Free knowledge base

CompTIA PenTest+ (PT0-003) — key terms, tricks & tips

Everything from the course in one searchable place: 292 entries. Use it to review before a practice test or look up a word you forgot.

292 results

Key term

Performance-Based Questions (PBQs)

Interactive simulations testing practical skills in a virtual environment.

Getting Started: How the PT0-003 Exam Works

Key term

Scaled Score

A standardized score that adjusts raw scores to account for exam difficulty.

Getting Started: How the PT0-003 Exam Works

Key term

Domain Weighting

The percentage of questions on the exam dedicated to a specific topic area.

Getting Started: How the PT0-003 Exam Works

Key term

Nmap

A powerful open-source network scanner used for discovery and security auditing.

Getting Started: How the PT0-003 Exam Works

Key term

Burp Suite

A popular integrated platform for performing security testing of web applications.

Getting Started: How the PT0-003 Exam Works

Key term

Metasploit Framework

A penetration testing platform that provides exploits, payloads, and post-exploitation tools.

Getting Started: How the PT0-003 Exam Works

Key term

Hashcat

A fast and versatile password recovery tool, often used for cracking hashes.

Getting Started: How the PT0-003 Exam Works

Key term

Penetration Testing Lifecycle

The structured process of planning, executing, and reporting a penetration test.

Getting Started: How the PT0-003 Exam Works

Memory trick

Exam Overview: Format, Domains, and Scoring

To remember the PenTest+ domains, think: 'P-I-A-P-R' – Planning, Information, Attacks, Tools, Reporting. It's like planning for a big trip, gathering info, attacking the road, using your tools, and then reporting back!

Getting Started: How the PT0-003 Exam Works

Exam tip

Exam Overview: Format, Domains, and Scoring

The exam objectives explicitly list the tools you should be familiar with. For PT0-003, this includes Nmap, Burp Suite, Metasploit, and Hashcat. Expect PBQs to test your practical ability to use these tools.

Getting Started: How the PT0-003 Exam Works

Common mistake

Exam Overview: Format, Domains, and Scoring

Underestimating the importance of Performance-Based Questions (PBQs) and not practicing hands-on with tools.

Getting Started: How the PT0-003 Exam Works

Common mistake

Exam Overview: Format, Domains, and Scoring

Focusing too much on one domain while neglecting others, especially those with higher weighting.

Getting Started: How the PT0-003 Exam Works

Common mistake

Exam Overview: Format, Domains, and Scoring

Not managing time effectively during the exam, spending too long on difficult questions.

Getting Started: How the PT0-003 Exam Works

Key term

Virtualization

Running multiple OSes on one physical machine.

Getting Started: How the PT0-003 Exam Works

Key term

Kali Linux

A Debian-derived Linux distribution for penetration testing.

Getting Started: How the PT0-003 Exam Works

Key term

Vulnerable VM

A virtual machine intentionally configured with security flaws.

Getting Started: How the PT0-003 Exam Works

Key term

Performance-Based Question

Exam questions requiring practical, hands-on skill demonstration.

Getting Started: How the PT0-003 Exam Works

Memory trick

Study Strategy, Resources, and Lab Setup

LABS: Learn, Apply, Build, Study. Remember to build your lab to apply what you learn and study effectively!

Getting Started: How the PT0-003 Exam Works

Exam tip

Study Strategy, Resources, and Lab Setup

The PT0-003 exam heavily emphasizes practical application, especially in domains like tools and code analysis. Expect PBQs that require you to use specific tools or interpret their output. Memorize common Nmap flags and Burp Suite functionalities.

Getting Started: How the PT0-003 Exam Works

Common mistake

Study Strategy, Resources, and Lab Setup

Relying solely on theoretical knowledge without hands-on practice.

Getting Started: How the PT0-003 Exam Works

Common mistake

Study Strategy, Resources, and Lab Setup

Not isolating your lab environment, potentially compromising your host.

Getting Started: How the PT0-003 Exam Works

Common mistake

Study Strategy, Resources, and Lab Setup

Underestimating the time needed to set up and troubleshoot your lab.

Getting Started: How the PT0-003 Exam Works

Key term

Scoping

Defining the boundaries, objectives, and limitations of a pen test.

Engagement Management Fundamentals

Key term

In-scope

Assets explicitly authorized for penetration testing.

Engagement Management Fundamentals

Key term

Out-of-scope

Assets explicitly excluded from penetration testing.

Engagement Management Fundamentals

Key term

Rules of Engagement (ROE)

A formal document detailing authorized pen test procedures and limits.

Engagement Management Fundamentals

Key term

Get Out of Jail Free Letter

Formal authorization from the client for testing activities.

Engagement Management Fundamentals

Key term

Statement of Work (SOW)

A document detailing project-specific activities, deliverables, and timelines.

Engagement Management Fundamentals

Key term

Engagement Letter

A formal letter outlining the terms of a professional engagement.

Engagement Management Fundamentals

Memory trick

Scoping Engagements and Defining Rules of Engagement

SCOPE: S-pecifics, C-onstraints, O-bjectives, P-ermissions, E-xclusions. Remember these to define your test boundaries!

Engagement Management Fundamentals

Exam tip

Scoping Engagements and Defining Rules of Engagement

The CompTIA PenTest+ exam frequently tests your understanding of the legal and ethical implications of penetration testing. Be prepared to identify the components of a valid 'Get Out of Jail Free' letter and the importance of a signed SOW or ROE before commencing any testing. Keywords like 'authorization,' 'boundaries,' and 'legal protection' are critical.

Engagement Management Fundamentals

Common mistake

Scoping Engagements and Defining Rules of Engagement

Starting a penetration test without a signed Rules of Engagement (ROE) or 'Get Out of Jail Free' letter.

Engagement Management Fundamentals

Common mistake

Scoping Engagements and Defining Rules of Engagement

Assuming certain systems are in-scope without explicit client confirmation, leading to unauthorized testing.

Engagement Management Fundamentals

Common mistake

Scoping Engagements and Defining Rules of Engagement

Failing to communicate changes in scope or unexpected findings to the client immediately.

