CompTIA PT0-003 시험요강:
| 주제 | 소개 |
|---|
| 주제 1 | - Reconnaissance and Enumeration: This topic focuses on applying information gathering and enumeration techniques. Cybersecurity analysts will learn how to modify scripts for reconnaissance and enumeration purposes. They will also understand which tools to use for these stages, essential for gathering crucial information before performing deeper penetration tests.
|
| 주제 2 | - Engagement Management: In this topic, cybersecurity analysts learn about pre-engagement activities, collaboration, and communication in a penetration testing environment. The topic covers testing frameworks, methodologies, and penetration test reports. It also explains how to analyze findings and recommend remediation effectively within reports, crucial for real-world testing scenarios.
|
| 주제 3 | - Post-exploitation and Lateral Movement: Cybersecurity analysts will gain skills in establishing and maintaining persistence within a system. This topic also covers lateral movement within an environment and introduces concepts of staging and exfiltration. Lastly, it highlights cleanup and restoration activities, ensuring analysts understand the post-exploitation phase’s responsibilities.
|
| 주제 4 | - Attacks and Exploits: This extensive topic trains cybersecurity analysts to analyze data and prioritize attacks. Analysts will learn how to conduct network, authentication, host-based, web application, cloud, wireless, and social engineering attacks using appropriate tools. Understanding specialized systems and automating attacks with scripting will also be emphasized.
|
| 주제 5 | - Vulnerability Discovery and Analysis: In this section, cybersecurity analysts will learn various techniques to discover vulnerabilities. Analysts will also analyze data from reconnaissance, scanning, and enumeration phases to identify threats. Additionally, it covers physical security concepts, enabling analysts to understand security gaps beyond just the digital landscape.
|
참조: https://comptiacdn.azureedge.net/webcontent/docs/default-source/exam-objectives/comptia-pentest-pt0-003-exam-objectives-(3-0).pdf?sfvrsn=ea1da72b_2
CompTIA PT0-003 시험 개요:
| 인증 벤더: | CompTIA |
| 시험명: | CompTIA PenTest+ |
| 시험 번호: | PT0-003 |
| 지원 언어: | 일본어, 프랑스어, 포르투갈어, 영어 |
| 실제 시험 문항 수: | 최대 90문항 |
| 합격 점수: | 750 (100-900 척도 기준) |
| 응시료: | $439 USD |
| 시험 시간: | 165분 |
| 시험 형식: | 객관식, 성과 기반 문항 |
| 관련 자격증: | CompTIA CySA+ CompTIA Security+ |
| 자격증 유효 기간: | 3년 |
| 샘플 문제: | CompTIA PT0-003 샘플 문제 |
| 응시 방법: | 온라인 감독 시험 또는 Pearson VUE 시험 센터에서의 대면 시험. |
| 전제 조건: | 정식 선행 조건은 없습니다. Network+ 및 Security+ 수준의 지식을 갖춘 상태에서 3-4년의 실무 침투 테스트 경험 또는 이에 상응하는 사이버보안 경험을 권장합니다. |
| 공식 요강 URL: | https://www.comptia.org/en-us/certifications/pentest/ |