CompTIA credentialCER0402

PenTest+

Exam code: PT0-003
Official provider page
CompTIA
Credential
Certification
Level
Certification
Exam duration
165 min

credential overview

About this credential

Penetration-testing certification validating engagement management, reconnaissance and enumeration, vulnerability analysis, attacks and exploits, and post-exploitation/lateral movement across modern attack surfaces.

Who this is for

Penetration testers, security consultants, and cybersecurity professionals who assess and report vulnerabilities.

Assessment

Exam details

PT0-003
Duration
165 min

English, French, Japanese, Portuguese

Exam blueprint

Skills measured

Engagement management (13%)4 topics
  • Define rules of engagement, testing windows, and target selection.
  • Ensure legal and ethical compliance, including authorization and mandatory reporting.
  • Align with stakeholders through peer reviews, escalation paths, and risk articulation.
  • Create penetration-test reports with executive summaries, findings, and remediation recommendations.
Reconnaissance and enumeration (21%)4 topics
  • Perform active and passive reconnaissance using OSINT, sniffing, and protocol scanning.
  • Perform DNS, service, and directory enumeration.
  • Use tools such as Nmap, Wireshark, and Shodan.
  • Customize Python, PowerShell, and Bash scripts for reconnaissance and enumeration.
Vulnerability discovery and analysis (17%)3 topics
  • Conduct authenticated, unauthenticated, SAST, and DAST vulnerability scans.
  • Validate findings, troubleshoot configurations, and identify false positives.
  • Use tools such as Nessus, Nikto, and OpenVAS.
Attacks and exploits (35%)6 topics
  • Perform network attacks such as VLAN hopping, on-path attacks, and service exploitation.
  • Perform authentication attacks including brute force, pass-the-hash, and credential stuffing.
  • Conduct host-based attacks such as privilege escalation, process injection, and credential dumping.
  • Perform web application attacks including SQL injection, XSS, and directory traversal.
  • Exploit cloud attack surfaces such as container escapes, metadata services, and IAM misconfiguration.
  • Explain AI attacks including prompt injection and model manipulation.
Post-exploitation and lateral movement (14%)2 topics
  • Establish persistence, perform lateral movement, and clean up artifacts.
  • Create attack narratives and remediation recommendations.

Before you certify

Requirements and recommended experience

Recommended experience

3-4 years in a penetration tester job role

Recommended

Network+ and Security+ or equivalent knowledge

Corporate certification enablement

Turn this pathway into a team capability plan

We can align the learning path, instructor support, practice environment and delivery schedule to your team’s roles and certification target.