If you're studying from a PT0-002 book, a bootcamp recording, or a site that hasn't updated its listings, here's what you need to know: CompTIA retired the English-language PT0-002 exam on June 17, 2025, and pulled the remaining Japanese, Portuguese, and Thai versions a year later. You cannot register for or sit PT0-002 today. Every new candidate is routed to OFFICIAL PT0-003, which launched in December 2024 with a restructured domain list and a heavier lean toward cloud attacks and scripting. We're keeping this practice set live because a large share of people searching "PT0-002" are working through older study material and need to know how it lines up with what's actually tested now — not because you can still book this version at Pearson VUE. For candidates transitioning to PT0-003, a free exam preparation platform can also provide an accessible way to review updated topics and practice exam-style questions before moving on to official preparation resources.
What PT0-002 Actually Tested
PT0-002 measured whether a candidate could run a penetration testing engagement start to finish, not just recite attack names. It was built around five domains, and the weighting told you exactly where CompTIA expected competence:
Planning and Scoping (14%) — rules of engagement, contract review, legal and compliance boundaries (SOW, MSA, NDA), and distinguishing black box, white box, and gray box engagements.
Information Gathering and Vulnerability Scanning (22%) — OSINT techniques, active and passive reconnaissance, DNS enumeration, and reading Nessus/OpenVAS scan output well enough to prioritize findings by CVSS score.
Attacks and Exploits (30%) — the single largest domain, covering network attacks, wireless attacks (WPA/WPA2 cracking, rogue AP), web application attacks (SQLi, XSS, CSRF, XXE), social engineering, and cloud- and mobile-specific vectors.
Reporting and Communication (18%) — writing findings for a technical audience versus an executive summary for leadership, CVSS scoring, and remediation recommendations. This is the domain PenTest+ candidates most often underestimate, because it's the part that has nothing to do with hacking and everything to do with being employable afterward.
Tools and Code Analysis (16%) — reading (not necessarily writing) Python, Bash, and PowerShell snippets to identify what a script does, plus familiarity with Metasploit, Burp Suite, Nmap, and Hydra.
That domain list is worth knowing even if you're now PT0-003 bound, because Domains 1–3 carried over in spirit — Attacks and Exploits is still the largest single domain on PT0-003, just relabeled and reweighted at 35%. What disappeared was the standalone Tools and Code Analysis domain; PT0-003 folded scripting and tool usage into the other four domains instead of scoring it separately.
Who Took PT0-002 Exam, and Why It Matters Now
PenTest+ was never an entry-level cert. CompTIA's stated target was someone with three to four years of hands-on security experience, usually already holding Security+ or Network+, moving from a defensive or generalist security role into offensive work — vulnerability management analysts, network administrators picking up red team responsibilities, and SOC analysts who wanted to understand attacker tradecraft instead of just detecting it. If you're one of the people who studied PT0-002 material but haven't sat the exam yet, you're not behind schedule in the way you might think: the underlying skill set (scoping, enumeration, exploitation, reporting) is still exactly what PT0-003 tests. What changed is depth in specific areas — expect more cloud-native attack scenarios and heavier scripting emphasis on the current version than PT0-002 ever asked for.
Exam Format (as PT0-002 Ran It)
PT0-002 allowed a maximum of 85 questions — a mix of multiple choice and performance-based questions (PBQs) — inside a 165-minute window, with a passing score of 750 on a 100–900 scale. The PBQs were the part that actually separated candidates: instead of picking an answer, you'd be dropped into a simulated terminal or given a scan output and asked to interpret it, order a testing methodology correctly, or select the right Nmap flags for a given scenario. Candidates who only memorized flashcards consistently ran out of time or froze on PBQs, because those questions don't reward recognition, they reward having actually run the commands before. Retakes had no mandatory waiting period after a first failed attempt, but a 14-day wait applied before a third or later attempt.
How to Use PT0-002 Practice Set Effectively
Treat this set as a diagnostic for methodology, not a memorization drill. Run through a batch of Attacks and Exploits questions and time yourself the way the PBQs forced you to — under five minutes per scenario question, not per multiple-choice item. If you're studying with an eye toward PT0-003 rather than a now-defunct PT0-002 registration, pay closest attention to the questions on scan interpretation and reporting; those objectives barely moved between versions, so getting them solid here transfers directly. Skip spending study hours memorizing the Tools and Code Analysis weighting number itself — that domain doesn't exist as a standalone section anymore, though the tool knowledge underneath it is still tested elsewhere.
Common Mistakes Candidates Made on PT0-002 Exam
The most frequent failure pattern on PT0-002 wasn't lack of technical knowledge — it was treating Reporting and Communication as an afterthought worth 18% of their prep time proportional to score value, when in practice examiners wrote genuinely tricky questions there: distinguishing what belongs in an executive summary versus a technical appendix, or picking the correct CVSS vector components for a described vulnerability. A close second was misreading scope boundaries in scenario questions — engagement rules questions frequently included a detail (an out-of-scope subnet, a blackout window) that changed the correct answer, and candidates who skimmed the scenario missed it. Third, people consistently underprepared for wireless attack questions because wireless felt like a smaller slice of daily pentesting work, even though it sat inside the 30% Attacks and Exploits domain alongside network and web app content.
Study Tips Specific to PenTest+ Content
Build a home lab with a vulnerable target (Metasploitable2 or a TryHackMe/HTB room) and actually run a full engagement cycle — recon, scan, exploit, then write a one-page report — at least twice before you touch a practice exam. PenTest+ is one of the few CompTIA exams where you can't shortcut hands-on time with flashcards, because the PBQs are designed to catch people who've only read about a tool rather than used it. When you review a missed question on an Attacks and Exploits item, don't just learn the right answer — go run that specific attack technique in your lab if you can, since the exam tends to test the same technique from multiple angles across a test bank. For the Reporting domain specifically, find one (redacted) penetration test report online and read it end to end; nothing in a question bank teaches report structure as well as seeing a finished one.
Where to Go From Here
If you're prepping for an active certification today, your next step is a PT0-003-aligned practice test, not more PT0-002 material — the exam blueprint, question count (up to 90), and domain weighting have all shifted. Use this set to confirm your foundational methodology is solid, then move to current PT0-003 content for anything cloud- or scripting-heavy before you book an exam.