Video description
6+ Hours of Video Instruction
Overview
CompTIA PenTest+ (PT1-001) Complete Video Course is a complete resource to prepare for the CompTIA PenTest+ certification exam. This course covers all the topics on the exam, including planning and scoping a security penetration testing (ethical hacking) assessment, understanding legal and compliance requirements, and performing vulnerability scanning and penetration testing using appropriate tools and techniques. In addition, it guides the student on how to analyze the results and write a comprehensive report including remediation techniques and best practices on how to effectively communicate results to the relevant stakeholders.
The course is presented by a seasoned and active cybersecurity expert with years of field and teaching experience. Omar Santos walks you through the exam objectives and provides tips and scenarios throughout, helping to put the knowledge in context. He provides demonstrations as well as detailed explanations and samples of each topic.
Topics includeModule 1: Introduction to Ethical Hacking and How to Plan a Security Penetration TestModule 2: ReconnaissanceModule 3: Attacks and ExploitsModule 4: Tools and Reporting
Skill Level
Beginner/Intermediate
Learn How To
* Prepare for the CompTIA PenTest+ Exam* Plan and scope a security penetration test* Perform reconnaissance on a target* Gain access through vulnerable systems by knowing the various exploits* Restore environments after a pentest has successfully found vulnerabilities within the system* Record and log activities in a manner that is professional, clear, and advantageous to the client for system improvement
Who Should Take This Course
* Anyone interested in taking the CompTIA PenTest+ exam* Individuals seeking careers in the cybersecurity field
Course Requirements None
Lesson descriptions
Module 1, "Introduction to Ethical Hacking and How to Plan a Security Penetration Test," introduces the concept of ethical hacking and how the cybersecurity industry goes about implementing field-tested security parameters using penetration testing. It walks through the planning and scoping of a pentesting assessment.
Module 2, "Reconnaissance," covers all things related to the intelligence gathering phase of the pentest, including collecting information, port scanning, and vulnerability scanning. It then discusses how to use this intelligence to plan the pentest itself.
Module 3, "Attacks and Exploits," discusses how to use the intelligence gathered to perform the pentest. It goes over the various kinds of social engineering attacks and how to attack both wired and wireless networks. It then discusses how to exploit application-based vulnerabilities as well as local host and physical security vulnerabilities. Finally, it covers the clean-up and implementation of the post-exploitation techniques.
Module 4, "Tools and Reporting," shows how to find and leverage the various tools that are available for evasion, decompilation, forensics, and software assurance. It also goes into the reporting aspect of the job, including best practices and how to professionally recommend mitigation strategies for the vulnerabilities found.
About Pearson Video Training
Pearson publishes expert-led video tutorials covering a wide selection of technology topics designed to teach you the skills you need to succeed. These professional and personal technology videos feature world-leading author instructors published by your trusted technology brands: Addison-Wesley, Cisco Press, Pearson IT Certification, Prentice Hall, Sams, and Que. Topics include IT Certification, Network Security, Cisco Technology, Programming, Web Development, Mobile Development, and more. Learn more about Pearson Video training at http://www.informit.com/video.
Video Lessons are available for download for offline viewing within the streaming format. Look for the green arrow in each lesson.
