
Explore the CompTIA PenTest+ PT0-003 overview, covering five domains, learning objectives, sample scenarios, and the legal and ethical restrictions of pentesting with permission, all in a self-paced format.
Explore regulation and compliance in penetration testing, including pre-engagement activities and PCI DSS. Highlight GDPR articles 32 and 35, and standards such as HIPAA, Sox, NIST, ISO 27,001.
Understand pre-engagement activities with written authorization, defined scope, timing, and methods, while respecting confidentiality and client trust. Apply ethical frameworks like TS and OSS to guide responsible penetration testing.
Define testing boundaries by enforcing international and domestic laws, GDPR and CPRA privacy rules, and client tool restrictions to ensure legal, ethical penetration testing.
Define rules of engagement, time of day restrictions, environmental scope, and in-scope assets to guide a compliant, efficient penetration test.
Explore essential legal agreements and documentation for penetration testing, including SOWs, MSAs, NDAs, SLAs, and authorization letters to define scope and ensure compliance.
Explore professionalism and integrity in penetration testing, highlighting collaboration, communication, strict scope adherence, and prompt reporting of potential breaches to protect client trust.
Explore standards and methodologies that structure penetration testing across Mitre ATT&CK, OWASP, and NIST. Compare OSS TMM and TS to guide testing phases from reconnaissance to exfiltration, with regulatory alignment.
Define primary contact, technical contact, and emergency contact, and establish communication paths to report critical findings, status reports, indicators of prior compromise, and remediation in tailored executive and technical reports.
Explain the essential components of a penetration test report, including executive summary, scope, methodology, findings, and remediation, and tailor content for executives and technical readers.
Explore recommended remediation solutions across technical, administrative, operational, and physical controls, including system hardening, MFA, patch management, RBAC, and security training for stronger defense.
Learn post engagement cleanup, client acceptance, lessons learned, follow-up actions, retests, and secure data destruction to ensure remediation and protect client confidentiality.
Analyze network segmentation testing to verify isolation of the cardholder data environment and identify reachable hosts using ping, nmap, or Metasploit Pro for PCI DSS compliance.
Master target reconnaissance through passive information gathering and OSINT, leveraging Have I Been Pwned, Meta, Google Dorks, The Harvester, and Shodan to reveal infrastructure and vulnerabilities.
Learn DNS reconnaissance for information gathering in penetration testing, using nslookup, dig, and host to map domains to IPs, identify dns servers, perform reverse lookups, and assess zone transfer risks.
Map the web and cloud attack surface through information gathering and enumeration, using tools for domain discovery, site crawling, and cloud asset enumeration across AWS, Azure, and GCP.
Explore nmap for network discovery and vulnerability scanning, using stealth and connect scans, version and os detection, and scripting to reveal open ports, services, and vulnerabilities.
Identify business logic flaws in web applications that allow bypassing steps or unauthorized access, using Burp Suite and repeater for reconnaissance, enumeration, and scripting automation.
Identify vulnerabilities through customized vulnerability scanning, protocol-specific checks, and careful handling of fragile systems like ICS, SCADA, and IIoT; automate credentialed and non-credentialed scans to inform remediation.
Explore common physical attack vectors, including impersonation, tailgating, dumpster diving, badge cloning, and USB drops, and learn defensive measures like access controls and surveillance.
Explore data storage system vulnerabilities, including misconfigurations, improper permissions, and default credentials, across on-premises, cloud, and external storage to identify exposure risks and guide vulnerability testing.
Discover live hosts and enumerate services on a target network with ping sweeps and nmap. Capture banners and craft packets with Scapy; explore wardriving and packet sniffing for deeper recon.
Explore exploit resources for penetration testing, learn how to discover vulnerabilities, prioritize exploits with EPI scoring, and chain multiple exploits using tools like Metasploit, Exploit DB, and Search Sploit.
Explore how IoT and data storage vulnerabilities expand attack surfaces, from insecure defaults and weak credentials to misconfigurations, unencrypted communications, outdated firmware, and reconnaissance with Nmap.
Analyze ARP and DNS poisoning as on path attacks that intercept or modify traffic, using tools like Ettercap, Bettercap, Responder, and Impact.
Explore vlan hopping attacks, including switch spoofing and double tagging, to bypass network segmentation and access vlans that attackers should not reach.
