
CompTIA PenTest+ (v3)
Exam PT0-003 CompTIA Intermediate
The offensive counterpart to CySA+. Scoping, reconnaissance, exploitation and — the part most people underrate — writing the report.
The path
Step 1 — Learn the methodology
Plan and scope an engagement legally and professionally.
1 course
Learn
- CourseTotal: CompTIA PenTest+ v3 🔒 StationX Unlimited
16 sections · 138 lectures
- Course Overview 2
- Introduction to CompTIA PenTest+ (PT0-003) 3
- Planning and Engagement 13
- Information Gathering and Vulnerability Scanning 27
- Network-Based Attacks 9
- Wireless and RF Attacks 3
- Web and Database Attacks 15
- Attacking the Cloud 3
- Specialized and Fragile Systems 4
- Social Engineering and Physical Attacks 6
- Post-Exploitation 8
- Post-Engagement Activities 10
- Tools and Code Analysis 15
- Tools Inventory 18
- Next Steps & Certification 1
- Audio Version of Training 1
Free resources
Step 2 — Reconnaissance and scanning
Map an estate and find what is exposed.
29 labs
Learn
- CourseCovered in Total: CompTIA PenTest+ v3 — reconnaissance and scanning sections 🔒 StationX Unlimited
Practise
- LabsEthical Hacking Fundamentals — 18 labs 🔒 StationX Unlimited
- Additional Scanning Options
- Automated Vulnerability Assessments
- Basics of Metasploit
- Core Impact Vulnerability Scan
- Creating Recommendations Based on Vulnerability Assessments
- Host Identification Scanning via Windows
- Host Identification Scanning with Linux
- Identifying System Vulnerabilities with OpenVAS
- Manual Vulnerability Assessment
- Nessus Scanning and Reporting
- Nessus Setup and Config
- Network Discovery
- Open Source Collection
- Scanning From Windows
- Scanning and Enumeration
- Scanning and Enumeration (2026)
- Scanning and Mapping Networks
- Vulnerability Scanner Set-up and Configuration
- Labs+Introduction to Ethical Hacking — 11 labs 🔒 StationX Labs+
- Can You Explore Vulnerabilities in Systems, Network Traffic, and Passwords? [Advanced]
- Can You Perform DOS and AitM Attacks? [Advanced]
- Can You Perform OSINT and Host Discovery? [Advanced]
- Can You Perform OSINT by Using recon-ng, Perform Scans with Nmap & GSA, and Perform AitM Attacks? [Expert]
- Execute Network Reconnaissance [Guided]
- Intercept and Obtain Passwords [Guided]
- Monitor Network Traffic by Using Wireshark [Guided]
- Perform DOS Attacks [Guided]
- Perform Open Source Intelligence [Guided]
- Perform Vulnerability Scans [Guided]
- Perform an Attacker-in-the-Middle (AitM) Exploitation [Guided]
Step 3 — Exploitation
Turn a finding into proven impact.
26 labs
Learn
- CourseCovered in Total: CompTIA PenTest+ v3 — exploitation and attack sections 🔒 StationX Unlimited
Practise
- Labs+Operating System Exploits — 11 labs 🔒 StationX Labs+
- Can You Exploit Windows with Metasploit and Code Analysis? [Advanced]
- Can You Exploit Windows? [Advanced]
- Can You Find Flaws with OSINT and Vulnerability Scanning? [Advanced]
- Can You Perform Open-source Intelligence (OSINT)-Gathering Operations? [Expert]
- Discover and Exploit Targets by Using Metasploit [Guided]
- Exploit Common Windows Flaws [Guided]
- Exploit Flawed Code [Guided]
- Gain Remote Access to a Windows System [Guided]
- Perform Open System Intelligence (OSINT) Gathering [Guided]
- Perform Post-Exploit Activities [Guided]
- Schedule and Perform Network Vulnerability Scans [Guided]
- LabsPentesting and Network Exploitation — 15 labs 🔒 StationX Unlimited
- Basics of Metasploit
- Client-Side Exploitation with Social Engineering
- Cybersecurity Testing with Core Impact
- Evasive Maneuvers and Post Exploitation
- Intro To Linux - Backing Up, Compression, and Scheduling
- Intro to Linux - Routing and SSH Tunnels
- Linux Exploitation
- Network Miner
- Open Source Password Cracking
- Pentesting & Network Exploitation - Linux Target Analysis Labs
- Pentesting & Network Exploitation: DMZ Exploitation
- Pentesting & Network Exploitation: LAN Exploitation
- Pentesting & Network Exploitation: Windows Target Analysis Labs
- Post Exploitation and Pivoting
- Windows Exploitation
Step 4 — Web application testing
Work the OWASP Top Ten by hand.