Table of contents
- Introduction
- Lesson 1: Introduction to Ethical Hacking and Penetration Testing
- Lesson 2: Planning and Scoping a Penetration Testing Assessment
- Module 2: Reconnaissance
- Lesson 3: Information Gathering and Vulnerability Identification
- Module 3: Attacks and Exploits
-
Lesson 4: Social Engineering Attacks
- Learning objectives
- 4.1 Understanding Phishing and Spear Phishing Attacks
- 4.2 Understanding Pharming, Whaling, Malvertising, SMS Phishing, and Voice Phishing Attacks
- 4.3 Describing what is Elicitation, Interrogation, and Impersonation (Pretexting)
- 4.4 Understanding What is Social Engineering Motivation Techniques
- 4.5 Understanding What is Shoulder Surfing
- 4.6 Understanding What is USB Key Drop
-
Lesson 5: Exploiting Wired and Wireless Networks
- Learning objectives
- 5.1 Exploiting Windows Name Resolution-based Vulnerabilities
- 5.2 Surveying DNS Cache Poisoning Attacks
- 5.3 Attacking and Exploiting Server Message Block (SMB) Implementations
- 5.4 Understanding Simple Network Management Protocol (SNMP) Vulnerabilities and Exploits
- 5.5 Exploiting Simple Mail Transfer Protocol (SMTP) Vulnerabilities
- 5.6 Exploiting File Transfer Protocol (FTP) Vulnerabilities
- 5.7 Performing Pass-the-Hash, Man-in-the-middle (MiTM), and SSL Striping Attacks
- 5.8 Understanding Denial of Service (Dos) and Distributed Denial of Service (DDoS) Attacks
- 5.9 Performing Network Access Control (NAC) Bypass and VLAN Hopping Attacks
- 5.10 Understanding Rogue Access Points and Evil Twin Attacks
- 5.11 Performing Deauthentication Attacks and Attacking the Preferred Network Lists
- 5.12 Jamming Wireless Signal, Causing Interference, and War Driving
- 5.13 Understanding the WEP Protocol
- 5.14 Cracking WEP Implementations
- 5.15 Understanding the WPA Protocol
- 5.16 Attacking WPA2 Implementations
-
Lesson 6: Exploiting Application-based Vulnerabilities
- Learning objectives
- 6.1 Overview of Web Applications for Security Professionals
- 6.2 How to Build Your Own Web Application Lab
- 6.3 Understanding SQL Injection
- 6.4 Understanding Injection Vulnerabilities
- 6.5 Exploiting Command Injection Vulnerabilities
- 6.6 Understanding Authentication-based Vulnerabilities
- 6.7 Exploiting Authorization-based Vulnerabilities
- 6.8 Understanding Cross-site Scripting (XSS) Vulnerabilities
- 6.9 Understanding Cross-site Request Forgery (CSRF/XSRF)
- 6.10 Understanding Clickjacking
- 6.11 Exploiting Insecure Direct Object References and Path Traversal
- 6.12 Assessing Unsecure Code Practices and APIs
-
Lesson 7: Exploiting Local Host and Physical Security Vulnerabilities
- Learning objectives
- 7.1 Understanding How to Exploit Local Host Vulnerabilities
- 7.2 Exploiting Insecure Service and Protocol Configurations
- 7.3 Understanding Local Privilege Escalation
- 7.4 Understanding Linux Permissions
- 7.5 Understanding SUID or SGID and Unix Programs
- 7.6 Exploiting Insecure SUDO Implementations
- 7.7 Understanding Ret2libc Attacks
- 7.8 Understanding Windows Privileges
- 7.9 Surveying Kerberoasting
- 7.10 Exploiting Other Windows-based Vulnerabilities
- 7.11 Understanding What Are Key Loggers
- 7.12 Understanding What Are Scheduled Tasks
- 7.13 Exploring Sandboxes and Virtual Machine Escape Attacks
- 7.14 Surveying Mobile Device Security
- 7.15 Understanding How to Exploit Physical Security Vulnerabilities
- Lesson 8: Performing Post-Exploitation Techniques
- Module 4: Tools and Reporting
-
Lesson 9: Penetration Testing Tools
- Learning objectives
- 9.1 Understanding the Different Use Cases of Penetration Testing Tools
- 9.2 Exploring Tools for Reconnaissance
- 9.3 Exploring Tools for Vulnerability Scanning
- 9.4 Exploring Tools for Credential Attacks
- 9.5 Exploring Tools for Persistence
- 9.6 Exploring Tools for Evasion
- 9.7 Exploring Tools for De-compilation
- 9.8 Exploring Tools for Forensics
- 9.9 Exploring Tools for Software Assurance
- 9.10 Leveraging Bash, Python, Ruby, and PowerShell in Penetration Testing Engagements
- Lesson 10: Reporting and Communication
- Summary
Product information
- Title: CompTIA PenTest+ (PT1-001)
- Author(s):
- Release date: March 2020
- Publisher(s): Pearson
- ISBN: 0135305288
You might also like
video
CompTIA Security+ (SY0-501)
An updated edition of this video title is available. Please go to CompTIA Security+ SY0-601 Complete …
video
CompTIA Advanced Security Practitioner (CASP) CAS-003
18+ Hours of Video Instruction More than 18 hours of video instruction to prepare you for …
video
CompTIA Cybersecurity Analyst CySA+ (CS0-001)
The second edition of this video title is available. Please go to CompTIA Cybersecurity Analyst (CySA+) …
video
CCNP and CCIE Security Core SCOR 350-701
12+ Hours of Video Instruction More than 12 hours of video instruction and remediation organized to …