Skip to content
CBT Nuggets
DemoBook a Demo

CompTIA Pentest+ (PT0-003)

In this PenTest+ course, cybersecurity expert Bob Salmas guides you through simulating real-world cyberattacks, uncovering network vulnerabilities, and sharpening your ethical hacking skills. Once you complete this course, you’ll be prepared to pass the PenTest+ PT0-003 exam with confidence. This PenTest+ training is ideal for junior cybersecurity pros ready to advance or seasoned pentesters looking to validate their skills. You’ll practice modern penetration testing techniques in realistic virtual labs, document your findings in industry-standard reports, and prepare for exam day with unlimited PenTest+ practice tests.

Updated April 2025

31Skills
221Videos
21Virtual Labs
1Practice Exam
32hTotal

Who This Course Is For

This CompTIA PenTest+ (PT0-003) training is considered professional-level CompTIA training, which means it was designed for penetration testers. This penetration testing skills course is designed for penetration testers with three to five years of experience with penetration testing.

Skills Your Team Will Gain

  • Identifying exploitable weaknesses in systems by performing vulnerability scans
  • Executing real-world penetration testing strategies with industry-standard tools
  • Documenting findings in reports that meet compliance and regulatory standards
  • Refining scripting and automation skills to make penetration tests more efficient
  • Performing risk assessments to identify security threats and potential exploits
  • Developing incident response strategies and mitigating security breaches during penetration tests

Course Curriculum

One skill is free to watch — no signup needed. The other 30 premium skills unlock for your whole team with a CBT Nuggets plan.

Free skill preview

Web Application Vulnerabilities

Bob SalmansDuration: 55m16 videos

Watch this complete skill free — the same trainer, videos, and labs your team gets with a plan.

Watch free skill
  • Premium skill.Pre-Engagement Activities52m · 15 videos
  • Premium skill.Communications and Pentesting Methodologies1h 5m · 19 videos
  • Premium skill.Pentest Reports and Security Controls53m · 17 videos
  • Premium skill.Passive Reconnaissance and OSINT1h 10m · 20 videos
  • Premium skill.Passive Reconnaissance Practice50m · 15 videos
  • Premium skill.Active Enumeration In The Lab60m · 15 videos · 1 lab
  • Premium skill.NMAP In-Depth1h 9m · 19 videos · 1 lab
  • Premium skill.Active Enumeration - Network Services Part 11h 9m · 15 videos · 1 lab
  • Premium skill.Active Enumeration - Network Services Part 21h 2m · 21 videos · 1 lab
  • Premium skill.Active Enumeration - Network Services Part 31h 23m · 15 videos · 1 lab
  • Premium skill.Active Enumeration - Web Services Part 11h 3m · 15 videos · 1 lab
  • Premium skill.Active Enumeration - Web Services Part 256m · 13 videos · 1 lab
  • Premium skill.Analyzing Scripts1h 4m · 18 videos · 1 lab
  • Premium skill.Vulnerability Discovery and Analysis Pt.11h 2m · 15 videos · 1 lab
  • Premium skill.Vulnerability Discovery and Analysis Pt.21h 2m · 15 videos · 1 lab
  • Premium skill.Metasploit Framework (MSF)1h 10m · 17 videos · 1 lab
  • Premium skill.Analyze, Prioritize and Prepare Attacks57m · 16 videos
  • Premium skill.Authentication Attacks Pt.11h 9m · 13 videos · 1 lab
  • Premium skill.Authentication Attacks Pt.21h 5m · 13 videos · 1 lab
  • Premium skill.Host Based Attacks1h 5m · 13 videos · 1 lab
  • Web Application VulnerabilitiesFree55m · 16 videos
  • Premium skill.Web Application Attacks55m · 11 videos · 1 lab
  • Premium skill.All About Shells1h 3m · 15 videos · 1 lab
  • Premium skill.Cloud Based Attacks48m · 10 videos
  • Premium skill.Wireless and Mobile Device Attacks and Tools54m · 18 videos
  • Premium skill.Social Engineering Attacks60m · 14 videos · 1 lab
  • Premium skill.Attacks and Vulnerabilities of Specialized Systems1h 4m · 18 videos
  • Premium skill.Automating Enumeration and Pentesting1h 4m · 13 videos · 1 lab
  • Premium skill.Pivoting and Lateral Movement1h 3m · 15 videos · 1 lab
  • Premium skill.Establishing Persistence55m · 10 videos · 1 lab
  • Premium skill.Data Exfiltration and Pentest Cleanup50m · 13 videos · 1 lab
Want to browse the locked skills?
with no purchase required. Already have an account?

