← All courses

Start here

Penetration Testing Foundations

Build your cybersecurity skills through guided lessons, practical investigation and evidence-based reporting.

Read the course outline and practice options below. Your enrolled course keeps its assigned version.

Begin with the BEST B-CID method, then investigate networks and web applications within an authorized scope. Compare observations, test secure controls and document what the evidence supports. Practice combines lessons, supplied-record worksheets, local simulations and assigned isolated labs; availability varies by activity.

Start Foundations training — sign in with existing access. Starting module: administrative orientation. This public overview does not show personalized progress.

Who this course is for

Beginners exploring ethical hacking, penetration testing or web application testing, and defenders who want to understand how offensive observations inform defensive work.

Before you begin

Be comfortable opening web pages, managing files and reading short instructions. No prior penetration testing experience is required. Use only assigned targets and fictional accounts; introductory network and browser concepts are taught in the course.

Your learning roadmap

  1. Overview — audience, prerequisites and course scope on this page.
  2. Visual roadmap — the enrolled course shows version-bound lesson and practice links.
  3. Diagnostic — orientation locates the initial skills questions and recommended pathway; recommendations are not demonstrated skill.
  4. B-CID introduction — Baseline, Change, Compare, Interpret, Document is the first instructional method.
  5. Lab readiness — read workstation preparation and each assigned guide before practice. A guide does not launch a lab; unavailable runtimes remain unavailable.
  6. Lessons and guided labs — learn the concept, read a worked example, practice and deliberately save evidence in your notebook.
  7. Independent assessment — separate preparation; independent assessment is not currently open. No tutor, hints or AI/RAG (Artificial Intelligence/Retrieval-Augmented Generation) assistance during an attempt.
  8. Targeted remediation — the enrolled skills profile and pathway identify next practice; guided work does not establish independent mastery.

Use this outline to plan your learning. Sign in with existing course access to open lessons; this public page does not start a diagnostic, lab or assessment. Test deliberately. Interpret carefully. Document what you can prove.

What you will practice

  • Define an authorized scope and apply B-CID to an investigation.
  • Distinguish reachability, port state and observed service behavior from assumptions.
  • Interpret requests, sessions and common web trust boundaries using positive and negative controls.
  • Write reproducible evidence notes with limitations, remediation and retest steps.

Topics in learning order

View syllabus: Penetration Testing Foundations for module outcomes, equipment and assessment information. The complete HTML syllabus is readable without sign-in; an untagged PDF preview is available below.

Administrative orientation comes first. BEST B-CID is the first instructional module and guides the comparisons and reports throughout the course.

1. Orientation4 topics · Starting module
  • Learner journey
  • Authorization and scope
  • Lab safety
  • Assessment orientation
2. BEST B-CID Method5 topics
  • Baseline
  • Change
  • Compare
  • Interpret
  • Document
3. Penetration Testing Methodology3 topics
  • NIST SP 800-115
  • PTES
  • MITRE ATT&CK as a reference model
4. Network Foundations10 topics
  • TCP/IP
  • IP addressing
  • Routing
  • TCP/UDP
  • Common services and ports
  • DNS
  • HTTP/HTTPS
  • SSH
  • SMB
  • Open/closed/filtered
5. Reconnaissance & Enumeration6 topics
  • Host discovery
  • Port enumeration
  • Service identification
  • DNS enumeration
  • HTTP discovery
  • Nmap workflows
6. Web Application Foundations11 topics
  • HTTP requests/responses
  • Methods
  • Headers
  • Parameters
  • Cookies
  • Sessions
  • Authentication
  • Client vs server
  • HTML/JavaScript basics
  • Browser DevTools
  • Proxy concepts
7. Common Web Vulnerabilities8 topics
  • SQL injection
  • Reflected XSS
  • Stored XSS
  • Command injection
  • File inclusion/path behavior
  • Authentication weaknesses
  • Session weaknesses
  • Redirects
8. Evidence & Reporting8 topics
  • Observation vs finding
  • Evidence vs inference
  • Reproducibility
  • Limitations
  • Technical evidence notes
  • Severity concepts
  • Remediation
  • Technical vs executive reporting
9. Integrated Guided Pentest6 topics
  • Authorized fictional scope
  • Network discovery
  • Service analysis
  • Web investigation
  • Evidence collection
  • Structured report
10. Independent Skills Assessment3 topics
  • Transfer to an unfamiliar scenario
  • Finding, component/module, evidence
  • Skills results and recommended remediation