Engagement Management Fundamentals

Common mistake

Scoping Engagements and Defining Rules of Engagement

Not clearly defining the timeframe or permitted testing hours, potentially disrupting client operations.

Engagement Management Fundamentals

Key term

MSA

Master Service Agreement; general contract for future services.

Engagement Management Fundamentals

Key term

SOW

Statement of Work; details specific project scope and deliverables.

Engagement Management Fundamentals

Key term

NDA

Non-Disclosure Agreement; protects confidential information.

Engagement Management Fundamentals

Key term

Scope Creep

Uncontrolled expansion of project requirements.

Engagement Management Fundamentals

Key term

Deliverables

Tangible outcomes or products specified in a contract.

Engagement Management Fundamentals

Key term

Liability

Legal responsibility for damages or actions.

Engagement Management Fundamentals

Memory trick

Contracts: SOW, MSA, and NDA Essentials

Remember 'MSA, SOW, NDA' as 'My Specific Nitty-Gritty Details.' MSA is 'My' (general), SOW is 'Specific' (project), and NDA is 'Nitty-Gritty Details' (confidentiality).

Engagement Management Fundamentals

Exam tip

Contracts: SOW, MSA, and NDA Essentials

The exam often tests your ability to distinguish between the 'umbrella' agreement (MSA) and the 'project-specific' agreement (SOW). Keywords like 'general terms' point to MSA, while 'specific tasks' or 'project scope' indicate SOW. Remember that an NDA can be a standalone document or embedded within an MSA or SOW.

Engagement Management Fundamentals

Common mistake

Contracts: SOW, MSA, and NDA Essentials

Confusing the general terms of an MSA with the specific project details of an SOW.

Engagement Management Fundamentals

Common mistake

Contracts: SOW, MSA, and NDA Essentials

Beginning work without a signed SOW, leading to scope disputes or unclear expectations.

Engagement Management Fundamentals

Common mistake

Contracts: SOW, MSA, and NDA Essentials

Disclosing confidential client information without understanding the NDA's terms, even accidentally.

Engagement Management Fundamentals

Common mistake

Contracts: SOW, MSA, and NDA Essentials

Not understanding that an NDA can be a standalone document or part of an MSA/SOW.

Engagement Management Fundamentals

Key term

CFAA

Computer Fraud and Abuse Act; US law prohibiting unauthorized computer access.

Engagement Management Fundamentals

Key term

GDPR

General Data Protection Regulation; EU law for data privacy and protection.

Engagement Management Fundamentals

Key term

HIPAA

Health Insurance Portability and Accountability Act; US healthcare data privacy law.

Engagement Management Fundamentals

Key term

PCI DSS

Payment Card Industry Data Security Standard; for credit card data security.

Engagement Management Fundamentals

Key term

Authorization

Explicit written permission to perform a penetration test.

Engagement Management Fundamentals

Key term

Scope

The defined boundaries and targets of a penetration test.

Engagement Management Fundamentals

Key term

Ethics

Moral principles guiding professional conduct and decision-making.

Engagement Management Fundamentals

Memory trick

Legal, Ethical, and Compliance Considerations

LEGAL: 'L'aws, 'E'thics, 'G'et authorization, 'A'lways comply, 'L'imit scope.

Engagement Management Fundamentals

Exam tip

Legal, Ethical, and Compliance Considerations

The CompTIA PenTest+ exam expects you to know key regulations like GDPR, HIPAA, and PCI DSS. Understand their purpose and how they impact data handling during a test. Also, memorize that the Computer Fraud and Abuse Act (CFAA) is the primary US law against unauthorized computer access.

Engagement Management Fundamentals

Common mistake

Legal, Ethical, and Compliance Considerations

Assuming verbal permission is sufficient; always get written authorization.

Engagement Management Fundamentals

Common mistake

Legal, Ethical, and Compliance Considerations

Exploiting a vulnerability outside the agreed-upon scope, even if it's critical.

Engagement Management Fundamentals

Common mistake

Legal, Ethical, and Compliance Considerations

Failing to understand local laws and international regulations relevant to the client's location or data.

Engagement Management Fundamentals

Key term

OSSTMM

Open Source Security Testing Methodology Manual; scientific, measurable security testing.

Engagement Management Fundamentals

Key term

PTES

Penetration Testing Execution Standard; 7-phase lifecycle for pen testing.

Engagement Management Fundamentals

Key term

OWASP

Open Web Application Security Project; focuses on web application security.

Engagement Management Fundamentals

Key term

OWASP Top 10

List of the most critical web application security risks.

Engagement Management Fundamentals

Key term

Vulnerability Analysis

Phase in PTES to identify security weaknesses in systems.

Engagement Management Fundamentals

Key term

Exploitation

Phase in PTES where identified vulnerabilities are leveraged.

Engagement Management Fundamentals

Key term

Operational Security

Focus of OSSTMM, ensuring security measures are effective in practice.

Engagement Management Fundamentals

Memory trick

Frameworks: OSSTMM, PTES, and OWASP

Imagine an 'OWL' flying over a 'PENTAGON' with a 'SCIENTIST'. OWL for OWASP (web apps), PENTAGON for PTES (pen test lifecycle), SCIENTIST for OSSTMM (scientific, measurable).

Engagement Management Fundamentals

Exam tip

Frameworks: OSSTMM, PTES, and OWASP

Memorize the primary focus of each framework: OSSTMM for scientific, measurable, broad security testing; PTES for the end-to-end pen testing lifecycle; and OWASP specifically for web application security. Look for keywords like 'web application,' 'lifecycle,' or 'measurable metrics' in exam questions.

Engagement Management Fundamentals

Common mistake

Frameworks: OSSTMM, PTES, and OWASP

Confusing OSSTMM's broad scope with OWASP's web-specific focus.

Engagement Management Fundamentals

Common mistake

Frameworks: OSSTMM, PTES, and OWASP

Thinking PTES is just a list of vulnerabilities instead of a full methodology.

Engagement Management Fundamentals

Common mistake

Frameworks: OSSTMM, PTES, and OWASP

Assuming one framework covers all aspects of security testing without needing others.