Explore denial of service attacks, including dos, ddos, reflection, amplification, volumetric, and application-layer methods, and learn to ethically simulate them with hp3 for stress testing critical infrastructure.
Explore password attacks, including hash cracking, password spraying, Kerberos, and NTLM relay. Learn to automate password discovery with tools like John the Ripper, Hashcat, Hydra, Medusa, and Responder.
Explore mac spoofing techniques used by penetration testers to impersonate legitimate devices by changing mac addresses to bypass mac filtering and enable on-path wireless attacks.
Explore wireless attacks across Wi‑Fi, Bluetooth, RFID, and NFC, using aircrack-ng tools to capture handshakes, deauthenticate clients, and analyze rogue access points and evil twin scenarios.
Explore social engineering attacks, including pretexting, phishing (including spear phishing and whaling) and smishing, and influence tactics such as authority, urgency, fear, and social proof, with prevention via verification.
Explore the 2021 OWASP top ten web application security risks, including broken access control, cryptographic failures, and injection, with prevention strategies for pen testers.
Explore common session management attacks, including hijacking, replay, CSRF, and fixation, and learn how stolen tokens and cookies enable unauthorized access in web applications.
Explore SQL injection attacks, including error-based, union-based, and blind techniques, and learn to identify vulnerable input points, perform manual exploits, and automate testing with sqlmap to extract data.
Explore four main injection attacks—command, code, file inclusion, and LDAP injection—learning to identify vulnerabilities, automate web application attacks, and escalate to remote shells in pen testing.
Explore cross-site scripting attacks, including reflected and stored XSS, and learn how to identify, exploit, and test for these vulnerabilities using polyglots and web application attacks.
Explore server side request forgery (ssrf) vulnerabilities, where unsafely trusted user urls enable internal port scanning, local file access, and data exposure, bypassing controls and highlighting owasp top ten risks.
Detect web application firewalls and bypass techniques to test security using tools to identify WAF, inspect headers and cookies, and evade patterns with url encoding or base64 for sql injection and xss.
Explore cloud attacks from misconfigurations, credential harvesting, and metadata service exploits. Map and mitigate IAM, federation, and storage vulnerabilities with Scout Suite, Prowler, Cloud Brute, PACU, and Cloud Custodian.
Explore virtual environment vulnerabilities, including vm escape, hypervisor flaws, and malicious virtual machines in shared repositories, with practical reconnaissance and cloud-based attack concepts.
Explore common container vulnerabilities in applications, container engines, and cloud deployments; understand container escapes and misconfigurations in Kubernetes and EKS, and implement secure controls.
Explore vulnerabilities, threats, and tools in ICS, SCADA, and IIoT, including legacy tech, weak authentication, insecure communications, and IT-OT convergence creating attacker pivot points.
Master programming fundamentals for penetration testing, including loops, conditionals, operators, data structures, libraries, and classes. Learn to read proof of concept code and automate tasks with Python, PowerShell, or bash.
Analyze and modify scripts and code for pen test engagements, mastering reconnaissance, enumeration, and automated attacks including a reverse shell across bash, PowerShell, Python, and Ruby.
Drive automation in penetration testing by modifying scripts for reconnaissance and enumeration and automating attacks, using modular bash and Python workflows with nmap and Go-buster.
Explore API attacks across soap, rest, and xml-rpc to uncover command injection and sql injection vulnerabilities, using burp suite to manipulate requests and automate testing.
Explore mobile attack vectors, including reverse engineering, phishing, and smishing, and learn to identify insecure storage, weak authentication, permission abuse, and rooted device risk with modern pentesting tools.
Explore post-exploitation enumeration to map Active Directory networks, locate passwords, credentials, and other sensitive data, using PowerShell Empire, Mimikatz, and Bloodhound, while practicing lateral movement and persistence.
Master privilege escalation across Windows and Linux, detailing horizontal and vertical moves, cross-platform methods, and common techniques like password reuse, misconfigurations, and kernel exploits; apply lateral movement and persistence strategies.
Explore persistence techniques in pen testing by examining trojans, backdoors, daemons, services, and scheduled tasks, including reverse and bind shells and automation with Metasploit and PowerShell Empire.
Explore detection avoidance techniques to bypass defenders through living off the land, fileless malware, steganography, and covert channels, followed by post-exploitation cleanup and data exfiltration.
