
CompTIA PenTest+
Exam Code: PT0-002
The intermediate penetration testing certification validating hands-on vulnerability assessment and management skills. A practical stepping stone to OSCP.

Exam Code: PT0-002
The intermediate penetration testing certification validating hands-on vulnerability assessment and management skills. A practical stepping stone to OSCP.
CompTIA PenTest+ is an intermediate-level certification that validates hands-on penetration testing and vulnerability assessment skills. It bridges the gap between entry-level certifications (Security+) and advanced practical certifications (OSCP).
PenTest+ PT0-002 focuses on:
PenTest+ is designed for:
Recommended: 3-4 years of hands-on information security experience.
The PenTest+ PT0-002 exam includes:
Performance-based questions require you to:
| Experience Level | Recommended Study Time |
|---|---|
| Active security role | 6-8 weeks |
| Security+ certified | 8-10 weeks |
| Limited pentest exposure | 12-14 weeks |
| Aspect | PenTest+ | CEH | OSCP |
|---|---|---|---|
| Difficulty | Intermediate | Intermediate | Advanced |
| Format | MC + PBQ | Multiple choice | 100% practical |
| Duration | 165 min | 4 hours | 24 hours |
| Cost | $404 | $1,199 | $1,649 |
| Focus | Methodology | Breadth | Deep hands-on |
| Best for | Bridge cert | Compliance | Red team |
Planning and Scoping
Reconnaissance
Exploitation
Reporting
PenTest+ holders see an average 29% salary increase:
The PenTest+ PT0-002 exam is delivered at Pearson VUE testing centers or via online proctoring from your home. You will need two forms of identification and a clean workspace if testing remotely. The exam engine presents a mix of standard multiple choice questions and performance-based questions (PBQs), which appear at the beginning of the exam. PBQs simulate real scenarios where you interact with a virtual environment: analyzing Nmap output, writing a short Python or Bash snippet, or identifying the correct exploit chain for a given target.
Time management is critical. With up to 85 questions in 165 minutes, you have roughly two minutes per question. Many candidates make the mistake of spending too long on PBQs at the start. A better strategy: flag PBQs after an initial attempt, power through the multiple choice section, then return to PBQs with remaining time. The multiple choice questions are worth the same points, so securing those first builds a safety net.
Common mistakes include neglecting the "Reporting and Communication" domain (18% of the exam), which tests professional writing skills rather than technical exploitation. Candidates who focus exclusively on hacking tools often lose easy points on questions about executive summaries, risk ratings, and remediation timelines. Another frequent error is confusing the scoping phase with the reconnaissance phase; the exam draws a clear line between pre-engagement legal planning and active information gathering.
The most effective study path for PenTest+ combines structured learning with hands-on practice. If you already hold Security+ and have 2 or more years in a security role, plan for 8 to 10 weeks of focused preparation.
Paid courses: CompTIA CertMaster Learn + CertMaster Labs provides the official curriculum with integrated virtual labs. Jason Dion's PenTest+ course on Udemy is a popular budget alternative at under $20 during sales, covering all five domains with practice exams. Dion Training's practice tests are particularly well regarded for matching the actual exam difficulty.
Hands-on platforms: TryHackMe's "Jr Penetration Tester" learning path maps almost perfectly to PenTest+ objectives, with guided rooms that walk you through reconnaissance, exploitation, and reporting. Hack The Box's "Starting Point" machines provide a more challenging supplement. For scripting practice, OverTheWire's Bandit wargame builds the Linux and Bash skills tested in Domain 5.
Free resources: Professor Messer's PenTest+ video series on YouTube covers every objective. CompTIA's own exam objectives document (downloadable as a PDF) should be your study checklist; tick off each sub-objective as you master it.
Set up a home lab with Kali Linux attacking a vulnerable target like Metasploitable 3 or DVWA. Practice the full methodology: scope definition, scanning with Nmap and Nessus Community Edition, exploitation with Metasploit, privilege escalation, and writing a findings report. This end-to-end workflow mirrors what PBQs test.
PenTest+ positions you for specific roles that explicitly list it in job requirements. Junior Penetration Tester positions ($65,000 to $85,000 in the US) frequently require either PenTest+ or CEH. Vulnerability Assessment Analyst roles ($70,000 to $95,000) in financial services and healthcare sectors prefer PenTest+ because of its hands-on validation component.
