CompTIA PenTest+ is the entry-level penetration testing certification, competing with EC-Council's CEH and Offensive Security's OSCP. The exam includes a heavy PBQ portion testing actual tool usage—Nmap syntax, Metasploit workflows, Burp Suite intercepts, and Linux command-line. Choose by your current skills, the exam objectives, and a sample of the teaching and practice material; no single resource is sufficient for every learner.
Jason Dion's PenTest+ course is competent but not sufficient on its own for most candidates. The exam emphasizes hands-on penetration testing methodology and tool usage, and Dion's course is lecture-heavy with limited lab walkthroughs. Pair Dion with TryHackMe's PenTest+ learning path (check access requirements) (or HackTheBox Academy modules) for hands-on practice. Use fresh practice questions to find weak topics; no practice percentage proves that you will pass the certification exam.
What Dion's PenTest+ Course Covers
Dion's PenTest+ course is ~13 hours of lecture covering the five exam domains: Planning & Scoping, Information Gathering & Vulnerability Identification, Attacks & Exploits, Reporting & Communication, and Tools & Code Analysis. Dion sells the complete course and practice-exam pack separately on Udemy; direct bundles can include labs and different support terms. Check the exact listing. The lectures are clear and well-paced, especially the planning/scoping and reporting sections (often-overlooked exam areas).
Where Dion's PenTest+ Course Falls Short
The major gap is hands-on lab depth. PenTest+ PBQs require you to actually construct Nmap scans, identify Metasploit modules, and read tool output under time pressure. Dion shows tools conceptually but doesn't replicate the time-pressured "you have 4 minutes to enumerate this network" feel of the real PBQs. Use fresh practice questions to find weak topics; no practice percentage proves that you will pass the certification exam. TryHackMe's "PenTest+ Pathway" (free with the current listed price per month subscription unlocking advanced rooms) closes this gap.
Who Should Use Dion PenTest+ Alone vs Supplement
Choose by your current skills, the exam objectives, and a sample of the teaching and practice material; no single resource is sufficient for every learner. For everyone else—including most CySA+ holders, SOC analysts transitioning to offensive security, and self-taught hobbyists—Dion plus TryHackMe is the minimum viable stack. Adding HackTheBox Academy modules (free tier covers Nmap, web fundamentals, and basic enumeration) provides an additional layer for candidates targeting OSCP next.
Pro Tips
Pair Dion with TryHackMe's free Pre-Security and PenTest+ rooms; do not skip hands-on practice.
Practice Nmap syntax until you can write scans from memory—PBQs test this directly.
Read Metasploit module output until it's second nature; PBQs include screenshot interpretation.
Take Dion's planning/scoping section seriously—it's tested more than candidates expect.
After PenTest+, consider OSCP as the natural next step; Dion's course is not OSCP prep.
Common Mistakes to Avoid
Using only Dion's course. PenTest+ PBQs require hands-on practice that video lectures can't replicate.
Scoring well on multiple-choice and assuming you'll pass. CompTIA includes performance-based questions, but does not publish a fixed PBQ count or score share. Practise both knowledge questions and hands-on tasks.
Skipping reporting and communication domain because it's "easy"—it's 14% of the exam and easy points.
Treating PenTest+ as a stepping stone to OSCP. It teaches different methodologies; complementary but distinct.
Buying expensive lab platforms (HackTheBox Pro, PentesterLab) before exhausting free TryHackMe content.
Practice for 25+ Certifications—Free
Pair Jason Dion's courses with adaptive practice questions, detailed explanations, and progress tracking. Free daily questions across 25+ certifications.
Start Free Practice