CompTIA PenTest+ Lessons

Every lesson is free to read, with three practice questions each. Work through them in order, or jump to the objective you need.

Practise with the exam simulator

  1. What a penetration test actually is, and is notObjective 1.1Audio
  2. Building a lab you own and cannot accidentally escapeAudio
  3. Rules of engagement, testing windows and target selectionObjective 1.1Audio
  4. Authorisation, the law, and when you are obliged to reportObjective 1.2Audio
  5. Peer review, escalation paths and articulating riskObjective 1.3Audio
  6. Writing the penetration test reportObjective 1.4Audio
  7. Passive reconnaissance and OSINTObjective 2.1Audio
  8. Active reconnaissance, sniffing and protocol scanningObjective 2.1Audio
  9. DNS enumerationObjective 2.2Audio
  10. Service discovery and port scanningObjective 2.2Audio
  11. Directory and web content enumerationObjective 2.2Audio
  12. Nmap in depthObjective 2.3Audio
  13. Wireshark and Shodan for the testerObjective 2.3Audio
  14. Customising recon scripts in Python, PowerShell and BashObjective 2.4Audio
  15. What a vulnerability scan sees, and what it missesObjective 3.1Audio
  16. Authenticated and unauthenticated scanningObjective 3.1Audio
  17. SAST and DAST: testing the code and the running applicationObjective 3.1Audio
  18. Validating findings and killing false positivesObjective 3.2Audio
  19. When the scan is wrong: troubleshooting configurationObjective 3.2Audio
  20. Nessus and OpenVASObjective 3.3Audio
  21. Nikto and web scanningObjective 3.3Audio
  22. VLAN hopping and why segmentation failsObjective 4.1
  23. On-path attacksObjective 4.1
  24. Exploiting an exposed serviceObjective 4.1
  25. Brute force, password spraying and credential stuffingObjective 4.2
  26. Pass-the-hash and credential replayObjective 4.2
  27. Privilege escalation on LinuxObjective 4.3
  28. Privilege escalation on WindowsObjective 4.3
  29. Process injection and credential dumpingObjective 4.3
  30. SQL injectionObjective 4.4
  31. Cross-site scriptingObjective 4.4
  32. Directory traversal and file inclusionObjective 4.4
  33. Container escape and cloud metadata servicesObjective 4.5
  34. IAM misconfiguration in the cloudObjective 4.5
  35. AI attacks: prompt injection and model manipulation, explainedObjective 4.6
  36. Establishing persistenceObjective 5.1
  37. Lateral movementObjective 5.1
  38. Pivoting and tunnellingObjective 5.1
  39. Cleaning up: restoring everything you changedObjective 5.1
  40. Writing the attack narrativeObjective 5.2
  41. Remediation recommendations that get acted onObjective 5.2