CompTIA PT0-002 Exam Syllabus Topics:
Topic | Details |
---|---|
Planning and Scoping - 15% | |
Explain the importance of planning for an engagement. | - Understanding the target audience - Rules of engagement - Communication escalation path - Resources and requirements
- Budget
- Technical constraints
|
Explain key legal concepts. | - Contracts
- Environmental differences
- Written authorization
|
Explain the importance of scoping an engagement properly. | - Types of assessment
- Special scoping considerations
- Target selection
- Strategy
- Risk acceptance
|
Explain the key aspects of compliance-based assessments. | - Compliance-based assessments, limitations and caveats
- Clearly defined objectives based on regulations |
Information Gathering and Vulnerability Identification - 22% | |
Given a scenario, conduct information gathering using appropriate techniques. | - Scanning - Enumeration
- Packet crafting
- Eavesdropping
- Decompilation
|
Given a scenario, perform a vulnerability scan. | - Credentialed vs. non-credentialed - Types of scans
- Container security
- Considerations of vulnerability scanning
|
Given a scenario, analyze vulnerability scan results. | - Asset categorization - Adjudication
- Prioritization of vulnerabilities
|
Explain the process of leveraging information to prepare for exploitation. | - Map vulnerabilities to potential exploits - Prioritize activities in preparation for penetration test - Describe common techniques to complete attack
|
Explain weaknesses related to specialized systems. | - ICS - SCADA - Mobile - IoT - Embedded - Point-of-sale system - Biometrics - Application containers - RTOS |
Attacks and Exploits - 30% | |
Compare and contrast social engineering attacks. | - Phishing
- Elicitation
- Interrogation
|
Given a scenario, exploit network-based vulnerabilities. | - Name resolution exploits
- SMB exploits
- DoS/stress test |
Given a scenario, exploit wireless and RF-based vulnerabilities. | - Evil twin
- Deauthentication attacks |
Given a scenario, exploit application-based vulnerabilities. | - Injections
- Authentication
- Authorization
- Cross-site scripting (XSS)
- Cross-site request forgery (CSRF/XSRF)
- File inclusion
- Unsecure code practices
|
Given a scenario, exploit local host vulnerabilities. | - OS vulnerabilities
- Unsecure service and protocol configurations
- Default account settings
- Physical device security
|
Summarize physical security attacks related to facilities. | - Piggybacking/tailgating - Fence jumping - Dumpster diving - Lock picking - Lock bypass - Egress sensor - Badge cloning |
Given a scenario, perform post-exploitation techniques. | - Lateral movement
- Persistence
- Covering your tracks |
Penetration Testing Tools - 17% | |
Given a scenario, use Nmap to conduct information gathering exercises. | - SYN scan (-sS) vs. full connect scan (-sT) - Port selection (-p) - Service identification (-sV) - OS fingerprinting (-O) - Disabling ping (-Pn) - Target input file (-iL) - Timing (-T) - Output parameters
|
Compare and contrast various use cases of tools. | - Use cases
- Tools
|
Given a scenario, analyze tool output or data related to a penetration test. | - Password cracking - Pass the hash - Setting up a bind shell - Getting a reverse shell - Proxying a connection - Uploading a web shell - Injections |
Given a scenario, analyze a basic script (limited to Bash, Python, Ruby, and PowerShell). | - Logic
- I/O
- Substitutions
- Error handling |
Reporting and Communication - 16% | |
Given a scenario, use report writing and handling best practices. | - Normalization of data - Written report of findings and remediation
- Risk appetite |
Explain post-report delivery activities. | - Post-engagement cleanup
- Client acceptance |
Given a scenario, recommend mitigation strategies for discovered vulnerabilities. | - Solutions
- Findings
- Remediation
|
Explain the importance of communication during the penetration testing process. | - Communication path - Communication triggers
- Reasons for communication
- Goal reprioritization |
CompTIA PenTest+ Exam Certification Details:
Exam Code | PT0-002 |
Exam Price | $381 (USD) |
Exam Name | CompTIA PenTest+ |
Duration | 165 mins |
Passing Score | 750 / 900 |
Schedule Exam | CompTIA Marketplace Pearson VUE |
Number of Questions | 85 |
Books / Training | CompTIA PenTest+ Certification Training |
Sample Questions | CompTIA PenTest+ Sample Questions |
Reference: https://www.comptia.org/certifications/pentest
How much is the salary of a CompTIA PT0-002 certified professional?
