CompTIA PenTest+ Study Guide 2026: Syllabus, Exam Topics & Study Plan -Edureify
๐Ÿ“‹ 2026 Edition  ยท  Updated September 2026

CompTIA PenTest+ Study Guide 2026

Complete exam coverage for the CompTIA PenTest+: syllabus, domains, key topics, study plan and practical exam preparation strategy.

90
Questions
165 min
Duration
75
Passing score
5
Domains
95%
First-attempt pass rate
47K+
Candidates prepared
4.9โ˜…
Average rating
"Passed my CompTIA PenTest+ exam on the first try after just 6 weeks of studying with Edureify AI. The domain-level analysis showed me exactly what I was missing."
- Verified Edureify User
Your readiness score - take the free diagnostic to unlock your personalised analysis
-%
Overall readiness (locked)
Engagement Management
-
Reconnaissance and Enumeration
-
Vulnerability Discovery and Analysis
-
Attacks and Exploits
-
Post-Exploitation and Lateral Movement
-
Run 10-Minute Free Diagnostic โ†’
Exam at a Glance

CompTIA PenTest+ Exam Overview

Key facts about the CompTIA PenTest+ exam structure, format and scoring.

๐Ÿ†”
comptia-pentest-plus
Exam code
๐Ÿ“
90 questions
Total questions
โฑ
165 minutes
Duration
๐ŸŽฏ
75
Passing score
๐Ÿ“‹
5 domains
Exam domains
๐Ÿ†
Certification
Credential type
โ„น๏ธ
Scoring method: Scaled scoring (100-900). A score of 750 or higher is required to pass. Maximum 90 questions in 165 minutes including MCQ and Performance-Based Questions (PBQs). Launched December 17, 2024; DoD 8570/8140 approved.. The exam may include unscored pilot questions - treat every question seriously.
Focus Areas

What should you study for the CompTIA PenTest+ exam?

Start with the domains that make up the CompTIA PenTest+ exam. Use the detailed syllabus below to work through the individual topics.

โš ๏ธ
Common mistake: Candidates often memorise terminology but struggle with scenario-based questions. Focus on when to use what, not just what exists.
🔐
Engagement Management (13%)
Covers pre-engagement activities including scoping, legal documentation, rules of engagement, and professional reporting.
🏗
Reconnaissance and Enumeration (21%)
Covers passive and active information gathering, OSINT techniques, network scanning, service enumeration, and vulnerability identification.
Vulnerability Discovery and Analysis (17%)
Covers vulnerability scanning, manual analysis, validating findings, and assessing risk of discovered vulnerabilities.
💰
Attacks and Exploits (35%)
Covers exploitation of network services, applications, wireless networks, social engineering, cloud infrastructure, and AI systems.
🔄
Post-Exploitation and Lateral Movement (14%)
Covers establishing persistence, privilege escalation, lateral movement, credential harvesting, and data exfiltration techniques.
Full Syllabus

CompTIA PenTest+ Exam Syllabus and Topics

The CompTIA PenTest+ exam is divided into 5 domains. Each domain covers specific skills and topics. Expand a domain to see the detailed syllabus.