How practice works

Self-paced text lessons and formative checks, staged practice and evidence reporting. Supplied records and simulations are preparation, not verified live observations. Independent assessment uses separate unfamiliar materials and excludes AI/RAG assistance.

Check each guide’s availability before starting. Some activities use supplied records or simulations; a worksheet or saved draft does not establish independent practical skill.

Practice only within the authorization and scope supplied by the assigned guide. Supplied records and simulations do not prove live competency. Independent preparation materials are inactive and ungraded; saving them does not submit an assessment.

Complete practice inventory and availability

Hands-on labs and practice

The syllabus is public. Course lessons and practice materials require enrollment or an authorized access entitlement.

The list distinguishes guides, supplied-record exercises and simulations from available lab execution. Training links require sign-in and existing access; opening a guide starts no lab.

  • How a web request works

    Compare public products and identify request paths, parameters and responses.

    Type: Assigned-lab browser guide
    Availability: Guide available; use only the Harbor lab already assigned to your account. Reading the guide does not start a lab.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: B-CID, HTTP and browser tools

    Topic: Web Application Foundations · Access practice - enrollment required: How a web request works

  • Who may read this order?

    Compare fictional order access with a server ownership control.

    Type: Assigned-lab scenario
    Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: Request basics and authentication

    Topic: Common Web Vulnerabilities · Access practice - enrollment required: Who may read this order?

  • Where may a manual reader look?

    Compare fictional file disclosure with a root-confined reader.

    Type: Virtual-file simulation
    Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: Request basics and file boundaries

    Topic: Common Web Vulnerabilities · Access practice - enrollment required: Where may a manual reader look?

  • Customer versus staff access

    Compare navigation visibility with enforced role permissions.

    Type: Form-session simulation
    Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: Request basics and authentication

    Topic: Common Web Vulnerabilities · Access practice - enrollment required: Customer versus staff access

  • What does an error reveal?

    Compare controlled technical detail with a generic error.

    Type: Fixed-response simulation
    Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: Request basics and file boundaries

    Topic: Common Web Vulnerabilities · Access practice - enrollment required: What does an error reveal?

  • Who asked to change delivery?

    Compare unwanted preference updates with token controls and repeated state reads.

    Type: Supplied-record rehearsal and browser preparation
    Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: Request basics and cookies

    Topic: Common Web Vulnerabilities · Access practice - enrollment required: Who asked to change delivery?

  • What did the attachment check?

    Compare file labels, inert text validation and safe retrieval.

    Type: Non-executable attachment experiment
    Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: Request basics and browser tools

    Topic: Common Web Vulnerabilities · Access practice - enrollment required: What did the attachment check?

  • Does logout end the session?

    Compare login messages and retained-session access after logout.

    Type: Form-session simulation
    Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: Request basics and authentication

    Topic: Web Application Foundations · Access practice - enrollment required: Does logout end the session?

  • Who calculates the cart total?

    Compare a display preview with a server-stored fictional receipt.

    Type: Fictional cart simulation
    Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: Request basics

    Topic: Common Web Vulnerabilities · Access practice - enrollment required: Who calculates the cart total?

  • Did an extra command run?

    Compare a harmless fixed-program marker with literal and unavailable controls.

    Type: Fixed-program simulation
    Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: Request basics and command boundaries

    Topic: Common Web Vulnerabilities · Access practice - enrollment required: Did an extra command run?

  • Owned network service discovery

    Distinguish reachability, port state, silence and observed service identity.