The salary of the CompTIA PT0-002 certified professional is dependent on the experience of the candidate, the type of organization they work for, the skills and qualifications they have, the company, location, and the certification. The average salary of a CompTIA PT0-002 certified professional who prepared himself with the help of the PT0-002 Dumps is as follows:
- In Canada: 50,000 CAD
- In Australia: 55,000 AUD
- In the United States: 65,000 USD
- In the United Kingdom: 59,000 GBP
- In India: 40,000 INR
All we know an attractive certification will help you to find a decent job and get a promotion, such as PT0-002日本語. PT0-002日本語 test dump is a kind of certification that you can improve yourself and help you to stand out from other people. If you pass PT0-002日本語 test dump you will have a good reputation and considerable salary and make friends with different successful men in the bright future. CompTIA PenTest+ certification can be used in different IT Company and it will be your access to the IT elites. But you may find that the PT0-002日本語 test dump is difficult for you. You need much time to prepare and the cost of the PT0-002日本語 test dump is high, you wonder it will be a great loss for you when fail the exam. It will be bad thing. Our TestsDumps will help you to reduce the loss and save the money and time for you.
TestsDumps is a one of the CompTIA exam questions providers of PT0-002日本語 test dump in the IT industry that ensure you to pass the PT0-002日本語 test almostly 100%. We have experienced and professional IT experts to create the latest PT0-002日本語 test dump and CompTIA PT0-002日本語 study guide dump which is approach to the real exam questions. We will provide you the accurate PT0-002日本語 test dump questions and PT0-002日本語 practice dump which attach the correct answers and detailed explanation and analysis. You just need to take 20-30 hours to learn the PT0-002日本語 test CompTIA PenTest+ Certification (PT0-002日本語版) dump questions and know it skillfully; you will pass the exam easily. If you get any problems and doubts about PT0-002日本語 test dump questions you can contact our customer service freely and they will solve the problems.
You can download the free demo of PT0-002日本語 test dumps questions before you buy, and you have the right to one-year free update the PT0-002日本語 test dump questions after you pay. And there are three versions for you choose. The PDF version of PT0-002日本語 test dump questions means that you can print it out and practice it on the paper, it is very convenient for people who are not available to the computer. For software version, the most advantage is that you can stimulate the real PT0-002日本語 test dumps scene, you can practice the PT0-002日本語 test dump like the real test and limit your test time so that you can know your shortcoming and improve your ability. But you can only use the software version on the computer. The third version is On-line APP, the function of On-line PT0-002日本語 (CompTIA PenTest+ Certification (PT0-002日本語版)) test dump is same as the software version, the difference between the two versions is that On-line APP can use be all electronic products, such as: iPad, iWatch but the PT0-002日本語 test dump of software version is only used in the computer. So you can choose your best version according to your studying habits.
Our website offers 24/7 customer service assisting to you, in case you may get some problems in the course of learning PT0-002日本語 test dump. And we adheres the principle of No help, Full refund, and you can get your money back when you fail the PT0-002日本語 test dump.
After purchase, Instant Download: Upon successful payment, Our systems will automatically send the product you have purchased to your mailbox by email. (If not received within 12 hours, please contact us. Note: don't forget to check your spam.)
The difficulties you can face while writing the CompTIA PT0-002 Certification Exam
The CompTIA PT0-002 Certification Exam is a tough exam. The difficulties of the CompTIA PT0-002 Certification Exam are as given here. The candidate doesn't know how and from where to start writing the actual CompTIA PT0-002 Certification Exam. The candidate doesn't know what the questions are and how to answer them. Unawareness about the topic of the CompTIA PT0-002 Certification Exam will result in failure. The candidate has to face many problems while writing the PT0-002 Certification Exam. It is difficult to predict the time required to complete the PT0-002 Certification Exam. The CompTIA PT0-002 Certification Exam is written by the expert, and the candidate has to face many difficulties while writing the PT0-002 Certification Exam. The candidates don't know about the resources that they can use to prepare for the CompTIA PT0-002 Certification Exam. If you are facing all these difficulties, keep calm and start reading from the PT0-002 Dumps.