Engagement Management Fundamentals

Key term

Executive Summary

High-level report overview for non-technical stakeholders.

Engagement Management Fundamentals

Key term

Technical Summary

Detailed report section for IT and security teams.

Engagement Management Fundamentals

Key term

Remediation Recommendation

Specific, actionable steps to fix identified vulnerabilities.

Engagement Management Fundamentals

Key term

Severity Rating

Classification of a vulnerability's potential impact.

Engagement Management Fundamentals

Key term

Proof of Concept (PoC)

Demonstration of a vulnerability's exploitability.

Engagement Management Fundamentals

Key term

Actionable

Recommendations that are practical and can be implemented.

Engagement Management Fundamentals

Key term

Evidence

Screenshots, logs, or data supporting a finding.

Engagement Management Fundamentals

Memory trick

Reporting Findings and Remediation Recommendations

REPORT: R-isk, E-vidence, P-riority, O-utcome, R-ecommendations, T-ools.

Engagement Management Fundamentals

Exam tip

Reporting Findings and Remediation Recommendations

The exam often tests your understanding of report components. Memorize what belongs in an executive summary (high-level, business impact) versus a technical summary (detailed findings, specific vulnerabilities). Keywords like 'non-technical audience' or 'actionable steps' are clues.

Engagement Management Fundamentals

Common mistake

Reporting Findings and Remediation Recommendations

Providing vague or generic remediation recommendations instead of specific, actionable steps.

Engagement Management Fundamentals

Common mistake

Reporting Findings and Remediation Recommendations

Failing to include sufficient evidence (screenshots, logs) to support findings.

Engagement Management Fundamentals

Common mistake

Reporting Findings and Remediation Recommendations

Not tailoring the report sections (e.g., executive summary) to the intended audience.

Engagement Management Fundamentals

Common mistake

Reporting Findings and Remediation Recommendations

Omitting severity ratings or failing to prioritize findings, leaving the client unsure where to start.

Engagement Management Fundamentals

Key term

OSINT

Open-Source Intelligence; gathering information from public sources.

Reconnaissance and Enumeration Techniques

Key term

Passive Reconnaissance

Gathering information without direct interaction with the target.

Reconnaissance and Enumeration Techniques

Key term

WHOIS

Database query tool for domain registration information.

Reconnaissance and Enumeration Techniques

Key term

Maltego

Graphical link analysis tool for data mining and visualization.

Reconnaissance and Enumeration Techniques

Key term

Shodan

Search engine for internet-connected devices and services.

Reconnaissance and Enumeration Techniques

Key term

theHarvester

Tool for gathering emails, subdomains, hosts, and employee names.

Reconnaissance and Enumeration Techniques

Key term

Doxing

Publicly revealing private or identifying information about an individual.

Reconnaissance and Enumeration Techniques

Memory trick

OSINT: Gathering Public Intelligence

OSINT: O-pen S-ources I-nform N-ice T-argets. Remember, it's all about finding publicly available info to make your target analysis 'nice' and effective!

Reconnaissance and Enumeration Techniques

Exam tip

OSINT: Gathering Public Intelligence

For the CompTIA PenTest+ exam, be prepared to identify various OSINT sources (e.g., social media, public records, corporate websites, search engines) and understand their utility in reconnaissance. Keywords to spot include 'passive information gathering' and 'publicly available information'.

Reconnaissance and Enumeration Techniques

Common mistake

OSINT: Gathering Public Intelligence

Confusing OSINT with active scanning or direct interaction with the target.

Reconnaissance and Enumeration Techniques

Common mistake

OSINT: Gathering Public Intelligence

Failing to document OSINT sources and findings, leading to unverified intelligence.

Reconnaissance and Enumeration Techniques

Common mistake

OSINT: Gathering Public Intelligence

Overlooking the ethical and legal implications of using publicly available personal data.

Reconnaissance and Enumeration Techniques

Key term

Reconnaissance

Initial phase of gathering information about a target.

Reconnaissance and Enumeration Techniques

Key term

Active Reconnaissance

Information gathering involving direct interaction with the target.

Reconnaissance and Enumeration Techniques

Memory trick

Passive vs Active Reconnaissance Methods

Think 'P' for Passive, 'Public' (sources), and 'Private' (no direct interaction). Think 'A' for Active, 'Attack' (like), and 'Alert' (potential detection).

Reconnaissance and Enumeration Techniques

Exam tip

Passive vs Active Reconnaissance Methods

The exam often distinguishes between 'footprinting' (passive) and 'scanning' (active). Be prepared to identify tools and methods specific to each. Remember, anything that sends a packet to the target's network is active.

Reconnaissance and Enumeration Techniques

Common mistake

Passive vs Active Reconnaissance Methods

Confusing a public web search for a target's IP address with an active scan of that IP address.

Reconnaissance and Enumeration Techniques

Common mistake

Passive vs Active Reconnaissance Methods

Using active scanning tools without explicit authorization, potentially violating the engagement scope.

Reconnaissance and Enumeration Techniques

Common mistake

Passive vs Active Reconnaissance Methods

Failing to document which reconnaissance methods were used and when, especially for active techniques.

Reconnaissance and Enumeration Techniques

Key term

DNS

Domain Name System, translates domain names to IPs.

Reconnaissance and Enumeration Techniques

Key term

DNS Enumeration

Process of discovering all DNS records for a domain.

Reconnaissance and Enumeration Techniques

Key term

Zone Transfer

Replication of DNS database files between DNS servers.

Reconnaissance and Enumeration Techniques

Key term

A Record

Maps a domain name to an IPv4 address.

Reconnaissance and Enumeration Techniques

Key term

MX Record

Specifies mail servers for a domain.

Reconnaissance and Enumeration Techniques

Key term

dig

Command-line tool for querying DNS servers.

Reconnaissance and Enumeration Techniques

Key term

AXFR

Request for a full zone transfer.

Reconnaissance and Enumeration Techniques

Key term

NS Record

Indicates authoritative DNS servers for a domain.

