dc dotCreds
Reference guide

PenTest+ PT0-003 Course Notes

Study PenTest+ PT0-003 section notes, then jump straight into the guided course or related practice questions without losing your place.

Continue CourseStart PracticePDF downloads available in Pro.
Checking access

Checking Pro access...

Looking for your active Pro access before showing Course Notes. This usually takes just a moment.

Course Notes preview

Unlock Pro for the full per-exam reference guide.

Preview one piece from each section. Pro includes every Course Notes section, summary, key point, common mistake, exam tip, related-question review, and PDF export.

Includes full Course Mode and Course Notes.

Section 11. Engagement Management (13%)Preview
More in this section
  • 13 more key points in Pro version
  • 9 more common mistakes in Pro version
  • 9 more exam tips in Pro version
  • 23 more related questions in Pro version

Summary

This section covers 1. Engagement Management (13%). It covers the critical requirement of obtaining written authorization before initiating any intrusive testing activities. It covers understanding how to manage the defined scope of a penetration test, specifically recognizing and respecting exclusions, even when technical pathways exist. It covers ensuring testing activities align with applicable laws, regulations, and contractual obligations. Across the section, identify the trigger fact before applying the specific rule or procedure tested.

Key Points

  • Written Authorization: The foundational requirement for commencing any intrusive testing

Common Mistakes

  • Technical Reach vs. Authorization: Simply reaching a target does not grant permission to perform intrusive activities. Authorization is the prerequisite

Exam Tips

  • Always prioritize verifying written authorization before proceeding with any testing activity
Section 22. Reconnaissance and Enumeration (21%)Preview
More in this section
  • 13 more key points in Pro version
  • 9 more common mistakes in Pro version
  • 9 more exam tips in Pro version
  • 39 more related questions in Pro version

Summary

This section covers 2. Reconnaissance and Enumeration (21%). It covers the initial information gathering phase of a penetration test, differentiating between passive and active reconnaissance techniques. It covers leveraging public records to identify potential targets during reconnaissance. It covers leveraging DNS and registration data to identify potential targets and vulnerabilities during reconnaissance. Across the section, identify the trigger fact before applying the specific rule or procedure tested.

Key Points

  • Passive Reconnaissance: Gathering information without direct interaction, reducing the risk of detection

Common Mistakes

  • Passive vs. Active: Passive reconnaissance minimizes observable interaction, while active reconnaissance directly probes systems, increasing the risk of detection

Exam Tips

  • Understand the ROE: The rules of engagement are paramount. Failure to adhere to them can invalidate the entire test
Section 33. Vulnerability Discovery and Analysis (17%)Preview
More in this section
  • 13 more key points in Pro version
  • 9 more common mistakes in Pro version
  • 9 more exam tips in Pro version
  • 31 more related questions in Pro version

Summary

This section covers 3. Vulnerability Discovery and Analysis (17%). It covers the appropriate use of authenticated and unauthenticated scanning techniques. It covers the critical process of validating findings generated by automated scanning tools. It covers leveraging CVSS scores effectively by recognizing their limitations and incorporating organizational-specific factors for accurate risk assessment. Across the section, identify the trigger fact before applying the specific rule or procedure tested.

Key Points

  • Credential privilege should be limited to the assessment need

Common Mistakes

  • Authenticated scanning provides granular insights into local systems, while unauthenticated scanning offers a broader external view

Exam Tips

  • When presented with access options, prioritize authenticated scanning for detailed configuration and patch verification
Section 44. Attacks and Exploits (35%)Preview
More in this section
  • 13 more key points in Pro version
  • 8 more common mistakes in Pro version
  • 8 more exam tips in Pro version
  • 67 more related questions in Pro version

Summary

This section covers 4. Attacks and Exploits (35%). It covers differentiating between password spraying and brute force attacks, understanding their distinct methodologies. Credential stuffing attacks leverage previously compromised credentials to gain unauthorized access to other services. It covers the authorized offline testing of password verifiers to determine their vulnerability without impacting live systems. Across the section, identify the trigger fact before applying the specific rule or procedure tested.

Key Points

  • Password spraying attempts to evade lockout triggers by distributing a small number of common passwords across multiple accounts

Common Mistakes

  • Password spraying distributes a small number of passwords across many accounts to avoid lockout triggers, whereas brute force focuses on many guesses against a single account

Exam Tips

  • Focus on the distribution of login attempts. A wide spread suggests spraying
Section 55. Post-exploitation and Lateral Movement (14%)Preview
More in this section
  • 13 more key points in Pro version
  • 9 more common mistakes in Pro version
  • 9 more exam tips in Pro version
  • 25 more related questions in Pro version

Summary

This section covers 5. Post-exploitation and Lateral Movement (14%). Perform bounded privilege escalation. It covers the critical task of handling evidence generated during credential dumping engagements. It covers selecting a suitable method for lateral movement within the approved target environment, emphasizing the importance of network reachability, valid credentials, and platform compatibility. Across the section, identify the trigger fact before applying the specific rule or procedure tested.

Key Points

  • Privilege escalation paths (local/cloud)

Common Mistakes

  • Privilege escalation vs. Reconnaissance: Reconnaissance gathers information; privilege escalation *uses* that information to elevate access

Exam Tips

  • Focus on demonstrating the *path* to escalation, not just achieving it