Skip to main content
Course

Penetration Testing Foundations

Think like an attacker. Test like a professional.

Intermediate

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

9 hours

Estimated time

What you will be able to do

  • Explain the full penetration testing lifecycle and describe where recognized standards such as the Penetration Testing Execution Standard (PTES) and National Institute of Standards and Technology (NIST) Special Publication 800-115 fit within it.
  • Recommend the right kind of assessment for a client's goal by explaining how a vulnerability scan, a penetration test, and a red team engagement differ.
  • Confirm that an engagement is properly authorized by reviewing contracts, signed authorization letters, and the laws that govern computer access, including the Computer Fraud and Abuse Act (CFAA).
  • Turn a client conversation into a written scope and rules of engagement document that sets clear boundaries, testing windows, and escalation contacts.
  • Profile a target using passive and active reconnaissance, including Open Source Intelligence (OSINT) and footprinting techniques.
  • Run network scans that reveal live hosts, open ports, and running services, and interpret the results without disrupting the target.
  • Enumerate services to map the attack surface, confirm findings, and rate their severity with the Common Vulnerability Scoring System (CVSS).
  • Write a clear penetration test report with an executive summary, supporting evidence, fair risk ratings, and practical remediation advice.

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    The Penetration Testing Lifecycle

    Before you touch a single tool, you need to know how a real engagement is put together and why. This module walks you through the complete penetration testing lifecycle and the industry standards that shape it, so you can speak the language of the trade with confidence. You will also learn how a penetration test differs from a simple vulnerability scan and from a full red team exercise.

    2 lessons · 5 quiz questions

  2. 02

    Authorization, Ethics, and Scope

    Authorized testing is what separates a professional from a criminal, so this module puts the paperwork and the ethics first. You will learn how to confirm you truly have permission to test, how to stay inside the law, and how to turn a client conversation into a written scope and rules of engagement. Getting this stage right protects your client, your employer, and you.

    2 lessons · 5 quiz questions · assignment

  3. 03

    Reconnaissance and Scanning

    Every strong engagement begins with patient information gathering. In this module you gather intelligence on a target the way an attacker would, moving from quiet open source research to active network scanning. By the end you can build an accurate map of live hosts, open ports, and running services before you probe any deeper.

    2 lessons · 5 quiz questions

  4. 04

    Enumeration, Safe Execution, and Reporting

    This is where raw scan data becomes verified, real findings. You will enumerate services in depth to confirm what is genuinely exposed, learn to test safely so you never harm a client's systems, and turn your evidence into a report people will actually act on. A clear report with fair, well-reasoned risk ratings is the product your client is paying for.

    2 lessons · 5 quiz questions · assignment