Penetration Testing Foundations syllabus
Course outline for review. Your enrolled course keeps its assigned version; this page does not change your access or progress.
Begin with the BEST B-CID method, then investigate networks and web applications within an authorized scope. Compare observations, test secure controls and document what the evidence supports. Practice combines lessons, supplied-record worksheets, local simulations and assigned isolated labs; availability varies by activity.
Start Foundations training — sign in with existing access. Starting module: administrative orientation, followed by BEST B-CID instruction. This public syllabus does not show personalized progress.
Audience and prerequisites
Beginners exploring ethical hacking, penetration testing or web application testing, and defenders who want to understand how offensive observations inform defensive work.
Be comfortable opening web pages, managing files and reading short instructions. No prior penetration testing experience is required. Use only assigned targets and fictional accounts; introductory network and browser concepts are taught in the course.
Course outcomes
- Define an authorized scope and apply B-CID to an investigation.
- Distinguish reachability, port state and observed service behavior from assumptions.
- Interpret requests, sessions and common web trust boundaries using positive and negative controls.
- Write reproducible evidence notes with limitations, remediation and retest steps.
Equipment and format
- Use a desktop or laptop with a current browser, keyboard and space to save text or JSON evidence. Browser practice introduces the built-in developer tools; a proxy is optional, not a starting requirement.
- Text lessons and worksheets can be read on a phone. Use a desktop or laptop for browser inspection and workstation activities. Compatibility with every mobile device or assistive technology is not established.
- The workstation command walkthrough uses Linux Bash on an already approved local workstation. Open its Terminal application and select Bash; BEST does not provide a browser terminal. Do not paste these commands into the browser address bar or Windows PowerShell. If you do not have approved Linux Bash access, use the supplied-output rehearsal and ask your instructor or workstation administrator before execution. No installation or elevated privileges are required for this walkthrough.
- The separate command-boundary and file-boundary fixtures require an approved copy of the supplied application files and Python 3.10 or later. The command-boundary fixture also requires a POSIX shell at /bin/sh. A public syllabus or browser lesson does not supply this checkout. Without the approved files or tools, use the supplied-record rehearsal; do not substitute arbitrary commands or targets. Network socket exercises require a separately approved isolated host and host acceptance before execution. No paid cloud account, arbitrary scanning target or real customer account is required.
- Assigned isolated labs require sign-in, existing course/lab access and completed safety orientation. Availability and host acceptance differ by lab; reading a guide does not allocate or reset a lab.
Self-paced text lessons and formative checks, staged practice and evidence reporting. Supplied records and simulations are preparation, not verified live observations. Independent assessment uses separate unfamiliar materials and excludes AI/RAG assistance.
Module outline
Administrative orientation precedes instruction. BEST B-CID is the first instructional module and is applied throughout practice and reporting. Dependencies below describe recommended learning order; existing enrolled versions and progress remain unchanged.
1. Orientation
Prepare for authorized learning before touching a target.
Before this module: No prior module; begin here.
Topics
- Learner journey
- Authorization and scope
- Lab safety
- Assessment orientation
Learning outcomes
- Identify permitted targets, stop rules and assistance boundaries.
- Explain how to retain evidence without exposing credentials or other learners.
Associated practice
Text lessons and formative checks; apply this module during the later technical investigations and evidence reports. No separate executable lab is listed for this module.
2. BEST B-CID Method
Use BEST B-CID as the first instructional method and carry it through every investigation.
Before this module: Orientation
Topics
- Baseline
- Change
- Compare
- Interpret
- Document
Learning outcomes
- Record a baseline before changing one input.
- Compare and repeat observations, then separate interpretation from documented fact.
Associated practice
Text lessons and formative checks; apply this module during the later technical investigations and evidence reports. No separate executable lab is listed for this module.
3. Penetration Testing Methodology
Turn an authorized scope into a small, ordered testing plan.
Before this module: BEST B-CID Method
Topics
- NIST SP 800-115
- PTES
- MITRE ATT&CK as a reference model
Learning outcomes
- Explain the difference between a testing methodology and a reference model.