An account gets you the full catalog to browse, pre-assessments, quiz questions on free skills, and IT Trainerbot, with every answer citing its source video.

Certification

Pentest+

The CompTIA PenTest+ certification validates the skills and knowledge required to plan and scope penetration tests, understand legal and compliance requirements, analyze results, and create reports. It is ideal for IT professionals who want to demons...

Exam PT0-003Level ProfessionalDifficulty IntermediateCost $425
Penetration testingVulnerability assessmentSecurity controlsNetwork securityApplication securityCloud security
Official certification page

Put this course to work for your team

Every plan includes this course plus the full library, virtual labs, and practice exams — or talk it through with sales.

For IT leaders

What IT leaders need to know before assigning this course

Security teams need penetration testing skills that improve risk discovery without introducing unmanaged testing practices. This CompTIA PenTest+ (PT0-003) course gives IT Directors a structured way to build or validate intermediate pentesting capability across practitioners who already have security experience. The curriculum is substantial — about 32 hours per learner — and fits penetration testers or security practitioners moving into authorized assessment work.

Teams progress from pre-engagement planning, communication, methodology, and reporting into reconnaissance, enumeration, vulnerability analysis, exploitation, post-exploitation, cleanup, and exam preparation. For change management, Team Leads should set clear rules of engagement and keep practice confined to approved lab or training environments. CBT Nuggets can support rollout with organized learning paths, realistic lab practice where available, exam-focused preparation, and Team Reporting to help Training Managers track progress.

Team Impact

How this training helps your team succeed

This training helps security teams standardize how they plan, execute, and communicate penetration testing work. The course follows the lifecycle of an authorized assessment, from pre-engagement activities through cleanup and reporting, so teams can reduce ad hoc testing habits and produce more useful findings for stakeholders.

  • Improve assessment readiness by covering scoping, communications, methodologies, and report writing before technical testing begins.
  • Strengthen vulnerability discovery through passive reconnaissance, OSINT, active enumeration, Nmap, service enumeration, and web service testing.
  • Build safer exploitation judgment by analyzing, prioritizing, and preparing attacks before practicing authentication, host-based, web application, cloud, wireless, mobile, social engineering, and specialized-system attacks.
  • Support audit and remediation workflows with training on documentation, security controls, data exfiltration considerations, persistence, lateral movement, cleanup, and final reporting.

After completion

Capabilities your team walks away with

Knowledge

  • How pre-engagement activities, communication plans, and pentesting methodologies shape an authorized assessment.
  • How passive reconnaissance, OSINT, active enumeration, and Nmap support target discovery.
  • How vulnerability discovery, analysis, and prioritization inform attack planning.
  • How common attack categories apply across authentication, hosts, web applications, cloud, wireless, mobile, social engineering, and specialized systems.
  • How pentest reporting, security controls, cleanup, and documentation support remediation.

Ability

  • Plan penetration testing work with scope, methodology, and stakeholder communication in mind.
  • Enumerate networks, services, and web services using structured reconnaissance techniques.
  • Analyze scripts and vulnerability data to prepare appropriate testing actions.
  • Practice exploitation workflows with tools and concepts such as Metasploit, shells, pivoting, lateral movement, persistence, and exfiltration.
  • Produce findings that help security leaders prioritize remediation and prepare for the CompTIA PenTest+ PT0-003 exam.

