
Certified Penetration Testing Professional (CPENT) Exam Guide
Rahul Deshmukh
This audiobook is narrated by a digital voice.
DESCRIPTION
There has been a rise in demand for cybersecurity professionals who can identify vulnerabilities proactively in applications and infrastructure and offer their skills and expertise in the...
Location:
United States
Description:
This audiobook is narrated by a digital voice. DESCRIPTION There has been a rise in demand for cybersecurity professionals who can identify vulnerabilities proactively in applications and infrastructure and offer their skills and expertise in the form of remedial actions to plug these vulnerabilities. CPENT is one such examination testing the skills and expertise of a penetration testing professional and offers a global, coveted certification to those who clear this examination. This guide walks you through each CPENT domain in a sequential and easy-to-understand format. You will begin with learning how to plan for the exam and prepare your system environment. It then covers critical techniques like Open-Source Intelligence (OSINT), social engineering attacks, vulnerability scanning, and tool usage. You will also explore advanced topics such as privilege escalation, binary exploitation, malware detection, and post-exploitation strategies. The book also teaches you how to document and submit professional pentest reports and includes realistic mock exams to prepare you for the real test environment. By the end of this book, you will have the skills to perform penetration testing, gather intelligence from various sources, perform social engineering penetration testing, perform penetration testing on IoT, wireless, cloud based systems, advanced exploitation techniques and various tools and techniques to be used for penetration testing. WHAT YOU WILL LEARN ● Learning different modules to prepare for the CPENT exam. ● Pre-requisites for system and CPENT exam preparation. ● Understanding and learning tools and techniques for penetration testing. ● Learning about the Cyber Kill Chain process. ● Conducting penetration testing on network and web applications. ● Penetration testing methods for IoT, SCADA, cloud assets, and various strategies. ● Drafting and submitting a report for certification. Duration - 14h 38m. Author - Rahul Deshmukh. Narrator - Digital Voice Madison G. Published Date - Friday, 31 January 2025. Copyright - © 2026 BPB ©.
Language:
English
Title Page
Duration:00:00:20
Copyright Page
Duration:00:01:21
Dedication Page
Duration:00:00:07
About the Author
Duration:00:01:57
About the Reviewer
Duration:00:01:26
Acknowledgement
Duration:00:01:27
Preface
Duration:00:17:16
Table of Contents
Duration:00:23:07
1. CPENT Module Mastery
Duration:00:00:05
Introduction
Duration:00:00:48
Structure
Duration:00:00:20
Objectives
Duration:00:00:28
Basic fundamental knowledge
Duration:00:01:44
Vulnerabilities
Duration:00:00:42
Impact of vulnerabilities on systems and organizations
Duration:00:02:12
The Cyber Kill Chain® process
Duration:00:04:48
Penetration testing
Duration:00:00:47
Different penetration testing techniques
Duration:00:01:31
Tools and techniques in penetration testing
Duration:00:00:59
Difference between penetration testing and ethical hacking
Duration:00:01:54
Certified Penetration Testing Professional exam
Duration:00:01:00
Why should you attempt the CPENT exam
Duration:00:00:47
How to prepare yourself for CPENT
Duration:00:01:37
Modules in CPENT
Duration:00:02:10
Targeted learning for Module 1
Duration:00:04:22
Installing and using Wireshark
Duration:00:04:46
Installing and using Nmap
Duration:00:14:01
Conclusion
Duration:00:00:38
Exercises
Duration:00:00:29
Questions
Duration:00:00:24
2. System Requirements, Pre-requisites, Do’s and Don’ts
Duration:00:00:05
