Skip to content

Repository files navigation

PenTest+ PT0-003 Study Console

📘 Curious how the tool list and quizzes here get built? See LLM_Study_Instructions.md for the workflow: turn your own CertMaster Perform materials into LLM-generated, source-checked study content.

A free, single-file, self-hosted study tool for the CompTIA PenTest+ (PT0-003) exam -- a searchable reference of 91 real pentesting tools mapped to the actual PT0-003 exam objectives, plus a multiple-choice match drill with progress tracking.

Try it live

What it does

  • Tool List -- all 91 tools with description, exam objective(s), domain, OS, and a plain-English "exam tip" for each, filterable by name. Each row has a SKIP toggle to hide that tool from Match Drill for the session -- handy if you already know it cold. Session-only, clears on RESET or reload.
  • Match Drill -- a 4-option multiple-choice quiz drawn from the same 91-tool pool. Get a tool right twice in a row and it goes "mastered" (grey) and drops out of rotation; get it wrong and it goes back to square one. Each question also has a "VIEW IN LIST" button per option, so you can look a tool up without it counting as an answer. REDS ONLY filters the drill down to just the tools you haven't proven yet -- unlike SKIP, this one is saved in your password. DOMAINS (beta) narrows the drill further to just the PT0-003 domain(s) you pick, via checkboxes in the status bar -- handy for drilling one weak domain instead of the whole pool. Session-only, not saved in your password; the Tool List always shows all 91 regardless of this filter.
  • TOP 12 (beta) -- a status-bar toggle that narrows Match Drill to the 12 tools an instructor's exam-prep deep-dive flags as the highest-frequency scenario-question tools (Nmap, Nessus, Burp Suite, SQLMap, Metasploit, msfvenom, Hashcat, Responder, Aircrack-ng, Mimikatz, CrackMapExec, and Impacket). They're marked with a ★ badge in the Tool List, and about half the time a question on one of them shows a real terminal-output snippet instead of a plain description -- asking "which tool produced this" instead of "which tool matches this" -- with a short explanation of what happened and what the tester would do next revealed once you answer. Session-only, not saved in your password.
  • No account, no backend, no database. Progress is encoded into a 20-character save password (Metroid/Mega Man style) you can copy, write down, or paste back in later -- including a checksum digit that catches typos or swapped characters, plus a REDS ONLY flag bit. A best-effort local auto-save also runs in the background where your browser allows it, but the password code is what's guaranteed to work everywhere.
  • SYNTAX CHECK -- a bonus Bash/PowerShell/Python syntax-difference quiz that pops up sporadically during Match Drill (or on demand via the SUDO cheat code below). 44 questions across variable syntax, comparisons, quoting, arrays, loops, functions, and language philosophy (why Bash shells out, PowerShell ships its own cmdlets, Python leans on libraries). Doesn't affect your real score or save code.
  • Works without JavaScript too, in a reduced form: a full static reference table of all 91 tools renders directly in the page's HTML for search engines, AI crawlers, and anyone browsing with scripting off. The interactive drill, quiz, and save-code system all require JavaScript.
  • Runs entirely as a single static HTML file. No build step, no server, no tracking.

Cheat codes

A few Easter eggs are baked in -- click a tag in the footer, or type one into the password box and hit CONTINUE: THEEND, MATRIX, DISCO, GLITCH, CONFETTI, FLIP, SUDO (fires a SYNTAX CHECK question on demand).

Running it locally

Just open index.html in a browser. No dependencies, no install, no build step.

How this was built

Built with Claude (Anthropic) via natural-language iteration rather than hand-coded top to bottom -- describing what a feature should do, reviewing what came back, correcting it, and repeating. All 91 tool entries and their exam-objective mappings are cross-checked against the official CompTIA PenTest+ PT0-003 Exam Objectives document rather than generated from memory. Descriptions and "exam tip" text are original writing, not CompTIA prose -- the official objectives document only lists bare tool names per objective, with no descriptions of its own.