    Type: Supplied-record rehearsal and workstation preparation
    Availability: Supplied-record rehearsal available; managed network execution Coming soon. Interpret the provided records without scanning a target.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: B-CID, addressing and transport

    Topic: Reconnaissance & Enumeration · Access practice - enrollment required: Owned network service discovery

  • Returns workflow: fix and retest

    Connect order ownership and price evidence; compare repairs and restore.

    Type: Supplied-record rehearsal and workflow simulation
    Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: Order and cart practice

    Topic: Integrated Guided Pentest · Access practice - enrollment required: Returns workflow: fix and retest

  • Campus paths and permissions

    Diagnose route/firewall faults with administrator tickets; keep tester rights and application permissions separate.

    Type: Socket-free configuration simulation and supplied records
    Availability: Local simulation, saved copies and reports available; real campus network Coming soon.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: Addressing, routing and introductory service discovery

    Topic: Network Foundations · Access practice - enrollment required: Campus paths and permissions

  • Cookies and login sessions

    Compare preferences, header direction, login/logout and cookie-flag limitations.

    Type: Supplied-record rehearsal and browser preparation
    Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: HTTP, browser tools and sessions

    Topic: Web Application Foundations · Access practice - enrollment required: Cookies and login sessions

  • Catalog query investigation

    Compare query behavior and document SQL-injection evidence.

    Type: Existing assigned Harbor lab
    Availability: Assigned-lab practice requires existing access and an assigned Harbor environment. Follow its scope and setup instructions; this page allocates no lab.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: B-CID, HTTP and relevant SQL/XSS lessons

    Topic: Common Web Vulnerabilities · Access practice - enrollment required: Catalog query investigation

  • Project-note investigation

    Compare stored note behavior with a safe rendering control.

    Type: Existing assigned Harbor lab
    Availability: Assigned-lab practice requires existing access and an assigned Harbor environment. Follow its scope and setup instructions; this page allocates no lab.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: B-CID, HTTP and relevant SQL/XSS lessons

    Topic: Common Web Vulnerabilities · Access practice - enrollment required: Project-note investigation

  • Command investigation

    Run fixed authored programs in a disposable directory and retain controls and cleanup.

    Type: Local workstation activity
    Availability: Local materials available; no managed lab is started.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: Command boundaries and safe workstation preparation

    Topic: Common Web Vulnerabilities · Access practice - enrollment required: Command investigation

  • File investigation

    Compare fictional file reads, disclosure and confined controls.

    Type: Local workstation activity
    Availability: Local materials available; no host-file targets or managed lab.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: File boundaries and safe workstation preparation

    Topic: Common Web Vulnerabilities · Access practice - enrollment required: File investigation

  • Network workstation investigation

    Prepare bounded TCP/UDP comparisons and retain original exports.

    Type: Local workstation activity
    Availability: Materials available; socket execution requires a separately authorized isolated host. Without one, use supplied records and do not run network probes.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: Addressing, transport and approved disposable scope

    Topic: Network Foundations · Access practice - enrollment required: Network workstation investigation

  • Willow / Maple investigation

    Combine supplied observations and write a bounded evidence report.

    Type: Supplied-record worksheet
    Availability: Preparation available and ungraded; not live execution.

    Learning format: Guided, Semi-guided and Blind preparation; Document
    Before you begin: Introductory lessons and evidence reporting

    Topic: Integrated Guided Pentest · Access practice - enrollment required: Willow / Maple investigation

  • Assigned guided engagement

    Investigate only the isolated environment assigned to your account.

    Type: Existing assigned live lab
    Availability: Existing entry requirements apply; no lab allocated by this inventory. Expanded scenarios are not automatically enabled.

    Learning format: Guided investigation and Document
    Before you begin: Existing orientation, diagnostic and guided-entry requirements

    Topic: Integrated Guided Pentest · Access practice - enrollment required: Assigned guided engagement

Independent assessment is separate

Juniper preparation and frozen handover materials are inactive and ungraded. They are not practice labs or an active independent assessment sitting. Independent assessment is not currently open. Artificial Intelligence (AI) and Retrieval-Augmented Generation (RAG) assistance, tutor help and hints are excluded during independent assessment. No activity listed here certifies mastery.