Jargon to be familiar with
Duration:00:02:37
Different attack types
Duration:00:00:49
Eavesdropping attacks
Duration:00:02:04
Phishing attacks
Duration:00:01:09
Spear-phishing attacks
Duration:00:00:57
Whale-phishing attacks
Duration:00:00:59
DoS and DDoS attacks
Duration:00:02:34
MITM attacks
Duration:00:00:48
Session hijacking
Duration:00:00:55
Password attack
Duration:00:02:40
Brute force attack
Duration:00:01:57
Ransomware
Duration:00:01:35
URL interpretation
Duration:00:01:13
Malware attack
Duration:00:01:06
DNS spoofing
Duration:00:01:04
SQL injection attack
Duration:00:01:27
Web application attacks
Duration:00:01:00
Cross-site scripting attacks
Duration:00:01:36
Cross-site request forgery attack
Duration:00:01:19
Clickjacking attacks
Duration:00:00:53
Insider threats
Duration:00:01:51
Trojan horses
Duration:00:00:49
Types of penetration testing
Duration:00:07:26
White, black, and grey box pen testing
Duration:00:02:37
Phases of penetration testing
Duration:00:01:59
Resources to practice penetration testing
Duration:00:04:58
Eligibility criteria
Duration:00:00:35
CPENT
Duration:00:00:45
Pre-requisites
Duration:00:01:22
System requirements
Duration:00:01:40
Do’s and don’ts during your CPENT exam
Duration:00:03:58
Mapping attack surface during exam
Duration:00:01:29
Next steps
Duration:00:00:36
Reporting
Duration:00:00:28
3. Penetration Testing Network and Web Applications
Duration:00:00:05
Gathering information on assets
Duration:00:06:52
Vulnerability assessment of applications
Duration:00:04:42
Penetration testing infrastructure
Duration:00:01:27
External network penetration testing
Duration:00:00:32
Performing external penetration testing
Duration:00:01:36
Port scanning
Duration:00:01:23
OS and service fingerprinting
Duration:00:01:06
Vulnerability research
Duration:00:00:55
Exploitation of vulnerabilities
Duration:00:01:22
Internal network penetration testing
Duration:00:02:09
Footprinting
Duration:00:00:59
Windows exploitation
Duration:00:02:02
Making the executable FUD
Duration:00:00:24
Install and run Shellter
Duration:00:02:11
Executing the payload
Duration:00:01:02
Privilege escalation
Duration:00:01:56
Persistence
Duration:00:05:04
Automation of internal network penetration testing
Duration:00:00:37
Post exploitation
Duration:00:00:40
Perimeter devices network penetration testing
Duration:00:00:59
Assessing firewall security implementation
Duration:00:01:39
4. Open-source Intelligence for Penetration Testing
Duration:00:00:05
Introduction to the OSINT framework
Duration:00:01:37
Gathering and analyzing the intelligence
Duration:00:02:18
Using OSINT in penetration testing
Duration:00:02:37
Five steps of OSINT
Duration:00:03:57
OSINT tools for penetration testing
Duration:00:01:10
OSINT framework
Duration:00:00:28
SecurityTrails API
Duration:00:00:53
SpiderFoot
Duration:00:00:47
CheckUserNames
Duration:00:00:46
Google Dorks
Duration:00:01:45
HaveIbeenPwned
Duration:00:01:19
Maltego
Duration:00:00:38
Recon-ng
Duration:00:01:07
Censys
Duration:00:00:45
Shodan
Duration:00:00:41
Wappalyzer
Duration:00:00:43
theHarvester
Duration:00:00:34
Creepy
Duration:00:00:34
Unicornscan
Duration:00:00:41
Jigsaw
Duration:00:00:44
Nmap
Duration:00:01:28
IVRE
Duration:00:01:02
FOCA
Duration:00:00:49
WebShag
Duration:00:01:00
ZoomEye
Duration:00:01:27
Fierce
Duration:00:00:42
ExifTool
Duration:00:00:57
OWASP Amass
Duration:00:00:43
Metagoofil
Duration:00:01:16
OpenVAS
Duration:00:00:58
5. Social Engineering Penetration Testing
Duration:00:00:05
Social engineering
Duration:00:00:34
Methods of social engineering attacks
Duration:00:04:54
Measures to counter social engineering attacks
Duration:00:12:02
Responsibilities of users
Duration:00:03:45
Hackers’ tactics, techniques, and methods
Duration:00:01:45
Social engineering lifecycle
