Module 1: Introduction to Ethical Hacking and Penetration Testingo
Module objective: Explain the importance of methodological ethical
Ethical Hacking and Penetration Testing
Hacking and penetration testing.
1.1 Understanding Ethical Hacking and Penetration Testing
Objective: Explain the importance of ethical hacking and penetration testing.
1.2 Exploring Penetration Testing Methodologies.
Objective: Explain different penetration testing methodologies and frameworks.
1.3 Building Your Own Lab.
Objective: Configure a virtual machine for your penetration testing learning experience.
Module 2: Planning and Scoping a Penetration Testing Assessment
Module objective: Create penetration testing preliminary documents.
2.1 Comparing and Contrasting Governance, Risk, and Compliance Concepts.
Objective: Explain the role of governance, risk, compliance, and environmental factors in planning penetration testing.
2.2 Explaining the Importance of Scoping and Organizational or Customer Requirements.
Objective: Create a penetration test scope and plan document that addresses organizational requirements for penetration testing services.
2.3 Demonstrating an Ethical Hacking Mindset by Maintaining Professionalism and Integrity.
Objective: Create your personal code of conduct to provide professionalism and integrity in your ethical hacking practice.
Module 3: Information Gathering and Vulnerability Scanning
Module objective: Perform information gathering and vulnerability scanning activities.
3.1 Performing Passive Reconnaissance.
Objective: Perform passive reconnaissance activities.
3.2 Performing Active Reconnaissance.
Objective: Perform active reconnaissance activities.
3.3 Understanding the Art of Performing Vulnerability Scans.
Objective: Perform vulnerability scans.
3.4 Understanding How to Analyze Vulnerability Scan Results.
Objective: Analyze the results of reconnaissance exercises
Module 4: Social Engineering Attacks
Module objective: Explain how social engineering attacks succeed.
4.1 Pretexting for an Approach and Impersonation.
Objective: Explain how pretexting is used in social engineering attacks.
4.2 Social Engineering Attacks.
Objective: Explain different types of social engineering attacks.
4.3 Physical Attacks.
Objective: Explain different types of physical attacks.
4.4 Social Engineering Tools.
Objective: Explain how social engineering attack tools facilitate attacks.
4.5 Methods of Influence.
Objective: Explain how social engineering a tacks enlist user participation.
Module 5: Exploiting Wired and Wireless Networks
Module objective: Explain how to exploit wired and wireless network vulnerabilities.
5.1 Exploiting Network-Based Vulnerabilities.
Objective: Explain how to exploit network-based vulnerabilities.
5.2 Exploiting Wireless Vulnerabilities.
Objective: Explain how to exploit wireless vulnerabilities.
Module 6: Exploiting Application-Based Vulnerabilities
Module objective: Explain how to exploit application-based vulnerabilities.
6.1 Overview of Web Application-Based Attacks for Security Professionals and the OWASP Top 10.
Objective: Explain common web application attacks.
6.2 How to Build Your Own Web Application Lab
Objective: Describe common web application testing tools.
6.3 Understanding Business Logic Flaws.
Objective: Explain how business logic flows enable attackers to exploit web applications.
6.4 Understanding Injection-Based Vulnerabilities.
Objective: Use tools to conduct injection attacks.
6.5 Exploiting Authentication-Based Vulnerabilities.
Objective: Use tools to exploit authentication-based vulnerabilities.
6.6 Exploiting Authorization-Based Vulnerabilities.
Objective: Explain how authorization-based vulnerabilities are exploited.
6.7 Understanding Cross-Site Scripting (XSS) Vulnerabilities.
Objective: Explain cross-site scripting vulnerabil
Module 7: Cloud, Mobile, and IoT Security
Module objective: Explain how to exploit cloud, mobile, and IoT security vulnerabilities.
7.1 Researching Attack Vectors and Performing Attacks on Cloud Technologies.
Objective: Explain how to attack cloud technologies.
7.2 Explaining Common Attacks and Vulnerabilities Against Specialized Systems.
Objective: Explain common attacks against specialized systems.
Module 8: Performing Post-Exploitation Techniques
Module objective: Explain how to perform postexploitation activities.
8.1 Creating a Foothold and Maintaining Persistence After Compromising a System.
Objective: Explain how to create a foothold and maintain persistence after compromising a system.
8.2 Understanding How to Perform Lateral Movement, Detection Avoidance, and Enumeration.
Objective: Explain how to perform lateral movement, detection avoidance, and enumeration.
Module 9: Reporting and Communication
Module objective: Create a penetration testing report.
9.1 Comparing and Contrasting Important Components of Written Reports.
Objective: Describe the major components of a written pentest report.
9.2 Analyzing the Findings and Recommending the Appropriate Remediation Within a Report.
Objective: Recommend appropriate remediation based on the findings of a pentesting campaign.
9.3 Explaining the Importance of Communication During the Penetration Testing Process.
Objective: Explain the components necessary for communications during the pentest process.
9.4 Explaining Post-Report Delivery Activities.
Objective: Explain necessary processes to complete the pentesting engagement.
Module 10: Tools and Code Analysis
Module objective: Classify pentesting tools by use case.
10.1 Understanding the Basic Concepts of Scripting and Software Development.
Objective: Analyze code for pentesting use.
10.2 Understanding the Different Use Cases of Penetration Testing Tools and Analyzing Exploit Code.
Objective: Classify pentesting tools by their primary use cases.