CompTIA PenTest+

Get certified with CompTIA PenTest+. Learn to conduct penetration tests, analyze vulnerabilities, and produce effective remediation reports.

Category:

After completing this course, you will be able to plan, conduct, analyze, and report on penetration tests, including the ability to:

  • Plan and scope a penetration testing engagement
  • Understand legal and compliance requirements
  • Perform vulnerability scanning and penetration testing using appropriate tools and techniques, and then analyze the results
  • Produce a written report containing proposed remediation techniques, effectively communicate results to the management team, and provide practical recommendations

Network+, Security+ or equivalent knowledge. Minimum of 3-4 years of hands-on information security or related experience.

CompTIA PenTest+ is targeted at cybersecurity professionals responsible for hands-on penetration testing and vulnerability assessment. Some of the job roles that will benefit from this certification include:

  • Penetration Tester
  • Vulnerability Tester
  • Security Analyst (II)
  • Vulnerability Assessment Analyst
  • Network Security Operations
  • Application Security Vulnerability
1.1 - Summarize pre-engagement activities
1.2 – Explain collaboration and communication activities
1.3 – Compare and contrast testing frameworks and methodologies
1.4 – Explain the components of a penetration test report
1.5 – Given a scenario, analyse the findings and recommend the appropriate remediation within a report
2.1 – Given a scenario, apply information gathering techniques
2.2 – Given a scenario, apply enumeration techniques
2.3 – Given a scenario, modify scripts for reconnaissance and enumeration
2.4 – Given a scenario, use the appropriate tools for reconnaissance and enumeration
3.1 – Given a scenario, conduct vulnerability discovery using various techniques
3.2 – Given a scenario, analyse output from reconnaissance, scanning, and enumeration phases
3.3 – Explain physical security concepts
4.1 – Given a scenario, analyse output to prioritize and prepare attacks
4.2 – Given a scenario, perform networks attacks using the appropriate tools
4.3 – Given a scenario, perform authentication attacks using the appropriate tools
4.4 – Given a scenario, perform host-based attacks using the appropriate tools
4.5 – Given a scenario, perform web application attacks using the appropriate tools
4.6 – Given a scenario, perform cloud-based attacks using the appropriate tools
4.7 – Given a scenario, perform wireless attacks using the appropriate tools
4.8 – Given a scenario, perform social engineering attacks using the appropriate tools
4.9 – Explain common attacks against specialized systems
4.10 – Given a scenario, use scripting to automate attacks
5.1 – Given a scenario, perform tasks to establish and maintain persistence
5.2 – Given a scenario, perform tasks to move laterally throughout the environment
5.3 – Summarize concepts related to staging and exfiltration
5.4 – Explain cleanup and restoration activities
Length of exam 165 minutes
Number of questions Maximum of 85 questions
Question format Multiple choice and performance-based
Passing grade 750 (on a scale of 100-900)
Exam availability English, Japanese, Portuguese and Thai

 

Testing center Pearson VUE Testing Center

Description

As organizations scramble to protect themselves and their customers, the ability to conduct penetration testing is an emerging skill set that is becoming ever more valuable to the organizations seeking protection, and ever more lucrative for those who possess these skills. In this course, the CompTIA PenTest+ will certify the successful candidate has the knowledge and skills required to plan and scope a penetration testing engagement including vulnerability scanning, understand legal and compliance requirements, analyze results, and produce a written report with remediation techniques.