Career paths and workforce alignment

Connect course practice with selected tasks in the National Initiative for Cybersecurity Education (NICE) framework. These examples cover vulnerability identification, remediation advice and reporting. They are partial preparation, not a test of career suitability or qualification for a complete work role.

Source: NICE components 2.2.0, checked 2026-10-04.

Vulnerability Analysis (PD-WRL-007)

NICE category: PROTECTION and DEFENSE (PD). Everyday career names can span several work roles; this selected task mapping does not define a complete career path.

Read the official NIST NICE components and version information. View the official NICE 2.2.0 source data (JSON).

T1118: Identify vulnerabilities — Practiced in preparation

Course outcome: Compare suspected web, command and file weaknesses with secure controls; distinguish service observations and session behavior from proven vulnerabilities.

Relevant lessons: Apply BEST B-CID; Separate observations, inferences, and findings; Build a bounded SQL injection evidence comparison; Separate TCP and UDP observations; Corroborate service names and version evidence; Bound a command-injection conclusion to its observed effect; Separate path traversal, file disclosure, and inclusion claims; Observe cookie and session lifecycle.

Practice and availability:

  • Search reflection investigation (HARBOR-SEARCH): Existing assigned Harbor lab. Assigned-lab practice requires existing access and an assigned Harbor environment. Follow its scope and setup instructions; this page allocates no lab.
  • Who may read this order? (FND-LAB-02): Assigned-lab scenario. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
  • Network workstation investigation (LOCAL-NETWORK): Local workstation activity. Materials available; socket execution requires a separately authorized isolated host. Without one, use supplied records and do not run network probes.
  • Command investigation (LOCAL-COMMAND): Local workstation activity. Local materials available; no managed lab is started.
  • File investigation (LOCAL-FILE): Local workstation activity. Local materials available; no host-file targets or managed lab.
  • Cookies and login sessions (FND-LAB-14): Supplied-record rehearsal and browser preparation. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.

Evidence offered: B-CID comparisons, fixed command/file programs and staged session records rehearse narrow claims. The network workbook practices corroboration and ambiguous-response interpretation; an open port or timeout is not itself a vulnerability. Current practice availability is listed separately.

Remaining gap: No accepted enterprise vulnerability program, broad scanner coverage or independent live transfer is established. Supplied records and host-gated network materials do not establish learner execution; browser session effects need actual browser evidence.

Optional practice questions: Use these with the named course activities when available. Keep your writing in your existing notebook or a local draft; this public page saves nothing.

  • Network workstation investigation (LOCAL-NETWORK): Compare one permitted service over TCP and UDP. What replied, what stayed silent, and which application observation supports the service name?
    Keep the claim bounded: Use supplied records if an authorized socket host is unavailable. Label their source; silence does not prove absence and a port number does not prove service identity.
  • Command investigation (LOCAL-COMMAND): Compare the ordinary input, harmless marker and literal-argument control. Which observed effect supports a command-boundary conclusion?
    Keep the claim bounded: Use only the fixed disposable scenario. Error text alone is not execution; do not test other hosts or add outbound callbacks.
  • Cookies and login sessions (FND-LAB-14): Compare login, logout and later access. Which record shows the server decision, and what do the cookie flags tell you?
    Keep the claim bounded: Separate browser sending rules from application access. Supplied headers are rehearsal; flags alone do not prove that logout invalidated a session.

Assessment: Not independently assessed. Course artifacts and saved writing do not prove learner competence.

T1119: Recommend vulnerability remediation strategies — Practiced in preparation

Course outcome: Explain a boundary repair and define positive and negative retest criteria without expanding configuration authority.

Relevant lessons: Turn findings into a useful report; Define remediation and retest acceptance criteria; Separate path traversal, file disclosure, and inclusion claims; Read subnets, gateways, and routes.