Reconnaissance and Enumeration Techniques

Memory trick

DNS Enumeration and Zone Transfers

AXFR: 'All eXtra Files Retrieved' – for when a zone transfer gives you everything!

Reconnaissance and Enumeration Techniques

Exam tip

DNS Enumeration and Zone Transfers

For PT0-003, remember that a successful DNS zone transfer (AXFR) provides a complete list of all records for a domain, which is a critical finding for an attacker. Know the 'dig' command syntax for performing zone transfer attempts.

Reconnaissance and Enumeration Techniques

Common mistake

DNS Enumeration and Zone Transfers

Forgetting to identify authoritative name servers before attempting a zone transfer; you must target the correct server.

Reconnaissance and Enumeration Techniques

Common mistake

DNS Enumeration and Zone Transfers

Not checking for various record types beyond 'A' records, missing valuable information like MX, TXT, or SRV records.

Reconnaissance and Enumeration Techniques

Common mistake

DNS Enumeration and Zone Transfers

Assuming a zone transfer won't work and skipping the attempt; misconfigurations are common.

Reconnaissance and Enumeration Techniques

Key term

SYN Scan (-sS)

A stealthy port scan that sends SYN packets but doesn't complete the handshake.

Reconnaissance and Enumeration Techniques

Key term

Connect Scan (-sT)

A port scan that completes the TCP three-way handshake, less stealthy.

Reconnaissance and Enumeration Techniques

Key term

Version Detection (-sV)

Nmap feature to determine the service and version of applications on open ports.

Reconnaissance and Enumeration Techniques

Key term

OS Detection (-O)

Nmap feature to identify the operating system and its version of a target host.

Reconnaissance and Enumeration Techniques

Key term

Nmap Scripting Engine (NSE)

A powerful Nmap component for automating advanced network tasks and vulnerability checks.

Reconnaissance and Enumeration Techniques

Key term

Timing Templates (-T)

Nmap option to control scan speed and aggressiveness, from T0 (paranoid) to T5 (insane).

Reconnaissance and Enumeration Techniques

Key term

UDP Scan (-sU)

A scan type used to discover open UDP ports and services.

Reconnaissance and Enumeration Techniques

Memory trick

Network Scanning with Nmap: Techniques and Scripts

Nmap: Never Miss A Port! Visualize a map where every single port is highlighted, ensuring nothing is overlooked.

Reconnaissance and Enumeration Techniques

Exam tip

Network Scanning with Nmap: Techniques and Scripts

The CompTIA PenTest+ exam often presents scenarios where you need to choose the appropriate Nmap command for a given objective, such as 'identify open ports without completing a full connection' (SYN scan) or 'determine the version of a web server' (version detection). Memorize common flags and their functions.

Reconnaissance and Enumeration Techniques

Common mistake

Network Scanning with Nmap: Techniques and Scripts

Running Nmap scans without proper authorization, which can be illegal or violate company policy.

Reconnaissance and Enumeration Techniques

Common mistake

Network Scanning with Nmap: Techniques and Scripts

Using overly aggressive timing templates (-T5) on production networks, potentially causing instability or being easily detected.

Reconnaissance and Enumeration Techniques

Common mistake

Network Scanning with Nmap: Techniques and Scripts

Not saving Nmap output (e.g., -oN, -oX) for later analysis and reporting, requiring rescans.

Reconnaissance and Enumeration Techniques

Key term

Service Fingerprinting

Identifying specific applications and their versions running on open ports.

Reconnaissance and Enumeration Techniques

Key term

OS Fingerprinting

Determining the operating system of a target host by analyzing network responses.

Reconnaissance and Enumeration Techniques

Key term

Web Enumeration

Gathering information about web applications, directories, and technologies.

Reconnaissance and Enumeration Techniques

Key term

Nmap -sV

Nmap option for service version detection.

Reconnaissance and Enumeration Techniques

Key term

Nmap -O

Nmap option for operating system detection.

Reconnaissance and Enumeration Techniques

Key term

Directory Brute-forcing

Systematically guessing directory and file names on a web server.

Reconnaissance and Enumeration Techniques

Key term

Burp Suite Spider

A Burp Suite feature to automatically crawl a website and discover content.

Reconnaissance and Enumeration Techniques

Key term

HTTP Headers

Information exchanged between client and server, revealing server details.

Reconnaissance and Enumeration Techniques

Memory trick

Service, OS Fingerprinting, and Web Enumeration

Remember 'S-V' for 'Service Version' and 'O' for 'Operating System' when using Nmap. For web, think 'DIR' for 'Directory' brute-forcing.

Reconnaissance and Enumeration Techniques

Exam tip

Service, OS Fingerprinting, and Web Enumeration

The exam expects you to know the specific Nmap flags for OS (-O) and service (-sV) detection. Also, be familiar with common web enumeration techniques like directory brute-forcing and subdomain enumeration, and the tools used (e.g., Nmap, Burp Suite).

Reconnaissance and Enumeration Techniques

Common mistake

Service, OS Fingerprinting, and Web Enumeration

Forgetting to combine -sV and -O for comprehensive Nmap scans.

Reconnaissance and Enumeration Techniques

Common mistake

Service, OS Fingerprinting, and Web Enumeration

Not using a sufficiently large or relevant wordlist for directory brute-forcing, leading to missed content.

Reconnaissance and Enumeration Techniques

Common mistake

Service, OS Fingerprinting, and Web Enumeration

Overlooking manual inspection of robots.txt or HTML source code during web enumeration.

Reconnaissance and Enumeration Techniques

Key term

Vulnerability Scan

Automated process identifying known security weaknesses in systems.

Vulnerability Discovery and Analysis

Key term

Non-credentialed Scan

Scan performed without user credentials, simulating an external attacker.

Vulnerability Discovery and Analysis

Key term

Credentialed Scan

Scan performed with user credentials, providing deeper access and insights.

Vulnerability Discovery and Analysis

Key term

Nessus

A popular commercial vulnerability scanning tool with extensive plugin databases.

Vulnerability Discovery and Analysis

Key term

OpenVAS

An open-source vulnerability scanner, derived from Nessus, offering similar features.

Vulnerability Discovery and Analysis

Key term

CVE

Common Vulnerabilities and Exposures; a list of publicly known cyber security vulnerabilities.

Vulnerability Discovery and Analysis

Memory trick

Vulnerability Scanning Tools and Methodology

SCAN: S-Scope, C-Choose Tools, A-Authenticate (or not), N-Now Scan!

Vulnerability Discovery and Analysis

Exam tip

Vulnerability Scanning Tools and Methodology

The CompTIA PenTest+ exam frequently asks about the differences and use cases for credentialed vs. non-credentialed scans. Remember that credentialed scans provide a more accurate and comprehensive view of vulnerabilities by simulating an insider or an attacker who has already gained access.

Vulnerability Discovery and Analysis

Common mistake

Vulnerability Scanning Tools and Methodology

Confusing a vulnerability scan with a penetration test; a scan identifies, a pen test exploits.

Vulnerability Discovery and Analysis

Common mistake

Vulnerability Scanning Tools and Methodology

Relying solely on non-credentialed scans for internal network assessments, missing critical internal vulnerabilities.

Vulnerability Discovery and Analysis

Common mistake

Vulnerability Scanning Tools and Methodology

Failing to update scanner plugins and vulnerability databases, leading to missed, newly discovered vulnerabilities.

Vulnerability Discovery and Analysis

Key term

True Positive

A correctly identified vulnerability.

Vulnerability Discovery and Analysis

Key term

False Positive

A scanner reports a vulnerability that doesn't exist.

Vulnerability Discovery and Analysis

Key term

True Negative

A scanner correctly finds no vulnerability.

Vulnerability Discovery and Analysis

Key term

False Negative

A real vulnerability exists but is undetected.

Vulnerability Discovery and Analysis

Key term

Manual Verification

Human confirmation of scanner findings.

Vulnerability Discovery and Analysis

Key term

Cross-referencing

Comparing results from multiple tools.

Vulnerability Discovery and Analysis

Key term

Remediation

The process of fixing vulnerabilities.

Vulnerability Discovery and Analysis

Memory trick

Analyzing Results and Identifying False Positives

Think of a 'FAlse Positive' as a 'FAke Alarm' – it looks like a problem, but it's not real. A 'FAlse Negative' is a 'FAlling through the cracks' problem – it's real, but you missed it.

Vulnerability Discovery and Analysis

Exam tip

Analyzing Results and Identifying False Positives

The exam expects you to differentiate clearly between true positives, false positives, and false negatives. Understand that manual verification is essential for reducing false positives and identifying false negatives, and that automated tools alone are insufficient for comprehensive testing.

Vulnerability Discovery and Analysis

Common mistake

Analyzing Results and Identifying False Positives

Trusting automated scanner results without manual verification, leading to wasted time on non-existent issues.

Vulnerability Discovery and Analysis

Common mistake

Analyzing Results and Identifying False Positives

Failing to document false positives, causing them to be re-reported in future scans or by other testers.

Vulnerability Discovery and Analysis

Common mistake

Analyzing Results and Identifying False Positives

Over-relying on a single tool or methodology, increasing the risk of false negatives and missed critical vulnerabilities.

Vulnerability Discovery and Analysis

Key term

Proxy

An intermediary that intercepts and forwards network traffic.

Vulnerability Discovery and Analysis

Key term

Passive Scan

Analyzes observed traffic without sending new requests.

Vulnerability Discovery and Analysis

Key term

Active Scan

Sends crafted requests to probe for vulnerabilities.

Vulnerability Discovery and Analysis

Key term

Repeater

Burp tool to manually modify and resend individual requests.

Vulnerability Discovery and Analysis

Key term

Intruder

Burp tool for automated, customized attacks against web apps.

Vulnerability Discovery and Analysis

Key term

Spider

Burp tool to automatically crawl and map a web application.

Vulnerability Discovery and Analysis

Key term

CA Certificate

A digital certificate issued by a Certificate Authority.

Vulnerability Discovery and Analysis

Memory trick

Web Application Scanning with Burp Suite

Remember 'P.R.I.S.T.' for Burp's core tools: Proxy, Repeater, Intruder, Scanner, Target.

Vulnerability Discovery and Analysis

Exam tip

Web Application Scanning with Burp Suite

The PenTest+ exam often tests your practical knowledge of Burp Suite. Be prepared to identify its core tools (Proxy, Repeater, Intruder, Scanner) and their functions, especially for intercepting traffic, modifying requests, and identifying common web vulnerabilities like SQLi and XSS.

Vulnerability Discovery and Analysis

Common mistake

Web Application Scanning with Burp Suite

Forgetting to install Burp's CA certificate, leading to HTTPS errors.

Vulnerability Discovery and Analysis

Common mistake

Web Application Scanning with Burp Suite

Not configuring the browser's proxy settings correctly, resulting in no traffic interception.

Vulnerability Discovery and Analysis

Common mistake

Web Application Scanning with Burp Suite

Relying solely on automated scans without manual verification of findings.

Vulnerability Discovery and Analysis

Common mistake

Web Application Scanning with Burp Suite

Running active scans without proper authorization, potentially causing service disruption.

Vulnerability Discovery and Analysis

Key term

Shared Responsibility Model

Defines security duties between cloud provider and customer.

Vulnerability Discovery and Analysis

Key term

IAM (Identity and Access Management)

Controls who can do what in a cloud environment.

Vulnerability Discovery and Analysis

Key term

Aircrack-ng

Suite of tools for auditing wireless networks.

Vulnerability Discovery and Analysis

Key term

Tailgating

Gaining unauthorized access by following an authorized person.

Vulnerability Discovery and Analysis

Key term

WPA2-PSK

Wi-Fi Protected Access II with a pre-shared key.

Vulnerability Discovery and Analysis

Key term

RFID

Radio-Frequency Identification, used for tracking/access.

Vulnerability Discovery and Analysis

Key term

Social Engineering

Manipulating people to divulge info or perform actions.

Vulnerability Discovery and Analysis

Memory trick

Cloud, Wireless, and Physical Security Assessment

Think 'CWP' for Cloud, Wireless, Physical. Each is a distinct attack surface, like a layer of an onion, protecting the core data.