- Prepare a workstation and evidence plan using fixed local activities.
Associated practice
Text lessons and formative checks; apply this module during the later technical investigations and evidence reports. No separate executable lab is listed for this module.
4. Network Foundations
Build the addressing and transport vocabulary needed to reason about connectivity.
Before this module: Penetration Testing Methodology
Topics
- TCP/IP
- IP addressing
- Routing
- TCP/UDP
- Common services and ports
- DNS
- HTTP/HTTPS
- SSH
- SMB
- Open/closed/filtered
Learning outcomes
- Identify an address, subnet, route and service endpoint.
- Explain why TCP, UDP and a missing response require different interpretations.
Associated practice
- Campus paths and permissions — Socket-free configuration simulation and supplied records. Guided, Semi-guided and Blind preparation; Document. Local simulation, saved copies and reports available; real campus network Coming soon.
- Network workstation investigation — Local workstation activity. Guided, Semi-guided and Blind preparation; Document. Materials available; socket execution requires a separately authorized isolated host. Without one, use supplied records and do not run network probes.
5. Reconnaissance & Enumeration
Investigate scoped reachability, ports and services without treating guesses as observations.
Before this module: Network Foundations
Topics
- Host discovery
- Port enumeration
- Service identification
- DNS enumeration
- HTTP discovery
- Nmap workflows
Learning outcomes
- Distinguish open, closed and ambiguous observations and corroborate service identity.
- In campus preparation, separate ticket-approved administrator changes from read-only tester rights and application access.
Associated practice
- Owned network service discovery — Supplied-record rehearsal and workstation preparation. Guided, Semi-guided and Blind preparation; Document. Supplied-record rehearsal available; managed network execution Coming soon. Interpret the provided records without scanning a target.
6. Web Application Foundations
Read browser requests and follow fictional login and cookie state.
Before this module: Reconnaissance & Enumeration
Topics
- HTTP requests/responses
- Methods
- Headers
- Parameters
- Cookies
- Sessions
- Authentication
- Client vs server
- HTML/JavaScript basics
- Browser DevTools
- Proxy concepts
Learning outcomes
- Identify method, path, parameters, headers and response evidence.
- Distinguish Set-Cookie from Cookie, preference persistence from authentication and logout appearance from invalidation.
Associated practice
- How a web request works — Assigned-lab browser guide. Guided, Semi-guided and Blind preparation; Document. Guide available; use only the Harbor lab already assigned to your account. Reading the guide does not start a lab.
- Does logout end the session? — Form-session simulation. Guided, Semi-guided and Blind preparation; Document. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
- Cookies and login sessions — Supplied-record rehearsal and browser preparation. Guided, Semi-guided and Blind preparation; Document. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
7. Common Web Vulnerabilities
Compare controlled web trust-boundary weaknesses with repaired and ambiguous cases.
Before this module: Web Application Foundations
Topics
- SQL injection
- Reflected XSS
- Stored XSS
- Command injection
- File inclusion/path behavior
- Authentication weaknesses
- Session weaknesses
- Redirects
Learning outcomes
- Investigate query, script, command and file boundaries without equating an error with execution.
- Compare record/role authorization, CSRF, upload and business-logic observations with secure controls, respecting each activity's availability.
Associated practice
- Who may read this order? — Assigned-lab scenario. Guided, Semi-guided and Blind preparation; Document. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
- Where may a manual reader look? — Virtual-file simulation. Guided, Semi-guided and Blind preparation; Document. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
- Customer versus staff access — Form-session simulation. Guided, Semi-guided and Blind preparation; Document. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
- What does an error reveal? — Fixed-response simulation. Guided, Semi-guided and Blind preparation; Document. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
- Who asked to change delivery? — Supplied-record rehearsal and browser preparation. Guided, Semi-guided and Blind preparation; Document. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
- What did the attachment check? — Non-executable attachment experiment. Guided, Semi-guided and Blind preparation; Document. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
- Who calculates the cart total? — Fictional cart simulation. Guided, Semi-guided and Blind preparation; Document. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
- Did an extra command run? — Fixed-program simulation. Guided, Semi-guided and Blind preparation; Document. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
- Catalog query investigation — Existing assigned Harbor lab. Guided, Semi-guided and Blind preparation; Document. Assigned-lab practice requires existing access and an assigned Harbor environment. Follow its scope and setup instructions; this page allocates no lab.