Duration:00:00:49
Baiting and quid pro quo attacks
Duration:00:00:34
Pretexting
Duration:00:00:40
Impersonation and tailgating
Duration:00:01:12
Real-world case studies
Duration:00:02:02
Social engineering in the corporate environment
Duration:00:03:21
Red team social engineering practices
Duration:00:01:34
Future of social engineering
Duration:00:00:40
Penetration testing associated with social engineering
Duration:00:00:15
Introduction to social engineering penetration testing
Duration:00:05:03
Social engineering pen testing using email vector
Duration:00:00:14
Overview of email-based social engineering pen testing
Duration:00:04:11
Social engineering pen testing using telephone vector
Duration:00:00:14
Understanding vishing as a penetration testing vector
Duration:00:04:18
Social engineering pen testing using physical vector
Duration:00:00:14
Introduction to physical social engineering pen tests
Duration:00:04:59
Analyzing real-world cases of social engineering
Duration:00:00:11
Case study, The Twitter 2020 hack
Duration:00:01:36
Case study, RSA SecureID breach (2011)
Duration:00:01:40
Case study, Target data breach (2013)
Duration:00:02:05
Integrating social engineering into penetration testing
Duration:00:00:15
Why social engineering matters
Duration:00:00:33
Phases of penetration testing with social engineering integration
Duration:00:04:04
6. IoT, Wireless, OT, and SCADA Penetration Testing
Duration:00:00:06
Introduction to Internet of Things
Duration:00:03:52
IoT attacks and threats
Duration:00:23:28
IoT penetration testing
Duration:00:07:20
Step-by-step firmware analysis with Binwalk
Duration:00:04:07
Wireless local area network penetration testing
Duration:00:03:29
RFID penetration testing
Duration:00:00:32
Understanding RFID technology
Duration:00:01:15
Techniques of hacking RFID
Duration:00:01:13
Common types of RFID attacks
Duration:00:01:05
Consequences of RFID hacking
Duration:00:01:24
Key principles to protect RFID
Duration:00:00:20
Importance of encryption in RFID security
Duration:00:00:53
Authentication in RFID protection
Duration:00:00:50
RFID hacking and penetration testing overview
Duration:00:05:37
NFC penetration testing
Duration:00:00:41
Working of NFC
Duration:00:01:54
Top 10 NFC security risks
Duration:00:00:31
Penetration testing of NFC
Duration:00:02:56
OT/SCADA concepts
Duration:00:00:48
Overview of OT
Duration:00:03:46
SCADA in industrial operations
Duration:00:00:30
Cybersecurity risks across OT, ICS, and SCADA
Duration:00:01:14
Unique security challenges in SCADA systems
Duration:00:01:20
Security in integrated OT/ICS environments
Duration:00:01:35
SCADA security architecture
Duration:00:01:00
Modbus
Duration:00:01:15
Layers of the Modbus protocol
Duration:00:00:42
Protocol data unit
Duration:00:00:59
Data model of Modbus and accessing data
Duration:00:00:47
Application data unit
Duration:00:00:29
Common features
Duration:00:00:37
Modbus protocol messaging structure
Duration:00:00:39
The request
Duration:00:00:38
The response
Duration:00:00:41
ASCII mode
Duration:00:00:38
RTU mode
Duration:00:00:26
Coding system
Duration:00:01:12
RTU framing
Duration:00:01:41
Address field
Duration:00:00:16
Function field
Duration:00:01:16
Contents of the error checking field
Duration:00:11:38
ICS and SCADA penetration testing
Duration:00:00:42
ICS/SCADA penetration testing
Duration:00:01:54
Additional ICS/SCADA testing resources
Duration:00:02:22
Benefits of ICS/SCADA security testing
Duration:00:01:25
Analyzing the Modbus traffic using Wireshark
Duration:00:00:55
Introduction to Wireshark
Duration:00:00:47
Network example
Duration:00:00:27
Modbus RTU capture extension for Wireshark
Duration:00:01:03
Wireshark COM port setup
Duration:00:01:31
Wireshark capture
Duration:00:00:57
Wireshark capture save
Duration:00:00:22