Vulnerability Discovery and Analysis

Exam tip

Cloud, Wireless, and Physical Security Assessment

For the exam, be prepared to differentiate between the responsibilities of the cloud provider and the customer under the shared responsibility model. Also, know the common tools for wireless assessments like Aircrack-ng and Kismet, and understand the basic principles of physical security bypasses.

Vulnerability Discovery and Analysis

Common mistake

Cloud, Wireless, and Physical Security Assessment

Ignoring the shared responsibility model in cloud assessments.

Vulnerability Discovery and Analysis

Common mistake

Cloud, Wireless, and Physical Security Assessment

Underestimating the impact of physical security breaches.

Vulnerability Discovery and Analysis

Common mistake

Cloud, Wireless, and Physical Security Assessment

Focusing only on Wi-Fi and neglecting other wireless technologies.

Vulnerability Discovery and Analysis

Key term

Exploit

Code designed to take advantage of a specific vulnerability in a system.

Attacks and Exploits Deep Dive

Key term

Payload

Code executed on a target system after successful exploitation.

Attacks and Exploits Deep Dive

Key term

Meterpreter

Advanced, extensible payload providing a powerful interactive shell.

Attacks and Exploits Deep Dive

Key term

Auxiliary Module

Metasploit module for scanning, fuzzing, or information gathering.

Attacks and Exploits Deep Dive

Key term

Post Module

Module used after exploitation for tasks like privilege escalation.

Attacks and Exploits Deep Dive

Key term

RHOSTS

Required Metasploit option specifying the target host's IP address.

Attacks and Exploits Deep Dive

Key term

LHOST

Required Metasploit option specifying the attacker's listening IP address.

Attacks and Exploits Deep Dive

Memory trick

Network Attacks: Exploitation with Metasploit

To remember Metasploit's core modules, think of 'E-P-A-P': Exploits Pave A Path (to) Payloads.

Attacks and Exploits Deep Dive

Exam tip

Network Attacks: Exploitation with Metasploit

The CompTIA PenTest+ exam expects you to know the purpose of Metasploit's core components (exploits, payloads, auxiliary, post) and how to use msfconsole for basic exploitation, including setting options like RHOSTS and LHOST. Look for questions describing scenarios where a penetration tester needs to leverage known vulnerabilities.

Attacks and Exploits Deep Dive

Common mistake

Network Attacks: Exploitation with Metasploit

Forgetting to set both RHOSTS and LHOST, leading to failed exploit attempts or unhandled sessions.

Attacks and Exploits Deep Dive

Common mistake

Network Attacks: Exploitation with Metasploit

Using an exploit without understanding the target's specific vulnerability or patch level, resulting in system instability or detection.

Attacks and Exploits Deep Dive

Common mistake

Network Attacks: Exploitation with Metasploit

Not checking 'show options' for an exploit or payload, missing critical parameters that are required for successful execution.

Attacks and Exploits Deep Dive

Key term

Brute-force attack

Systematically trying all possible password combinations until the correct one is found.

Attacks and Exploits Deep Dive

Key term

Dictionary attack

Using a list of common words and phrases as password guesses.

Attacks and Exploits Deep Dive

Key term

Credential stuffing

Using leaked credentials from one breach to try logging into other services.

Attacks and Exploits Deep Dive

Key term

Rainbow table

Pre-computed tables of hashes used to reverse cryptographic hashes quickly.

Attacks and Exploits Deep Dive

Key term

Pass-the-hash (PtH)

Authenticating using a user's password hash instead of the plaintext password.

Attacks and Exploits Deep Dive

Key term

NTLM hash

A hash format commonly used in Windows networks for storing and transmitting passwords.

Attacks and Exploits Deep Dive

Key term

Mask attack

A brute-force attack where specific character sets and lengths are defined.

Attacks and Exploits Deep Dive

Memory trick

Authentication Attacks & Password Cracking

For Hashcat, remember 'H.A.S.H. - Hash Algorithm, Attack Mode, Source, Hashfile'. It helps recall the key parameters.

Attacks and Exploits Deep Dive

Exam tip

Authentication Attacks & Password Cracking

The PT0-003 exam expects you to know the purpose and application of various password attack types (e.g., brute-force, dictionary, rainbow table, credential stuffing, pass-the-hash) and common tools like Hashcat for cracking hashes. Memorize the basic Hashcat command-line options for different attack modes and hash types.

Attacks and Exploits Deep Dive

Common mistake

Authentication Attacks & Password Cracking

Forgetting to specify the correct hash type (-m) in Hashcat, leading to incorrect or failed cracking attempts.

Attacks and Exploits Deep Dive

Common mistake

Authentication Attacks & Password Cracking

Using a generic wordlist for all cracking scenarios instead of tailoring it to the target's likely password choices or language.

Attacks and Exploits Deep Dive

Common mistake

Authentication Attacks & Password Cracking

Attempting to crack hashes without proper authorization, which is illegal and unethical in real-world scenarios.

Attacks and Exploits Deep Dive

Key term

SQL Injection (SQLi)

Code injection technique exploiting database vulnerabilities via malicious SQL statements.

Attacks and Exploits Deep Dive

Key term

Cross-Site Scripting (XSS)

Injecting malicious client-side scripts into web pages viewed by other users.

Attacks and Exploits Deep Dive

Key term

Server-Side Request Forgery (SSRF)

Inducing a server-side application to make requests to an arbitrary domain.

Attacks and Exploits Deep Dive

Key term

sqlmap

An open-source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws.

Attacks and Exploits Deep Dive

Key term

DOM-based XSS

XSS vulnerability where the attack is executed by modifying the Document Object Model (DOM) in the client's browser.

Attacks and Exploits Deep Dive

Key term

Burp Collaborator

A Burp Suite tool for detecting out-of-band interactions during web vulnerability testing.

Attacks and Exploits Deep Dive

Memory trick

Web App Attacks: SQLi, XSS, and SSRF

SQLi is for 'Stealing Queries' from the database. XSS is for 'eXecuting Scripts' in the browser. SSRF is for 'Server Sends Requests' internally.

