SELECT A LESSON TO BEGIN
Prove you can run an offensive engagement end to end — scope, exploit, and report.
People moving from "I know security" to "I can test it": aspiring pentesters and red-teamers with the fundamentals down.
Up to 90 questions · 165 minutes · multiple-choice + performance-based · hands-on tooling · valid 3 years
Three tasters — the real track has hundreds, graded, with full rationale.
B. The rules of engagement / scope statement authorises the test and bounds it. Testing outside it is unauthorised access — illegal, regardless of intent.
B. -sV probes open ports to determine the service and version running. -sn is ping-only host discovery, -Pn skips host discovery, -oN writes normal output.
A. Pass-the-hash reuses the captured hash directly for authentication, skipping the need to recover the plaintext password.
The full CompTIA PenTest+ track — lectures, graded checks and labs — is free to start. Create an account to save your progress, earn points and climb the leaderboard.