The gold standard for penetration testing. Prove your hands-on skills with a 24-hour practical exam.
Passive and active reconnaissance techniques
Identifying and analyzing security weaknesses
Exploiting common web vulnerabilities
Cracking and brute-forcing authentication
Targeting end users and client applications
Escalating access on Windows and Linux
Attacking Windows domains
The exam tests persistence. If one approach doesn't work, enumerate more and try different techniques.
Take detailed notes and screenshots during the exam. Your report must prove you completed each step.
80% of the exam is finding the right vulnerability. Thorough enumeration is key.
You'll need to move through networks. Practice port forwarding and tunneling techniques.