Cloud Penetration Testing Training Boot Camp

4.6 (738 ratings)

Duration
5 days
Method
Live online or team onsite
Price
$4,599.00
Learn how to conduct penetration tests on cloud services and applications! This boot camp goes in-depth into the tools and techniques used to exploit and defend cloud infrastructure components with a combination of hands-on labs and expert instruction.
Exam Pass Guarantee

What you'll learn

Training overview

Infosec’s Cloud Penetration Testing Boot Camp is a practical, hands-on training focused on teaching you the skills, tools and techniques required for conducting comprehensive security tests of cloud servers and applications.

You will learn the secrets of cloud penetration testing in an immersive environment, including exploiting and defending AWS and Azure services, building your pentesting toolbox in the cloud, and diving deep into security features and vulnerabilities of cloud infrastructure. You will also learn how to deal with the unique challenges presented by cloud pentesting, such as multi-tenant environments and pivoting. The boot camp also prepares you to earn the Certified Cloud Penetration Tester (CCPT) certification.

What's included

Everything you need to know

Certification Logo
  • 90-day extended access to Boot Camp components, including class recordings
  • 100% Satisfaction Guarantee
  • Exam Pass Guarantee
  • Exam voucher
  • Free 90-day Infosec Skills subscription (access to 1,400+ additional courses and labs)
  • Hands-on cyber ranges and labs
  • Knowledge Transfer Guarantee
  • Pre-study learning path
  • Unlimited practice exam attempts

Syllabus

Training schedule

Day 1
Morning session

Introduction

Cloud pentesting process and requirements

  • The need for cloud pentesting
  • Cloud architecture fundamentals
  • Cloud security responsibilities (within service models)
  • Unique challenges for cloud pentesting
  • Multi-tenancy considerations (data privacy, legal requirements, rules of engagement)
  • Cloud attack surface
  • Virtualization concepts
  • Pentesting methodologies
  • Cloud pentesting process
  • Pentesting tools: traditional and cloud-specific
  • Setting up a cloud pentesting environment
Afternoon session

Reconnaissance in the cloud

  • OSINT techniques
  • Azure and AWS IP ranges
  • Tools for obtaining IP and host information (Shodan, Censys, Google dorks)
  • Enumerating access with Nimbostratus, ScoutSuite and Prowler
  • Finding exposed buckets
  • Bucket enumeration with Slurp
  • Service discovery
Evening session

Optional group & individual study

Schedule may vary from class to class

Day 2
Morning session

Attacking AWS

  • AWS security features
  • AWS Console overview
  • Working with AWS CLI
  • Exploiting remote access protocols (SSH , RDP)
  • Exploiting application security misconfigurations
  • Abusing EC2 metadata
  • Stealing IAM credentials
  • EC2 IMDSv2
  • Attacking lambda endpoints
  • Assessments with AWS Inspector
  • Attacking misconfigured S3 buckets
  • Discovering and stealing EBS snapshots
  • Recovering data from EBS snapshots
  • Exploiting AWS RDS misconfigurations
  • RDS data pilfering with AWS CLI and Amazon API
  • Persistence
Afternoon session

Attacking AWS continued

Evening session

Optional group & individual study

Schedule may vary from class to class

Day 3
Morning session

Attacking Azure

  • Understanding Azure Services
  • Mapping Azure Services to AWS Services
  • Attacking Azure Virtual Machines
  • Attacking Azure Blob Storage misconfigurations
  • Extracting data from disk snapshots
  • Subdomain takeover via Azure App Services
  • Gaining shell access with Azure run command
  • Finding and examining Azure SQL Database servers
Afternoon session

Attacking Azure continued

Evening session

Optional group & individual study

Schedule may vary from class to class

Day 4
Morning session

Attacking containerized and serverless applications

  • Understanding containers
  • Working with Docker
  • Container breakout
  • Exploiting misconfigured containers
  • Trojanized Docker images
  • Understanding Kubernetes
  • Attacking deployed applications
  • Attacking Kubernetes clusters
  • Understanding AWS Lambda
  • Attacking serverless applications
Afternoon session

Attacking containerized and serverless applications continued

Evening session

Attacking containerized and serverless applications continued

Day 5
Morning session

Reporting

  • Cloud security frameworks and best practices
  • Collecting and reporting evidence in cloud accounts, aliases, metadata, keys and AMIs
  • Developing and communicating follow-up items
Afternoon session

Take CCPT exam


What makes the Infosec CCPT prep course different?

