{"product_id":"comptia-pentest-study-guide-9781119823810","title":"CompTIA PenTest Study Guide","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eIntroduction xxxix\u003c\/p\u003e \u003cp\u003eAssessment Test xxv\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 1 Penetration Testing 1\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eWhat Is Penetration Testing? 2\u003c\/p\u003e \u003cp\u003eCybersecurity Goals 2\u003c\/p\u003e \u003cp\u003eAdopting the Hacker Mindset 4\u003c\/p\u003e \u003cp\u003eEthical Hacking 5\u003c\/p\u003e \u003cp\u003eReasons for Penetration Testing 5\u003c\/p\u003e \u003cp\u003eBenefits of Penetration Testing 6\u003c\/p\u003e \u003cp\u003eRegulatory Requirements for Penetration Testing 7\u003c\/p\u003e \u003cp\u003eWho Performs Penetration Tests? 8\u003c\/p\u003e \u003cp\u003eInternal Penetration Testing Teams 8\u003c\/p\u003e \u003cp\u003eExternal Penetration Testing Teams 9\u003c\/p\u003e \u003cp\u003eSelecting Penetration Testing Teams 10\u003c\/p\u003e \u003cp\u003eThe CompTIA Penetration Testing Process 10\u003c\/p\u003e \u003cp\u003ePlanning and Scoping 11\u003c\/p\u003e \u003cp\u003eInformation Gathering and Vulnerability Scanning 11\u003c\/p\u003e \u003cp\u003eAttacks and Exploits 12\u003c\/p\u003e \u003cp\u003eReporting and Communication 13\u003c\/p\u003e \u003cp\u003eTools and Code Analysis 13\u003c\/p\u003e \u003cp\u003eThe Cyber Kill Chain 14\u003c\/p\u003e \u003cp\u003eReconnaissance 15\u003c\/p\u003e \u003cp\u003eWeaponization 16\u003c\/p\u003e \u003cp\u003eDelivery 16\u003c\/p\u003e \u003cp\u003eExploitation 16\u003c\/p\u003e \u003cp\u003eInstallation 16\u003c\/p\u003e \u003cp\u003eCommand and Control 16\u003c\/p\u003e \u003cp\u003eActions on Objectives 17\u003c\/p\u003e \u003cp\u003eTools of the Trade 17\u003c\/p\u003e \u003cp\u003eReconnaissance 20\u003c\/p\u003e \u003cp\u003eVulnerability Scanners 21\u003c\/p\u003e \u003cp\u003eSocial Engineering 21\u003c\/p\u003e \u003cp\u003eCredential Testing Tools 22\u003c\/p\u003e \u003cp\u003eDebuggers and Software Testing Tools 22\u003c\/p\u003e \u003cp\u003eNetwork Testing 23\u003c\/p\u003e \u003cp\u003eRemote Access 23\u003c\/p\u003e \u003cp\u003eExploitation 24\u003c\/p\u003e \u003cp\u003eSteganography 24\u003c\/p\u003e \u003cp\u003eCloud Tools 25\u003c\/p\u003e \u003cp\u003eSummary 25\u003c\/p\u003e \u003cp\u003eExam Essentials 25\u003c\/p\u003e \u003cp\u003eLab Exercises 26\u003c\/p\u003e \u003cp\u003eActivity 1.1: Adopting the Hacker Mindset 26\u003c\/p\u003e \u003cp\u003eActivity 1.2: Using the Cyber Kill Chain 26\u003c\/p\u003e \u003cp\u003eReview Questions 27\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 2 Planning and Scoping Penetration Tests 31\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eScoping and Planning Engagements 34\u003c\/p\u003e \u003cp\u003eAssessment Types 35\u003c\/p\u003e \u003cp\u003eKnown Environments and Unknown Environments 35\u003c\/p\u003e \u003cp\u003eThe Rules of Engagement 37\u003c\/p\u003e \u003cp\u003eScoping