CompTIA PenTest+
Overview
CompTIA® PenTest+® (Exam PT0-001) is the only penetration testing exam taken at a Pearson VUE testing center with both hands-on, performance-based questions and multiple-choice, to ensure each candidate possesses the skills, knowledge, and ability to perform tasks on systems. PenTest+ also includes management skills used to plan, scope, and manage weaknesses, not just exploit them.
PenTest+ is unique because it requires a candidate to demonstrate the hands-on ability and knowledge to test devices in new environments such as the cloud and mobile, in addition to traditional desktops and servers. The course provides the most up-to-date penetration testing, and vulnerability assessment and management skills necessary to determine the resiliency of the network against attacks.
Successful candidates will have the intermediate skills required to customize assessment frameworks to effectively collaborate on and report findings. They will also have the best practices to communicate recommended strategies to improve the overall state of IT security.
This course includes a voucher for the CompTIA Pentest+ Exam.
What's Included
- This course includes:
- 5 Full Days of Instructor Led CompTIA Authorized Training
- CertMaster Learn (12 month access)
- CertMaster Labs (12 month access)
- CertMaster Practice (12 month access)
- CompTIA Authorized PenTest+ eBook (Unlimited Access)
- PenTest+ Instructor Slides
- Office hours with certified CompTIA Instructors
- Detailed Reporting on Course Progress and Exam Readiness
- 1 Exam Voucher (Valid for 12 months)
- Free Repeat for 12 months
- Certificate of Completion for up to 40 CEUs/CPEs
- 5 Full Days of Instructor Led CompTIA Authorized Training
Who Should Take This Course
Audience
This course is targeted toward the information technology (IT) professional who has networking and administrative skills in Windows®-based Transmission Control Protocol/Internet Protocol (TCP/IP) networks and familiarity with other operating systems, such as Mac OS® X, Unix, or Linux, and who wants to further a career in IT by acquiring a foundational knowledge of security topics; prepare for the CompTIA PenTest+ Certification examination; or use PenTest+ as the foundation for further advanced security certifications or career roles.
Prerequisites
Students should have CompTIA Network+ and Security+ certifications, or have equivalent knowledge / experience. Recommend minimum of 3-4 years of hands-on information security or related experience. PenTest+ has a technical, hands-on focus and is intended to follow CompTIA Security+ or equivalent experience.
Course Objectives
Upon completion of this course, the student will be able to:
- Explain the importance of planning and key aspects of compliance-based assessments
- Gather information to prepare for exploitation
- Perform a vulnerability scan and analyze results
- Exploit network, wireless, application, and RF-based vulnerabilities
- Summarize physical security attacks
- Perform post-exploitation techniques
- Conduct information gathering with various tools and perform analysis on their output
- Analyze basic scripts in Bash, Python, Ruby, and PowerShell
- Utilize report writing and handling best practices
- Explain recommended mitigation strategies for discovered vulnerabilities
Course Outline
CompTIA PenTest+
Day 1: Planning and Scoping
- Overview
- Penetration testing methodology
- Planning a penetration test
- Rules of engagement
- Legal concepts
- Testing strategies
- White box support resources
- Types of assessments
- Threat actors
- Target selection
- Other scoping considerations
Day 2: Information Gathering and Vulnerability Identification
- Information gathering
- Reconnaissance with CentralOps
- Scanning and enumeration
- Fingerprinting
- Cryptographic inspection
- Eavesdropping
- Decompiling and debugging
- Open source research
- Vulnerability scanning
- Scanning considerations
- Application and container scans
- Analyzing vulnerability scans
- Leverage information for exploit
- Common attack vectors
- Weaknesses in specialized systems
Day 3: Attacks and Exploits
- Social engineering
- Motivation factors
- Physical security attacks
- Lock picking
- Network-based vulnerabilities
- Wireless-based vulnerabilities
- Wireless network attack
- Application-based vulnerabilities
- Local host vulnerabilities
- Privilege escalation (Linux)
- Privilege escalation (Windows)
- Lateral movement
- Persistence
- Covering your tracks
- Persistence and covering tracks
Day 4: Penetration Testing Tools
- Nmap Usage
- Use Cases for Tools
- Scanners
- Credential Testing Tools
- Password Cracking
- Debuggers
- Software Assurance
- OSINT
- Wireless
- Web Proxies
- Social Engineering Tools
- Remote Access Tools
- Networking Tools
- Mobile Tools
- Miscellaneous Tools
- Intro to Programming
- Programming Concepts
- BASH Script Example
- Python Script Example
- PowerShell Script Example
- Ruby Script Example
Day 5: Reporting and Communication
-
- Pentest Communications
- Report Writing
- Mitigation Strategies
- Post-Report Activities
- Pentest Report Example