In the US federal space, PenTest+ satisfies DoD 8570/8140 requirements for CSSP Analyst and CSSP Incident Responder positions, making it valuable for government contractors. In Europe, penetration testing roles in Germany and the Netherlands offer EUR 55,000 to EUR 75,000 for PenTest+ holders, with UK salaries ranging from GBP 40,000 to GBP 60,000.
Compared to CEH, PenTest+ costs significantly less ($404 vs $1,199) while providing similar job qualification. Compared to OSCP, PenTest+ is far more accessible and serves as proof that you understand penetration testing methodology, even if you have not yet mastered the deep exploitation skills OSCP demands. Many professionals use PenTest+ as a stepping stone: passing PenTest+ first, then pursuing OSCP within 12 to 18 months while gaining real engagement experience.
| Item | Cost |
|---|---|
| Exam voucher | $404 |
| CertMaster Learn + Labs bundle | $649 |
| Jason Dion Udemy course (sale) | $15 to $20 |
| TryHackMe premium (3 months) | $30 |
| Retake voucher (if needed) | $404 |
| Total (budget path) | $450 to $860 |
| Total (premium path) | $1,053 to $1,480 |
PenTest+ requires renewal every three years. You can renew by earning 60 Continuing Education (CE) credits or by passing a higher level certification. The annual CE fee is $50 per year ($150 over three years). Given the average $20,000 salary increase post-certification, the ROI pays for itself within the first month of a new role.
Employer sponsorship tip: Many organizations cover certification costs as part of professional development budgets. Frame your request around the DoD 8570 compliance value if your company has government contracts; this shifts the cost from "nice to have" to "compliance requirement."
Before registering for the exam, confirm you meet these readiness criteria:
Recommended timeline: Register for the exam 8 to 10 weeks out. This creates a fixed deadline that prevents study drift. Study 1 to 2 hours on weekdays and 3 to 4 hours on weekends, totaling 80 to 120 hours of preparation.
Mental preparation: The PBQs can feel intimidating because they look like a real terminal. Practice in TryHackMe or CertMaster Labs until the virtual environment feels routine. On exam day, read each question twice before answering. The exam tests methodology comprehension, not speed of exploitation.
Build a cheat sheet even though it is not open book. The process of creating condensed notes forces you to organize knowledge. Many successful candidates report that writing a one-page summary per domain was the single most effective study technique.
Do not underestimate scripting questions. Domain 5 (Tools and Code Analysis) at 16% is not huge, but the questions require you to read Python and Bash code and identify what it does. You do not need to be a developer, but you must recognize common patterns: socket connections, file read/write operations, and loop structures.
Join the CompTIA subreddit (r/CompTIA) and the PenTest+ Discord channels. Real exam takers share their experiences without violating NDA. Common themes: the exam is "wider than expected" (covering wireless, social engineering, and physical security, not just network exploitation) and "reporting questions are free points if you prepared."
Schedule your exam for the morning. Cognitive performance peaks early in the day for most people, and PBQs demand focused problem-solving. Avoid scheduling after a work day.
The official CompTIA exam objectives document is your syllabus. If you cannot confidently explain every single sub-objective, you are not ready. This document is free and downloadable from CompTIA's website.
Average Before
$70,000
Average After
$90,000
Average Increase
$20,000 (+29%)
Source: CompTIA IT Salary Research 2024
Yes, significantly. PenTest+ uses multiple choice and performance-based questions in 165 minutes. OSCP is a 24-hour practical exam requiring actual exploitation.
PenTest+ is more affordable ($404 vs $1,199), vendor-neutral, and has performance-based questions. CEH has broader market recognition and DoD approval.
No, PenTest+ is intermediate-level. Start with Security+ first, then pursue PenTest+ after gaining 3-4 years of security experience.
Junior Penetration Tester, Vulnerability Assessment Analyst, Security Consultant, and entry Red Team positions. It's also DoD 8570/8140 compliant.
Industry-standard entry-level cybersecurity certification validating core security skills. Globally recognized by employers and DoD-approved.
The world's most recognized ethical hacking certification. Learn to think like a hacker to better defend organizations against cyber attacks.
The most respected hands-on penetration testing certification. Prove your ability to identify vulnerabilities and execute attacks in a controlled environment.