27 labs
Learn
- CourseCovered in Total: CompTIA PenTest+ v3 — web application testing sections 🔒 StationX Unlimited
Practise
- LabsIntroduction To OWASP Top Ten — 13 labs 🔒 StationX Unlimited
- OWASP Top Ten 2025 - A01 Broken Access Controls
- OWASP Top Ten 2025 - A02 Security Misconfiguration
- OWASP Top Ten 2025 - A03 Software Supply Chain Failures
- OWASP Top Ten 2025 - A04 Cryptographic Failures
- OWASP Top Ten 2025 - A05 Injection
- OWASP Top Ten 2025 - A06 Insecure Design
- OWASP Top Ten 2025 - A07 Authentication Failures
- OWASP Top Ten 2025 - A08 Software or Data Integrity Failures
- OWASP Top Ten 2025 - A09 Security Logging & Alerting Failures
- OWASP Top Ten 2025 - A10 Mishandling of Exceptional Conditions
- OWASP Top Ten 2025 - Capstone
- OWASP Top Ten 2025 - Capstone (pt.1)
- OWASP Top Ten 2025 - Capstone (pt.2)
- LabsAdvanced Web Application Exploitation — 14 labs 🔒 StationX Unlimited
- Web 201 - Lab 1: Recon Tools
- Web 201 - Lab 2.1: Detecting and Exploiting Hard to Find SQL injections
- Web 201 - Lab 2.2: Advanced Sqlmap
- Web 201 - Lab 2.3: Manual Blind SQL Injection
- Web 201 - Lab 2.4: NoSQL Injection
- Web 201 - Lab 3.1: Cross Site Scripting Filter Evasion
- Web 201 - Lab 3.2: Exploiting Misconfigured CORS
- Web 201 - Lab 4: Advanced OS Command Injection
- Web 201 - Lab 5: Advanced Local File Inclusion
- Web 201 - Lab 6: Advanced CSRF
- Web 201 - Lab 7.1: XXE to Obtain Arbitrary Files
- Web 201 - Lab 7.2: Out of Band XXE Attacks
- Web 201 - Lab 8: Server Side Request Forgery
- Web 201 - Lab 9: Insecure Deserialization in Python and Java
Free resources
Step 5 — Scripting for testers
Automate the boring parts.
7 labs
Learn
- CourseCovered in Total: CompTIA PenTest+ v3 — scripting and automation sections 🔒 StationX Unlimited
Free resources
Before the exam
- FreeFree PenTest+ Performance Based Questions (PBQs)
- FreePenTest+ Cheat Sheet
- FreeCompTIA Certification Cost Guide
- CourseCompTIA PenTest+ The Ultimate Practice Exam 🔒 StationX Unlimited
1 section · 5 lectures
- Practice Tests 5
- CourseCompTIA PenTest+ v3 Certification Practice Tests 🔒 StationX Unlimited
4 sections · 10 lectures
- Pentest+ v3 Practice Tests 3
- Practice Question by Question 1
- Practice Questions per Domain 5
- Next Steps & Certification 1
- CourseCompTIA PenTest+ Practice Flashcards 🔒 StationX Unlimited
3 sections · 6 lectures
- Practice Questions 0
- Practice Flashcards 5
- Next Steps & Certification 1