Considerations— A Deeper Dive 39\u003c\/p\u003e \u003cp\u003eSupport Resources for Penetration Tests 42\u003c\/p\u003e \u003cp\u003ePenetration Testing Standards and Methodologies 44\u003c\/p\u003e \u003cp\u003eKey Legal Concepts for Penetration Tests 46\u003c\/p\u003e \u003cp\u003eContracts 46\u003c\/p\u003e \u003cp\u003eData Ownership and Retention 47\u003c\/p\u003e \u003cp\u003ePermission to Attack (Authorization) 47\u003c\/p\u003e \u003cp\u003eEnvironmental Differences and Location Restrictions 48\u003c\/p\u003e \u003cp\u003eRegulatory Compliance Considerations 49\u003c\/p\u003e \u003cp\u003eSummary 51\u003c\/p\u003e \u003cp\u003eExam Essentials 52\u003c\/p\u003e \u003cp\u003eLab Exercises 53\u003c\/p\u003e \u003cp\u003eReview Questions 54\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 3 Information Gathering 59\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eFootprinting and Enumeration 63\u003c\/p\u003e \u003cp\u003eOsint 64\u003c\/p\u003e \u003cp\u003eLocation and Organizational Data 65\u003c\/p\u003e \u003cp\u003eInfrastructure and Networks 68\u003c\/p\u003e \u003cp\u003eSecurity Search Engines 74\u003c\/p\u003e \u003cp\u003eGoogle Dorks and Search Engine Techniques 77\u003c\/p\u003e \u003cp\u003ePassword Dumps and Other Breach Data 77\u003c\/p\u003e \u003cp\u003eSource Code Repositories 78\u003c\/p\u003e \u003cp\u003ePassive Enumeration and Cloud Services 78\u003c\/p\u003e \u003cp\u003eActive Reconnaissance and Enumeration 78\u003c\/p\u003e \u003cp\u003eHosts 79\u003c\/p\u003e \u003cp\u003eServices 79\u003c\/p\u003e \u003cp\u003eNetworks, Topologies, and Network Traffic 85\u003c\/p\u003e \u003cp\u003ePacket Crafting and Inspection 88\u003c\/p\u003e \u003cp\u003eEnumeration 90\u003c\/p\u003e \u003cp\u003eInformation Gathering and Code 97\u003c\/p\u003e \u003cp\u003eAvoiding Detection 99\u003c\/p\u003e \u003cp\u003eInformation Gathering and Defenses 99\u003c\/p\u003e \u003cp\u003eDefenses Against Active Reconnaissance 100\u003c\/p\u003e \u003cp\u003ePreventing Passive Information Gathering 100\u003c\/p\u003e \u003cp\u003eSummary 100\u003c\/p\u003e \u003cp\u003eExam Essentials 101\u003c\/p\u003e \u003cp\u003eLab Exercises 102\u003c\/p\u003e \u003cp\u003eActivity 3.1: Manual OSINT Gathering 102\u003c\/p\u003e \u003cp\u003eActivity 3.2: Exploring Shodan 102\u003c\/p\u003e \u003cp\u003eActivity 3.3: Running an Nmap Scan 103\u003c\/p\u003e \u003cp\u003eReview Questions 104\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 4 Vulnerability Scanning 109\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIdentifying Vulnerability Management Requirements 112\u003c\/p\u003e \u003cp\u003eRegulatory Environment 112\u003c\/p\u003e \u003cp\u003eCorporate Policy 116\u003c\/p\u003e \u003cp\u003eSupport for Penetration Testing 116\u003c\/p\u003e \u003cp\u003eIdentifying Scan Targets 117\u003c\/p\u003e \u003cp\u003eDetermining Scan Frequency 118\u003c\/p\u003e \u003cp\u003eActive vs. Passive Scanning 120\u003c\/p\u003e \u003cp\u003eConfiguring