Appearance

A little motion, or a quiet place to read.

Following your device’s motion preference.

← RESOURCE INDEX

INTERACTIVE STUDY RESOURCE

PenTest Plus Flashcards 2026

The notes were getting long. So I made flashcards.

2026-09-13

ACTIVE RECALL / 2026361 cards · 19 topics
due now
new cards
introduced
0this session

Loading your study session…

Space reveals the answer · 1–4 rates recall. Again returns in 10 minutes. Each successful review increases the interval.

Deck tools

Import the TSV as Basic notes in Anki. It includes cards and topic tags; review schedules do not sync with Anki.

I've been taking a lot of notes for PenTest+. Unfortunately, having something written down and being able to remember it are two different things. The notes keep growing, too.

So, flashcards! There are 361 here so far. I broke the material into short questions because I want to practice a concept, not memorize a paragraph. I'll be studying with these myself and revising them as I go.

How to study this deck

Have a go before revealing the answer. Again means you missed it, Hard means it took some work, Good means you knew it, and Easy means you barely had to think. Again brings the card back in ten minutes. The others give you longer before you see it again.

Cards due for review come first, then new ones. You can pick a single topic or use Browse all to look something up without affecting your schedule.

You can start without signing in. Those reviews stay in this browser. If you're going to be moving between devices (I am), sign in with an email code to save progress to your account. Guest progress doesn't transfer when you sign in.

There's also an optional checkbox for emails when I add resources. Getting a sign-in code doesn't put you on the mailing list. You can unsubscribe or delete your account in the study settings.

What is in the deck?

The 19 topics cover scope and agreements, ethics, evidence, risk, frameworks, reporting, reconnaissance, network evidence, vulnerability assessment, wireless and physical security, cryptography, web security, scripting, and credential defenses. There's more in the notes than I've put into cards yet.

Some of the questions are definitions. Others are about the little distinctions that matter:

  • Authentication versus authorization: knowing who made a request does not establish permission to read an object or change it.
  • CVE versus CWE: one identifies a specific disclosed vulnerability; the other describes a class of weakness.
  • A banner versus a verified version: software identification is evidence to corroborate, not automatic proof of a vulnerability.
  • A scan result versus business risk: technical severity needs context before it determines remediation order.

Use it with Anki

Open Deck tools and choose Download deck for Anki. Import the tab-separated file as Basic notes. Questions become fronts, answers become backs, and topics become tags. This exports the cards, not your browser review schedule.

The website uses a small spaced-review scheduler with visible intervals. It is not Anki's FSRS scheduler, and the website and Anki do not synchronize reviews with each other.

About the source material

These come from my PenTest+ PT0-003 notes, reviewed through September 13, 2026. The questions and explanations were written for this deck. Each answer names its source note so I can find the relevant material when something needs a correction.

This isn't an official CompTIA deck or a complete exam checklist. It also doesn't contain practice-exam questions or lab answer keys. The attack-related cards cover concepts, evidence and defenses; you'll still need an authorized lab for hands-on practice.

Some lessons refer to older material, and a few claims in the notes needed checking. I've left those out or qualified them. For the exam scope, check CompTIA; for the classifications that keep changing, there's OWASP and MITRE ATT&CK. I'll keep working through the notes.