
Plan and scope a penetration test by preparing the client and the test team, documenting data, and establishing escalation, backups, and go-live procedures to minimize impact.
This module covers active reconnaissance through enumeration to identify hosts, services, and credentials, using banner grabbing and tools like Nmap and RPC client.
Analyze vulnerability scan results with asset classification, false positives validation, and CVSS-based adjudication to prioritize vulnerabilities and leverage gathered information for preparation for exploitation.
Analyze wireless and radio frequency vulnerabilities, including WEP weaknesses, WPA/WPA2 protections, and offline attacks like pixie dust. Explore replay, deauthentication, evil twin, sniffing, and bluejacking techniques on wireless networks.
Examine how attackers exploit specialized systems, including mobile devices, industrial control systems, embedded and rtos devices, IoT, and point-of-sale terminals, to access data, disrupt operations, and test defenses.
Explore host-based vulnerabilities in Windows, Unix, and Linux and learn common weakness patterns, memory exploits, and password-related attacks. Apply defensive context by examining default accounts, sandbox escapes, and responsible patching.
The CompTIA PenTest+ certification verifies that successful candidates have the knowledge and skills required to plan and scope an assessment, understand legal and compliance requirements, perform vulnerability scanning and penetration testing, analyse data, and effectively report and communicate results.
Successful candidates will have the intermediate skills required to customise assessment frameworks to effectively collaborate on and report findings. Candidates will also have the best practices to communicate recommended strategies to improve the overall state of IT security.