and Executing Vulnerability Scans 121\u003c\/p\u003e \u003cp\u003eScoping Vulnerability Scans 121\u003c\/p\u003e \u003cp\u003eConfiguring Vulnerability Scans 122\u003c\/p\u003e \u003cp\u003eScanner Maintenance 129\u003c\/p\u003e \u003cp\u003eSoftware Security Testing 131\u003c\/p\u003e \u003cp\u003eAnalyzing and Testing Code 131\u003c\/p\u003e \u003cp\u003eWeb Application Vulnerability Scanning 133\u003c\/p\u003e \u003cp\u003eDeveloping a Remediation Workflow 138\u003c\/p\u003e \u003cp\u003ePrioritizing Remediation 140\u003c\/p\u003e \u003cp\u003eTesting and Implementing Fixes 141\u003c\/p\u003e \u003cp\u003eOvercoming Barriers to Vulnerability Scanning 141\u003c\/p\u003e \u003cp\u003eSummary 143\u003c\/p\u003e \u003cp\u003eExam Essentials 143\u003c\/p\u003e \u003cp\u003eLab Exercises 144\u003c\/p\u003e \u003cp\u003eActivity 4.1: Installing a Vulnerability Scanner 144\u003c\/p\u003e \u003cp\u003eActivity 4.2: Running a Vulnerability Scan 145\u003c\/p\u003e \u003cp\u003eActivity 4.3: Developing a Penetration Test Vulnerability Scanning Plan 145\u003c\/p\u003e \u003cp\u003eReview Questions 146\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 5 Analyzing Vulnerability Scans 151\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eReviewing and Interpreting Scan Reports 152\u003c\/p\u003e \u003cp\u003eUnderstanding CVSS 156\u003c\/p\u003e \u003cp\u003eValidating Scan Results 162\u003c\/p\u003e \u003cp\u003eFalse Positives 162\u003c\/p\u003e \u003cp\u003eDocumented Exceptions 162\u003c\/p\u003e \u003cp\u003eUnderstanding Informational Results 163\u003c\/p\u003e \u003cp\u003eReconciling Scan Results with Other Data Sources 164\u003c\/p\u003e \u003cp\u003eTrend Analysis 164\u003c\/p\u003e \u003cp\u003eCommon Vulnerabilities 165\u003c\/p\u003e \u003cp\u003eServer and Endpoint Vulnerabilities 166\u003c\/p\u003e \u003cp\u003eNetwork Vulnerabilities 175\u003c\/p\u003e \u003cp\u003eVirtualization Vulnerabilities 181\u003c\/p\u003e \u003cp\u003eInternet of Things (IoT) 183\u003c\/p\u003e \u003cp\u003eWeb Application Vulnerabilities 184\u003c\/p\u003e \u003cp\u003eSummary 186\u003c\/p\u003e \u003cp\u003eExam Essentials 187\u003c\/p\u003e \u003cp\u003eLab Exercises 188\u003c\/p\u003e \u003cp\u003eActivity 5.1: Interpreting a Vulnerability Scan 188\u003c\/p\u003e \u003cp\u003eActivity 5.2: Analyzing a CVSS Vector 188\u003c\/p\u003e \u003cp\u003eActivity 5.3: Developing a Penetration Testing Plan 189\u003c\/p\u003e \u003cp\u003eReview Questions 190\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 6 Exploiting and Pivoting 195\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eExploits and Attacks 198\u003c\/p\u003e \u003cp\u003eChoosing Targets 198\u003c\/p\u003e \u003cp\u003eEnumeration 199\u003c\/p\u003e \u003cp\u003eIdentifying the Right Exploit 201\u003c\/p\u003e \u003cp\u003eExploit Resources 204\u003c\/p\u003e \u003cp\u003eExploitation Toolkits 206\u003c\/p\u003e \u003cp\u003eMetasploit 206\u003c\/p\u003e \u003cp\u003ePowerSploit 212\u003c\/p\u003e \u003cp\u003eBloodHound 213\u003c\/p\u003e \u003cp\u003eExploit Specifics 213\u003c\/p\u003e \u003cp\u003eRpc\/dcom 213\u003c\/p\u003e \u003cp\u003ePsExec 214\u003c\/p\u003e \u003cp\u003ePS Remoting\/WinRM 214\u003c\/p\u003e \u003cp\u003eWmi 214\u003c\/p\u003e \u003cp\u003eFileless Malware and Living Off the Land 215\u003c\/p\u003e \u003cp\u003eScheduled Tasks and cron Jobs 216\u003c\/p\u003e \u003cp\u003eSmb 217\u003c\/p\u003e \u003cp\u003eDns 219\u003c\/p\u003e \u003cp\u003eRdp 220\u003c\/p\u003e \u003cp\u003eApple Remote Desktop 220\u003c\/p\u003e \u003cp\u003eVnc 220\u003c\/p\u003e \u003cp\u003eSsh 220\u003c\/p\u003e \u003cp\u003eNetwork Segmentation Testing and Exploits 221\u003c\/p\u003e \u003cp\u003eLeaked Keys 222\u003c\/p\u003e \u003cp\u003eLeveraging Exploits 222\u003c\/p\u003e \u003cp\u003eCommon Post- Exploit Attacks 222\u003c\/p\u003e \u003cp\u003eCross Compiling 225\u003c\/p\u003e \u003cp\u003ePrivilege Escalation 226\u003c\/p\u003e \u003cp\u003eSocial Engineering 226\u003c\/p\u003e \u003cp\u003eEscaping and Upgrading Limited Shells 227\u003c\/p\u003e \u003cp\u003ePersistence and Evasion 228\u003c\/p\u003e \u003cp\u003eScheduled Jobs and Scheduled Tasks 228\u003c\/p\u003e \u003cp\u003eInetd Modification 228\u003c\/p\u003e \u003cp\u003eDaemons and Services 229\u003c\/p\u003e \u003cp\u003eBackdoors and Trojans 229\u003c\/p\u003e \u003cp\u003eData Exfiltration and Covert Channels 230\u003c\/p\u003e \u003cp\u003eNew Users 230\u003c\/p\u003e \u003cp\u003ePivoting 231\u003c\/p\u003e \u003cp\u003eCovering Your Tracks 232\u003c\/p\u003e \u003cp\u003eSummary 233\u003c\/p\u003e \u003cp\u003eExam Essentials 234\u003c\/p\u003e \u003cp\u003eLab Exercises 235\u003c\/p\u003e \u003cp\u003eActivity 6.1: Exploit 235\u003c\/p\u003e \u003cp\u003eActivity 6.2: Discovery 235\u003c\/p\u003e \u003cp\u003eActivity 6.3: Pivot 236\u003c\/p\u003e \u003cp\u003eReview Questions 237\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 7 Exploiting Network Vulnerabilities 243\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIdentifying Exploits 247\u003c\/p\u003e \u003cp\u003eConducting Network Exploits 247\u003c\/p\u003e \u003cp\u003eVLAN Hopping 247\u003c\/p\u003e \u003cp\u003eDNS Cache Poisoning 249\u003c\/p\u003e \u003cp\u003eOn- Path Attacks 251\u003c\/p\u003e \u003cp\u003eNAC Bypass 254\u003c\/p\u003e \u003cp\u003eDoS Attacks and Stress Testing 255\u003c\/p\u003e \u003cp\u003eExploit Chaining 257\u003c\/p\u003e \u003cp\u003eExploiting Windows Services 257\u003c\/p\u003e \u003cp\u003eNetBIOS Name Resolution Exploits 257\u003c\/p\u003e \u003cp\u003eSMB Exploits 261\u003c\/p\u003e \u003cp\u003eIdentifying and Exploiting Common Services 261\u003c\/p\u003e \u003cp\u003eIdentifying and Attacking Service Targets 262\u003c\/p\u003e \u003cp\u003eSNMP Exploits 263\u003c\/p\u003e \u003cp\u003eSMTP Exploits 264\u003c\/p\u003e \u003cp\u003eFTP Exploits 265\u003c\/p\u003e \u003cp\u003eKerberoasting 266\u003c\/p\u003e \u003cp\u003eSamba Exploits 267\u003c\/p\u003e \u003cp\u003ePassword Attacks 268\u003c\/p\u003e \u003cp\u003eStress Testing for Availability 269\u003c\/p\u003e \u003cp\u003eWireless Exploits 269\u003c\/p\u003e \u003cp\u003eAttack Methods 269\u003c\/p\u003e \u003cp\u003eFinding Targets 270\u003c\/p\u003e \u003cp\u003eAttacking Captive Portals 270\u003c\/p\u003e \u003cp\u003eEavesdropping, Evil Twins, and Wireless On- Path Attacks 271\u003c\/p\u003e \u003cp\u003eOther Wireless Protocols and Systems 275\u003c\/p\u003e \u003cp\u003eRFID Cloning 276\u003c\/p\u003e \u003cp\u003eJamming 277\u003c\/p\u003e \u003cp\u003eRepeating 277\u003c\/p\u003e \u003cp\u003eSummary 278\u003c\/p\u003e \u003cp\u003eExam Essentials 279\u003c\/p\u003e \u003cp\u003eLab Exercises 279\u003c\/p\u003e \u003cp\u003eActivity 7.1: Capturing Hashes 279\u003c\/p\u003e \u003cp\u003eActivity 7.2: Brute- Forcing Services 280\u003c\/p\u003e \u003cp\u003eActivity 7.3: Wireless Testing 281\u003c\/p\u003e \u003cp\u003eReview Questions 282\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 8 Exploiting Physical and Social Vulnerabilities 287\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003ePhysical Facility Penetration Testing 290\u003c\/p\u003e \u003cp\u003eEntering Facilities 290\u003c\/p\u003e \u003cp\u003eInformation Gathering 294\u003c\/p\u003e \u003cp\u003eSocial Engineering 294\u003c\/p\u003e \u003cp\u003eIn- Person Social Engineering 295\u003c\/p\u003e \u003cp\u003ePhishing Attacks 297\u003c\/p\u003e \u003cp\u003eWebsite- Based Attacks 298\u003c\/p\u003e \u003cp\u003eUsing Social Engineering Tools 298\u003c\/p\u003e \u003cp\u003eSummary 302\u003c\/p\u003e \u003cp\u003eExam Essentials 303\u003c\/p\u003e \u003cp\u003eLab Exercises 303\u003c\/p\u003e \u003cp\u003eActivity 8.1: Designing a Physical Penetration Test 303\u003c\/p\u003e \u003cp\u003eActivity 8.2: Brute- Forcing Services 304\u003c\/p\u003e \u003cp\u003eActivity 8.3: Using BeEF 305\u003c\/p\u003e \u003cp\u003eReview Questions 306\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 9 Exploiting Application Vulnerabilities 311\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eExploiting Injection Vulnerabilities 314\u003c\/p\u003e \u003cp\u003eInput Validation 314\u003c\/p\u003e \u003cp\u003eWeb Application Firewalls 315\u003c\/p\u003e \u003cp\u003eSQL Injection Attacks 316\u003c\/p\u003e \u003cp\u003eCode Injection Attacks 319\u003c\/p\u003e \u003cp\u003eCommand Injection Attacks 319\u003c\/p\u003e \u003cp\u003eLDAP Injection Attacks 320\u003c\/p\u003e \u003cp\u003eExploiting Authentication Vulnerabilities 320\u003c\/p\u003e \u003cp\u003ePassword Authentication 321\u003c\/p\u003e \u003cp\u003eSession Attacks 322\u003c\/p\u003e \u003cp\u003eKerberos Exploits 326\u003c\/p\u003e \u003cp\u003eExploiting Authorization Vulnerabilities 327\u003c\/p\u003e \u003cp\u003eInsecure Direct Object References 327\u003c\/p\u003e \u003cp\u003eDirectory Traversal 328\u003c\/p\u003e \u003cp\u003eFile Inclusion 330\u003c\/p\u003e \u003cp\u003ePrivilege Escalation 