Jason Edwards

Certified: The CompTIA PenTest+ (Plus) Audio Course

This PrepCast series is a comprehensive, audio-first preparation program designed to help learners build the judgment, terminology fluency, and decision-making skills required for modern penetration testing scenarios. Rather than focusing on tools, commands, or hands-on labs, the series emphasizes how to think like a tester under real-world constraints: interpreting scope and rules of engagement, selecting safe and defensible next steps, validating findings responsibly, and communicating risk in clear business-aligned language. Each episode is structured to reinforce engagement flow, from plan...

Author

Jason Edwards

Category

Technology

Latest episode

Jan 6, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 96 — Final Exam Readiness Drill (Audio Practice) 06.01.2026

This episode provides a structured audio drill designed to improve decision speed and consistency by repeatedly practicing the same recognition and selection steps used in scenario questions. You’ll learn to identify the phase from clue words, classify the asset type, extract constraints like scope and safety, and choose the smallest next action that increases certainty or supports a defensible ou...

Episode 95 — Executive Summary That Doesn’t Suck 06.01.2026

This episode teaches you to write executive summaries that drive decisions by focusing on top risks, business impact, and clear actions, rather than repeating technical logs. You’ll learn how to state outcomes plainly, what was possible, why it matters, and what should happen next, while avoiding jargon and defining necessary terms in natural language. We’ll cover how to prioritize a small number...

Episode 94 — Building the Attack Narrative 06.01.2026

This episode teaches you to build an attack narrative that connects technical actions to business meaning, turning scattered steps into a coherent story that supports prioritization and remediation. You’ll learn a simple structure, initial access, expansion, impact, and recommendations, and how to keep chronology clear so stakeholders understand what happened first and why each step mattered. We’l...

Episode 93 — Cleanup and Restoration 06.01.2026

This episode focuses on cleanup and restoration as the final responsibility of a disciplined engagement, ensuring systems are left stable and risk is not increased by lingering artifacts. You’ll learn what kinds of artifacts often remain, such as test accounts, temporary configurations, files, tasks, and other changes, and why maintaining a running change list throughout the engagement makes clean...

Episode 92 — Data Handling and Evidence 06.01.2026

This episode teaches evidence handling as a core professional competency that protects clients, supports defensible findings, and reduces harm while still documenting meaningful risk. You’ll learn what counts as evidence in practice, such as observed behavior, logs, configuration excerpts, and limited screenshots, and how to apply the minimum necessary principle so you avoid collecting sensitive d...

Episode 91 — Staging and Exfiltration Concepts 06.01.2026

This episode explains staging and exfiltration as controlled data-handling decisions that must balance evidence needs, confidentiality, monitoring, and engagement constraints. You’ll learn staging as the process of collecting, organizing, and preparing proof in a way that supports reporting, and exfiltration as moving data out through a chosen channel, where the “best” option depends on restrictio...

Episode 90 — Common Lateral Paths (SMB/RDP/SSH/WinRM/WMI) 06.01.2026

This episode teaches you to interpret common movement-enabling services conceptually so you can recognize what open ports and service clues imply about possible access paths and risk. You’ll learn how file sharing, remote desktop, secure shell, and remote management interfaces enable remote interaction when credentials and policies allow, and why exposure of these services often signals segmentati...

Episode 89 — Pivoting Concepts 06.01.2026

This episode explains pivoting as extending reach through a controlled foothold to access networks or services that are not directly reachable from your original position. You’ll learn why pivoting becomes necessary when segmentation blocks direct paths, how it differs from lateral movement by enabling new routes rather than simply switching hosts, and what risks pivoting introduces in terms of co...

Episode 88 — Lateral Movement Logic 06.01.2026

This episode teaches lateral movement as a purposeful decision process that depends on objectives, prerequisites, and trust boundaries, not as a default “keep moving” mindset. You’ll learn the prerequisites that enable movement, such as reachability, credentials, and suitable services, and how crossing boundaries changes both impact and risk. We’ll cover how to decide between moving to another sys...

Episode 87 — Credential Reuse and Expansion 06.01.2026

This episode focuses on how credential reuse turns a single discovery into broad access, and how to reason about expansion safely under scope, safety, and evidence-handling constraints. You’ll learn reuse as the same credential working across multiple systems or services, why shared accounts and service credentials create outsized risk, and how to decide which validation attempts are justified and...

Episode 86 — Persistence Families 06.01.2026

This episode teaches persistence as a risk and control topic, focusing on the main ways long-term access is maintained and how those mechanisms show up in scenario descriptions. You’ll learn persistence families such as account-based persistence, scheduled tasks, services and startup behaviors, configuration and registry changes, and hidden web-based access points, emphasizing the shared idea of s...

Episode 85 — Post-Exploitation Goals 06.01.2026

This episode explains what to do after gaining access in a way that remains controlled, authorized, and focused on demonstrating meaningful impact rather than maximizing chaos. You’ll learn post-access goals such as confirming what you can reach, understanding privilege boundaries, identifying high value assets, and collecting evidence that supports a defensible finding while minimizing data expos...

