Skip to content

The Five PenTest+ (PT0-003) Domains

The core knowledge areas of the CompTIA PenTest+ (PT0-003) exam. Each page below is written toward the official PT0-003 exam objectives and covers the domain's concepts, a Mermaid diagram, and the key terms a sysadmin moving into penetration testing needs — with techniques explained conceptually, for understanding and for defence/methodology, never as weaponized step-by-step playbooks. The percentages are CompTIA's published weightings (the share of scored content per domain) (verify on CompTIA — weightings change per exam version).

[!IMPORTANT] Authorised use only. Every technique these pages describe is performed in practice only with explicit written authorisation from the system owner, a defined scope, and agreed Rules of Engagement (RoE). Penetration testing without that permission is a crime — the difference is permission, not tooling. This hub mirrors the CEH hub's framing: techniques are taught conceptually and defensively, with no operational exploit code. See ../../ceh/00-overview/legal-and-ethics.md.

The objectives PDF is the canonical checklist for exact wording and every listed term, tool, and acronym — see how to get it. These pages follow it but do not replace it.

Learning objectives

  • Identify the five PT0-003 domains, their weightings, and their themes.
  • Use the weightings to prioritise study time (Attacks and Exploits is the largest at 35%).
  • Navigate to the per-domain page written toward the official objectives.

Domain index

# Domain Weight Theme (one line)
1 Engagement Management 13% Pre-engagement scoping, RoE, contracts, ethics, methodology, and reporting
2 Reconnaissance and Enumeration 21% OSINT, scanning, service/host enumeration, and target profiling
3 Vulnerability Discovery and Analysis 17% Finding, validating, and prioritising weaknesses (CVSS, false positives)
4 Attacks and Exploits 35% Exploiting network, host, web, wireless, cloud, and social-engineering weaknesses
5 Post-exploitation and Lateral Movement 14% Persistence, pivoting, privilege escalation, and proving impact within scope
flowchart LR
    Idx(["PT0-003 domains<br/>(by weight)"])
    Idx --> D4["4 · Attacks &<br/>Exploits — 35%"]
    Idx --> D2["2 · Recon &<br/>Enumeration — 21%"]
    Idx --> D3["3 · Vuln Discovery<br/>& Analysis — 17%"]
    Idx --> D5["5 · Post-exploit &<br/>Lateral Move — 14%"]
    Idx --> D1["1 · Engagement<br/>Management — 13%"]

How to use these pages

  • Prioritise by weight. Domain 4 (Attacks and Exploits, 35%) is the largest — but it depends entirely on the recon and analysis in Domains 2 and 3 (~38% combined). Domain 1 (Engagement Management, 13%) carries the planning, ethics, and reporting that make the rest lawful and useful; do not skip it because it is the smallest.
  • Pair with the objectives PDF. Track each sub-objective against the official list; these pages are written toward those objectives but the PDF is the authoritative checklist — see exam-and-objectives.md.
  • Cross-reference the defensive view. Where this hub covers an attack, the Security+ hub and the attack-to-defense matrix cover the controls that stop it; the CEH modules cover the same techniques from a parallel offensive curriculum; the protocols reference and foundations reinforce shared fundamentals.

Where to go next

Sources