- Search reflection investigation — Existing assigned Harbor lab. Guided, Semi-guided and Blind preparation; Document. Assigned-lab practice requires existing access and an assigned Harbor environment. Follow its scope and setup instructions; this page allocates no lab.
- Project-note investigation — Existing assigned Harbor lab. Guided, Semi-guided and Blind preparation; Document. Assigned-lab practice requires existing access and an assigned Harbor environment. Follow its scope and setup instructions; this page allocates no lab.
- Command investigation — Local workstation activity. Guided, Semi-guided and Blind preparation; Document. Local materials available; no managed lab is started.
- File investigation — Local workstation activity. Guided, Semi-guided and Blind preparation; Document. Local materials available; no host-file targets or managed lab.
8. Evidence & Reporting
Write a finding that another reviewer can reproduce and challenge.
Before this module: Common Web Vulnerabilities
Topics
- Observation vs finding
- Evidence vs inference
- Reproducibility
- Limitations
- Technical evidence notes
- Severity concepts
- Remediation
- Technical vs executive reporting
Learning outcomes
- Separate observation, inference, impact and uncertainty.
- Record baseline/change/repeat, counter-evidence, remediation and positive/negative retest criteria for technical and nontechnical readers.
Associated practice
Text lessons and formative checks; apply this module during the later technical investigations and evidence reports. No separate executable lab is listed for this module.
9. Integrated Guided Pentest
Combine network, web and reporting practice within one fictional engagement brief.
Before this module: Evidence & Reporting
Topics
- Authorized fictional scope
- Network discovery
- Service analysis
- Web investigation
- Evidence collection
- Structured report
Learning outcomes
- Join separately scoped evidence without inventing a causal chain.
- Produce a structured report that preserves provenance, controls, limitations and restoration.
Associated practice
- Returns workflow: fix and retest — Supplied-record rehearsal and workflow simulation. Guided, Semi-guided and Blind preparation; Document. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
- Willow / Maple investigation — Supplied-record worksheet. Guided, Semi-guided and Blind preparation; Document. Preparation available and ungraded; not live execution.
- Assigned guided engagement — Existing assigned live lab. Guided investigation and Document. Existing entry requirements apply; no lab allocated by this inventory. Expanded scenarios are not automatically enabled.
10. Independent Skills Assessment
Understand the separate unfamiliar-transfer and review stage; current preparation does not activate a sitting.
Before this module: Integrated Guided Pentest
Topics
- Transfer to an unfamiliar scenario
- Finding, component/module, evidence
- Skills results and recommended remediation
Learning outcomes
- Explain independent evidence and the AI/RAG assistance exclusion.
- Prepare to submit reproducible evidence against a versioned rubric without claiming an award from an ungraded candidate.
Associated practice
Independent materials and review are separate from practice; see assessment status below.
Complete practice inventory and availability
Hands-on labs and practice
The syllabus is public. Course lessons and practice materials require enrollment or an authorized access entitlement.
The list distinguishes guides, supplied-record exercises and simulations from available lab execution. Training links require sign-in and existing access; opening a guide starts no lab.
How a web request works
Compare public products and identify request paths, parameters and responses.
Type: Assigned-lab browser guide
Availability: Guide available; use only the Harbor lab already assigned to your account. Reading the guide does not start a lab.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: B-CID, HTTP and browser toolsTopic: Web Application Foundations · Access practice - enrollment required: How a web request works
Who may read this order?
Compare fictional order access with a server ownership control.