Data & QA

The tool-to-objective mapping went through multiple independent verification rounds rather than a single pass -- category taxonomy, active-vs-passive classification, and cross-tool consistency were each reviewed and checked against the actual data rather than trusted at face value. A few real errors were caught and fixed this way, including a couple of tools that had been miscategorized as passive-only when they actually touch the live target. Tool descriptions and quiz answer options were also scanned to make sure no description accidentally gives away the tool it's describing, since this is a quiz.

Exam-tip text for 23 tools (including all 12 TOP 12 tools) was cross-checked against a separate instructor exam-prep deep-dive and corrected or expanded where it added real detail. That source wasn't treated as automatically right, either -- a few things it stated were independently verified as wrong (an incorrect password paired with a sample password hash, a mislabeled field name, a wrong technical claim about how a WiFi handshake attack actually works) and were not carried into this app's content.

Version history

  • Initial 91-tool reference list and 4-option match drill, every entry mapped to a real PT0-003 exam objective.
  • No-account save system: progress encodes into a short password-style code, including a checksum digit to catch typos, no login or backend required.
  • "Mastered" screen for finishing the full tool pool, plus a handful of cheat codes as Easter eggs.
  • Checkpoint screen every 10 questions, with the current save code and a one-click copy button front and center.
  • Searchable tool list.
  • SEO metadata and a social preview image for link sharing.
  • Best-effort local auto-save: if your browser allows it, progress saves automatically between visits on the same device -- the save code above still works everywhere as the reliable fallback.
  • SYNTAX CHECK mini-game: random pop-up quizzes on Bash/PowerShell/Python variable syntax, a bonus track separate from your real score.
  • REDS ONLY drill filter (saved in your password) and per-tool SKIP (session-only), a HOW TO USE button to recall the instructions, and issue-tracker/support links in the footer.
  • A crawler-visible static HTML fallback of the full tool reference, plus robots.txt and sitemap.xml, so search and AI-answer engines can actually index what this page covers -- previously all real content only ever existed after JavaScript ran.
  • SYNTAX CHECK question pool nearly doubled (25 -> 44), answer options now actually shuffle per question instead of the correct one sitting in a fixed slot, and repeat questions are drawn from a proper no-repeat window instead of just excluding the one immediately before.
  • Accessibility/hardening pass: keyboard-operable tabs and quiz options (not just mouse), a visible focus ring, prefers-reduced-motion support, a real page heading for screen readers and SEO, and closed a low-severity self-XSS spot in the tool filter box.
  • Fixed a bug where the SYNTAX CHECK bonus popup could fire mid-Sudden-Death and leave a question stuck; added a settling delay/fade between questions either way.
  • DOMAINS (beta): pick which PT0-003 domain(s) are in rotation for Match Drill, from the status bar.
  • A SKIP INSTRUCTIONS button on the welcome popup, for anyone who's seen it before and just wants into the app.
  • TOP 12 (beta): a Match Drill filter for the 12 highest-frequency exam tools per an instructor deep-dive, with real terminal-output questions mixed in for them and a ★ badge in the Tool List. Exam-tip text for those 12 (and 11 other tools) was also reconciled against that same source.
  • Removed SUDDEN DEATH -- the timed-question mode was too unreliable in practice and has been pulled.

Disclaimer

This is an unofficial, community-made study aid. It is not affiliated with, endorsed by, or sponsored by CompTIA. PenTest+ and CompTIA are trademarks of CompTIA Properties, LLC.

Support

If this helped you study, consider buying me a coffee. Not required, just appreciated.

License

MIT -- see LICENSE.


Built with Claude (Sonnet 5) via Cowork.

About

Free, no-login CompTIA PenTest+ (PT0-003) study console — 91 tools mapped to real exam objectives, a match-drill quiz, and password-based progress saves.

Topics

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages