Performance-Based Questions (PBQs)
Interactive simulations testing practical skills in a virtual environment.
Getting Started: How the PT0-003 Exam Works
Free knowledge base
Everything from the course in one searchable place: 292 entries. Use it to review before a practice test or look up a word you forgot.
292 results
Interactive simulations testing practical skills in a virtual environment.
Getting Started: How the PT0-003 Exam Works
A standardized score that adjusts raw scores to account for exam difficulty.
Getting Started: How the PT0-003 Exam Works
The percentage of questions on the exam dedicated to a specific topic area.
Getting Started: How the PT0-003 Exam Works
A powerful open-source network scanner used for discovery and security auditing.
Getting Started: How the PT0-003 Exam Works
A popular integrated platform for performing security testing of web applications.
Getting Started: How the PT0-003 Exam Works
A penetration testing platform that provides exploits, payloads, and post-exploitation tools.
Getting Started: How the PT0-003 Exam Works
A fast and versatile password recovery tool, often used for cracking hashes.
Getting Started: How the PT0-003 Exam Works
The structured process of planning, executing, and reporting a penetration test.
Getting Started: How the PT0-003 Exam Works
To remember the PenTest+ domains, think: 'P-I-A-P-R' – Planning, Information, Attacks, Tools, Reporting. It's like planning for a big trip, gathering info, attacking the road, using your tools, and then reporting back!
Getting Started: How the PT0-003 Exam Works
The exam objectives explicitly list the tools you should be familiar with. For PT0-003, this includes Nmap, Burp Suite, Metasploit, and Hashcat. Expect PBQs to test your practical ability to use these tools.
Getting Started: How the PT0-003 Exam Works
Underestimating the importance of Performance-Based Questions (PBQs) and not practicing hands-on with tools.
Getting Started: How the PT0-003 Exam Works
Focusing too much on one domain while neglecting others, especially those with higher weighting.
Getting Started: How the PT0-003 Exam Works
Not managing time effectively during the exam, spending too long on difficult questions.
Getting Started: How the PT0-003 Exam Works
Running multiple OSes on one physical machine.
Getting Started: How the PT0-003 Exam Works
A Debian-derived Linux distribution for penetration testing.
Getting Started: How the PT0-003 Exam Works
A virtual machine intentionally configured with security flaws.
Getting Started: How the PT0-003 Exam Works
Exam questions requiring practical, hands-on skill demonstration.
Getting Started: How the PT0-003 Exam Works
LABS: Learn, Apply, Build, Study. Remember to build your lab to apply what you learn and study effectively!
Getting Started: How the PT0-003 Exam Works
The PT0-003 exam heavily emphasizes practical application, especially in domains like tools and code analysis. Expect PBQs that require you to use specific tools or interpret their output. Memorize common Nmap flags and Burp Suite functionalities.
Getting Started: How the PT0-003 Exam Works
Relying solely on theoretical knowledge without hands-on practice.
Getting Started: How the PT0-003 Exam Works
Not isolating your lab environment, potentially compromising your host.
Getting Started: How the PT0-003 Exam Works
Underestimating the time needed to set up and troubleshoot your lab.
Getting Started: How the PT0-003 Exam Works
Defining the boundaries, objectives, and limitations of a pen test.
Engagement Management Fundamentals
Assets explicitly authorized for penetration testing.
Engagement Management Fundamentals
Assets explicitly excluded from penetration testing.
Engagement Management Fundamentals
A formal document detailing authorized pen test procedures and limits.
Engagement Management Fundamentals
Formal authorization from the client for testing activities.
Engagement Management Fundamentals
A document detailing project-specific activities, deliverables, and timelines.
Engagement Management Fundamentals
A formal letter outlining the terms of a professional engagement.
Engagement Management Fundamentals
SCOPE: S-pecifics, C-onstraints, O-bjectives, P-ermissions, E-xclusions. Remember these to define your test boundaries!
Engagement Management Fundamentals
The CompTIA PenTest+ exam frequently tests your understanding of the legal and ethical implications of penetration testing. Be prepared to identify the components of a valid 'Get Out of Jail Free' letter and the importance of a signed SOW or ROE before commencing any testing. Keywords like 'authorization,' 'boundaries,' and 'legal protection' are critical.
Engagement Management Fundamentals
Starting a penetration test without a signed Rules of Engagement (ROE) or 'Get Out of Jail Free' letter.
Engagement Management Fundamentals
Assuming certain systems are in-scope without explicit client confirmation, leading to unauthorized testing.
Engagement Management Fundamentals
Failing to communicate changes in scope or unexpected findings to the client immediately.
Engagement Management Fundamentals
Not clearly defining the timeframe or permitted testing hours, potentially disrupting client operations.
Engagement Management Fundamentals
Master Service Agreement; general contract for future services.
Engagement Management Fundamentals
Statement of Work; details specific project scope and deliverables.
Engagement Management Fundamentals
Non-Disclosure Agreement; protects confidential information.
Engagement Management Fundamentals
Uncontrolled expansion of project requirements.
Engagement Management Fundamentals
Tangible outcomes or products specified in a contract.
Engagement Management Fundamentals
Legal responsibility for damages or actions.
Engagement Management Fundamentals
Remember 'MSA, SOW, NDA' as 'My Specific Nitty-Gritty Details.' MSA is 'My' (general), SOW is 'Specific' (project), and NDA is 'Nitty-Gritty Details' (confidentiality).
Engagement Management Fundamentals
The exam often tests your ability to distinguish between the 'umbrella' agreement (MSA) and the 'project-specific' agreement (SOW). Keywords like 'general terms' point to MSA, while 'specific tasks' or 'project scope' indicate SOW. Remember that an NDA can be a standalone document or embedded within an MSA or SOW.
Engagement Management Fundamentals
Confusing the general terms of an MSA with the specific project details of an SOW.
Engagement Management Fundamentals
Beginning work without a signed SOW, leading to scope disputes or unclear expectations.
Engagement Management Fundamentals
Disclosing confidential client information without understanding the NDA's terms, even accidentally.
Engagement Management Fundamentals
Not understanding that an NDA can be a standalone document or part of an MSA/SOW.
Engagement Management Fundamentals
Computer Fraud and Abuse Act; US law prohibiting unauthorized computer access.
Engagement Management Fundamentals
General Data Protection Regulation; EU law for data privacy and protection.
Engagement Management Fundamentals
Health Insurance Portability and Accountability Act; US healthcare data privacy law.
Engagement Management Fundamentals
Payment Card Industry Data Security Standard; for credit card data security.
Engagement Management Fundamentals
Explicit written permission to perform a penetration test.
Engagement Management Fundamentals
The defined boundaries and targets of a penetration test.
Engagement Management Fundamentals
Moral principles guiding professional conduct and decision-making.
Engagement Management Fundamentals
LEGAL: 'L'aws, 'E'thics, 'G'et authorization, 'A'lways comply, 'L'imit scope.
Engagement Management Fundamentals
The CompTIA PenTest+ exam expects you to know key regulations like GDPR, HIPAA, and PCI DSS. Understand their purpose and how they impact data handling during a test. Also, memorize that the Computer Fraud and Abuse Act (CFAA) is the primary US law against unauthorized computer access.
Engagement Management Fundamentals
Assuming verbal permission is sufficient; always get written authorization.
Engagement Management Fundamentals
Exploiting a vulnerability outside the agreed-upon scope, even if it's critical.
Engagement Management Fundamentals
Failing to understand local laws and international regulations relevant to the client's location or data.
Engagement Management Fundamentals
Open Source Security Testing Methodology Manual; scientific, measurable security testing.
Engagement Management Fundamentals
Penetration Testing Execution Standard; 7-phase lifecycle for pen testing.
Engagement Management Fundamentals
Open Web Application Security Project; focuses on web application security.
Engagement Management Fundamentals
List of the most critical web application security risks.
Engagement Management Fundamentals
Phase in PTES to identify security weaknesses in systems.
Engagement Management Fundamentals
Phase in PTES where identified vulnerabilities are leveraged.
Engagement Management Fundamentals
Focus of OSSTMM, ensuring security measures are effective in practice.
Engagement Management Fundamentals
Imagine an 'OWL' flying over a 'PENTAGON' with a 'SCIENTIST'. OWL for OWASP (web apps), PENTAGON for PTES (pen test lifecycle), SCIENTIST for OSSTMM (scientific, measurable).
Engagement Management Fundamentals
Memorize the primary focus of each framework: OSSTMM for scientific, measurable, broad security testing; PTES for the end-to-end pen testing lifecycle; and OWASP specifically for web application security. Look for keywords like 'web application,' 'lifecycle,' or 'measurable metrics' in exam questions.
Engagement Management Fundamentals
Confusing OSSTMM's broad scope with OWASP's web-specific focus.
Engagement Management Fundamentals
Thinking PTES is just a list of vulnerabilities instead of a full methodology.
Engagement Management Fundamentals
Assuming one framework covers all aspects of security testing without needing others.
Engagement Management Fundamentals
High-level report overview for non-technical stakeholders.
Engagement Management Fundamentals
Detailed report section for IT and security teams.
Engagement Management Fundamentals
Specific, actionable steps to fix identified vulnerabilities.
Engagement Management Fundamentals
Classification of a vulnerability's potential impact.
Engagement Management Fundamentals
Demonstration of a vulnerability's exploitability.
Engagement Management Fundamentals
Recommendations that are practical and can be implemented.
Engagement Management Fundamentals
Screenshots, logs, or data supporting a finding.
Engagement Management Fundamentals
REPORT: R-isk, E-vidence, P-riority, O-utcome, R-ecommendations, T-ools.
Engagement Management Fundamentals
The exam often tests your understanding of report components. Memorize what belongs in an executive summary (high-level, business impact) versus a technical summary (detailed findings, specific vulnerabilities). Keywords like 'non-technical audience' or 'actionable steps' are clues.
Engagement Management Fundamentals
Providing vague or generic remediation recommendations instead of specific, actionable steps.
Engagement Management Fundamentals
Failing to include sufficient evidence (screenshots, logs) to support findings.
Engagement Management Fundamentals
Not tailoring the report sections (e.g., executive summary) to the intended audience.
Engagement Management Fundamentals
Omitting severity ratings or failing to prioritize findings, leaving the client unsure where to start.
Engagement Management Fundamentals
Open-Source Intelligence; gathering information from public sources.
Reconnaissance and Enumeration Techniques
Gathering information without direct interaction with the target.
Reconnaissance and Enumeration Techniques
Database query tool for domain registration information.
Reconnaissance and Enumeration Techniques
Graphical link analysis tool for data mining and visualization.
Reconnaissance and Enumeration Techniques
Search engine for internet-connected devices and services.
Reconnaissance and Enumeration Techniques
Tool for gathering emails, subdomains, hosts, and employee names.
Reconnaissance and Enumeration Techniques
Publicly revealing private or identifying information about an individual.
Reconnaissance and Enumeration Techniques
OSINT: O-pen S-ources I-nform N-ice T-argets. Remember, it's all about finding publicly available info to make your target analysis 'nice' and effective!
Reconnaissance and Enumeration Techniques
For the CompTIA PenTest+ exam, be prepared to identify various OSINT sources (e.g., social media, public records, corporate websites, search engines) and understand their utility in reconnaissance. Keywords to spot include 'passive information gathering' and 'publicly available information'.
Reconnaissance and Enumeration Techniques
Confusing OSINT with active scanning or direct interaction with the target.
Reconnaissance and Enumeration Techniques
Failing to document OSINT sources and findings, leading to unverified intelligence.
Reconnaissance and Enumeration Techniques
Overlooking the ethical and legal implications of using publicly available personal data.
Reconnaissance and Enumeration Techniques
Initial phase of gathering information about a target.
Reconnaissance and Enumeration Techniques
Information gathering involving direct interaction with the target.
Reconnaissance and Enumeration Techniques
Think 'P' for Passive, 'Public' (sources), and 'Private' (no direct interaction). Think 'A' for Active, 'Attack' (like), and 'Alert' (potential detection).
Reconnaissance and Enumeration Techniques
The exam often distinguishes between 'footprinting' (passive) and 'scanning' (active). Be prepared to identify tools and methods specific to each. Remember, anything that sends a packet to the target's network is active.
Reconnaissance and Enumeration Techniques
Confusing a public web search for a target's IP address with an active scan of that IP address.
Reconnaissance and Enumeration Techniques
Using active scanning tools without explicit authorization, potentially violating the engagement scope.
Reconnaissance and Enumeration Techniques
Failing to document which reconnaissance methods were used and when, especially for active techniques.
Reconnaissance and Enumeration Techniques
Domain Name System, translates domain names to IPs.
Reconnaissance and Enumeration Techniques
Process of discovering all DNS records for a domain.
Reconnaissance and Enumeration Techniques
Replication of DNS database files between DNS servers.
Reconnaissance and Enumeration Techniques
Maps a domain name to an IPv4 address.
Reconnaissance and Enumeration Techniques
Specifies mail servers for a domain.
Reconnaissance and Enumeration Techniques
Command-line tool for querying DNS servers.
Reconnaissance and Enumeration Techniques
Request for a full zone transfer.
Reconnaissance and Enumeration Techniques
Indicates authoritative DNS servers for a domain.
Reconnaissance and Enumeration Techniques
AXFR: 'All eXtra Files Retrieved' – for when a zone transfer gives you everything!
Reconnaissance and Enumeration Techniques
For PT0-003, remember that a successful DNS zone transfer (AXFR) provides a complete list of all records for a domain, which is a critical finding for an attacker. Know the 'dig' command syntax for performing zone transfer attempts.
Reconnaissance and Enumeration Techniques
Forgetting to identify authoritative name servers before attempting a zone transfer; you must target the correct server.
Reconnaissance and Enumeration Techniques
Not checking for various record types beyond 'A' records, missing valuable information like MX, TXT, or SRV records.
Reconnaissance and Enumeration Techniques
Assuming a zone transfer won't work and skipping the attempt; misconfigurations are common.
Reconnaissance and Enumeration Techniques
A stealthy port scan that sends SYN packets but doesn't complete the handshake.
Reconnaissance and Enumeration Techniques
A port scan that completes the TCP three-way handshake, less stealthy.
Reconnaissance and Enumeration Techniques
Nmap feature to determine the service and version of applications on open ports.
Reconnaissance and Enumeration Techniques
Nmap feature to identify the operating system and its version of a target host.
Reconnaissance and Enumeration Techniques
A powerful Nmap component for automating advanced network tasks and vulnerability checks.
Reconnaissance and Enumeration Techniques
Nmap option to control scan speed and aggressiveness, from T0 (paranoid) to T5 (insane).
Reconnaissance and Enumeration Techniques
A scan type used to discover open UDP ports and services.
Reconnaissance and Enumeration Techniques
Nmap: Never Miss A Port! Visualize a map where every single port is highlighted, ensuring nothing is overlooked.
Reconnaissance and Enumeration Techniques
The CompTIA PenTest+ exam often presents scenarios where you need to choose the appropriate Nmap command for a given objective, such as 'identify open ports without completing a full connection' (SYN scan) or 'determine the version of a web server' (version detection). Memorize common flags and their functions.
Reconnaissance and Enumeration Techniques
Running Nmap scans without proper authorization, which can be illegal or violate company policy.
Reconnaissance and Enumeration Techniques
Using overly aggressive timing templates (-T5) on production networks, potentially causing instability or being easily detected.
Reconnaissance and Enumeration Techniques
Not saving Nmap output (e.g., -oN, -oX) for later analysis and reporting, requiring rescans.
Reconnaissance and Enumeration Techniques
Identifying specific applications and their versions running on open ports.
Reconnaissance and Enumeration Techniques
Determining the operating system of a target host by analyzing network responses.
Reconnaissance and Enumeration Techniques
Gathering information about web applications, directories, and technologies.
Reconnaissance and Enumeration Techniques
Nmap option for service version detection.
Reconnaissance and Enumeration Techniques
Nmap option for operating system detection.
Reconnaissance and Enumeration Techniques
Systematically guessing directory and file names on a web server.
Reconnaissance and Enumeration Techniques
A Burp Suite feature to automatically crawl a website and discover content.
Reconnaissance and Enumeration Techniques
Information exchanged between client and server, revealing server details.
Reconnaissance and Enumeration Techniques
Remember 'S-V' for 'Service Version' and 'O' for 'Operating System' when using Nmap. For web, think 'DIR' for 'Directory' brute-forcing.
Reconnaissance and Enumeration Techniques
The exam expects you to know the specific Nmap flags for OS (-O) and service (-sV) detection. Also, be familiar with common web enumeration techniques like directory brute-forcing and subdomain enumeration, and the tools used (e.g., Nmap, Burp Suite).
Reconnaissance and Enumeration Techniques
Forgetting to combine -sV and -O for comprehensive Nmap scans.
Reconnaissance and Enumeration Techniques
Not using a sufficiently large or relevant wordlist for directory brute-forcing, leading to missed content.
Reconnaissance and Enumeration Techniques
Overlooking manual inspection of robots.txt or HTML source code during web enumeration.
Reconnaissance and Enumeration Techniques
Automated process identifying known security weaknesses in systems.
Vulnerability Discovery and Analysis
Scan performed without user credentials, simulating an external attacker.
Vulnerability Discovery and Analysis
Scan performed with user credentials, providing deeper access and insights.
Vulnerability Discovery and Analysis
A popular commercial vulnerability scanning tool with extensive plugin databases.
Vulnerability Discovery and Analysis
An open-source vulnerability scanner, derived from Nessus, offering similar features.
Vulnerability Discovery and Analysis
Common Vulnerabilities and Exposures; a list of publicly known cyber security vulnerabilities.
Vulnerability Discovery and Analysis
SCAN: S-Scope, C-Choose Tools, A-Authenticate (or not), N-Now Scan!
Vulnerability Discovery and Analysis
The CompTIA PenTest+ exam frequently asks about the differences and use cases for credentialed vs. non-credentialed scans. Remember that credentialed scans provide a more accurate and comprehensive view of vulnerabilities by simulating an insider or an attacker who has already gained access.
Vulnerability Discovery and Analysis
Confusing a vulnerability scan with a penetration test; a scan identifies, a pen test exploits.
Vulnerability Discovery and Analysis
Relying solely on non-credentialed scans for internal network assessments, missing critical internal vulnerabilities.
Vulnerability Discovery and Analysis
Failing to update scanner plugins and vulnerability databases, leading to missed, newly discovered vulnerabilities.
Vulnerability Discovery and Analysis
A correctly identified vulnerability.
Vulnerability Discovery and Analysis
A scanner reports a vulnerability that doesn't exist.
Vulnerability Discovery and Analysis
A scanner correctly finds no vulnerability.
Vulnerability Discovery and Analysis
A real vulnerability exists but is undetected.
Vulnerability Discovery and Analysis
Human confirmation of scanner findings.
Vulnerability Discovery and Analysis
Comparing results from multiple tools.
Vulnerability Discovery and Analysis
The process of fixing vulnerabilities.
Vulnerability Discovery and Analysis
Think of a 'FAlse Positive' as a 'FAke Alarm' – it looks like a problem, but it's not real. A 'FAlse Negative' is a 'FAlling through the cracks' problem – it's real, but you missed it.
Vulnerability Discovery and Analysis
The exam expects you to differentiate clearly between true positives, false positives, and false negatives. Understand that manual verification is essential for reducing false positives and identifying false negatives, and that automated tools alone are insufficient for comprehensive testing.
Vulnerability Discovery and Analysis
Trusting automated scanner results without manual verification, leading to wasted time on non-existent issues.
Vulnerability Discovery and Analysis
Failing to document false positives, causing them to be re-reported in future scans or by other testers.
Vulnerability Discovery and Analysis
Over-relying on a single tool or methodology, increasing the risk of false negatives and missed critical vulnerabilities.
Vulnerability Discovery and Analysis
An intermediary that intercepts and forwards network traffic.
Vulnerability Discovery and Analysis
Analyzes observed traffic without sending new requests.
Vulnerability Discovery and Analysis
Sends crafted requests to probe for vulnerabilities.
Vulnerability Discovery and Analysis
Burp tool to manually modify and resend individual requests.
Vulnerability Discovery and Analysis
Burp tool for automated, customized attacks against web apps.
Vulnerability Discovery and Analysis
Burp tool to automatically crawl and map a web application.
Vulnerability Discovery and Analysis
A digital certificate issued by a Certificate Authority.
Vulnerability Discovery and Analysis
Remember 'P.R.I.S.T.' for Burp's core tools: Proxy, Repeater, Intruder, Scanner, Target.
Vulnerability Discovery and Analysis
The PenTest+ exam often tests your practical knowledge of Burp Suite. Be prepared to identify its core tools (Proxy, Repeater, Intruder, Scanner) and their functions, especially for intercepting traffic, modifying requests, and identifying common web vulnerabilities like SQLi and XSS.
Vulnerability Discovery and Analysis
Forgetting to install Burp's CA certificate, leading to HTTPS errors.
Vulnerability Discovery and Analysis
Not configuring the browser's proxy settings correctly, resulting in no traffic interception.
Vulnerability Discovery and Analysis
Relying solely on automated scans without manual verification of findings.
Vulnerability Discovery and Analysis
Running active scans without proper authorization, potentially causing service disruption.
Vulnerability Discovery and Analysis
Defines security duties between cloud provider and customer.
Vulnerability Discovery and Analysis
Controls who can do what in a cloud environment.
Vulnerability Discovery and Analysis
Suite of tools for auditing wireless networks.
Vulnerability Discovery and Analysis
Gaining unauthorized access by following an authorized person.
Vulnerability Discovery and Analysis
Wi-Fi Protected Access II with a pre-shared key.
Vulnerability Discovery and Analysis
Radio-Frequency Identification, used for tracking/access.
Vulnerability Discovery and Analysis
Manipulating people to divulge info or perform actions.
Vulnerability Discovery and Analysis
Think 'CWP' for Cloud, Wireless, Physical. Each is a distinct attack surface, like a layer of an onion, protecting the core data.
Vulnerability Discovery and Analysis
For the exam, be prepared to differentiate between the responsibilities of the cloud provider and the customer under the shared responsibility model. Also, know the common tools for wireless assessments like Aircrack-ng and Kismet, and understand the basic principles of physical security bypasses.
Vulnerability Discovery and Analysis
Ignoring the shared responsibility model in cloud assessments.
Vulnerability Discovery and Analysis
Underestimating the impact of physical security breaches.
Vulnerability Discovery and Analysis
Focusing only on Wi-Fi and neglecting other wireless technologies.
Vulnerability Discovery and Analysis
Code designed to take advantage of a specific vulnerability in a system.
Attacks and Exploits Deep Dive
Code executed on a target system after successful exploitation.
Attacks and Exploits Deep Dive
Advanced, extensible payload providing a powerful interactive shell.
Attacks and Exploits Deep Dive
Metasploit module for scanning, fuzzing, or information gathering.
Attacks and Exploits Deep Dive
Module used after exploitation for tasks like privilege escalation.
Attacks and Exploits Deep Dive
Required Metasploit option specifying the target host's IP address.
Attacks and Exploits Deep Dive
Required Metasploit option specifying the attacker's listening IP address.
Attacks and Exploits Deep Dive
To remember Metasploit's core modules, think of 'E-P-A-P': Exploits Pave A Path (to) Payloads.
Attacks and Exploits Deep Dive
The CompTIA PenTest+ exam expects you to know the purpose of Metasploit's core components (exploits, payloads, auxiliary, post) and how to use msfconsole for basic exploitation, including setting options like RHOSTS and LHOST. Look for questions describing scenarios where a penetration tester needs to leverage known vulnerabilities.
Attacks and Exploits Deep Dive
Forgetting to set both RHOSTS and LHOST, leading to failed exploit attempts or unhandled sessions.
Attacks and Exploits Deep Dive
Using an exploit without understanding the target's specific vulnerability or patch level, resulting in system instability or detection.
Attacks and Exploits Deep Dive
Not checking 'show options' for an exploit or payload, missing critical parameters that are required for successful execution.
Attacks and Exploits Deep Dive
Systematically trying all possible password combinations until the correct one is found.
Attacks and Exploits Deep Dive
Using a list of common words and phrases as password guesses.
Attacks and Exploits Deep Dive
Using leaked credentials from one breach to try logging into other services.
Attacks and Exploits Deep Dive
Pre-computed tables of hashes used to reverse cryptographic hashes quickly.
Attacks and Exploits Deep Dive
Authenticating using a user's password hash instead of the plaintext password.
Attacks and Exploits Deep Dive
A hash format commonly used in Windows networks for storing and transmitting passwords.
Attacks and Exploits Deep Dive
A brute-force attack where specific character sets and lengths are defined.
Attacks and Exploits Deep Dive
For Hashcat, remember 'H.A.S.H. - Hash Algorithm, Attack Mode, Source, Hashfile'. It helps recall the key parameters.
Attacks and Exploits Deep Dive
The PT0-003 exam expects you to know the purpose and application of various password attack types (e.g., brute-force, dictionary, rainbow table, credential stuffing, pass-the-hash) and common tools like Hashcat for cracking hashes. Memorize the basic Hashcat command-line options for different attack modes and hash types.
Attacks and Exploits Deep Dive
Forgetting to specify the correct hash type (-m) in Hashcat, leading to incorrect or failed cracking attempts.
Attacks and Exploits Deep Dive
Using a generic wordlist for all cracking scenarios instead of tailoring it to the target's likely password choices or language.
Attacks and Exploits Deep Dive
Attempting to crack hashes without proper authorization, which is illegal and unethical in real-world scenarios.
Attacks and Exploits Deep Dive
Code injection technique exploiting database vulnerabilities via malicious SQL statements.
Attacks and Exploits Deep Dive
Injecting malicious client-side scripts into web pages viewed by other users.
Attacks and Exploits Deep Dive
Inducing a server-side application to make requests to an arbitrary domain.
Attacks and Exploits Deep Dive
An open-source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws.
Attacks and Exploits Deep Dive
XSS vulnerability where the attack is executed by modifying the Document Object Model (DOM) in the client's browser.
Attacks and Exploits Deep Dive
A Burp Suite tool for detecting out-of-band interactions during web vulnerability testing.
Attacks and Exploits Deep Dive
SQLi is for 'Stealing Queries' from the database. XSS is for 'eXecuting Scripts' in the browser. SSRF is for 'Server Sends Requests' internally.
Attacks and Exploits Deep Dive
For the PenTest+ exam, be able to differentiate between reflected, stored, and DOM-based XSS. Also, understand the primary impact of each attack type: SQLi for data compromise, XSS for client-side compromise, and SSRF for internal network access.
Attacks and Exploits Deep Dive
Confusing the impact of XSS (client-side) with SQLi (server/database-side).
Attacks and Exploits Deep Dive
Underestimating the potential severity of SSRF, especially in cloud environments.
Attacks and Exploits Deep Dive
Not properly sanitizing all user inputs, which is the root cause of many web vulnerabilities.
Attacks and Exploits Deep Dive
Amazon Web Services (AWS) object storage container.
Attacks and Exploits Deep Dive
Forces a client to disconnect from a wireless network.
Attacks and Exploits Deep Dive
An unauthorized access point mimicking a legitimate one.
Attacks and Exploits Deep Dive
Exchange of messages to establish a WPA/WPA2 connection key.
Attacks and Exploits Deep Dive
Wireless adapter mode to capture all nearby wireless traffic.
Attacks and Exploits Deep Dive
Wi-Fi Protected Setup, a vulnerable method for easy connection.
Attacks and Exploits Deep Dive
Code executed by a cloud provider without managing servers.
Attacks and Exploits Deep Dive
CLOUD: C - Configs are bad. L - Loose IAM. O - Open buckets. U - Unsecured APIs. D - Docker's exposed.
Attacks and Exploits Deep Dive
The exam often focuses on identifying cloud misconfigurations (e.g., S3 bucket permissions, IAM roles) and understanding the steps for WPA/WPA2 cracking (capture handshake, offline attack). Memorize the purpose of key Aircrack-ng tools.
Attacks and Exploits Deep Dive
Forgetting that cloud security is a shared responsibility model, where the customer is responsible for configuration.
Attacks and Exploits Deep Dive
Confusing the purpose of different Aircrack-ng tools (e.g., airodump-ng vs. aireplay-ng).
Attacks and Exploits Deep Dive
Underestimating the impact of weak WPA2-PSK passphrases, assuming WPA2 is always 'secure'.
Attacks and Exploits Deep Dive
Fraudulent communication to trick individuals into revealing sensitive info.
Attacks and Exploits Deep Dive
Creating a false scenario to obtain information or access.
Attacks and Exploits Deep Dive
Phishing conducted over voice communication (telephone).
Attacks and Exploits Deep Dive
AI-generated synthetic media, often audio or video, mimicking real people.
Attacks and Exploits Deep Dive
Targeted phishing attack on a specific individual or organization.
Attacks and Exploits Deep Dive
Think 'PAID' for common social engineering tactics: Pretexting, Authority, Intimidation, Deception.
Attacks and Exploits Deep Dive
The PenTest+ exam expects you to differentiate between various social engineering techniques (e.g., phishing vs. spear phishing vs. pretexting) and understand their impact. Pay close attention to how AI can enhance these attacks, making them more sophisticated and harder to detect.
Attacks and Exploits Deep Dive
Underestimating the human element in security; technical controls alone are not enough.
Attacks and Exploits Deep Dive
Failing to conduct regular, realistic security awareness training for employees.
Attacks and Exploits Deep Dive
Not having clear, documented procedures for verifying unusual or urgent requests.
Attacks and Exploits Deep Dive
Techniques to maintain access to a compromised system.
Post-Exploitation and Lateral Movement
Gaining higher-level permissions on a system.
Post-Exploitation and Lateral Movement
Linux permission that runs an executable with owner's permissions.
Post-Exploitation and Lateral Movement
Windows registry locations for programs to start with OS.
Post-Exploitation and Lateral Movement
Leveraging vulnerabilities in system services for higher privileges.
Post-Exploitation and Lateral Movement
Exploiting Windows to assume another process's security token.
Post-Exploitation and Lateral Movement
Exploiting vulnerabilities in the operating system's core.
Post-Exploitation and Lateral Movement
To remember Persistence methods: 'S.C.R.E.W.S.' - Services, Cron jobs, Registry, Environmental variables, Web shells, Startup folders.
Post-Exploitation and Lateral Movement
The PenTest+ exam frequently tests your knowledge of specific Windows registry keys (e.g., Run, RunOnce, HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run) and Linux files/directories (e.g., /etc/rc.local, /etc/cron.d/, SUID binaries) used for persistence. Be prepared to identify these by name.
Post-Exploitation and Lateral Movement
Forgetting to establish persistence after gaining initial access, leading to lost access upon system reboot.
Post-Exploitation and Lateral Movement
Focusing solely on kernel exploits for privilege escalation and overlooking simpler misconfigurations like weak service permissions.
Post-Exploitation and Lateral Movement
Not properly cleaning up persistence mechanisms after a penetration test, leaving backdoors for real attackers.
Post-Exploitation and Lateral Movement
Technique to move between systems after initial compromise.
Post-Exploitation and Lateral Movement
Extracting usernames, passwords, or hashes from a compromised system.
Post-Exploitation and Lateral Movement
Authenticating using a stolen Kerberos ticket.
Post-Exploitation and Lateral Movement
Using legitimate system tools for malicious purposes.
Post-Exploitation and Lateral Movement
Dividing a network into smaller, isolated segments.
Post-Exploitation and Lateral Movement
Windows tool to extract credentials from memory.
Post-Exploitation and Lateral Movement
Remember 'CHART' for Lateral Movement: **C**redential Harvesting, **H**ashes, **A**dmin Tools, **R**emote Services, **T**argets.
Post-Exploitation and Lateral Movement
The exam expects you to know common lateral movement techniques like Pass-the-Hash, Pass-the-Ticket, and the use of tools such as Mimikatz, Metasploit, and Nmap in this context. Focus on the *how* and *why* these techniques are effective.
Post-Exploitation and Lateral Movement
Forgetting to clean up traces after moving laterally, which can alert defenders.
Post-Exploitation and Lateral Movement
Attempting to move laterally without proper reconnaissance, leading to detection or dead ends.
Post-Exploitation and Lateral Movement
Only focusing on one type of lateral movement (e.g., just RDP) and missing other opportunities.
Post-Exploitation and Lateral Movement
Using a compromised system to access other internal networks.
Post-Exploitation and Lateral Movement
Forwards a local port to a remote port via a pivot host.
Post-Exploitation and Lateral Movement
Forwards a remote port to a local port via a pivot host.
Post-Exploitation and Lateral Movement
Creates a SOCKS proxy for routing arbitrary traffic.
Post-Exploitation and Lateral Movement
A protocol that routes network packets between client and server.
Post-Exploitation and Lateral Movement
A tool to force applications to use a proxy chain.
Post-Exploitation and Lateral Movement
Another term for network pivoting or lateral movement.
Post-Exploitation and Lateral Movement
P.I.V.O.T.: Proxy Infiltrates Various Other Targets. Remember it's about using one system to get to many others.
Post-Exploitation and Lateral Movement
The exam expects you to know the difference between local and remote port forwarding, and when to use a SOCKS proxy. Keywords like 'unreachable subnet' or 'internal network access' indicate pivoting.
Post-Exploitation and Lateral Movement
Forgetting to configure firewall rules on the compromised host to allow forwarded traffic.
Post-Exploitation and Lateral Movement
Not understanding the difference between local and remote port forwarding, leading to incorrect setup.
Post-Exploitation and Lateral Movement
Attempting to pivot without first establishing a stable and persistent connection to the initial compromised host.
Post-Exploitation and Lateral Movement
Unauthorized transfer of data from a compromised system.
Post-Exploitation and Lateral Movement
Hidden communication path used to bypass security controls.
Post-Exploitation and Lateral Movement
Techniques to hinder forensic analysis and hide activities.
Post-Exploitation and Lateral Movement
Removing all traces of a penetration test or compromise.
Post-Exploitation and Lateral Movement
Exfiltrating data by encoding it into DNS queries and responses.
Post-Exploitation and Lateral Movement
Framework with modules for exploitation, post-exploitation, and exfiltration.
Post-Exploitation and Lateral Movement
To remember cleanup steps, think 'CLEAR': **C**lear logs, **L**eave no files, **E**rase users, **A**lter nothing, **R**estore settings.
Post-Exploitation and Lateral Movement
For PT0-003, memorize common exfiltration protocols (DNS, ICMP, HTTP/S, FTP) and associated tools (Metasploit's `download`, Burp Suite for web, `wevtutil` for logs). Understand that anti-forensics aims to remove indicators of compromise (IOCs).
Post-Exploitation and Lateral Movement
Forgetting to clear all relevant logs (e.g., application logs in addition to system logs).
Post-Exploitation and Lateral Movement
Leaving behind tools or temporary files that could be traced back to the attacker.
Post-Exploitation and Lateral Movement
Not restoring system configurations to their original state, causing operational issues for the client.
Post-Exploitation and Lateral Movement