Scoping and Legal Agreements
Statement of Work (SOW) and Master Service Agreement (MSA)
Rules of Engagement (ROE) definition
Permission to attack documentation
Legal considerations: Computer Fraud and Abuse Act (CFAA)
NDA and confidentiality requirements
Reporting and Communication
Executive summary for non-technical stakeholders
Technical report: vulnerability details and evidence
Risk ratings: CVSS scoring and custom risk rating
Remediation recommendations and prioritization
Report handling, storage, and destruction
~12 questions
117 marks
13% of exam weight
OSINT and Passive Gathering
DNS reconnaissance: zone transfers, WHOIS, DNS enumeration
OSINT tools: Maltego, Shodan, theHarvester, Recon-ng
Google dorks and advanced search operators
Social media and corporate intelligence gathering
Email harvesting and credential exposure discovery
Network Scanning and Enumeration
Nmap scanning: TCP SYN, UDP, stealth scan techniques
Service and version detection with Nmap
SMB enumeration: enum4linux, smbclient, rpcclient
SNMP enumeration and MIB walking
Web application enumeration: Nikto, dirb, gobuster
Active Directory enumeration: BloodHound, ldapsearch
~19 questions
189 marks
21% of exam weight
Automated Scanning Tools
Nessus and OpenVAS for vulnerability scanning
Web application scanners: Burp Suite, OWASP ZAP
Authenticated vs unauthenticated scans
Cloud security scanning: Prowler, Scout Suite
Container vulnerability scanning: Trivy, Anchore
Vulnerability Analysis
CVE and NVD for vulnerability research
CVSS v3.1 scoring: base, temporal, environmental metrics
False positive identification and verification
Manual validation of automated scan findings
AI and ML model vulnerability assessment
~15 questions
153 marks
17% of exam weight
Network Attacks
Metasploit Framework for exploitation
Password attacks: hashcat, John the Ripper, credential stuffing
Man-in-the-middle attacks: Responder, Bettercap
Exploit databases: Exploit-DB, Searchsploit
Buffer overflow exploitation concepts
Web Application Attacks
OWASP Top 10: SQL injection, XSS, CSRF, SSRF, IDOR
API security testing: REST and GraphQL API attacks
Authentication bypass techniques
File inclusion: LFI and RFI exploitation
JWT token manipulation and OAuth misconfigurations
Wireless and Social Engineering
Wireless attacks: WPA2 cracking, evil twin, deauthentication
Aircrack-ng suite for wireless testing
Phishing campaigns and pretexting
Vishing and physical security testing
Cloud and AI Attack Techniques
AWS, Azure, GCP privilege escalation paths
Cloud metadata service exploitation (IMDS)
Container escape techniques
AI/ML model attacks: prompt injection and model manipulation
Supply chain attack techniques
~32 questions
315 marks
35% of exam weight
Persistence and Privilege Escalation
Windows persistence: registry, scheduled tasks, services
Linux persistence: cron jobs, SUID binaries, SSH keys
Windows privilege escalation: token impersonation, UAC bypass
Linux privilege escalation: SUDO abuse, SUID/GUID exploitation
Lateral Movement and Exfiltration
Pass-the-hash and pass-the-ticket attacks
Mimikatz for credential harvesting from LSASS
BloodHound for Active Directory attack path analysis
Living off the Land (LOtL) techniques with built-in tools
Data exfiltration via DNS, HTTPS, and covert channels
Covering tracks and log manipulation
~12 questions
126 marks
14% of exam weight
๐Ÿ”ฅ 1,247 professionals tested in the last 24 hours

Know if you'll pass CompTIA PenTest+ before exam day

Take our 10-minute diagnostic and get a personalised report showing your readiness, weak domains and where to focus next.

Start Free Diagnostic โ†’
100% FreeNo credit cardResults in 10 minutes
Study Plan

CompTIA PenTest+ Structured Study Roadmap

Choose a preparation timeline based on how much time you have available. For a plan based on your actual readiness and weak domains, use the personalised Edureify study experience. Get My Training Plan โ†’

Weeks 1-2
Core Services + Highest-Weighted Domain
Deep-dive into the most heavily tested domain. Spend more time here when its exam weight is significantly higher.
Official exam guideDomain 1 completeCore conceptsPractice questions
Week 3
Domain 2 - Hands-on Practice
Focus on scenario-based study and reinforce concepts through practical application where applicable.
Domain 2Scenario walkthroughsHands-on practicePractice questions
Week 4
Domain 3 - Deeper Concepts
Work through complex concepts and decision scenarios.
Domain 3Scenario drillsPractice examReview
Week 5
Remaining Domains + Weak Area Targeting
Identify your weaker domains and spend focused time closing those gaps.
Remaining domainsDiagnosticTargeted reviewStudy notes
Week 6
Full Simulations + Final Preparation
Use timed simulations to test your preparation and review the reasoning behind incorrect answers.
Full mock examsWrong-answer reviewFinal reviewExam logistics
Exam Strategy

Tips to pass CompTIA PenTest+ on your first attempt

Practical advice for applying what you know, managing questions and preparing for exam conditions.

🗓
Attacks and Exploits is the dominant domain at 35% — invest the most preparation time here, particularly web application attacks, password cracking, and network exploitation techniques.
🔍
Performance-based questions simulate real tool output — practice reading Nmap scan results, interpreting Nessus reports, and analyzing Burp Suite HTTP traffic.
OWASP Top 10 is core to web application attack questions — know SQL injection (UNION-based, blind, time-based), XSS (reflected, stored, DOM), and SSRF in detail.
📊
AI attack coverage is new in PT0-003 — understand prompt injection (manipulating LLM behavior through input) and model manipulation as emerging attack vectors.
🔁
Reconnaissance order: passive first (OSINT, Shodan, WHOIS) to avoid detection, then active scanning (Nmap, vulnerability scanners) when engagement is authorized.
🧪
CVSS v3.1 base score components: Attack Vector, Attack Complexity, Privileges Required, User Interaction, Scope, Confidentiality/Integrity/Availability impact — know how each affects score.
📝
Post-exploitation lateral movement: Pass-the-Hash uses NTLM hash without knowing password; Pass-the-Ticket uses Kerberos TGT — both enable authentication without cracking passwords.
🎯
BloodHound uses graph theory to identify the shortest attack path to Domain Admin — exam questions may ask about its use in Active Directory engagements.
🗓
Always start with rules of engagement — the exam often presents scenarios where you must determine what is in-scope before describing attack methodology.
🔍
Living off the Land techniques use built-in OS tools (PowerShell, certutil, wmic, mshta) to avoid AV detection — know common LOtL binaries for both Windows and Linux.
Recommended Resources

