CompTIA PenTest+ is the entry-level penetration testing certification, competing with EC-Council's CEH and Offensive Security's OSCP. The exam includes a heavy PBQ portion testing actual tool usage—Nmap syntax, Metasploit workflows, Burp Suite intercepts, and Linux command-line. Jason Dion's PenTest+ course is the dominant Udemy option, but it's less self-sufficient than his Security+ or A+ courses because penetration testing genuinely requires hands-on practice that videos can't fully provide.
Jason Dion's PenTest+ course is competent but not sufficient on its own for most candidates. The exam emphasizes hands-on penetration testing methodology and tool usage, and Dion's course is lecture-heavy with limited lab walkthroughs. Pair Dion with TryHackMe's free PenTest+ path (or HackTheBox Academy modules) for hands-on practice. Candidates who use Dion alone tend to fail PBQs even when they ace the multiple-choice section.
What Dion's PenTest+ Course Covers
Dion's PenTest+ course is ~13 hours of lecture covering the five exam domains: Planning & Scoping, Information Gathering & Vulnerability Identification, Attacks & Exploits, Reporting & Communication, and Tools & Code Analysis. He includes 6 practice exams and walks through high-level tool usage for Nmap, Metasploit, Burp Suite, and basic Linux. The lectures are clear and well-paced, especially the planning/scoping and reporting sections (often-overlooked exam areas).
Where Dion's PenTest+ Course Falls Short
The major gap is hands-on lab depth. PenTest+ PBQs require you to actually construct Nmap scans, identify Metasploit modules, and read tool output under time pressure. Dion shows tools conceptually but doesn't replicate the time-pressured "you have 4 minutes to enumerate this network" feel of the real PBQs. Candidates who skip hands-on supplements often score 85%+ on Dion practice exam multiple-choice sections but fail the PBQs on the real exam. TryHackMe's "PenTest+ Pathway" (free with $10/month subscription unlocking advanced rooms) closes this gap.
Who Should Use Dion PenTest+ Alone vs Supplement
Dion alone is sufficient only for candidates with active penetration testing job experience (1+ year using Nmap, Metasploit, Burp daily). For everyone else—including most CySA+ holders, SOC analysts transitioning to offensive security, and self-taught hobbyists—Dion plus TryHackMe is the minimum viable stack. Adding HackTheBox Academy modules (free tier covers Nmap, web fundamentals, and basic enumeration) provides an additional layer for candidates targeting OSCP next.
Pro Tips
Pair Dion with TryHackMe's free Pre-Security and PenTest+ rooms; do not skip hands-on practice.
Practice Nmap syntax until you can write scans from memory—PBQs test this directly.
Read Metasploit module output until it's second nature; PBQs include screenshot interpretation.
Take Dion's planning/scoping section seriously—it's tested more than candidates expect.
After PenTest+, consider OSCP as the natural next step; Dion's course is not OSCP prep.
Common Mistakes to Avoid
Using only Dion's course. PenTest+ PBQs require hands-on practice that video lectures can't replicate.
Scoring well on multiple-choice and assuming you'll pass. PBQs are where most failures happen.
Skipping reporting and communication domain because it's "easy"—it's 14% of the exam and easy points.
Treating PenTest+ as a stepping stone to OSCP. It teaches different methodologies; complementary but distinct.
Buying expensive lab platforms (HackTheBox Pro, PentesterLab) before exhausting free TryHackMe content.
Frequently Asked Questions
Only for candidates with 1+ year of hands-on penetration testing experience. Most candidates need Dion plus TryHackMe (or equivalent hands-on labs) to pass the PBQ-heavy exam.
The multiple-choice questions are accurate. The PBQ representations are weaker than the real exam's—do not assume Dion PBQ scores predict real PBQ scores.
They teach different methodologies. PenTest+ is broader/more methodology-focused; OSCP is deeper/more hands-on. Many candidates do PenTest+ first as a softer entry.
30-60 hours of TryHackMe practice across the PenTest+ Pathway is the typical successful pattern.
Conceptually yes, but not deeply enough for the real exam's PBQ depth. Supplement with TryHackMe's free Burp Suite room.
Lecture portion is ~13 hours. Realistic total prep time with hands-on labs is 8-10 weeks at 10 hours/week.
Related Resources
Jason Dion Honest Review Jason Dion Practice Exams Jason Dion CySA+ Review Jason Dion vs Professor Messer Jason Dion Study Plan Free PenTest+ PracticePractice for 25+ Certifications—Free
Pair Jason Dion's courses with adaptive practice questions, detailed explanations, and progress tracking. Free daily questions across 25+ certifications.
Start Free Practice