You can finish a PenTest+ study guide, pass every end of chapter quiz, and still fail the exam, because it does not ask you to define an attack. It asks you to run one. A share of the questions are performance based: you sit in front of a simulated target, read tool output, and demonstrate. Read a study guide cold and you will know the vocabulary of penetration testing without being able to do any of it, which is the one thing this certification is built to check.
That is the thing to get right before you spend anything on CompTIA PenTest+ prep. This is the hands on exam in CompTIA’s security line. Attacks and exploits alone is 35% of the paper, and the publisher backed book market for it is thin. There is exactly one current, cleanly stocked study guide from a major publisher, the Sybex guide for PT0-003, sitting in a shelf full of self published titles that borrow the exam code and little else. So the real question is not which of ten study guides to buy. It is which single guide to pair with the hands on books that teach you to actually pop a box.
The current version is PT0-003. Buy the one current guide for the objectives and the reporting, then spend most of your money and nearly all of your time on the books below that put you at a keyboard. This guide sorts the shelf: the one exam guide worth owning, the hands on books that carry the weight, and the retired code and filler to walk past.
Checked against CompTIA’s PT0-003 exam page and live Amazon listings in September 2026. Nothing here was lab tested, because these are books.
Why a study guide alone will not get you through PenTest+
PenTest+ is at most 90 questions, multiple choice and performance based, in 165 minutes, scored from 100 to 900 with a pass at 750. CompTIA recommends three to four years in a penetration testing role behind you, with Network+ and Security+ level knowledge assumed. The questions are drawn from five domains, and the weights tell you where the exam actually spends its attention.
| Domain | Weight |
|---|---|
| Engagement management | 13% |
| Reconnaissance and enumeration | 21% |
| Vulnerability discovery and analysis | 17% |
| Attacks and exploits | 35% |
| Post-exploitation and lateral movement | 14% |
Look at the split. Engagement management, the scoping, rules of engagement, compliance and reporting work, is the one domain a study guide is genuinely built to teach, and it is 13% of the paper. The other 87% is technique: finding hosts, finding holes, exploiting them, and moving through what you land on. You do not learn technique by reading about it, and the performance based questions exist precisely to catch the candidate who tried. This is why the shape of a good PenTest+ shelf is lopsided. One book covers the 13% properly and gives you the exam’s language and question format. The rest of your reading has to be the kind that ends with you at a shell.
The exam you are buying for, and the one still on the shelf
PenTest+ has an exam code on the cover, and unlike a job practice it changes cleanly, so the trap is simpler to describe and just as easy to fall into. The current version is PT0-003, launched in December 2024. The previous version, PT0-002, retired in June 2025 and cannot be sat any more. The failure mode here is buying a good book for a code you can no longer test on, and the listings that lead you there are the older editions from the same authors, at the same price, still selling well.
| Exam version | Status | What to check |
|---|---|---|
| PT0-003 | Current | Cover reads “Exam PT0-003” |
| PT0-002 | Retired June 2025, cannot be sat | Cover reads “Exam PT0-002”; walk past it |
Read the code on the cover before anything else, every time. The Sybex second edition for PT0-002 is still in stock, by the same author line, at almost exactly the price of the current one. Sort a search by reviews and it floats to the top on years of accumulated ratings the new edition has not had time to earn. That is the single most common way to waste forty dollars on this certification.
The five PenTest+ books at a glance
One of these is the exam guide. The other four are how you learn to pass a performance based exam, and none of them carries an exam code, because technique does not expire the way a blueprint does. Prices move week to week, so each figure is a band to check against the live listing.