Attacks and Exploits Deep Dive

Exam tip

Web App Attacks: SQLi, XSS, and SSRF

For the PenTest+ exam, be able to differentiate between reflected, stored, and DOM-based XSS. Also, understand the primary impact of each attack type: SQLi for data compromise, XSS for client-side compromise, and SSRF for internal network access.

Attacks and Exploits Deep Dive

Common mistake

Web App Attacks: SQLi, XSS, and SSRF

Confusing the impact of XSS (client-side) with SQLi (server/database-side).

Attacks and Exploits Deep Dive

Common mistake

Web App Attacks: SQLi, XSS, and SSRF

Underestimating the potential severity of SSRF, especially in cloud environments.

Attacks and Exploits Deep Dive

Common mistake

Web App Attacks: SQLi, XSS, and SSRF

Not properly sanitizing all user inputs, which is the root cause of many web vulnerabilities.

Attacks and Exploits Deep Dive

Key term

S3 Bucket

Amazon Web Services (AWS) object storage container.

Attacks and Exploits Deep Dive

Key term

Deauthentication Attack

Forces a client to disconnect from a wireless network.

Attacks and Exploits Deep Dive

Key term

Rogue AP

An unauthorized access point mimicking a legitimate one.

Attacks and Exploits Deep Dive

Key term

4-way Handshake

Exchange of messages to establish a WPA/WPA2 connection key.

Attacks and Exploits Deep Dive

Key term

Monitor Mode

Wireless adapter mode to capture all nearby wireless traffic.

Attacks and Exploits Deep Dive

Key term

WPS

Wi-Fi Protected Setup, a vulnerable method for easy connection.

Attacks and Exploits Deep Dive

Key term

Serverless Function

Code executed by a cloud provider without managing servers.

Attacks and Exploits Deep Dive

Memory trick

Cloud and Wireless Attack Techniques

CLOUD: C - Configs are bad. L - Loose IAM. O - Open buckets. U - Unsecured APIs. D - Docker's exposed.

Attacks and Exploits Deep Dive

Exam tip

Cloud and Wireless Attack Techniques

The exam often focuses on identifying cloud misconfigurations (e.g., S3 bucket permissions, IAM roles) and understanding the steps for WPA/WPA2 cracking (capture handshake, offline attack). Memorize the purpose of key Aircrack-ng tools.

Attacks and Exploits Deep Dive

Common mistake

Cloud and Wireless Attack Techniques

Forgetting that cloud security is a shared responsibility model, where the customer is responsible for configuration.

Attacks and Exploits Deep Dive

Common mistake

Cloud and Wireless Attack Techniques

Confusing the purpose of different Aircrack-ng tools (e.g., airodump-ng vs. aireplay-ng).

Attacks and Exploits Deep Dive

Common mistake

Cloud and Wireless Attack Techniques

Underestimating the impact of weak WPA2-PSK passphrases, assuming WPA2 is always 'secure'.

Attacks and Exploits Deep Dive

Key term

Phishing

Fraudulent communication to trick individuals into revealing sensitive info.

Attacks and Exploits Deep Dive

Key term

Pretexting

Creating a false scenario to obtain information or access.

Attacks and Exploits Deep Dive

Key term

Vishing

Phishing conducted over voice communication (telephone).

Attacks and Exploits Deep Dive

Key term

Deepfake

AI-generated synthetic media, often audio or video, mimicking real people.

Attacks and Exploits Deep Dive

Key term

Spear Phishing

Targeted phishing attack on a specific individual or organization.

Attacks and Exploits Deep Dive

Memory trick

Social Engineering and AI-Based Attacks

Think 'PAID' for common social engineering tactics: Pretexting, Authority, Intimidation, Deception.

Attacks and Exploits Deep Dive

Exam tip

Social Engineering and AI-Based Attacks

The PenTest+ exam expects you to differentiate between various social engineering techniques (e.g., phishing vs. spear phishing vs. pretexting) and understand their impact. Pay close attention to how AI can enhance these attacks, making them more sophisticated and harder to detect.

Attacks and Exploits Deep Dive

Common mistake

Social Engineering and AI-Based Attacks

Underestimating the human element in security; technical controls alone are not enough.

Attacks and Exploits Deep Dive

Common mistake

Social Engineering and AI-Based Attacks

Failing to conduct regular, realistic security awareness training for employees.

Attacks and Exploits Deep Dive

Common mistake

Social Engineering and AI-Based Attacks

Not having clear, documented procedures for verifying unusual or urgent requests.

Attacks and Exploits Deep Dive

Key term

Persistence

Techniques to maintain access to a compromised system.

Post-Exploitation and Lateral Movement

Key term

Privilege Escalation

Gaining higher-level permissions on a system.

Post-Exploitation and Lateral Movement

Key term

SUID Bit

Linux permission that runs an executable with owner's permissions.

Post-Exploitation and Lateral Movement

Key term

Registry Run Keys

Windows registry locations for programs to start with OS.

Post-Exploitation and Lateral Movement

Key term

Service Exploitation

Leveraging vulnerabilities in system services for higher privileges.

Post-Exploitation and Lateral Movement

Key term

Token Impersonation

Exploiting Windows to assume another process's security token.

Post-Exploitation and Lateral Movement

Key term

Kernel Exploit

Exploiting vulnerabilities in the operating system's core.

Post-Exploitation and Lateral Movement

Memory trick

Establishing Persistence and Escalating Privileges

To remember Persistence methods: 'S.C.R.E.W.S.' - Services, Cron jobs, Registry, Environmental variables, Web shells, Startup folders.

Post-Exploitation and Lateral Movement

Exam tip

Establishing Persistence and Escalating Privileges

The PenTest+ exam frequently tests your knowledge of specific Windows registry keys (e.g., Run, RunOnce, HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run) and Linux files/directories (e.g., /etc/rc.local, /etc/cron.d/, SUID binaries) used for persistence. Be prepared to identify these by name.