331\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 10 Exploiting Web Application Vulnerabilities 331\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eCross- Site Scripting (XSS) 331\u003c\/p\u003e \u003cp\u003eRequest Forgery 334\u003c\/p\u003e \u003cp\u003eClickjacking 335\u003c\/p\u003e \u003cp\u003eUnsecure Coding Practices 335\u003c\/p\u003e \u003cp\u003eSource Code Comments 335\u003c\/p\u003e \u003cp\u003eError Handling 336\u003c\/p\u003e \u003cp\u003eHard- Coded Credentials 336\u003c\/p\u003e \u003cp\u003eRace Conditions 337\u003c\/p\u003e \u003cp\u003eUnprotected APIs 337\u003c\/p\u003e \u003cp\u003eUnsigned Code 338\u003c\/p\u003e \u003cp\u003eSteganography 340\u003c\/p\u003e \u003cp\u003eApplication Testing Tools 341\u003c\/p\u003e \u003cp\u003eStatic Application Security Testing (SAST) 341\u003c\/p\u003e \u003cp\u003eDynamic Application Security Testing (DAST) 342\u003c\/p\u003e \u003cp\u003eMobile Tools 346\u003c\/p\u003e \u003cp\u003eSummary 346\u003c\/p\u003e \u003cp\u003eExam Essentials 347\u003c\/p\u003e \u003cp\u003eLab Exercises 347\u003c\/p\u003e \u003cp\u003eActivity 9.1: Application Security Testing Techniques 347\u003c\/p\u003e \u003cp\u003eActivity 9.2: Using the ZAP Proxy 348\u003c\/p\u003e \u003cp\u003eActivity 9.3: Creating a Cross- Site Scripting Vulnerability 348\u003c\/p\u003e \u003cp\u003eReview Questions 349\u003c\/p\u003e \u003cp\u003eAttacking Hosts, Cloud Technologies, and Specialized Systems 355\u003c\/p\u003e \u003cp\u003eAttacking Hosts 360\u003c\/p\u003e \u003cp\u003eLinux 361\u003c\/p\u003e \u003cp\u003eWindows 365\u003c\/p\u003e \u003cp\u003eCross- Platform Exploits 367\u003c\/p\u003e \u003cp\u003eCredential Attacks and Testing Tools 368\u003c\/p\u003e \u003cp\u003eCredential Acquisition 368\u003c\/p\u003e \u003cp\u003eOffline Password Cracking 369\u003c\/p\u003e \u003cp\u003eCredential Testing and Brute- Forcing Tools 371\u003c\/p\u003e \u003cp\u003eWordlists and Dictionaries 371\u003c\/p\u003e \u003cp\u003eRemote Access 372\u003c\/p\u003e \u003cp\u003eSsh 372\u003c\/p\u003e \u003cp\u003eNETCAT and Ncat 373\u003c\/p\u003e \u003cp\u003eMetasploit and Remote Access 373\u003c\/p\u003e \u003cp\u003eProxies and Proxychains 374\u003c\/p\u003e \u003cp\u003eAttacking Virtual Machines and Containers 374\u003c\/p\u003e \u003cp\u003eVirtual Machine Attacks 375\u003c\/p\u003e \u003cp\u003eContainerization Attacks 377\u003c\/p\u003e \u003cp\u003eAttacking Cloud Technologies 379\u003c\/p\u003e \u003cp\u003eAttacking Cloud Accounts 379\u003c\/p\u003e \u003cp\u003eAttacking and Using Misconfigured Cloud Assets 380\u003c\/p\u003e \u003cp\u003eOther Cloud Attacks 382\u003c\/p\u003e \u003cp\u003eTools for Cloud Technology Attacks 383\u003c\/p\u003e \u003cp\u003eAttacking Mobile Devices 384\u003c\/p\u003e \u003cp\u003eAttacking IoT, ICS, Embedded Systems, and SCADA Devices 389\u003c\/p\u003e \u003cp\u003eAttacking Data Storage 392\u003c\/p\u003e \u003cp\u003eSummary 393\u003c\/p\u003e \u003cp\u003eExam Essentials 395\u003c\/p\u003e \u003cp\u003eLab Exercises 396\u003c\/p\u003e \u003cp\u003eActivity 10.1: Dumping and Cracking the Windows SAM and Other Credentials 396\u003c\/p\u003e \u003cp\u003eActivity 10.2: Cracking Passwords Using Hashcat 397\u003c\/p\u003e \u003cp\u003eActivity 10.3: Setting Up a Reverse Shell and a Bind Shell 398\u003c\/p\u003e \u003cp\u003eReview Questions 400\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 11 Reporting and Communication 405\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eThe Importance of Communication 409\u003c\/p\u003e \u003cp\u003eDefining a Communication Path 409\u003c\/p\u003e \u003cp\u003eCommunication Triggers 410\u003c\/p\u003e \u003cp\u003eGoal Reprioritization 410\u003c\/p\u003e \u003cp\u003eRecommending Mitigation Strategies 411\u003c\/p\u003e \u003cp\u003eFinding: Shared Local Administrator Credentials 412\u003c\/p\u003e \u003cp\u003eFinding: Weak Password Complexity 413\u003c\/p\u003e \u003cp\u003eFinding: Plaintext Passwords 414\u003c\/p\u003e \u003cp\u003eFinding: No Multifactor Authentication 414\u003c\/p\u003e \u003cp\u003eFinding: SQL Injection 416\u003c\/p\u003e \u003cp\u003eFinding: Unnecessary Open Services 416\u003c\/p\u003e \u003cp\u003eWriting a Penetration Testing Report 416\u003c\/p\u003e \u003cp\u003eStructuring the Written Report 417\u003c\/p\u003e \u003cp\u003eSecure Handling and Disposition of Reports 420\u003c\/p\u003e \u003cp\u003eWrapping Up the Engagement 421\u003c\/p\u003e \u003cp\u003ePost- Engagement Cleanup 421\u003c\/p\u003e \u003cp\u003eClient Acceptance 421\u003c\/p\u003e \u003cp\u003eLessons Learned 421\u003c\/p\u003e \u003cp\u003eFollow- Up Actions\/Retesting 422\u003c\/p\u003e \u003cp\u003eAttestation of Findings 422\u003c\/p\u003e \u003cp\u003eRetention and Destruction of Data 422\u003c\/p\u003e \u003cp\u003eSummary 423\u003c\/p\u003e \u003cp\u003eExam Essentials 423\u003c\/p\u003e \u003cp\u003eLab Exercises 424\u003c\/p\u003e \u003cp\u003eActivity 11.1: Remediation Strategies 424\u003c\/p\u003e \u003cp\u003eActivity 11.2: Report Writing 424\u003c\/p\u003e \u003cp\u003eReview Questions 425\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 12 Scripting for Penetration Testing 429\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eScripting and Penetration Testing 431\u003c\/p\u003e \u003cp\u003eBash 432\u003c\/p\u003e \u003cp\u003ePowerShell 433\u003c\/p\u003e \u003cp\u003eRuby 434\u003c\/p\u003e \u003cp\u003ePython 435\u003c\/p\u003e \u003cp\u003ePerl 435\u003c\/p\u003e \u003cp\u003eJavaScript 436\u003c\/p\u003e \u003cp\u003eVariables, Arrays, and Substitutions 438\u003c\/p\u003e \u003cp\u003eBash 439\u003c\/p\u003e \u003cp\u003ePowerShell 440\u003c\/p\u003e \u003cp\u003eRuby 441\u003c\/p\u003e \u003cp\u003ePython 441\u003c\/p\u003e \u003cp\u003ePerl 442\u003c\/p\u003e \u003cp\u003eJavaScript 442\u003c\/p\u003e \u003cp\u003eComparison Operations 444\u003c\/p\u003e \u003cp\u003eString Operations 445\u003c\/p\u003e \u003cp\u003eBash 446\u003c\/p\u003e \u003cp\u003ePowerShell 447\u003c\/p\u003e \u003cp\u003eRuby 448\u003c\/p\u003e \u003cp\u003ePython 449\u003c\/p\u003e \u003cp\u003ePerl 450\u003c\/p\u003e \u003cp\u003eJavaScript 451\u003c\/p\u003e \u003cp\u003eFlow Control 452\u003c\/p\u003e \u003cp\u003eConditional Execution 453\u003c\/p\u003e \u003cp\u003efor Loops 458\u003ci\u003e \u003c\/i\u003e\u003c\/p\u003e \u003cp\u003ewhile Loops 465\u003c\/p\u003e \u003cp\u003eInput and Output (I\/O) 471\u003c\/p\u003e \u003cp\u003eRedirecting Standard Input and Output 471\u003c\/p\u003e \u003cp\u003eComma- Separated Values (CSV) 472\u003c\/p\u003e \u003cp\u003eError Handling 472\u003c\/p\u003e \u003cp\u003eBash 472\u003c\/p\u003e \u003cp\u003ePowerShell 473\u003c\/p\u003e \u003cp\u003eRuby 473\u003c\/p\u003e \u003cp\u003ePython 473\u003c\/p\u003e \u003cp\u003eAdvanced Data Structures 474\u003c\/p\u003e \u003cp\u003eJavaScript Object Notation (JSON) 474\u003c\/p\u003e \u003cp\u003eTrees 475\u003c\/p\u003e \u003cp\u003eReusing Code 475\u003c\/p\u003e \u003cp\u003eThe Role of Coding in Penetration Testing 476\u003c\/p\u003e \u003cp\u003eAnalyzing Exploit Code 476\u003c\/p\u003e \u003cp\u003eAutomating Penetration Tests 477\u003c\/p\u003e \u003cp\u003eSummary 477\u003c\/p\u003e \u003cp\u003eExam Essentials 477\u003c\/p\u003e \u003cp\u003eLab Exercises 478\u003c\/p\u003e \u003cp\u003eActivity 12.1: Reverse DNS Lookups 478\u003c\/p\u003e \u003cp\u003eActivity 12.2: Nmap Scan 479\u003c\/p\u003e \u003cp\u003eReview Questions 480\u003c\/p\u003e \u003cp\u003e\u003cb\u003eAppendix A Answers to Review Questions 485\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eChapter 1: Penetration Testing 486\u003c\/p\u003e \u003cp\u003eChapter 2: Planning and Scoping Penetration Tests 487\u003c\/p\u003e \u003cp\u003eChapter 3: Information Gathering 489\u003c\/p\u003e \u003cp\u003eChapter 4: Vulnerability Scanning 491\u003c\/p\u003e \u003cp\u003eChapter 5: Analyzing Vulnerability Scans 493\u003c\/p\u003e \u003cp\u003eChapter 6: Exploiting and Pivoting 495\u003c\/p\u003e \u003cp\u003eChapter 7: Exploiting Network Vulnerabilities 497\u003c\/p\u003e \u003cp\u003eChapter 8: Exploiting Physical and Social Vulnerabilities 499\u003c\/p\u003e \u003cp\u003eChapter 9: Exploiting Application Vulnerabilities 501\u003c\/p\u003e \u003cp\u003eChapter 10: Attacking Hosts, Cloud Technologies, and Specialized Systems 503\u003c\/p\u003e \u003cp\u003eChapter 11: Reporting and Communication 505\u003c\/p\u003e \u003cp\u003eChapter 12: Scripting for Penetration Testing 506\u003c\/p\u003e \u003cp\u003eAppendix B Solution to Lab Exercise 509\u003c\/p\u003e \u003cp\u003eSolution to Activity 5.2: Analyzing a CVSS Vector 510\u003c\/p\u003e \u003cp\u003eIndex 511 \u003c\/p\u003e","brand":"John Wiley \u0026 Sons Inc","offers":[{"title":"Default Title","offer_id":49407163498839,"sku":"9781119823810","price":43.35,"currency_code":"GBP","in_stock":false}],"url":"https:\/\/bookcurl.com\/products\/comptia-pentest-study-guide-9781119823810","provider":"Book Curl","version":"1.0","type":"link"}