Appearance

A little motion, or a quiet place to read.

Following your device’s motion preference.

← RESOURCE INDEX

INTERACTIVE STUDY RESOURCE

PenTest Plus Flashcards 2026

The notes were getting long. So I made flashcards.

2026-09-13

ACTIVE RECALL / 2026538 cards · 30 topics
—due now
—new cards
—introduced
0this session

Loading your study session…

Space reveals the answer · 1–4 rates recall. Again returns in 10 minutes. Each successful review increases the interval.

Deck tools

Counts help improve the deck. No emails, search text, or personal review history are included. Your browser’s Do Not Track or Global Privacy Control preference is respected.

I've been taking a lot of notes for PenTest+. Unfortunately, having something written down and being able to remember it are two different things. The notes keep growing, too.

So, flashcards! There are 538 here so far. I broke the material into short questions because I want to practice a concept, not memorize a paragraph. I'll be studying with these myself and revising them as I go.

How to study this deck

Have a go before revealing the answer. Again means you missed it, Hard means it took some work, Good means you knew it, and Easy means you barely had to think. Again brings the card back in ten minutes. The others give you longer before you see it again.

Cards due for review come first, then new ones. You can pick a single topic or use Browse all to look something up without affecting your schedule.

You can start without signing in. Those reviews stay in this browser. If you're going to be moving between devices (I am), sign in with an email code to save progress to your account. Guest progress doesn't transfer when you sign in.

There's also an optional checkbox for emails when I add resources. Getting a sign-in code doesn't put you on the mailing list. You can unsubscribe or delete your account in the study settings.

What is in the deck?

The 30 topics cover scope and agreements, ethics, evidence, risk, frameworks, reporting, reconnaissance, network evidence, vulnerability assessment, wireless and physical security, cryptography, web security, scripting, and credential defenses. The newer cards also cover network, cloud, authentication and host-based threats, social engineering, specialized systems, persistence and lateral movement awareness, data protection, cleanup, and remediation.

Some of the questions are definitions. Others are about the little distinctions that matter:

  • Authentication versus authorization: knowing who made a request does not establish permission to read an object or change it.
  • CVE versus CWE: one identifies a specific disclosed vulnerability; the other describes a class of weakness.
  • A banner versus a verified version: software identification is evidence to corroborate, not automatic proof of a vulnerability.
  • A scan result versus business risk: technical severity needs context before it determines remediation order.

Your study progress

Study the deck here with spaced review and visible intervals. Under Deck tools, you can export a backup of your review progress. This backup contains your schedule and review history, not the card questions and answers.

About the source material

These come from my PenTest+ PT0-003 notes, reviewed through September 27, 2026. The questions and explanations were written for this deck. Each answer names its source note so I can find the relevant material when something needs a correction.

This isn't an official CompTIA deck or a complete exam checklist. It also doesn't contain practice-exam questions or lab answer keys. The attack-related cards cover concepts, evidence and defenses; you'll still need an authorized lab for hands-on practice.

Some lessons refer to older material, and a few claims in the notes needed checking. I've left those out or qualified them. For the exam scope, check CompTIA; for the classifications that keep changing, there's OWASP and MITRE ATT&CK. I'll keep working through the notes.