Practice and availability:

  • Command investigation (LOCAL-COMMAND): Local workstation activity. Local materials available; no managed lab is started.
  • File investigation (LOCAL-FILE): Local workstation activity. Local materials available; no host-file targets or managed lab.
  • Where may a manual reader look? (FND-LAB-03): Virtual-file simulation. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
  • Returns workflow: fix and retest (FND-LAB-12): Supplied-record rehearsal and workflow simulation. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
  • Campus paths and permissions (FND-LAB-13): Socket-free configuration simulation and supplied records. Local simulation, saved copies and reports available; real campus network Coming soon.

Evidence offered: Fixed command/file controls, product-manual comparisons and the guided integration workflow support repair and retest planning. Campus simulation adds narrow administrator-ticket changes, unrelated-path denial and restoration; network permission remains separate from application ownership.

Remaining gap: This practice does not establish independently demonstrated skill or verified live-system performance.

Optional practice questions: Use these with the named course activities when available. Keep your writing in your existing notebook or a local draft; this public page saves nothing.

  • File investigation (LOCAL-FILE): Write a retest that allows the intended manual and denies an outside-root fictional file. What evidence distinguishes disclosure from inclusion?
    Keep the claim bounded: Keep tests inside the disposable file activity. A filename or denied request does not prove disclosed content or executable inclusion.
  • Campus paths and permissions (FND-LAB-13): For an administrator ticket, predict one narrow route or firewall change, a permitted check, an unrelated denied check and restoration. How would a tester without that ticket proceed?
    Keep the claim bounded: Use the socket-free model as simulation. Do not change real routes or firewalls; reachability does not grant payroll or grades access.

Assessment: Not independently assessed. Course artifacts and saved writing do not prove learner competence.

T1279: Prepare audit reports — Practiced in preparation

Course outcome: Write technical and executive accounts with scope, reproducible evidence and limitations.

Relevant lessons: Write a reproducible and appropriately redacted evidence note; Write technical and executive accounts of the same finding; Explain severity, confidence, and remediation priority; Rehearse a scoped multi-service network investigation.

Practice and availability:

  • Willow / Maple investigation (WILLOW-MAPLE): Supplied-record worksheet. Preparation available and ungraded; not live execution.
  • Network workstation investigation (LOCAL-NETWORK): Local workstation activity. Materials available; socket execution requires a separately authorized isolated host. Without one, use supplied records and do not run network probes.
  • Campus paths and permissions (FND-LAB-13): Socket-free configuration simulation and supplied records. Local simulation, saved copies and reports available; real campus network Coming soon.

Evidence offered: Willow/Maple supplied-record reporting, the network evidence workbook and campus simulation reports practice source references, audience-aware claims and recovery of historical writing. Preserve source type, generation, limitations and original evidence when revising.

Remaining gap: A fictional penetration-test report is only partial preparation for audit reporting; compliance audit planning, standards and independent audit acceptance are not covered.

Optional practice questions: Use these with the named course activities when available. Keep your writing in your existing notebook or a local draft; this public page saves nothing.

  • Willow / Maple investigation (WILLOW-MAPLE): Choose one supplied observation. Write a technical reproduction and a short executive explanation, then add counter-evidence, an unknown and a retest criterion.
    Keep the claim bounded: Mark the packet as supplied records, not your live observations. This supports reporting preparation, not compliance audit competence or independently assessed mastery.

Assessment: Not independently assessed. Course artifacts and saved writing do not prove learner competence.

No official 8140 approval, DCWF crosswalk, certification, employment eligibility or full work-role qualification is claimed. This course does not independently assess qualification for a work role. SOC monitoring, incident response and cloud defensive administration need additional training; specialist courses and career bundles remain planned, not included delivery.

Download Foundations syllabus PDF — untagged text export. Use the HTML syllabus for readable headings and navigation; the PDF may have accessibility limitations.

Explore this area: Penetration Testing Foundations

Price and access

$349 per course

Available for testing

Sign in to continue. Your existing access and progress apply.