Lab 2.1: Penetration Testing Techniques

CompTIA Security+ Module 02

Overview

This module gave me a practical foundation in penetration testing by connecting reconnaissance, testing scope, testing types, and reporting into one workflow. I learned how ethical testers assess targets, identify attack paths, and document findings in a way that supports business decisions and defensive improvement.

What I Learned

Testing Types

Blackbox, whitebox, and graybox testing, plus how each one changes what the tester knows, what they target, and how closely the test mirrors a real attack.

Testing Workflow

Discovery, enumeration, vulnerability mapping, exploitation, and reporting, with an emphasis on how each phase builds on the last to create a useful assessment.

Reconnaissance

The difference between active and passive recon, including footprinting, OSINT, banner grabbing, scanning, and stealthier information gathering methods.

Testing Roles

How blue, red, white, and purple teams support realistic testing, oversight, and defense-focused validation in a professional environment.

Tools, Methods, and Testing Types

Recon and Scanning Tools

  • Nmap, Superscan, and Hping for port and service discovery
  • Xprobe2, Queso, p0f, Httprint, Amap, and Winfingerprint for fingerprinting
  • Nessus, BurpSuite, Acunetix, SQLMap, and Vega for vulnerability analysis

Core Techniques

  • Lateral movement, privilege escalation, pivoting, and persistence
  • Bug bounty fundamentals and cleanup after testing
  • Rules of engagement, scope control, and responsible reporting

Recon Methods

  • Active recon with ping, traceroute, and web scanning
  • Passive recon with OSINT, subdomains, and external sites
  • War-driving, war-flying, and drone/UAV awareness

Exercise Summary

Exercise 1: Pen Testing Basics

I learned how penetration testing differs from a vulnerability assessment and why a structured process matters for proving risk and documenting findings.

Exercise 2: Rules of Engagement

I reviewed scope, contacts, timing, sensitive data handling, and target limits so the assessment stays controlled and professional.

Exercise 3: Testing Techniques

I studied lateral movement, privilege escalation, persistence, pivoting, bug bounty concepts, and cleanup to understand the lifecycle of a test.

Exercise 4: Reconnaissance

I learned when to use active vs. passive recon and how OSINT and footprinting help identify likely attack vectors before exploitation begins.

Exercise 5: Active Recon Assessment

I connected the theory to the toolset and saw how targeted testing turns raw data into meaningful findings for defenders and decision-makers.

How This Advanced My Cybersecurity Learning

Professional Scope Control

I learned that a strong assessment is not just about tools; it is about boundaries, timing, authorization, and clear reporting.

Technical Breadth

The module helped me connect scanning, fingerprinting, vulnerability discovery, and recon into one repeatable methodology.

Defensive Insight

I now understand how attackers think during recon and how defenders can limit exposure, detect probing, and prioritize remediation.

Professional Value

  • Recruiter-ready structure: This project shows that I can explain scope, process, tooling, and findings in a clear and organized way.
  • Hands-on assessment mindset: I learned how active and passive methods fit together when building a complete test plan.
  • Tool awareness: I gained exposure to scanners, fingerprinting tools, and web vulnerability tools commonly used in real assessments.
  • Ethical testing habits: The module reinforced why authorization, cleanup, and reporting are part of the job, not optional extras.

Security+ Alignment

This lab supports Security+ Objective 1.8 by reinforcing the techniques used in penetration testing and the assessment workflow behind them.

Testing Types

  • Blackbox, whitebox, and graybox testing
  • Scope-driven and knowledge-driven planning
  • Authorization-aware assessments

Methods

  • Active and passive reconnaissance
  • Footprinting and OSINT
  • Lateral movement and privilege escalation

Tools

  • Nmap, Nessus, and BurpSuite
  • Fingerprinting utilities and web scanners
  • SQLMap, Acunetix, and Vega
← Back to Portfolio