| Book | Publisher | Role | Pages | What comes with it | Price band |
|---|---|---|---|---|---|
| PenTest+ Study Guide, 3rd ed (PT0-003) | Sybex | Exam guide | 608 | 1 year Sybex online: practice exam, 100 flashcards, glossary | about $40 |
| Penetration Testing (Weidman) | No Starch | Lab teacher | 528 | Build-your-own lab walkthrough | about $28 |
| Hands on Hacking | Wiley | Modern hands on | 608 | Guided attack walkthroughs | about $24 |
| RTFM: Red Team Field Manual v2 | Ben Clark | Command reference | 130 | Command reference only | about $13 |
| The Hacker Playbook 3 | Peter Kim | Engagement playbook | 289 | Engagement-structured walkthroughs | about $30 |
The exam guide is the most expensive book on the list and does the least actual attacking, which is exactly as it should be: you are paying it for the objectives, the reporting domain, and the question format, not for teaching you to exploit. The cheapest book here, a 130 page field manual, will spend more time open on your desk than any of the others. Check the live price on all five, then read on for how each earns its place.
1. CompTIA PenTest+ Study Guide, Third Edition (Exam PT0-003)
Buy this one, and check the cover says PT0-003 before you do. Mike Chapple, Robert Shimonski and David Seidl wrote the current Sybex guide, and it is the only major publisher study guide for this version that is cleanly in stock.

What it does well is the part the hands on books skip. It maps chapter by chapter to the PT0-003 domains, it covers engagement management and reporting properly, and it drills you in the exam’s own question shapes, including a year of access to the Sybex online environment with a custom practice exam, a hundred electronic flashcards, and a searchable glossary. Chapple and Seidl are the same authorship behind much of Sybex’s security line, so the tone and structure are familiar if you came through Security+ or CySA+. Treat this as the map of what the exam wants, not the training for doing it.
Who it is for: everyone sitting PenTest+, as the one book that covers the objectives end to end and shows you the question format. Skip it if you are hoping a single guide will get you through the performance based questions. At 608 pages it explains the techniques, but reading about a Metasploit workflow is not the same as running one, and the exam knows the difference. Around $40, check the live price.
2. Penetration Testing: A Hands-On Introduction to Hacking by Georgia Weidman
Read the caveat first: this book is over a decade old, and its specific tool versions have moved on. Read it anyway, because nothing else teaches the workflow as cleanly for someone starting from nothing.
Georgia Weidman walks you through building a lab of vulnerable targets and then attacking it, in the same order the exam thinks in: reconnaissance, then finding a way in, then what you do once you are on the box. The commands and screenshots are dated, so treat them as the shape of the work rather than copy and paste, and expect to translate a few into the current Kali toolset. What has not aged is the reasoning, and that is what a beginner is actually missing. Pair it with the current guide so the domain coverage stays aligned to PT0-003, and use this to turn the study guide’s descriptions into things your hands have actually done.
Who it is for: anyone new to offensive work who needs the end to end methodology once, slowly and in a lab. Skip it if you already run engagements, because the tooling is dated and the methodology will be familiar ground. This is the oldest pick here, and it earns the place on method, not on currency. Around $28, check the live price.
3. Hands on Hacking by Matthew Hickey and Jennifer Arcuri
This is the newer hands on book, and the one to reach for where Weidman shows its age. Matthew Hickey and Jennifer Arcuri wrote it around live style targets and current attack chains.
It runs 608 pages of guided attacks across the same territory the exam covers, from open source intelligence and enumeration through exploitation and post exploitation, with the tooling recent enough that most of it still runs as printed. The authors run a training company, and it reads like a course: each technique is set up, explained, and then done. Where Weidman gives you the classic single narrative, this gives you a broader spread of modern targets and a purple team framing that fits how PenTest+ now talks about findings and remediation. It is the best value on the list, cheaper than the exam guide and doing more of the work the exam actually tests.
Who it is for: the reader who wants one current hands on book and will work the examples rather than skim them. Skip it if you want a terse reference; this teaches at length, which is the point, but it is a commitment. Around $24, check the live price.
4. RTFM: Red Team Field Manual, Version 2 by Ben Clark and Nick Downer
This is not a book you read. It is a book you keep open next to the keyboard, and on a timed performance based exam that habit is worth more than another study guide.
