Looking for your active Pro access before showing Course Notes. This usually takes just a moment.
Course Notes preview
Unlock Pro for the full per-exam reference guide.
Preview one piece from each section. Pro includes every Course Notes section, summary, key point, common mistake, exam tip, related-question review, and PDF export.
Includes full Course Mode and Course Notes.
Section 11. Engagement Management (13%)Preview
More in this section
13 more key points in Pro version
9 more common mistakes in Pro version
9 more exam tips in Pro version
23 more related questions in Pro version
Summary
This section covers 1. Engagement Management (13%). It covers the critical requirement of obtaining written authorization before initiating any intrusive testing activities. It covers understanding how to manage the defined scope of a penetration test, specifically recognizing and respecting exclusions, even when technical pathways exist. It covers ensuring testing activities align with applicable laws, regulations, and contractual obligations. Across the section, identify the trigger fact before applying the specific rule or procedure tested.
Key Points
Written Authorization: The foundational requirement for commencing any intrusive testing
Common Mistakes
Technical Reach vs. Authorization: Simply reaching a target does not grant permission to perform intrusive activities. Authorization is the prerequisite
Exam Tips
Always prioritize verifying written authorization before proceeding with any testing activity
Section 22. Reconnaissance and Enumeration (21%)Preview
More in this section
13 more key points in Pro version
9 more common mistakes in Pro version
9 more exam tips in Pro version
39 more related questions in Pro version
Summary
This section covers 2. Reconnaissance and Enumeration (21%). It covers the initial information gathering phase of a penetration test, differentiating between passive and active reconnaissance techniques. It covers leveraging public records to identify potential targets during reconnaissance. It covers leveraging DNS and registration data to identify potential targets and vulnerabilities during reconnaissance. Across the section, identify the trigger fact before applying the specific rule or procedure tested.
Key Points
Passive Reconnaissance: Gathering information without direct interaction, reducing the risk of detection
Common Mistakes
Passive vs. Active: Passive reconnaissance minimizes observable interaction, while active reconnaissance directly probes systems, increasing the risk of detection
Exam Tips
Understand the ROE: The rules of engagement are paramount. Failure to adhere to them can invalidate the entire test
Section 33. Vulnerability Discovery and Analysis (17%)Preview
More in this section
13 more key points in Pro version
9 more common mistakes in Pro version
9 more exam tips in Pro version
31 more related questions in Pro version
Summary
This section covers 3. Vulnerability Discovery and Analysis (17%). It covers the appropriate use of authenticated and unauthenticated scanning techniques. It covers the critical process of validating findings generated by automated scanning tools. It covers leveraging CVSS scores effectively by recognizing their limitations and incorporating organizational-specific factors for accurate risk assessment. Across the section, identify the trigger fact before applying the specific rule or procedure tested.
Key Points
Credential privilege should be limited to the assessment need
Common Mistakes
Authenticated scanning provides granular insights into local systems, while unauthenticated scanning offers a broader external view
Exam Tips
When presented with access options, prioritize authenticated scanning for detailed configuration and patch verification
Section 44. Attacks and Exploits (35%)Preview
More in this section
13 more key points in Pro version
8 more common mistakes in Pro version
8 more exam tips in Pro version
67 more related questions in Pro version
Summary
This section covers 4. Attacks and Exploits (35%). It covers differentiating between password spraying and brute force attacks, understanding their distinct methodologies. Credential stuffing attacks leverage previously compromised credentials to gain unauthorized access to other services. It covers the authorized offline testing of password verifiers to determine their vulnerability without impacting live systems. Across the section, identify the trigger fact before applying the specific rule or procedure tested.
Key Points
Password spraying attempts to evade lockout triggers by distributing a small number of common passwords across multiple accounts
Common Mistakes
Password spraying distributes a small number of passwords across many accounts to avoid lockout triggers, whereas brute force focuses on many guesses against a single account
Exam Tips
Focus on the distribution of login attempts. A wide spread suggests spraying
Section 55. Post-exploitation and Lateral Movement (14%)Preview
More in this section
13 more key points in Pro version
9 more common mistakes in Pro version
9 more exam tips in Pro version
25 more related questions in Pro version
Summary
This section covers 5. Post-exploitation and Lateral Movement (14%). Perform bounded privilege escalation. It covers the critical task of handling evidence generated during credential dumping engagements. It covers selecting a suitable method for lateral movement within the approved target environment, emphasizing the importance of network reachability, valid credentials, and platform compatibility. Across the section, identify the trigger fact before applying the specific rule or procedure tested.
Key Points
Privilege escalation paths (local/cloud)
Common Mistakes
Privilege escalation vs. Reconnaissance: Reconnaissance gathers information; privilege escalation *uses* that information to elevate access
Exam Tips
Focus on demonstrating the *path* to escalation, not just achieving it
Search catalog
Find a practice exam
Flexible search understands AI-901, ai901, ai 901, 901, ai, network plus, and saa c03.