You can rest assured that the CCPT training materials are fully updated and synced with the latest version of the CCPT exam. With 20 years of training experience, we stand by our CCPT training with an Exam Pass Guarantee. This means if you don’t pass the exam on the first attempt, we’ll pay for your second exam at no additional cost to you!

Guaranteed results

Our Boot Camp guarantees

Exam Pass Guarantee

Exam Pass Guarantee

If you don’t pass your exam on the first attempt, get a second attempt for free. Includes the ability to re-sit the course for free for up to one year (does not apply to CMMC-AB Boot Camps).

100% Satisfaction Guarantee

100% Satisfaction Guarantee

If you’re not 100% satisfied with your training at the end of the first day, you may withdraw and enroll in a different online or in-person course.

Knowledge Transfer Guarantee

Knowledge Transfer Guarantee

If an employee leaves within three months of obtaining certification, Infosec will train a different employee at the same organization tuition-free for up to one year.

Who should attend

Who Should Attend Image
  • Penetration testers
  • Cloud and system administrators
  • Application developers
  • DevSecOps engineers
  • Security consultants
  • Security analysts

Before your Boot Camp

Prerequisites

Before enrolling in the Cloud Penetration Testing Training Boot Camp, it is recommended that you have:

  • Familiarity with cloud and penetration testing concepts and at least one year in an information security role, or equivalent experience

Award-winning training you can trust

2025 G2 Summer - Leader Enterprise - eLearning Content
2024 Training Industry Top 20 Online Learning Library
2024 TrustRadius Top Rated - Skills
2024 G2 Winter - Users Love Us - SAT

Available scheduled dates

Price: $4,599.00
Online
Start Time:

Infosec vs. Competitors: Boot Camp Battlecard

Category

Infosec

SANS Institute

Training Camp

Global Knowledge

Triple Guarantee
Included
Not Included
Not Included
Not Included
Exam Pass Guarantee
Included
Not Included
Limited
Limited
100% Satisfaction Guarantee
Included
Not Included
Limited
Not Included
Knowledge Transfer Guarantee*
Included
Not Included
Limited
Not Included
Skills Verification Platform
Included

AI-powered, hands-on skill validation

Not Included
Not Included
Not Included
Validates methodology & problem-solving approach
Included
Not Included
Not Included
Not Included
Continuous skill tracking over time
Included
Not Included
Not Included
Limited
Hands-on labs & cyber ranges
Included
Included
Included
Included
Role-Based Learning Paths
Included

12 Roles

Limited
Not Included
Included
Role-Based Training
Included

Integrated for all roles

Separate
Limited
Separate
Post-Training Access & Additional Upskilling
Included

90 days

Limited
Not Included
Annual subscription
Instructor Quality
10+ years, active practitioners
10+ years, active practitioners
Varies
Varies
Delivery Options
Live-online, in-person, self-paced, accelerated, immersive, custom on-site
Live-online, in-person, self-paced, accelerated, immersive, custom on-site
Live, in-person, self-paced, accelerated, custom on-site
Live, in-person, self-paced, custom on-site
Partnerships / Programming
Not Included
Not Included
Not Included
Not Included
Compliance Coverage
DoD, NICE, MITRE, NIST, ISO, ISA/IEC
DoD, NICE, MITRE, NIST, ISO, ISA/IEC
Limited
Limited
CompTIA, ISACA, ISC2, EC-Council, Cisco Certifications
Included
Not Included
Included
Included
AWS / Azure / Cloud Certifications
Included
Limited
Included
Included
PMP & IT management Certifications
Included
Limited
Limited
Included

*Protects your investment if trained employees leave within three months of obtaining certification (Infosec will train a different employee at the same organization tuition-free for up to one year).