Readiness check

Confirm prerequisite knowledge before training begins

A short placement assessment on the CBT Nuggets assessments platform measures whether a learner already has the foundation this course assumes. IT Directors use it to put the right people in the right training — and any learner can take it right now to make sure they'll get full value from day one.

  • Questions generated from this course's own video transcripts — what gets measured is exactly what gets taught
  • Instant, per-learner results that show whether the prerequisite foundation is in place
  • Results roll up into team readiness reporting, so training hours go where they change outcomes
Runs on assessments.cbtnuggets.com — sign in with an Adept account so results roll up into team readiness reporting. Need one?
.

If gaps show up, start here

CompTIA Security+ (SY0-701)

Prepare for one of the most in-demand entry-level cybersecurity certifications with this CompTIA Security+ (SY0-701) training. This course covers essential cybersecurity skills including network security fundamentals, cryptography basics, threat dete...

~30h

This course is included with every subscription

Unlock this one course, or get one learner — or your whole team — access to all 287 courses, virtual labs, and practice exams.

Course Unlock

Just need this course?

$225one time

No subscription

One year of access to PenTest+

  • Every skill in this course
  • Its virtual labs and practice exam
  • Ask IT Trainerbot about it — free

CBT Nuggets Individual

IT Trainerbot Pro

$49per month

Billed annually

Every course, for one learner

See Individual pricing
For IT teams

CBT Nuggets Teams

IT Trainerbot for Teams

$59per seat / mo

Billed annually

From 1 learner seat · unlimited admin seats

Checking your access

Need tenant hosting, reseller terms, or payment plans on a larger agreement? Book a Demo to discuss an Enterprise contract.

See plans and pricing for your team

Trusted by 23,000+ organizations

Frequently Asked Questions

Is PenTest+ harder than CySA+?

It's tough to say whether PenTest+ or CySA+ is harder, since they deal with different aspects of cybersecurity, and they both depend on background and skill set. PenTest+ focuses on offensive security and would be hard for someone who didn't have practical experience with proactive cybersecurity measures. CySA+ emphasizes defensive security and would be a challenge for someone without a background in analytical tasks or incident response.

What is the difference between Comptia PenTest+ and CySA?

PenTest+ and CySA+ both cover skills in cybersecurity, but PenTest+ is mostly focused on offensive security and CySA+ is focused on defensive cybersecurity. PenTest+ teaches ethical hacking, vulnerability exploitation and penetration testing methods. CySA+ covers threat detection, incident response, and system hardening. PenTest+ is great for aspiring red team roles and ethical hackers – CySA+ is good for professionals in blue team roles, SOC analysts, or someone managing cybersecurity defense strategies.

Is the PenTest+ worth it?

PenTest+ is a big commitment of time and effort, and it's worth it for IT professionals who want certain things from their careers. If you already know you want to work in ethical hacking, penetration testing, or offensive security, the PenTest+ is worth it because it validates practical and hands-on skills in identifying and exploiting vulnerabilities in a network. The PenTest+ isn't as advanced as other offensive security certs, but it offers a well-rounded foundation in pen testing and is vendor-neutral, which makes it applicable in a wide range of environments.

Do I need Security+ if I have PenTest+?

Security+ is an earlier, less advanced certification compared to PenTest+, so if you're able to pass the PenTest+ exam, you might not benefit from going back for Security+. That said, CompTIA strongly recommends having the Network+, Security+, or both, before attempting the PenTest+, and at least three years of work experience in offensive security. So if you're experienced and trained and ready to move on to advanced offensive security techniques, you can go straight to the PenTest+. But the Security+ is a great way to get your feet under you first.

Who should earn the PenTest+?

IT professionals who know they want to work as ethical hackers, penetration testers, or find work doing red team operations are the ideal audience for this PenTest+ course and the certification. This course takes your foundational knowledge in cybersecurity and practical experience with security tools and puts them into practice in deliberate, forward-looking, proactive ways. Network administrators, security analysts, and aspiring offensive security specialists benefit the most from this course and the PenTest+ certification.

Ready to upskill your team?

Talk to our sales team to find the right plan for your organization.