CompTIA PenTest+ Lessons
Every lesson is free to read, with three practice questions each. Work through them in order, or jump to the objective you need.
- What a penetration test actually is, and is notObjective 1.1Audio
- Building a lab you own and cannot accidentally escapeAudio
- Rules of engagement, testing windows and target selectionObjective 1.1Audio
- Authorisation, the law, and when you are obliged to reportObjective 1.2Audio
- Peer review, escalation paths and articulating riskObjective 1.3Audio
- Writing the penetration test reportObjective 1.4Audio
- Passive reconnaissance and OSINTObjective 2.1Audio
- Active reconnaissance, sniffing and protocol scanningObjective 2.1Audio
- DNS enumerationObjective 2.2Audio
- Service discovery and port scanningObjective 2.2Audio
- Directory and web content enumerationObjective 2.2Audio
- Nmap in depthObjective 2.3Audio
- Wireshark and Shodan for the testerObjective 2.3Audio
- Customising recon scripts in Python, PowerShell and BashObjective 2.4Audio
- What a vulnerability scan sees, and what it missesObjective 3.1Audio
- Authenticated and unauthenticated scanningObjective 3.1Audio
- SAST and DAST: testing the code and the running applicationObjective 3.1Audio
- Validating findings and killing false positivesObjective 3.2Audio
- When the scan is wrong: troubleshooting configurationObjective 3.2Audio
- Nessus and OpenVASObjective 3.3Audio
- Nikto and web scanningObjective 3.3Audio
- VLAN hopping and why segmentation failsObjective 4.1
- On-path attacksObjective 4.1
- Exploiting an exposed serviceObjective 4.1
- Brute force, password spraying and credential stuffingObjective 4.2
- Pass-the-hash and credential replayObjective 4.2
- Privilege escalation on LinuxObjective 4.3
- Privilege escalation on WindowsObjective 4.3
- Process injection and credential dumpingObjective 4.3
- SQL injectionObjective 4.4
- Cross-site scriptingObjective 4.4
- Directory traversal and file inclusionObjective 4.4
- Container escape and cloud metadata servicesObjective 4.5
- IAM misconfiguration in the cloudObjective 4.5
- AI attacks: prompt injection and model manipulation, explainedObjective 4.6
- Establishing persistenceObjective 5.1
- Lateral movementObjective 5.1
- Pivoting and tunnellingObjective 5.1
- Cleaning up: restoring everything you changedObjective 5.1
- Writing the attack narrativeObjective 5.2
- Remediation recommendations that get acted onObjective 5.2