And here comes another PenTest+ story. This one has a happy ending. Passed PenTest+ with a 784! 🎉 this past Friday.
Below is my advice!
The below is for any Comptia exam but I thought I’d remind you all!
Pay close attention to words like “first,” “best,” “most,” and “least.” This is really important! Several answer choices may technically be correct, but the question is asking for the best option, the most appropriate response, the first step, or the least likely outcome. Look for the one that most precisely matches what the question is asking.
Now onto the actual PenTest+
Know the scripts and commands. Don’t just memorize them. Understand what each command and its switches actually do.
Know the tools and when to use them. The exam is very scenario-based. Don’t just know that Responder, Nmap, Burp, Metasploit, Hydra, etc. exist. Know which tool is best for a specific situation.
Know the frameworks and their differences. OSSTMM, CREST, PTES, MITRE ATT&CK, OWASP, MASVS, STRIDE, DREAD, OCTAVE, etc. The exam can give you a scenario and expect you to identify the appropriate one.
Pay attention to the clues. Ports, protocols, services, defensive controls, operating systems, and the goal of the tester all matter.
Understand how defensive controls affect your approach. Know how things like DLP, EDR, IDS/IPS, firewalls, and SIEMs can detect or prevent certain activities, and understand how a penetration tester may need to adjust their techniques based on the client’s defensive environment.
Know Linux! For me personally, passing Linux+ earlier this year helped A LOT. I already understood Linux commands, permissions, networking, processes, and Bash, so I could focus on applying that knowledge to penetration testing.
Practice scenarios, not just definitions. Ask yourself: What is the tester trying to accomplish, what restrictions exist, and what tool/technique is the best fit?
The biggest thing I learned is that PenTest+ isn’t just “Do you know this tool?” It’s “Do you know when this is the RIGHT tool?” That distinction is huge.