Episode 84 — Automation and BAS Concepts 06.01.2026

This episode teaches automation and breach-and-attack simulation concepts as structured ways to improve repeatability, measurement, and control validation without relying on ad hoc testing. You’ll learn why automation matters for consistency, how repeated checks make trends visible across time, and how simulation approaches can evaluate detection and response readiness by generating controlled act...

Episode 83 — AI-Related Attacks (High-Level) 06.01.2026

This episode explains AI-related risks in scenario-friendly terms by treating them as input manipulation, access control, and data exposure problems rather than as mysterious model magic. You’ll learn prompt injection as crafted input that changes system behavior, data leakage as unintended disclosure of sensitive context or training-related information, and model manipulation as steering outputs...

Episode 82 — Specialized Systems: OT, NFC, RFID, Bluetooth 06.01.2026

This episode introduces specialized environments and technologies that appear in scenario questions as constrained systems with unique risks and operational expectations. You’ll learn OT constraints at a high level, emphasizing that safety and uptime drive conservative choices, then shift to NFC and RFID as short-range identity and access technologies where cloning, weak authentication, and replay...

Episode 81 — Mobile Attack Concepts 06.01.2026

This episode explains mobile risk through a practical lens, focusing on how apps handle data, permissions, communication, and device posture rather than on device-specific tooling. You’ll learn where mobile apps commonly expose sensitive information, such as unencrypted local storage, caches, logs, and backups, and how excessive permissions can expand what an attacker can access or manipulate. We’...

Episode 80 — Social Engineering Patterns 06.01.2026

This episode teaches social engineering as a predictable set of persuasion patterns that exploit trust, urgency, and process gaps to bypass technical controls. You’ll learn how tactics like phishing, vishing, smishing, spearphishing, and whaling differ by channel and targeting, and how pretexting uses believable stories to extract actions, credentials, or approvals. We’ll cover scenario cues that...

Episode 79 — Wireless Attack Patterns 06.01.2026

This episode explains common wireless attack patterns as trust and configuration problems, helping you interpret scenario clues without needing hands-on tooling. You’ll learn concepts such as evil twin networks that mimic trusted names, deauthentication behavior that forces reconnects, weak pairing and legacy configurations that reduce protection, and captive portal tricks that harvest credentials...

Episode 78 — Cloud Attack Patterns: Storage and Metadata 06.01.2026

This episode teaches two major cloud risk themes, exposed storage and metadata access, and how each can lead from data leakage to broader compromise. You’ll learn common storage exposure patterns such as public access, weak sharing controls, and mispermissions, and how to reason about impact in terms of confidentiality, compliance, and operational consequences. We’ll cover metadata services as int...

Episode 77 — Cloud Attack Patterns: Identity First 06.01.2026

This episode explains why cloud compromise often begins with permissions and trust relationships rather than with traditional network exploits, and how to recognize identity-first attack patterns from scenario cues. You’ll learn the key identity components in cloud environments, users, roles, policies, keys, and trust relationships, and how overprivileged roles expand blast radius far beyond a sin...

Episode 76 — Web Attack Mini-Scenarios 06.01.2026

This episode uses short web-focused scenarios to practice identifying the most likely weakness and choosing the safest next validation step when multiple explanations could fit. You’ll apply a drill method that starts with the clue and context, then tests your ability to distinguish injection from access control failure, session weakness from authentication failure, and SSRF-like behaviors from us...

Episode 75 — Deserialization and File Inclusion Concepts 06.01.2026

This episode explains two high-impact weakness patterns that often appear as “strange behavior” clues in scenarios, unsafe deserialization and file inclusion, and teaches you to reason about them without relying on exploit mechanics. You’ll learn deserialization as turning structured data into objects in a way that can trigger unintended behavior when the data is attacker-controlled, and file incl...

Episode 74 — SSRF vs CSRF (And Why They Differ) 06.01.2026

This episode clarifies two easily confused concepts by focusing on the key difference, who initiates the request and whose authority is being abused. You’ll learn SSRF as the server making unintended requests to internal or restricted resources because it accepts attacker-controlled URLs or destinations, and CSRF as a victim user’s browser being tricked into sending state-changing requests using t...

Episode 73 — Access Control Failures: IDOR and AuthZ 06.01.2026

This episode teaches you to recognize access control failures as authorization problems, not authentication problems, and to identify the IDOR pattern that repeatedly appears in real applications and scenario questions. You’ll learn authorization as the server-side decision about what a user is allowed to access or do, and IDOR as the specific case where changing an object identifier grants access...

Episode 72 — XSS Types and Outcomes 06.01.2026

This episode explains cross-site scripting as executing attacker-controlled script in a user’s browser context, then teaches you to distinguish reflected, stored, and DOM-based XSS from scenario cues. You’ll learn reflected XSS as immediate response-based reflection, stored XSS as persistence that affects multiple users over time, and DOM-based XSS as browser-side logic creating the weakness durin...

Listen to the Certified: The CompTIA PenTest+ (Plus) Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.