Free shipping on orders over $99 · Use code LEARN26 for 10% off
Free Trial available for 5 days!4.9 star average ratingFree chapter every monthShipping to 120+ countries Free Trial available for 5 days!4.9 star average ratingFree chapter every monthShipping to 120+ countries
Support · Partner
Get the full year subscription for unlimited reading — 2 months freeBuy a 3-book bundle — 20% off each book!
Back to the blog
PenTest+10 min read

I Failed PenTest+ the First Time. Here's the Domain That Killed Me.

I could pop a shell in my sleep. I still failed PT0-003, and the reason was a domain I had quietly decided did not count. Here is what I got wrong, and how I passed on the resit.

I want to tell you about the most useful failure of my career, because I suspect you are about to make the same mistake I did. I walked into the PenTest+ PT0-003 exam confident to the point of arrogance. I had done real engagements. I could enumerate a network, find the weak spot, and get a shell without breaking a sweat. And I failed.

Not by a little. I walked out knowing it had gone badly, and the score confirmed it. What stung was that I had failed on the part of the job I was best at — or so I thought. The truth was more uncomfortable: I had failed on the parts I had decided, without ever admitting it to myself, did not really count.

The overconfidence trap

Here is the trap, and it catches experienced people far more than beginners. When you are good at the exciting part of a discipline, you assume the exam is mostly about that exciting part. I am good at exploitation, so I studied exploitation. I read about the latest techniques, practised in labs, and felt ready. I spent almost no time on scoping, planning, or reporting, because in my head those were paperwork — the boring wrapper around the real work.

That framing is exactly backwards for the exam, and honestly, for the profession. PenTest+ is not a hacking test. It is a test of whether you can conduct a professional engagement end to end, and the exciting exploitation part is only one slice of it. I had prepared for the slice I liked and ignored the rest.

The mindset that fails you

"I do this for a living, I don't need to study the basics." Every experienced candidate who fails says a version of this afterwards. Real-world skill in one domain creates a blind spot for the domains you never think about because someone else on your team handles them.

The domain that actually beat me

When the score report came, the pattern was brutal and clear. My exploitation and post-exploitation scores were fine. What dragged me under were the first and last stages of an engagement: Engagement Management — scoping, rules of engagement, legal and compliance considerations — and the reporting and communication that closes every real test.

Attacks & Exploits 88% Vulnerability Discovery 81% Recon & Enumeration 79% Post-Exploitation 74% Engagement Management 52% Reporting & Communication 49%
The two domains I dismissed as "paperwork" are exactly where I lost the exam.

Look at that chart and the story tells itself. I was strong where I was comfortable and weak where I was dismissive, and the exam weights those "dismissive" areas heavily on purpose. Engagement Management alone is a substantial chunk of PT0-003, and I had treated it as an afterthought. On the exam, a scoping question is worth exactly as much as an exploitation question, and I had prepared for one and not the other.

Get PenTest+ certified — first try, no resitAll-in-One Study Guide. Ebook $29.99, only $26.99 with code LEARN26.
Claim your discount

Why strong hackers fail this exam

It took the failure to make me understand why the exam is built this way. In the real world, an unscoped test is a crime. Attacking a system outside your agreed rules of engagement is not clever, it is illegal, and it can end a career and start a lawsuit. A tester who does not deeply understand scope, authorisation, and the legal frame of an engagement is not a skilled tester — they are a liability with good tooling.

The same is true for reporting. I have watched genuinely brilliant findings get completely ignored because the report was unclear, unprioritised, or written for other hackers instead of for the client who had to act on it. A vulnerability nobody fixes because nobody understood the writeup is, in business terms, a vulnerability you failed to find. The exam refuses to let you skip these things because the profession cannot afford testers who skip them.

1 Scope legal, rules, limits 2 Recon enumerate the target 3 Exploit the fun part 4 Report so it gets fixed
Exploitation is one box. The exam tests all four, and I had studied one.

How I passed the second time

The resit strategy was almost entirely about the two domains that beat me. I did not spend another hour on exploitation — I was already strong there and adding more would have been comfort studying, the certification equivalent of rearranging a desk instead of doing the work. Instead I did the thing I had been avoiding.

I learned the structure of a real rules-of-engagement document and what each clause protects against. I studied the legal and compliance frameworks that govern testing, not as trivia but as the guardrails they are. And I read real penetration test reports — good ones and bad ones — until I understood what makes a finding actionable: a clear description, an honest severity rating, evidence, and a specific remediation the client can actually implement.

What a finding should contain# Anatomy of a report finding that gets fixed
Title:        Clear, specific, non-sensational
Severity:     Justified by real impact + likelihood
Description:  What it is, in the client's language
Evidence:     Enough to reproduce, not to grandstand
Remediation:  A specific, achievable fix

I passed the resit comfortably, and the interesting part is that it made me better at the actual job, not just the exam. I scope engagements more carefully now. I write reports the client can act on. The domains I had dismissed as paperwork turned out to be the difference between someone who can break into things and a professional who can be trusted to do it for money.

If you are strong on the offensive side and about to sit PenTest+, take the warning from someone who learned it the expensive way: your strength is not the exam. Study the parts you find boring, because the exam — like the profession — weights them exactly as heavily as the parts you love.

The lesson that outlasted the exam

What I carry from that failure is bigger than a certificate. It reshaped how I think about competence itself. Being excellent at the visible, exciting part of a job creates a dangerous confidence that the whole job is that part — and it never is. The surgeon has to manage consent and records; the pilot has to file the flight plan; the penetration tester has to scope the engagement and write the report. The unglamorous surrounding work is not a tax on the real skill; it is what makes the real skill safe to sell. I failed because I had mistaken the thrilling middle of the job for the whole of it, and the exam, correctly, refused to let me. Now, when I train new testers, the first thing I tell them is to study the boring domains first — because those are the ones their pride will tell them to skip, and their pride is exactly what fails the exam.

Bundle all three best-sellers and save up to $50

A+ Core 1, A+ Core 2 and PenTest+ in one order — $135 in paperback or $80 for all three ebooks. The cheapest route to both certifications.

See the bundle