Type: Assigned-lab scenario
Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: Request basics and authenticationTopic: Common Web Vulnerabilities · Access practice - enrollment required: Who may read this order?
Where may a manual reader look?
Compare fictional file disclosure with a root-confined reader.
Type: Virtual-file simulation
Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: Request basics and file boundariesTopic: Common Web Vulnerabilities · Access practice - enrollment required: Where may a manual reader look?
Customer versus staff access
Compare navigation visibility with enforced role permissions.
Type: Form-session simulation
Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: Request basics and authenticationTopic: Common Web Vulnerabilities · Access practice - enrollment required: Customer versus staff access
What does an error reveal?
Compare controlled technical detail with a generic error.
Type: Fixed-response simulation
Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: Request basics and file boundariesTopic: Common Web Vulnerabilities · Access practice - enrollment required: What does an error reveal?
Who asked to change delivery?
Compare unwanted preference updates with token controls and repeated state reads.
Type: Supplied-record rehearsal and browser preparation
Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: Request basics and cookiesTopic: Common Web Vulnerabilities · Access practice - enrollment required: Who asked to change delivery?
What did the attachment check?
Compare file labels, inert text validation and safe retrieval.
Type: Non-executable attachment experiment
Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: Request basics and browser toolsTopic: Common Web Vulnerabilities · Access practice - enrollment required: What did the attachment check?
Does logout end the session?
Compare login messages and retained-session access after logout.
Type: Form-session simulation
Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: Request basics and authenticationTopic: Web Application Foundations · Access practice - enrollment required: Does logout end the session?
Who calculates the cart total?
Compare a display preview with a server-stored fictional receipt.
Type: Fictional cart simulation
Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: Request basicsTopic: Common Web Vulnerabilities · Access practice - enrollment required: Who calculates the cart total?
Did an extra command run?
Compare a harmless fixed-program marker with literal and unavailable controls.
Type: Fixed-program simulation
Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: Request basics and command boundariesTopic: Common Web Vulnerabilities · Access practice - enrollment required: Did an extra command run?
Owned network service discovery
Distinguish reachability, port state, silence and observed service identity.
Type: Supplied-record rehearsal and workstation preparation
Availability: Supplied-record rehearsal available; managed network execution Coming soon. Interpret the provided records without scanning a target.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: B-CID, addressing and transportTopic: Reconnaissance & Enumeration · Access practice - enrollment required: Owned network service discovery
Returns workflow: fix and retest
Connect order ownership and price evidence; compare repairs and restore.
Type: Supplied-record rehearsal and workflow simulation
Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: Order and cart practiceTopic: Integrated Guided Pentest · Access practice - enrollment required: Returns workflow: fix and retest
Campus paths and permissions
Diagnose route/firewall faults with administrator tickets; keep tester rights and application permissions separate.
Type: Socket-free configuration simulation and supplied records
Availability: Local simulation, saved copies and reports available; real campus network Coming soon.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: Addressing, routing and introductory service discoveryTopic: Network Foundations · Access practice - enrollment required: Campus paths and permissions
Cookies and login sessions
Compare preferences, header direction, login/logout and cookie-flag limitations.
Type: Supplied-record rehearsal and browser preparation
Availability: Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: HTTP, browser tools and sessionsTopic: Web Application Foundations · Access practice - enrollment required: Cookies and login sessions
Catalog query investigation
Compare query behavior and document SQL-injection evidence.
Type: Existing assigned Harbor lab
Availability: Assigned-lab practice requires existing access and an assigned Harbor environment. Follow its scope and setup instructions; this page allocates no lab.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: B-CID, HTTP and relevant SQL/XSS lessonsTopic: Common Web Vulnerabilities · Access practice - enrollment required: Catalog query investigation
Search reflection investigation
Compare reflected browser content and secure-control limits.
Type: Existing assigned Harbor lab
Availability: Assigned-lab practice requires existing access and an assigned Harbor environment. Follow its scope and setup instructions; this page allocates no lab.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: B-CID, HTTP and relevant SQL/XSS lessonsTopic: Common Web Vulnerabilities · Access practice - enrollment required: Search reflection investigation
Project-note investigation
Compare stored note behavior with a safe rendering control.
