Conduct penetration tests with CLEH–CEH
Conduct penetration tests (Pentesting Security)
Defending a system effectively requires the ability to test its weaknesses within an authorised framework. Structure penetration tests, analyse vulnerabilities and make findings actionable. Strengthen your ability to connect technical results with remediation priorities.
- Duration
- 4.5 days 31 hours
- Code
- SP-RS7394 Code
- CPF
- CPF eligible CPF
Presentation
The Conduct penetration tests (Pentesting Security) certification is designed for IT security professionals. It develops the skills needed to examine networks and IT systems by simulating the actions of a potential intruder within their working environment: traffic analysis, storage analysis and security analysis specific to the endpoint in use. The course is also compatible with the CLEH–CEH programme, adding a further dimension to your penetration testing expertise.
You will gain the skills and knowledge to master the phases of an attack, identify threat types, implement effective countermeasures and carry out practical tests in real-world scenarios. Intensive hands-on work and assessment exercises develop an in-depth understanding of penetration testing security. You will be ready to apply these skills in the field, strengthening both your expertise and your ability to anticipate and counter cyberthreats.
Whether you are a new IT security professional or a technician, this course is essential for organisations seeking to protect digital assets, meet regulatory requirements and stay ahead of evolving cyberthreats.
M2I Formation provides training in IT, digital technologies and cybersecurity.
Objectives
By the end of this course, you will achieve the following objectives:
- understand IT security fundamentals;
- identify threats and risks;
- use IT security tools and techniques;
- define penetration testing challenges and constraints to establish the most likely scenarios and obtain legal consent;
- apply a clear, repeatable penetration testing methodology to produce findings that can be compared using consistent approaches;
- design and adapt intrusion tools to address different penetration testing requirements;
- identify vulnerabilities by carrying out the penetration testing phases defined in the initial scope to uncover organisational weaknesses;
- report identified vulnerabilities and present an action plan with security measures that enable the organisation to address its weaknesses.
Program
Introductions and expectations
- Individual introductions.
- Exploring each participant's expectations and objectives.
- Introducing the training framework.
- Aligning with specific objectives and challenges.
- Identifying participants' individual expectations and perspectives.
- Information on the organisation of certification assessments.
- Registering each participant for certification assessments.
--------------------------------------------------------------------------------------------------------------------
Day 1: security fundamentals and terminology
- Introduction to information security.
- Penetration testing terminology and background
- Penetration tester terminology.
- Notable hacks and hackers.
- Virtualisation.
- Information systems security
- Vulnerabilities, threats, risks, veracity and severity.
- The 5 phases of an attack
- Reconnaissance.
- Vulnerability scanning.
- Gaining access.
- Maintaining access.
- Covering tracks.
- Assessment exercise: multiple-choice quiz.
Day 2: threats and countermeasures
- Malware
- Trojans, backdoors, viruses and worms.
- Denial-of-service attacks
- DoS, DDoS and DrDoS.
- Social engineering
- Phishing, spear phishing and Google Dorks.
- Cryptography
- Symmetric encryption, asymmetric encryption and encryption certificates.
- Assessment exercise: multiple-choice quiz.
Day 3: types of attack
- Network attacks
- Wireless networks (Wi-Fi), wired networks and spoofing.
- System attacks
- Impersonation, session hijacking and privilege escalation.
- Web server attacks
- Web server concepts, countermeasures and attack methodology.
- Web application attacks
- Web application concepts, web APIs, webhooks, web shells and attack methodology.
- Assessment exercise: multiple-choice quiz.
Day 4: the attack process
- Reconnaissance
- Reconnaissance tools.
- Fingerprinting
- Scanning.
- Enumeration
- In-depth scanning.
- Analysis.
- Assessment exercise: multiple-choice quiz.
Day 5: practical work and applications
- Practical work
- Detecting security weaknesses.
- Writing a report.
- Using a Linux virtual machine.
- 4 hours of practical exercises.
- Applying acquired skills to real-world scenarios.
Audience
This course is intended for:
- systems and network technicians;
- systems and network administrators;
- developers with good systems and networking knowledge;
- SOC analysts;
- cybersecurity professionals seeking to move into penetration testing.
Prerequisites
This course has the following prerequisites:
- basic networking knowledge: protocols, IP addressing, routing and more;
- an understanding of Linux and/or Windows operation: basic commands and file systems;
- familiarity with virtualisation systems such as VMware, Hyper-V or VirtualBox;
- an interest in the main cybersecurity domains: systems, network and application security.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Practical exercises
Course highlights
Certification training in IT security open to all industry professionals, with multiple-choice assessment exercises and a practical professional scenario.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en