Explore how to plan, scope, and execute penetration tests for the CompTIA PenTest Plus PT0-002 exam, with hands-on demos and expert insights from Ronnie Wong and Daniel Lowrie.
Explore how regulation and compliance shape pen testing, examining PCI-DSS and GDPR with merchant levels, SAQs, ASVs, and data protection impact assessments.
Navigate the legal, regulatory, and privacy constraints of penetration testing, including permission, federal and state laws, tool restrictions, and data privacy rules like GDPR.
Understand key legal concepts and documents for penetration testing, including service level agreements, nondisclosure agreements, master service agreements, statements of work, and permission to attack.
Explore standards and methodologies for penetration testing, including Mitre ATT&CK, OWASP Top Ten, NIST SP 800-series, OSSTMM, PTES, and ISSAF. Learn how threat emulation and testing guides shape real-world assessments.
Define the scope of a penetration test by outlining the rules of engagement and in-scope targets, assets, and environment, then validate with the client to stay within boundaries.
Uphold professionalism and integrity in pen testing with background checks, scope adherence, and confidential handling of data, while identifying criminal activity and limiting tool use to the engagement.
Master DNS recon for penetration testing to verify ownership, enumerate in-scope hosts, and learn about records, name servers, and zone transfers using nslookup, dig, and host.
Learn target recon via passive recon and open-source intelligence, leveraging social media and public data to assess security and gather actionable information with tools like recon-ng and the harvester.
Explore active reconnaissance via host discovery and enumeration with ping sweeps and nmap to identify live hosts and open ports. Use banner grabbing and service versioning to learn targets.
Learn web and cloud discovery and enumeration through domain brute forcing, subdomain discovery, directory fuzzing, and site crawling. Understand token-based authentication, API requests, and assets across AWS, Azure, and GCP.
Learn how penetration testers detect and bypass defenses like load balancers, web application firewalls, and antivirus, using tools like wafw00f and Nmap to assess defense controls.
Explore vulnerability scanning for pen testers, covering scanner types, host discovery, protocol and bandwidth considerations, credential vs non-credential scans, and automation with tools like Nessus and OpenVAS.
Nmap, a network mapper, discovers hosts, enumerates services and versions, and detects operating systems for penetration testing, using common options like stealth, connect, UDP scans, -sV, -O, -A, and scripts.
Learn why common application vulnerabilities exist and how to begin exploiting them in a controlled pen test. Explore public exploit resources like Exploit Database, searchsploit, Vulners, Google, GitHub, and PacketStorm.
Explore denial of service concepts, including distributed, reflective and amplification attacks, plus volumetric, protocol, and application-layer methods. See practical demos with hping3 and examples like ping of death and slowloris.
Explore ARP poisoning and DNS poisoning in penetration testing, learn how ARP cache poisoning enables man-in-the-middle attacks, and see practical demonstrations with common network tools.
Explore password attacks, including brute-force, dictionary cracking, and rainbow tables, using Hashcat and John the Ripper; build custom word lists with CEWL and SecLists.
Explore VLAN hopping defenses and attacks, including switch spoofing and double tagging, demonstrating how attackers traverse guest and accounting networks via 802.1Q trunks and potential man-in-the-middle tactics.
Learn mac spoofing in pen testing, including what mac addresses are and the burned-in address, and how mac filtering and NAC can be bypassed on wireless networks.
Explore wireless attack types across Wi-Fi, Bluetooth, and RFID/NFC, and learn tools like aircrack-ng and airmon-ng, plus techniques such as deauth, handshake capture, evil twin, WPS, and Proxmark.
Explore the OWASP top ten web application security risks and their attack scenarios. Learn how to identify, assess, and mitigate broken access control, cryptographic failures, injections, and more.
Explore server-side request forgery (ssrf) and how a web app fetches remote resources without validating input, enabling internal port scans and access to sensitive data and internal services.
Explore business logic flaws in web apps, from bad assumptions to untrusted input, and see an insecure direct object reference example with ticket ordering and post requests.
Explore SQL injection attacks, including boolean-based and union-based payloads, test methods with sqlmap, and enumerate databases, tables, and credentials to understand data exposure.
Explore command injection, code injection, and file inclusion attacks, including local and remote file inclusions and directory traversal, plus LDAP injection as alternatives to SQL injection.
Explore cross site scripting (XSS) and learn how to test for reflected and stored XSS attacks using web app inputs, JavaScript injection, and polyglot payloads.