CompTIA PenTest+ Study Resources

Use a focused set of resources alongside the study guide rather than trying to study from everything available.

Official
Official Exam Guide
Start with the authoritative exam objectives and blueprint.
Practice Tests
CompTIA PenTest+ Practice Test
Practice questions with explanations and domain-level performance analysis.
โ†’ Start free practice test
Mock Exam
CompTIA PenTest+ Mock Exam
Timed preparation under realistic exam-style conditions.
โ†’ Take free mock exam
Training
CompTIA PenTest+ Certification Training
Structured preparation with personalised learning support and adaptive practice.
โ†’ CompTIA PenTest+ certification online training
AI Tutor
CompTIA PenTest+ AI Tutor
Get help understanding concepts and work on weak areas with AI-powered learning support.
โ†’ Try CompTIA PenTest+ AI tutor
Reference
CompTIA PenTest+ Cheat Sheet
Quick-reference summaries for final revision.
โ†’ Get free cheat sheet
Diagnostic
CompTIA PenTest+ Readiness Test
Assess your preparation and identify weaker exam domains.
โ†’ Check my readiness
โš ๏ธ
Avoid brain dumps. Sites selling real or stolen exam questions may violate certification-provider rules and can leave candidates studying outdated material.
Reviews

What candidates say after passing

โ˜…โ˜…โ˜…โ˜…โ˜…
Scope and authorization questions appear throughout PenTest+ and the correct answer is always the most legally conservative one.Edureify AI's out-of-scope discovery scenarios - stop, document, notify, await authorization - built the professional reflex that distinguishes ethical penetration testers from threat actors.
Park J.
Cloud Architect
โ˜…โ˜…โ˜…โ˜…โ˜…
The reporting domain is underestimated by technically strong candidates.Edureify AI's executive summary scenarios - translate technical findings into business risk language - prepared me for the communication requirement that pure offensive security knowledge doesn't develop on its own.
Kevin O.
Security Architect
โ˜…โ˜…โ˜…โ˜…โ˜…
CVSS v3 scoring components need to be automatic for PenTest+ success.Edureify AI's vulnerability rating scenarios required me to construct and justify CVSS scores rather than just identify score ranges. That applied understanding is what the exam tests, and what a professional report requires.
Sophia M.
Project Manager
โ˜…โ˜…โ˜…โ˜…โ˜…
Post-exploitation discipline - minimum necessary access, document and report rather than continue extracting - is the ethical dimension most PenTest+ candidates underestimate.Edureify AI's post-exploitation scenarios consistently required me to stop at demonstrated impact rather than maximize access. The exam rewards exactly that restraint.
Dinesh N.
Network Engineer
FAQ

Frequently asked questions about CompTIA PenTest+

Most candidates with relevant background can structure their preparation over several weeks, depending on their existing knowledge, available study time and exam difficulty. Use the study roadmap above as a starting point and use the readiness diagnostic to identify where you need more preparation.
The guide covers the exam overview, domains, detailed syllabus and topics, study roadmap, exam preparation tips and links to practice, mock, readiness, cheat-sheet, AI Tutor and training resources.
The guide is designed to organize your preparation around the exam syllabus. You should combine it with practice questions and timed simulations so that you can test both your knowledge and your ability to apply it.
Yes. Start with the exam overview and domain breakdown, then work through the detailed topics using the study roadmap. Candidates with less experience may need additional time for foundational concepts.
Take the Edureify readiness diagnostic to assess your preparation and identify the domains where you need to focus more.
Edureify AI can help explain concepts, identify weaker areas from practice performance and support a more personalised preparation process.

Ready to prepare for CompTIA PenTest+?

Find your weak areas and build a more focused preparation plan.

Start My Free Diagnostic โ†’
95% first-attempt pass rate47,000+ candidates4.9โ˜… ratingNo credit card needed
Keep Learning

Related Cybersecurity Certification Study Guides

Explore related certification study guides within this category.