Type: Existing assigned Harbor lab
Availability: Assigned-lab practice requires existing access and an assigned Harbor environment. Follow its scope and setup instructions; this page allocates no lab.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: B-CID, HTTP and relevant SQL/XSS lessonsTopic: Common Web Vulnerabilities · Access practice - enrollment required: Project-note investigation
Command investigation
Run fixed authored programs in a disposable directory and retain controls and cleanup.
Type: Local workstation activity
Availability: Local materials available; no managed lab is started.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: Command boundaries and safe workstation preparationTopic: Common Web Vulnerabilities · Access practice - enrollment required: Command investigation
File investigation
Compare fictional file reads, disclosure and confined controls.
Type: Local workstation activity
Availability: Local materials available; no host-file targets or managed lab.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: File boundaries and safe workstation preparationTopic: Common Web Vulnerabilities · Access practice - enrollment required: File investigation
Network workstation investigation
Prepare bounded TCP/UDP comparisons and retain original exports.
Type: Local workstation activity
Availability: Materials available; socket execution requires a separately authorized isolated host. Without one, use supplied records and do not run network probes.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: Addressing, transport and approved disposable scopeTopic: Network Foundations · Access practice - enrollment required: Network workstation investigation
Willow / Maple investigation
Combine supplied observations and write a bounded evidence report.
Type: Supplied-record worksheet
Availability: Preparation available and ungraded; not live execution.Learning format: Guided, Semi-guided and Blind preparation; Document
Before you begin: Introductory lessons and evidence reportingTopic: Integrated Guided Pentest · Access practice - enrollment required: Willow / Maple investigation
Assigned guided engagement
Investigate only the isolated environment assigned to your account.
Type: Existing assigned live lab
Availability: Existing entry requirements apply; no lab allocated by this inventory. Expanded scenarios are not automatically enabled.Learning format: Guided investigation and Document
Before you begin: Existing orientation, diagnostic and guided-entry requirementsTopic: Integrated Guided Pentest · Access practice - enrollment required: Assigned guided engagement
Independent assessment is separate
Juniper preparation and frozen handover materials are inactive and ungraded. They are not practice labs or an active independent assessment sitting. Independent assessment is not currently open. Artificial Intelligence (AI) and Retrieval-Augmented Generation (RAG) assistance, tutor help and hints are excluded during independent assessment. No activity listed here certifies mastery.
Practice, assessment and AI assistance
Learn the concept, see an example, investigate with guidance, repeat with fewer hints, try unfamiliar practice and document the evidence. B-CID connects a baseline with a controlled comparison, interpretation and defensible documentation. Blind practice is preparation, not independent demonstration. Save your observations, negative controls, limitations and restoration checks.
Formative questions check understanding; they do not establish practical mastery. Integrated practice combines earlier skills. Independent assessment uses separate unfamiliar materials and review criteria. Juniper preparation is inactive and ungraded. A worksheet or saved report does not award course completion, certification or demonstrated skill.
Contextual help and any configured formative AI review are practice assistance, not an answer validator or skill award. A live provider is not verified by this syllabus; unavailable help must leave the lesson and notes usable. AI tutoring, RAG assistance, structured hints and correctness-driven retries are excluded during independent assessment, with server-side assistance restrictions.
Career paths and workforce alignment
Explore introductory security work through selected tasks from the National Initiative for Cybersecurity Education (NICE) framework. This is partial coverage, not a complete qualification. The course does not confer official Department of Defense 8140 qualification, certification or employment eligibility.
Connect course practice with selected tasks in the National Initiative for Cybersecurity Education (NICE) framework. These examples cover vulnerability identification, remediation advice and reporting. They are partial preparation, not a test of career suitability or qualification for a complete work role.
Source: NICE components 2.2.0, checked 2026-10-04.
