CompTIA updated the PenTest+ certification this year with a new version and the changes are significant enough that it is worth talking about separately from the existing credential reputation.
The original PenTest+ launched in 2018 and got a mixed reception. Some people in the penetration testing community felt it was too broad and not rigorous enough compared to hands-on credentials like the OSCP. Others saw it as a useful vendor-neutral bridge between general security knowledge and specialized offensive security skills. That debate is still going on, but the updated version has added enough substantive content that the “not rigorous enough” criticism applies less than it used to.
The updated PT0-002 exam covers planning and scoping, information gathering and vulnerability scanning, attacks and exploits, reporting and communication, and tools and code analysis. The attacks and exploits domain has been expanded to cover current attack techniques more thoroughly, including cloud attacks, web application vulnerabilities, and the kinds of social engineering scenarios that show up in real penetration testing engagements. The code analysis component requires candidates to review and understand scripts and code in ways that push past the pure click-through level of security knowledge.
It is still a multiple choice and performance-based hybrid exam rather than a pure hands-on credential like OSCP or GPEN. For people who are building toward a penetration testing career, those hands-on credentials remain the gold standard. But for security professionals who work in roles where they need to understand offensive security techniques well enough to evaluate findings, communicate with red teams, or perform scoped assessments without making pentesting their full-time specialty, the PenTest+ occupies a reasonable middle ground.
The DoD 8570 approval for the PenTest+ in the CND and CSSP-Auditor categories also gives it a specific audience for people in or adjacent to the federal security ecosystem. The CompTIA PenTest+ page has the current exam objectives and the DoD approval category information.
If you looked at the original PenTest+ and wrote it off, the updated version is worth a second look. It is a more substantive exam than the first version was.
Cody Davis is the Program Director for the certification courses on this site, where he oversees curriculum design and the overall learning experience. He holds several IT certifications and brings a practitioner's mindset to everything he builds. When he's not helping IT pros level up their careers, he's wrangling three kids and adding to a GI Joe collection that his family pretends not to notice.
