Exact 50-question proportional allocation
Engagement authority and safe range design
Weeks 1–2: make authorization a technical control, not a paragraph forgotten after kickoff.
- Define parties, owned targets, accounts or tenants, methods, payload classes, dates, windows, rates, exclusions, and third parties.
- Set service-health monitoring, emergency contacts, stop conditions, rollback authority, evidence rules, retention, cost limits, and cleanup acceptance.
- Translate signed scope into machine-enforced target, identity, endpoint, protocol, and method allowlists.
- Use private reserved addressing, denied public and production routes, disposable snapshots, synthetic identities, and inert canary data.
- Plan immediate critical-finding escalation and mandatory-reporting consultation through named legal and engagement contacts.
- Protect evidence through provenance, encryption, need-to-know access, redaction, transfer records, and scheduled deletion.
- Practice executive and technical report structures and retest criteria before the first probe.
- Complete all 7 Engagement management questions.
Reconnaissance, enumeration, and coverage
Weeks 3–4: build an accurate attack-surface map without confusing discovery with permission.
- Distinguish passive approved metadata from direct active interaction with a target.
- Validate ownership and freshness for registration, certificate, archive, and public-like range fixtures.
- Start active discovery at safe rates, observe health, respect exclusions, and expand only within the rules of engagement.
- Enumerate DNS, certificates, protocols, routes, applications, APIs, synthetic directories, and read-only cloud inventories.
- Do not identify services by port alone; correlate protocol behavior, certificate, banner, response, and owner records.
- Bind scripts to exact target and account identifiers with dry runs, timeouts, concurrency limits, errors, and audit logs.
- Minimize packet collection by interface, filter, field, duration, access, and retention.
- Complete all 10 Reconnaissance and enumeration questions.
Vulnerability discovery and safe validation
Weeks 5–6: combine complementary methods and distinguish presence, reachability, exploitability, and impact.
- Use bounded authenticated and unauthenticated host scanning plus source, dependency, image, configuration, application, and API analysis.
- Verify credentials, privileges, platform support, policies, target reachability, and successful checks before interpreting clean results.
- Reconcile duplicate findings while preserving original evidence and tool versions.
- Validate version findings with vendor advisories, package provenance, configuration, and non-destructive checks.
- Prioritize validation by reachability, exploitability, controls, target value, business impact, and operational safety.
- Use synthetic objects, inert files, canary endpoints, and safe policy evidence instead of real data or harmful payloads.
- During retest, verify the deployed version, root condition, alternative paths, regressions, and service health.
- Complete all 9 Vulnerability discovery and analysis questions.
Attacks, exploits, and bounded attack paths
Weeks 7–8: understand exploit classes through defensive proof, remediation, and detection—not uncontrolled payload execution.
- Study server-side object and function authorization, parameterized queries, context encoding, canonical paths, upload controls, sessions, and server-side fetch restrictions.
- Assess cloud metadata, workload identity, effective policy, egress, secrets, container privilege, mounts, capabilities, and runtime isolation.
- Evaluate identity defenses with synthetic accounts, MFA, breached-password screening, recovery, rate controls, and session revocation.
- Treat AI retrieval content as untrusted data; expose no secrets or unrestricted tools and enforce policy outside the model.
- Reject destructive public proof-of-concept behavior; use code review, vendor evidence, safe indicators, or reviewed inert rewrites.
- Use designated canaries to validate segmentation and privilege without collecting credentials or unrelated files.
- Keep monitoring enabled and activity visible. Do not practice stealth, evasion, destructive payloads, real-target testing, or durable persistence.
- Complete all 17 Attacks and exploits questions.
Post-exploitation reporting, remediation, and cleanup
Weeks 9–10+: show how a path matters, then break it and prove the range is gone.
- Build source-linked narratives of prerequisites, control gaps, minimum proofs, impact, detections, remediation, limitations, and cleanup.
- Separate demonstrated access from possible next steps and avoid claims of total compromise from one path.
- Replace standing administrative reach with tiering, just-in-time identities, hardened origins, restricted management paths, and session monitoring.
- Simulate persistence only when pre-approved through a visible, expiring, reversible marker; remove it immediately after observation.
- Complete the hybrid test, web/API/AI lab, and segmentation/identity path project.
- Retest original and adjacent paths, required business flows, detections, service health, and rollback.
- Review 40 cards and all 50 questions, explaining authorization, evidence, minimum impact, and cleanup in every answer.
- Attest that no identity, token, file, task, process, rule, listener, route, snapshot, schedule, raw artifact, or charge remains.
Three deep authorized projects
All learning surfaces
Two 25-question files with exact 7/10/9/17/7 allocation and zero-based answers.40 flashcards
Unique concepts across all five PT0-003 domains.3 projects
Authorization, architecture, safe steps, tests, cost, evidence, retest, and cleanup.Study guide
Substantial objective reasoning and a ten-week plan.Roadmap catalog
Explore adjacent security paths.Editorial policy
Originality, safety, sourcing, and exam integrity.
Official sources
Frequently asked questions
What is the current PenTest+ exam code?
The current CompTIA PenTest+ V3 exam is PT0-003.
How long is PT0-003 and which formats can appear?
CompTIA lists 165 minutes and a maximum of 90 questions, including multiple-choice and performance-based questions.
What are the official domain weights?
Engagement management 13%, Reconnaissance and enumeration 21%, Vulnerability discovery and analysis 17%, Attacks and exploits 35%, and Post-exploitation and lateral movement 14%.
How are the 50 practice questions allocated?
Using the requested exact proportional allocation: 7, 10, 9, 17, and 7 across the five domains, split 25 and 25.
Are the projects safe and authorized?
Yes. They require isolated owned environments, written scope, synthetic identities and data, inert canaries, visible reversible activity, monitoring, and verified cleanup. They prohibit credential theft, stealth and evasion, real targets, destructive payloads, and durable persistence.
Are the materials exam dumps?
No. They are independently authored educational scenarios based on CompTIA's public current page and objectives, without live, recalled, leaked, or proprietary items.
Practice the full authorized lifecycle
Start with signed scope, gather minimum evidence, remediate and retest, and prove cleanup.
Start questionsReview cardsOpen projectsRead guide