Ben Clark’s field manual is 130 pages of the exact syntax you forget under pressure: the one liners for Windows and Linux enumeration, the pivoting commands, the PowerShell and networking recipes you know exist but cannot quite recall at the moment you need them. Version 2 is a real revision of the original, not a reprint. It teaches nothing on its own, which is why it is here alongside the books that do, and it is where recall stops being a bottleneck once you have learned the technique from Weidman or Hands on Hacking. It is also the cheapest thing on this list by a wide margin, and it stays useful long after you certify, in the actual job.
Who it is for: anyone who has done the technique and now needs the syntax at their fingertips, in the exam and on real engagements. Skip it if you are still learning what the commands do, because a reference will not teach you that. Around $13, check the live price.
5. The Hacker Playbook 3 by Peter Kim
The last pick is structured the way an engagement runs, which is also the way PenTest+ is weighted. Peter Kim’s playbook moves from reconnaissance through exploitation to post exploitation and lateral movement, in that order.
It reads as a series of plays rather than a textbook, each a concrete attack you set up and execute, which is why it maps so neatly onto the domains that carry the most weight. It is eight years old now, so some tooling has been superseded, and it assumes more baseline than Weidman does. What it gives you that the others do not is the feel of an engagement as a sequence of decisions, chaining one foothold into the next, which is the mindset the post exploitation and lateral movement questions probe. Work it after you have the fundamentals down, as the book that ties recon, exploitation and pivoting into one continuous attack.
Who it is for: readers past the basics who want to think in whole engagements rather than isolated techniques. Skip it if you are still on your first lab, because it moves fast and expects the groundwork. Around $30, check the live price.
The books to leave on the shelf
Two of the picks above are self published, which may make you wonder about the warning that follows, so let me draw the line clearly. Self published is not the same as low quality. RTFM and The Hacker Playbook are self published, and both are written by named practitioners with a decade of citations behind them. The tell of a book to avoid is not the imprint. It is a generic title built to match the exam code, from an author with no track record, published to ride the search traffic.
The first thing to walk past is the retired code. The Sybex second edition for PT0-002 and the McGraw Hill All-in-One second edition are both still on Amazon, both good books in their day, and both written for an exam that closed in June 2025. McGraw Hill has not shipped a third edition for PT0-003, so its PenTest+ line is stranded on the old code. There is also an academic textbook, Cengage’s guide to penetration testing, but it predates the current version, lists around ninety dollars, and does not sit in clean stock, so it is not the buy for a self funded candidate.
The larger pile is the row of cheap paperbacks with titles like PenTest+ PT0-003 Exam Prep and PenTest+ Fast Track Study Guide, priced from a few dollars to the mid thirties, carrying no established publisher and no author you can look up. Sybex is the one major house maintaining a current PenTest+ study guide, with McGraw Hill and Cengage a version behind. A generically titled guide from none of them is not worth the saving, and Amazon has been tightening its rules on study guide and companion titles for exactly this reason. If you are certifying across the wider security stack, our guide to CompTIA CySA+ books covers the analyst path alongside this offensive one, the CISA book guide covers the audit side, and the broader cybersecurity and penetration testing reading list applies the same publisher and edition checks.
Where the study time actually goes
The books are the smaller part of passing PenTest+. The larger part is a lab, and the order you use these in matters more than which ones you own. Buy the Sybex guide first, but do not sit and read it front to back. Skim it once for the shape of the domains, then build a target lab and start attacking it, with Weidman if you are new to this or Hands on Hacking if you want current tooling as your walkthrough.
Once the techniques are in your hands, use The Hacker Playbook to chain them into whole engagements, and keep RTFM open the entire time so recall stops slowing you down. Come back to the study guide last, to close the gaps the lab did not cover, drill its practice questions, and read the engagement management and reporting chapters properly, because that 13% is the part you cannot practice against a target and the part the hands on books ignore. Set your target on running the attacks, not reading about them, and the exam stops being the obstacle. The lab is where you pass it. The books just tell you what to do there.