Post-Exploitation and Lateral Movement

Common mistake

Establishing Persistence and Escalating Privileges

Forgetting to establish persistence after gaining initial access, leading to lost access upon system reboot.

Post-Exploitation and Lateral Movement

Common mistake

Establishing Persistence and Escalating Privileges

Focusing solely on kernel exploits for privilege escalation and overlooking simpler misconfigurations like weak service permissions.

Post-Exploitation and Lateral Movement

Common mistake

Establishing Persistence and Escalating Privileges

Not properly cleaning up persistence mechanisms after a penetration test, leaving backdoors for real attackers.

Post-Exploitation and Lateral Movement

Key term

Lateral Movement

Technique to move between systems after initial compromise.

Post-Exploitation and Lateral Movement

Key term

Credential Harvesting

Extracting usernames, passwords, or hashes from a compromised system.

Post-Exploitation and Lateral Movement

Key term

Pass-the-Ticket (PtT)

Authenticating using a stolen Kerberos ticket.

Post-Exploitation and Lateral Movement

Key term

Living-off-the-Land (LotL)

Using legitimate system tools for malicious purposes.

Post-Exploitation and Lateral Movement

Key term

Network Segmentation

Dividing a network into smaller, isolated segments.

Post-Exploitation and Lateral Movement

Key term

Mimikatz

Windows tool to extract credentials from memory.

Post-Exploitation and Lateral Movement

Memory trick

Lateral Movement Across Networks

Remember 'CHART' for Lateral Movement: **C**redential Harvesting, **H**ashes, **A**dmin Tools, **R**emote Services, **T**argets.

Post-Exploitation and Lateral Movement

Exam tip

Lateral Movement Across Networks

The exam expects you to know common lateral movement techniques like Pass-the-Hash, Pass-the-Ticket, and the use of tools such as Mimikatz, Metasploit, and Nmap in this context. Focus on the *how* and *why* these techniques are effective.

Post-Exploitation and Lateral Movement

Common mistake

Lateral Movement Across Networks

Forgetting to clean up traces after moving laterally, which can alert defenders.

Post-Exploitation and Lateral Movement

Common mistake

Lateral Movement Across Networks

Attempting to move laterally without proper reconnaissance, leading to detection or dead ends.

Post-Exploitation and Lateral Movement

Common mistake

Lateral Movement Across Networks

Only focusing on one type of lateral movement (e.g., just RDP) and missing other opportunities.

Post-Exploitation and Lateral Movement

Key term

Pivoting

Using a compromised system to access other internal networks.

Post-Exploitation and Lateral Movement

Key term

Local Port Forwarding

Forwards a local port to a remote port via a pivot host.

Post-Exploitation and Lateral Movement

Key term

Remote Port Forwarding

Forwards a remote port to a local port via a pivot host.

Post-Exploitation and Lateral Movement

Key term

Dynamic Port Forwarding

Creates a SOCKS proxy for routing arbitrary traffic.

Post-Exploitation and Lateral Movement

Key term

SOCKS Proxy

A protocol that routes network packets between client and server.

Post-Exploitation and Lateral Movement

Key term

Proxychains

A tool to force applications to use a proxy chain.

Post-Exploitation and Lateral Movement

Key term

Island Hopping

Another term for network pivoting or lateral movement.

Post-Exploitation and Lateral Movement

Memory trick

Pivoting Techniques and Tools

P.I.V.O.T.: Proxy Infiltrates Various Other Targets. Remember it's about using one system to get to many others.

Post-Exploitation and Lateral Movement

Exam tip

Pivoting Techniques and Tools

The exam expects you to know the difference between local and remote port forwarding, and when to use a SOCKS proxy. Keywords like 'unreachable subnet' or 'internal network access' indicate pivoting.

Post-Exploitation and Lateral Movement

Common mistake

Pivoting Techniques and Tools

Forgetting to configure firewall rules on the compromised host to allow forwarded traffic.

Post-Exploitation and Lateral Movement

Common mistake

Pivoting Techniques and Tools

Not understanding the difference between local and remote port forwarding, leading to incorrect setup.

Post-Exploitation and Lateral Movement

Common mistake

Pivoting Techniques and Tools

Attempting to pivot without first establishing a stable and persistent connection to the initial compromised host.

Post-Exploitation and Lateral Movement

Key term

Data Exfiltration

Unauthorized transfer of data from a compromised system.

Post-Exploitation and Lateral Movement

Key term

Covert Channel

Hidden communication path used to bypass security controls.

Post-Exploitation and Lateral Movement

Key term

Anti-Forensics

Techniques to hinder forensic analysis and hide activities.

Post-Exploitation and Lateral Movement

Key term

Cleanup

Removing all traces of a penetration test or compromise.

Post-Exploitation and Lateral Movement

Key term

DNS Tunneling

Exfiltrating data by encoding it into DNS queries and responses.

Post-Exploitation and Lateral Movement

Key term

Metasploit

Framework with modules for exploitation, post-exploitation, and exfiltration.

Post-Exploitation and Lateral Movement

Memory trick

Data Exfiltration and Cleanup Procedures

To remember cleanup steps, think 'CLEAR': **C**lear logs, **L**eave no files, **E**rase users, **A**lter nothing, **R**estore settings.

Post-Exploitation and Lateral Movement

Exam tip

Data Exfiltration and Cleanup Procedures

For PT0-003, memorize common exfiltration protocols (DNS, ICMP, HTTP/S, FTP) and associated tools (Metasploit's `download`, Burp Suite for web, `wevtutil` for logs). Understand that anti-forensics aims to remove indicators of compromise (IOCs).

Post-Exploitation and Lateral Movement

Common mistake

Data Exfiltration and Cleanup Procedures

Forgetting to clear all relevant logs (e.g., application logs in addition to system logs).

Post-Exploitation and Lateral Movement

Common mistake

Data Exfiltration and Cleanup Procedures

Leaving behind tools or temporary files that could be traced back to the attacker.

Post-Exploitation and Lateral Movement

Common mistake

Data Exfiltration and Cleanup Procedures

Not restoring system configurations to their original state, causing operational issues for the client.

Post-Exploitation and Lateral Movement