Vulnerability Analysis (PD-WRL-007)
NICE category: PROTECTION and DEFENSE (PD). Everyday career names can span several work roles; this selected task mapping does not define a complete career path.
Read the official NIST NICE components and version information. View the official NICE 2.2.0 source data (JSON).
T1118: Identify vulnerabilities — Practiced in preparation
Course outcome: Compare suspected web, command and file weaknesses with secure controls; distinguish service observations and session behavior from proven vulnerabilities.
Relevant lessons: Apply BEST B-CID; Separate observations, inferences, and findings; Build a bounded SQL injection evidence comparison; Separate TCP and UDP observations; Corroborate service names and version evidence; Bound a command-injection conclusion to its observed effect; Separate path traversal, file disclosure, and inclusion claims; Observe cookie and session lifecycle.
Practice and availability:
- Search reflection investigation (HARBOR-SEARCH): Existing assigned Harbor lab. Assigned-lab practice requires existing access and an assigned Harbor environment. Follow its scope and setup instructions; this page allocates no lab.
- Who may read this order? (FND-LAB-02): Assigned-lab scenario. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
- Network workstation investigation (LOCAL-NETWORK): Local workstation activity. Materials available; socket execution requires a separately authorized isolated host. Without one, use supplied records and do not run network probes.
- Command investigation (LOCAL-COMMAND): Local workstation activity. Local materials available; no managed lab is started.
- File investigation (LOCAL-FILE): Local workstation activity. Local materials available; no host-file targets or managed lab.
- Cookies and login sessions (FND-LAB-14): Supplied-record rehearsal and browser preparation. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
Evidence offered: B-CID comparisons, fixed command/file programs and staged session records rehearse narrow claims. The network workbook practices corroboration and ambiguous-response interpretation; an open port or timeout is not itself a vulnerability. Current practice availability is listed separately.
Remaining gap: No accepted enterprise vulnerability program, broad scanner coverage or independent live transfer is established. Supplied records and host-gated network materials do not establish learner execution; browser session effects need actual browser evidence.
Optional practice questions: Use these with the named course activities when available. Keep your writing in your existing notebook or a local draft; this public page saves nothing.
- Network workstation investigation (LOCAL-NETWORK): Compare one permitted service over TCP and UDP. What replied, what stayed silent, and which application observation supports the service name?
Keep the claim bounded: Use supplied records if an authorized socket host is unavailable. Label their source; silence does not prove absence and a port number does not prove service identity. - Command investigation (LOCAL-COMMAND): Compare the ordinary input, harmless marker and literal-argument control. Which observed effect supports a command-boundary conclusion?
Keep the claim bounded: Use only the fixed disposable scenario. Error text alone is not execution; do not test other hosts or add outbound callbacks. - Cookies and login sessions (FND-LAB-14): Compare login, logout and later access. Which record shows the server decision, and what do the cookie flags tell you?
Keep the claim bounded: Separate browser sending rules from application access. Supplied headers are rehearsal; flags alone do not prove that logout invalidated a session.
Assessment: Not independently assessed. Course artifacts and saved writing do not prove learner competence.
T1119: Recommend vulnerability remediation strategies — Practiced in preparation
Course outcome: Explain a boundary repair and define positive and negative retest criteria without expanding configuration authority.
Relevant lessons: Turn findings into a useful report; Define remediation and retest acceptance criteria; Separate path traversal, file disclosure, and inclusion claims; Read subnets, gateways, and routes.
Practice and availability:
- Command investigation (LOCAL-COMMAND): Local workstation activity. Local materials available; no managed lab is started.
- File investigation (LOCAL-FILE): Local workstation activity. Local materials available; no host-file targets or managed lab.
- Where may a manual reader look? (FND-LAB-03): Virtual-file simulation. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
- Returns workflow: fix and retest (FND-LAB-12): Supplied-record rehearsal and workflow simulation. Guide available; live execution is not currently available for this activity. Not a verified live lab. Use supplied records or simulation from the guide where provided.
