenTest+.

What's on the CompTIA PenTest+ (PT0-003) exam?

The PT0-003 exam has five weighted domains: Engagement Management (13%), Reconnaissance and Enumeration (21%), Vulnerability Discovery and Analysis (17%), Attacks and Exploits (35%), and Post-exploitation and Lateral Movement (14%). You get 165 minutes for a maximum of 90 questions, which are a mix of multiple choice and performance-based items, and you need a scaled score of 750 on a scale of 100 to 900 to pass. PT0-003 is the current version, launched in December 2024.

PenTest+ sits at the intermediate level. There are no formal prerequisites, but CompTIA recommends Network+ and Security+ or equivalent knowledge along with three to four years of hands-on penetration testing or related experience. The certification is valid for three years and can be renewed through continuing education.

How to use this practice test

Take it once without notes to get an honest baseline, then read the explanation for every answer, including the ones you got right. The incorrect-choice explanations are where the distinctions the exam likes to test (SAST versus DAST, pass-the-hash versus pass-the-ticket, CVSS versus EPSS) get spelled out. Study your weakest domain and retake the test in a week. Every scenario here is framed as an authorized engagement with a signed scope, which mirrors how the exam expects you to think: the rules of engagement come first, and the right next step is always the one that stays inside scope.

Domains Covered · PT0-003

Engagement Management13%

Scoping, rules of engagement, agreements, methodologies, reporting, and remediation guidance.

Reconnaissance and Enumeration21%

Passive and active recon, OSINT, DNS, enumeration techniques, scripting, and the right tools.

Vulnerability Discovery and Analysis17%

Scan types, authenticated scanning, output analysis, exploit selection, and physical security.

Attacks and Exploits35%

Network, authentication, host, web, cloud, wireless, social engineering, and specialized attacks.

Post-exploitation and Lateral Movement14%

Persistence, lateral movement, pivoting, staging and exfiltration, and cleanup.

Try Before You Start

Sample PenTest+ Practice Questions

Four questions from the bank, one per domain, with the reasoning behind every answer. The full test has 50.

Question 1 Engagement Management

A client requires that one legacy system never be tested during an authorized assessment. Which of the following sections of the rules of engagement records this requirement?

  1. Testing window
  2. Escalation process
  3. Exclusions Correct
  4. Test cases
Why this is the best answer

Correct. Exclusions in the rules of engagement list the systems, addresses or techniques that are off limits for the engagement. A system that must never be tested is recorded there.

Question 2 Reconnaissance and Enumeration

A tester reviews an authorized target's certificate transparency logs and public DNS records without sending any packets to the client's systems. Which of the following BEST describes this activity?

  1. Passive reconnaissance Correct
  2. Active reconnaissance
  3. Authenticated scanning
  4. Protocol fuzzing
Why this is the best answer

Correct. Passive reconnaissance gathers information from public sources such as search engines, DNS records and certificate transparency logs, so the target never sees traffic from the tester.

Question 3 Vulnerability Discovery and Analysis

Which of the following application security testing approaches examines source code for flaws without running the application?

  1. Dynamic application security testing (DAST)
  2. Interactive application security testing (IAST)
  3. Static application security testing (SAST) Correct
  4. Software composition analysis (SCA)
Why this is the best answer

Correct. Static application security testing (SAST) analyzes source code or compiled binaries without executing them, which is why it is often described as white-box or code review testing.

Question 4 Attacks and Exploits

A tester needs to prioritize confirmed vulnerabilities by how likely each one is to be exploited in the near term. Which of the following metrics should the tester use?

  1. The CVSS base score
  2. The EPSS score Correct
  3. The CVE number
  4. The CWE identifier
Why this is the best answer

Correct. The Exploit Prediction Scoring System (EPSS) estimates the probability that a vulnerability will be exploited in the wild within the next 30 days, which is exactly the likelihood question being asked.

Every one of the 50 questions works this way: an explanation for the right answer and for the one you picked, so a wrong answer teaches you something. Questions last reviewed against the current CompTIA PenTest+ (PT0-003) objectives.

PenTest+ Practice Test

Frequently Asked Questions

Quick answers about the test, the CompTIA PenTest+ (PT0-003) exam, and how to prepare.

Is this CompTIA PenTest+ practice test free?

Yes. Training Camp's CompTIA PenTest+ (PT0-003) practice test is free to take. You get 50 exam-style questions across all five domains, with a written explanation for every answer choice.

How does this practice test work?

It is 50 multiple-choice scenario questions drawn from all five PT0-003 domains, with an instant explanation after each answer and a 90-minute timer. You can retake it as often as you want. Treat it as a readiness check rather than a substitute for full preparation.

How many questions are on the real CompTIA PenTest+ exam?

The PT0-003 exam has a maximum of 90 questions and gives you 165 minutes. The questions are a mix of multiple choice and performance-based items, where you complete a hands-on style task rather than pick a single answer.

What score do I need to pass the CompTIA PenTest+ exam?

You need a scaled score of 750 on a scale of 100 to 900. CompTIA reports one overall scaled score, so a strong domain can offset a weaker one. There is no separate bar to clear in each domain.

What domains does the CompTIA PenTest+ exam cover?

The five domains are Engagement Management (13%), Reconnaissance and Enumeration (21%), Vulnerability Discovery and Analysis (17%), Attacks and Exploits (35%), and Post-exploitation and Lateral Movement (14%). Attacks and Exploits is the largest, so most of your study time belongs there.

Do I need experience to take the CompTIA PenTest+ exam?

There are no formal prerequisites. CompTIA recommends CompTIA Network+ and CompTIA Security+ or equivalent knowledge along with three to four years of hands-on penetration testing or related experience, which makes it an intermediate rather than an entry-level certification.

How long is the CompTIA PenTest+ certification valid?

PenTest+ is valid for three years from the date you pass. You renew it through CompTIA's continuing education program, by earning credits or a higher-level certification, rather than by retaking the exam.

How should you prepare for the CompTIA PenTest+ exam?

Start with the PT0-003 exam objectives and learn each attack, tool and reporting step at the level the objectives name, then use practice questions like these to find your weak domains. If you want a structured path with an instructor and hands-on labs, our CompTIA PenTest+ Boot Camp covers all five domains.