PenTest+: assessment, evidence, and remediation
Six lessons, 35 questions, and five cases on scope, enumeration, validation, web and cloud flaws, retesting, and restoration.
Objectives and progression
Initial course with six lessons and 40 original decisions in fictional labs and projects. Internal assessment of 23 decisions in 55 minutes. Covers all five domains at introductory depth; executable labs, wireless, mobile, OT, social engineering, and detailed tool operation need further study. Preparation for PenTest+ V3 / PT0-003, launched 2024-12-17, using official objectives 3.0. The reference to retirement in 2027 is an estimate rather than a confirmed date.
Audience: Security, development, APS, and technical coordination professionals involved in assessments and project acceptance.
Prerequisites: Networking, systems, and security basics. CompTIA recommends three to four years in penetration testing and Network+/Security+ or equivalent knowledge; prior certification is not mandatory.
310 estimated study minutes
- Define an authorized assessment and conclusions proportional to demonstrated evidence.
- Turn leads into hypotheses without inventing exposure or permission.
- Combine techniques and validate findings before classifying them.
- Identify the failed boundary and choose an appropriate control.
- Evaluate permissions and exploitation conditions precisely.
- Close work with access removed and state confirmed.
Modules
- Scope, communication, and evidence
- Reconnaissance and result interpretation
- Discovery, coverage, and validation
- Web and API flaws and remediation
- Identity, host, and cloud
- Post-test evidence and restoration
Continue learning
References and version
PT0-003 / PenTest+ V3; objectives 3.0; launched 2024-12-17
- PenTest+ current exam facts · 2026-09-30
- PenTest+ PT0-003 exam objectives · 2026-09-30
- Security testing and assessment · 2026-09-30
- Enterprise patch management planning · 2026-09-30
- CVSS v4.0 user guide · 2026-09-30
- Security backporting practice · 2026-09-30
- Prompt injection risks and controls · 2026-09-30
- Nmap port states · 2026-09-30
- Nmap service and version detection · 2026-09-30
- Nmap Scripting Engine scope · 2026-09-30
- Broken object-level authorization · 2026-09-30
- SQL injection prevention · 2026-09-30
- XSS prevention · 2026-09-30
- SSRF prevention · 2026-09-30
- Authorization checks · 2026-09-30
- CSRF prevention · 2026-09-30
- MFA risks and controls · 2026-09-30
- Secret lifecycle and revocation · 2026-09-30
- Session expiration and invalidation · 2026-09-30
- Static source analysis · 2026-09-30
- Component and dependency analysis · 2026-09-30
- IP address and network membership · 2026-09-30
- Robots exclusion protocol · 2026-09-30
- Certificate transparency · 2026-09-30
- Domain names concepts · 2026-09-30
- IAM policy evaluation · 2026-09-30
- Instance Metadata Service versions · 2026-09-30
- SMB signing behavior · 2026-09-30
- Service executable path configuration · 2026-09-30
What you will explore
0 / 6Scope, communication, and evidence
Define an authorized assessment and conclusions proportional to demonstrated evidence.
Reconnaissance and result interpretation
Turn leads into hypotheses without inventing exposure or permission.
Discovery, coverage, and validation
Combine techniques and validate findings before classifying them.
Web and API flaws and remediation
Identify the failed boundary and choose an appropriate control.
Identity, host, and cloud
Evaluate permissions and exploitation conditions precisely.
Post-test evidence and restoration
Close work with access removed and state confirmed.