CompTIA PenTest+ (PT0-003) — Study Guide
Free, topic-by-topic study notes for the CompTIA PenTest+ (PT0-003) exam. Read a chapter, then practice it.
Engagement Management
This chapter covers the professional and legal foundation of a penetration test. You will learn scoping, rules of engagement, authorization, communication triggers, and how findings are reported and remediated responsibly.
Reconnaissance and Enumeration
This chapter covers gathering information about a target. You will learn the difference between passive and active reconnaissance, open-source intelligence, DNS and network enumeration, port scanning, and service and operating-system fingerprinting.
Vulnerability Discovery and Analysis
This chapter covers finding and evaluating weaknesses. You will learn automated vulnerability scanning, how to validate results and handle false positives, severity scoring with CVSS, and how to prioritize what to address first.
Attacks and Exploits
This chapter surveys the major categories of attack at a conceptual, defensive level. You will learn common application, network, social-engineering, and credential attacks, along with the tools testers use and the defenses that mitigate each.
Post-exploitation and Lateral Movement
This chapter covers what happens after a system is compromised. You will learn lateral movement and pivoting, persistence, data-exfiltration concepts, and the essential cleanup and restoration that ends a responsible engagement.
Practice by topic
Jump straight into free practice questions for any single CompTIA PenTest+ (PT0-003) topic.