CompTIA PT0-003 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|
| トピック 1 | - Engagement Management: In this topic, cybersecurity analysts learn about pre-engagement activities, collaboration, and communication in a penetration testing environment. The topic covers testing frameworks, methodologies, and penetration test reports. It also explains how to analyze findings and recommend remediation effectively within reports, crucial for real-world testing scenarios.
|
| トピック 2 | - Vulnerability Discovery and Analysis: In this section, cybersecurity analysts will learn various techniques to discover vulnerabilities. Analysts will also analyze data from reconnaissance, scanning, and enumeration phases to identify threats. Additionally, it covers physical security concepts, enabling analysts to understand security gaps beyond just the digital landscape.
|
| トピック 3 | - Attacks and Exploits: This extensive topic trains cybersecurity analysts to analyze data and prioritize attacks. Analysts will learn how to conduct network, authentication, host-based, web application, cloud, wireless, and social engineering attacks using appropriate tools. Understanding specialized systems and automating attacks with scripting will also be emphasized.
|
| トピック 4 | - Reconnaissance and Enumeration: This topic focuses on applying information gathering and enumeration techniques. Cybersecurity analysts will learn how to modify scripts for reconnaissance and enumeration purposes. They will also understand which tools to use for these stages, essential for gathering crucial information before performing deeper penetration tests.
|
| トピック 5 | - Post-exploitation and Lateral Movement: Cybersecurity analysts will gain skills in establishing and maintaining persistence within a system. This topic also covers lateral movement within an environment and introduces concepts of staging and exfiltration. Lastly, it highlights cleanup and restoration activities, ensuring analysts understand the post-exploitation phase’s responsibilities.
|
参照:https://comptiacdn.azureedge.net/webcontent/docs/default-source/exam-objectives/comptia-pentest-pt0-003-exam-objectives-(3-0).pdf?sfvrsn=ea1da72b_2
CompTIA PT0-003 試験概要:
| 認定ベンダー: | CompTIA |
| 試験名: | CompTIA PenTest+ |
| 試験番号: | PT0-003 |
| 受験料: | $439 USD |
| 出題数: | 最大90問 |
| 試験形式: | 多肢選択式, パフォーマンスベースの問題 |
| 認定の有効期間: | 3年 |
| 関連資格: | CompTIA Security+ CompTIA CySA+ |
| 合格点: | 750(100-900の尺度) |
| 対応言語: | 英語, フランス語, 日本語, ポルトガル語 |
| 試験時間: | 165 minutes |
| サンプル問題: | CompTIA PT0-003 サンプル問題 |
| 受験方法: | オンライン監督試験またはPearson VUE試験センターでの対面試験。 |
| 前提条件: | 正式な前提条件はありません。Network+およびSecurity+レベルの知識を備えた、3〜4年の実践的なペネトレーションテスト、または同等のサイバーセキュリティ経験が推奨されます。 |
| 公式シラバスのURL: | https://www.comptia.org/en-us/certifications/pentest/ |