← CertOwl Blog

PenTest+

PenTest+ vs CEH: format, price and which to pick

By SunTzu, founder of CertOwl Published 3 min read

Quick answer

They certify similar ground but work very differently. CompTIA PenTest+ is a $439 exam with performance-based questions and no eligibility paperwork. CEH costs roughly $950 to $1,199 plus a $100 application unless you buy EC-Council training, and its knowledge exam is pure multiple choice. Pick CEH when a specific employer or contract names it; pick PenTest+ when you are paying your own way and want hands-on testing for a third of the money.

PenTest+ exam PT0-003, up to 90 questions in 165 minutesCEH exam 125 questions in 240 minutesPenTest+ voucher $439CEH exam about $950 to $1,199 plus $100 applicationDoD 8140 both appear

A job posting goes up for a junior penetration tester. Halfway down, the requirements line reads "CEH preferred". You have been eyeing CompTIA PenTest+, the maths says it costs a third as much, and now you are wondering whether the cheaper route costs you the interview. That posting is the real battleground of this comparison, so let us take the two certifications apart properly.

What each one is

CompTIA PenTest+ is a vendor-neutral exam about doing the work: planning and scoping an engagement, finding and exploiting vulnerabilities, moving through a network, and writing the report that clients actually pay for. The current version, PT0-003, arrived in December 2024 and folds in cloud targets and AI-assisted attack tooling.

CEH, from EC-Council, is the older name. It certifies the vocabulary and workflow of ethical hacking across a long list of attack types, and its v13 revision leans into AI on both sides of the keyboard. It is the certification non-technical recruiters recognise on sight, and that recognition is its strongest card.

Side by side

CompTIA PenTest+CEH
Current versionPT0-003v13
Questionsup to 90, including performance-based125, all multiple choice
Time165 minutes240 minutes
Exam cost$439 voucherabout $950 to $1,199
Getting inbook and sittraining package, or 2 years verified experience plus a $100 application
Hands-on testingin the main examseparate CEH Practical exam

The two rows that decide most real decisions are the last three. PenTest+ has no gate: you pay $439 and book. CEH without EC-Council training requires two years of verifiable security experience, an employer attestation and a $100 non-refundable application, and the exam voucher alone costs roughly twice to nearly three times the CompTIA one before any training is added.

What the formats tell you

PenTest+ mixes multiple choice with performance-based tasks, so part of the exam is you doing things rather than recognising them. The CEH knowledge exam is 125 multiple-choice questions; hands-on skills live in a separate CEH Practical, which is a second exam and a second cost. If your goal is proving you can run an engagement rather than describe one, that difference matters more than the logos.

For defence work the choice is often made for you. Both certifications appear in the DoD 8140 framework, and the role you are targeting decides which is listed. We mapped where the CompTIA exams sit in the DoD 8140 guide; check the posting before you spend anything.

The order most people should take

Neither exam is an entry point. CompTIA aims PenTest+ at people with Network+ and Security+ level knowledge plus a few years of hands-on security work, and CEH's own eligibility rule assumes two years in the field. If you are earlier than that, the certification path guide shows the usual ladder, and the same logic we described for the blue-team side in CySA+ vs Security+ applies here: the offensive certifications sit after the fundamentals, not instead of them.

So which one

Choose CEH when a specific job posting, a government contract or your employer's approved list names it, or when someone else is paying for the training bundle. The name still unlocks doors on paper, and that is worth real money in some markets.

Choose PenTest+ when you are funding yourself, when you want hands-on questions in the main exam, and when the postings you care about say "penetration testing experience" rather than a specific logo. You keep several hundred dollars for lab time, which does more for your first engagement than any certificate.

Test yourself: 3 quick questions

During directory brute-forcing, why is it useful to filter responses by HTTP status code (e.g. show 200 and 301, hide 404)?

HTTP 404 indicates a nonexistent resource, so filtering it out isolates paths that actually exist (200/301/302) and reduces noise. The other statements misinterpret the meaning of status codes.

What is an 'evil twin' in the context of a wireless attack?

An evil twin is a rogue access point that imitates a legitimate SSID (often also the channel/BSSID) in order to intercept victims' traffic. The other options describe a MAC duplicate, a rogue DHCP and RFID cloning.

Before a pretexting call to the helpdesk, a pentester wants to collect employee names and email formats from public sources. Which tool is the MOST suitable?

theHarvester collects email addresses, names and subdomains from public sources (OSINT), which is the basis for preparing social engineering. Reaver attacks WPS, Kismet discovers Wi-Fi networks, and hostapd creates a rogue AP.

Score: · Hundreds more with explanations, free in the app: Get CertOwl on the App Store

Frequently asked questions

Is PenTest+ equivalent to CEH?

They cover similar territory at a similar career stage, and both appear in DoD 8140, but they are not copies. PenTest+ tests hands-on tasks in the main exam; CEH splits knowledge and practice into two separate exams.

Is CEH worth the extra cost?

Only when the name itself is the requirement. If no posting or contract in front of you says CEH, the extra several hundred dollars buys recognition you may never use.

Do I need Security+ before PenTest+?

There is no enforced prerequisite, but the exam assumes Security+ level knowledge plus real security experience. Sitting it straight after your first certification usually ends in an expensive lesson.

CertOwl's PenTest+ track drills the exam the way it is written: scenario questions with every option explained, spaced repetition for the tools and flags that slip, and full simulations with an indicative score. The A+ and Network+ tracks are completely free.

Get CertOwl on the App Store

Free download · A+ and Network+ completely free
+ daily lessons, flashcards and full exam simulations

More CompTIA guides