Explore how web sessions identify users and protect access. Learn session hijacking, replay, cross-site scripting, CSRF, and session fixation techniques for penetration testing.
Explore api attacks across soap, rest, and xml-rpc, examine wsdl and xml structures, and demonstrate command and sql injection, brute-force login, and testing with burp and whistler.
Explore cloud attacks and misconfigurations that expand the attack surface beyond on-prem networks, including credential harvesting, metadata service abuse, and cloud-specific tools like Scout Suite and Pacu.
Explore how mobile devices become attack vectors and reveal vulnerabilities like insecure storage. Identify mobile attacks and testing tools, including phishing, sandbox analysis, reverse engineering, and weak permissions.
Explore the risks of IoT devices on networks, including insecure defaults, clear text credentials, and firmware update practices, and learn practical pen testing—from nmap scans to exploitation.
Identify data storage vulnerabilities across on-prem, cloud, and portable devices, including misconfigurations and weak credentials that expose PII and PHI.
Explore vulnerabilities in operational technology, including ICS, SCADA, and IIoT devices. Identify threats such as malware, DoS, side-channel, and RF attacks, and review tools for testing and securing these systems.
Explore container vulnerabilities in pen testing by comparing containers with virtual machines, and examining docker basics, container escapes, misconfigurations, and cloud deployment risks in Kubernetes and AWS ECS.
Discover how social engineering and physical attacks drive pen testing, including pretexting, phishing, impersonation, tailgating, and tools like the social engineering toolkit and beef.
Identify post-exploitation enumeration techniques to locate sensitive information and credentials after gaining access. Explore tools like Power Shell Empire, BloodHound, Mimi Cats, and pass-the-hash for lateral movement in active directory.
Test network segmentation to verify the cardholder data environment is isolated from other networks using firewalls, ACLs, VLANs, and routing, and perform annual PCI DSS–compliant penetration tests.
Explore privilege escalation concepts, distinguishing horizontal and vertical moves, and examine cross-platform techniques such as password reuse, misconfigured permissions, unquoted service paths, and dll hijacking across Windows and Linux.
Discover persistence in pen testing by mapping trojans, backdoors, daemons, and scheduled tasks, with reverse and bind shells, startup services, cron, init.d, and PowerShell Empire.
Explore detection avoidance in pen testing, including living-off-the-land techniques, fileless malware, and covert channels for data exfiltration, plus methods to cover tracks by clearing logs.
Explore practical remediation strategies across technical, administrative, operational, and physical controls, from system hardening and patch management to role-based access control, secrets management, and network segmentation.
Define clear communication paths with primary, technical, and emergency contacts, set triggers for status reports and critical findings, and promote situational awareness and presentation of findings during a pentest.
Complete post engagement cleanup by removing shells and backdoors, logging actions, and restoring the client environment. Deliver acceptance, capture lessons learned, plan mitigations, retest, and securely destroy data.
CompTIA PenTest+ (PT0-003) is an intermediate-level cybersecurity certification preparation course designed to develop the hands-on skills required to identify, exploit, and remediate vulnerabilities across diverse computing environments. This course prepares learners to perform comprehensive penetration testing and vulnerability assessments on networks, cloud platforms, web applications, and hybrid systems.
Aligned with the latest CompTIA PenTest+ exam objectives, the course emphasizes real-world, scenario-based learning to help participants master the entire penetration testing process—from engagement planning through post-exploitation and reporting. Learners gain practical experience in reconnaissance, vulnerability discovery, exploitation, lateral movement, and remediation.
Through five structured domains—Engagement Management, Reconnaissance and Enumeration, Vulnerability Discovery and Analysis, Attacks and Exploits, and Post-exploitation and Lateral Movement—participants build a strong foundation in both offensive and defensive security techniques. The course also covers professional ethics, legal considerations, and effective communication of testing outcomes through actionable reports.
By combining conceptual understanding with practical exercises, this program equips professionals to think like attackers while acting as responsible defenders. Graduates will be prepared to conduct authorized penetration tests, analyze results, and recommend effective mitigation strategies that strengthen organizational security posture.
Whether you are pursuing the CompTIA PenTest+ certification or seeking to advance your career as a Penetration Tester, Ethical Hacker, Red Team Specialist, or Security Analyst, this course provides the critical technical expertise, methodologies, and professional discipline needed to operate confidently in today’s complex cybersecurity landscape.