- Campus paths and permissions (FND-LAB-13): Socket-free configuration simulation and supplied records. Local simulation, saved copies and reports available; real campus network Coming soon.
Evidence offered: Fixed command/file controls, product-manual comparisons and the guided integration workflow support repair and retest planning. Campus simulation adds narrow administrator-ticket changes, unrelated-path denial and restoration; network permission remains separate from application ownership.
Remaining gap: This practice does not establish independently demonstrated skill or verified live-system performance.
Optional practice questions: Use these with the named course activities when available. Keep your writing in your existing notebook or a local draft; this public page saves nothing.
- File investigation (LOCAL-FILE): Write a retest that allows the intended manual and denies an outside-root fictional file. What evidence distinguishes disclosure from inclusion?
Keep the claim bounded: Keep tests inside the disposable file activity. A filename or denied request does not prove disclosed content or executable inclusion. - Campus paths and permissions (FND-LAB-13): For an administrator ticket, predict one narrow route or firewall change, a permitted check, an unrelated denied check and restoration. How would a tester without that ticket proceed?
Keep the claim bounded: Use the socket-free model as simulation. Do not change real routes or firewalls; reachability does not grant payroll or grades access.
Assessment: Not independently assessed. Course artifacts and saved writing do not prove learner competence.
T1279: Prepare audit reports — Practiced in preparation
Course outcome: Write technical and executive accounts with scope, reproducible evidence and limitations.
Relevant lessons: Write a reproducible and appropriately redacted evidence note; Write technical and executive accounts of the same finding; Explain severity, confidence, and remediation priority; Rehearse a scoped multi-service network investigation.
Practice and availability:
- Willow / Maple investigation (WILLOW-MAPLE): Supplied-record worksheet. Preparation available and ungraded; not live execution.
- Network workstation investigation (LOCAL-NETWORK): Local workstation activity. Materials available; socket execution requires a separately authorized isolated host. Without one, use supplied records and do not run network probes.
- Campus paths and permissions (FND-LAB-13): Socket-free configuration simulation and supplied records. Local simulation, saved copies and reports available; real campus network Coming soon.
Evidence offered: Willow/Maple supplied-record reporting, the network evidence workbook and campus simulation reports practice source references, audience-aware claims and recovery of historical writing. Preserve source type, generation, limitations and original evidence when revising.
Remaining gap: A fictional penetration-test report is only partial preparation for audit reporting; compliance audit planning, standards and independent audit acceptance are not covered.
Optional practice questions: Use these with the named course activities when available. Keep your writing in your existing notebook or a local draft; this public page saves nothing.
- Willow / Maple investigation (WILLOW-MAPLE): Choose one supplied observation. Write a technical reproduction and a short executive explanation, then add counter-evidence, an unknown and a retest criterion.
Keep the claim bounded: Mark the packet as supplied records, not your live observations. This supports reporting preparation, not compliance audit competence or independently assessed mastery.
Assessment: Not independently assessed. Course artifacts and saved writing do not prove learner competence.
No official 8140 approval, DCWF crosswalk, certification, employment eligibility or full work-role qualification is claimed. This course does not independently assess qualification for a work role. SOC monitoring, incident response and cloud defensive administration need additional training; specialist courses and career bundles remain planned, not included delivery.
Accessibility and support
Use the HTML syllabus for headings, links and labeled controls. Compatibility with every browser or assistive technology, and accessibility conformance, have not been established. If you encounter an access barrier, use the contact link below and describe the page, task, browser or assistive technology. Do not send passwords or private evidence.
Price and access
Study at your own pace. A reliable completion-time estimate is not yet available. This syllabus does not promise an access duration or lab allowance; check the current account terms and available access before purchasing. The displayed standard course price is $349; partner proposals and career bundles are not available offers.
Use Start Foundations training above to sign in with existing access.
Download Foundations syllabus PDF (current syllabus wording; untagged PDF. Use the HTML syllabus for accessible headings and navigation). For readable headings and navigation, use this HTML syllabus; the PDF may have accessibility limitations.