Skip to content
CBT Nuggets
DemoBook a Demo

Network Penetration Testing Essentials (PEN-200)

This OSCP training​ prepares penetration testers, cybersecurity professionals, and red team operators to pass the challenging PEN-200 exam and earn their OSCP certification. You'll practice real-world penetration testing with virtual labs designed by experienced infosec pro Erik Choron. You'll also gain deep experience in areas like enumeration, privilege escalation, and Active Directory exploitation as you apply tools like Metasploit, Kali Linux, and tunneling frameworks in real-world scenarios. After taking this OSCP training, you'll be ready to pass the PEN-200 exam with confidence.

Updated December 2025

46Skills
358Videos
43Virtual Labs
1Practice Exam
37hTotal

Who This Course Is For

This course is for IT professionals who want to break into offensive security, including those in blue team roles ready to pivot to red teaming. If you're ready to move from theory to hands-on, real-world exploitation in a lab setting, this PEN-200 and OSCP+ course are meant for you.

Skills Your Team Will Gain

  • Perform enumeration and vulnerability scanning
  • Exploit SQL injection and client-side vulnerabilities
  • Bypass protections and escalate privileges on Windows and Linux
  • Conduct tunneling and port redirection
  • Use Metasploit Framework to manage and deliver exploits
  • Attack Active Directory authentication and move laterally

Course Curriculum

One skill is free to watch — no signup needed. The other 45 premium skills unlock for your whole team with a CBT Nuggets plan.

Free skill preview

Beginning Pen-200

Erik ChoronDuration: 50m16 videos

Watch this complete skill free — the same trainer, videos, and labs your team gets with a plan.

Watch free skill
  • Beginning Pen-200Free50m · 16 videos
  • Premium skill.Pen Testing Lifecycle with Reconnaissance46m · 16 videos
  • Premium skill.Exploit resources47m · 15 videos
  • Premium skill.Metasploit fundamentals54m · 13 videos · 1 lab
  • Premium skill.Metasploit Payloads57m · 16 videos · 1 lab
  • Premium skill.Scanning with nMap46m · 12 videos · 1 lab
  • Premium skill.Scanning with Nessus (Active)53m · 14 videos · 2 labs
  • Premium skill.Detailed Active Scanning with Nessus52m · 12 videos · 1 lab
  • Premium skill.OpenVAS51m · 12 videos · 1 lab
  • Premium skill.Passive Scanning for Vulnerabilities59m · 12 videos · 2 labs
  • Premium skill.Deeper into Passive Scanning48m · 10 videos · 1 lab
  • Premium skill.Web Application Assessment51m · 13 videos · 1 lab
  • Premium skill.Web Application Assessment Tools55m · 14 videos · 1 lab
  • Premium skill.Burpsuite46m · 12 videos · 1 lab
  • Premium skill.Cross-Site Scripting XSS50m · 12 videos · 1 lab
  • Premium skill.Directory Traversal48m · 12 videos · 1 lab
  • Premium skill.File Inclusion Attack48m · 11 videos · 1 lab
  • Premium skill.Command Injection47m · 13 videos · 1 lab
  • Premium skill.SQL Theory and Exploration50m · 14 videos · 1 lab
  • Premium skill.Exploiting Microsoft Office47m · 13 videos
  • Premium skill.Windows Library Files52m · 13 videos · 1 lab
  • Premium skill.Abusing Windows Library Files55m · 13 videos · 1 lab
  • Premium skill.Advanced DLL Injection45m · 13 videos · 1 lab
  • Premium skill.Post-Exploitation with Metasploit50m · 13 videos · 1 lab
  • Premium skill.Password Attacks - Understanding47m · 13 videos · 1 lab
  • Premium skill.Password Attacks - Methodology50m · 14 videos · 1 lab
  • Premium skill.Password Attacks - Physical Attack47m · 10 videos · 1 lab
  • Premium skill.Password Attacks - Tools48m · 14 videos · 1 lab
  • Premium skill.Windows Enumeration53m · 15 videos · 1 lab
  • Premium skill.Leveraging Windows Services47m · 14 videos · 1 lab
  • Premium skill.Linux Enumeration47m · 14 videos · 1 lab
  • Premium skill.Linux Insecurity47m · 12 videos · 1 lab
  • Premium skill.Linux File Insecurity46m · 14 videos · 1 lab
  • Premium skill.Port Forwarding and Tunneling45m · 12 videos · 1 lab
  • Premium skill.Deep Packet Inspection47m · 13 videos · 1 lab
  • Premium skill.Other Tunneling Tools45m · 10 videos · 1 lab
  • Premium skill.Antivirus Evasion44m · 13 videos
  • Premium skill.Automating Metasploit46m · 14 videos · 1 lab
  • Premium skill.Memory Corruption Exploits46m · 13 videos · 1 lab
  • Premium skill.Fixing Web Exploits44m · 12 videos · 1 lab
  • Premium skill.Understanding Active Directory Authentication46m · 12 videos · 1 lab
  • Premium skill.Active Directory Manual Enumeration47m · 11 videos · 1 lab
  • Premium skill.Active Directory Automated Enumeration46m · 11 videos · 1 lab
  • Premium skill.Attacks on Active Directory Authentication50m · 14 videos · 1 lab
  • Premium skill.Active Directory Persistence44m · 12 videos · 1 lab
  • Premium skill.Lateral Movements and Post-cleanup46m · 13 videos · 1 lab
Want to browse the locked skills?
with no purchase required. Already have an account?

An account gets you the full catalog to browse, pre-assessments, quiz questions on free skills, and IT Trainerbot, with every answer citing its source video.

Certification

Offensive Security Certified Professional (OSCP)

PEN-200 is OffSec’s hands-on ethical hacking and penetration testing certification course for aspiring penetration testers and security professionals. It teaches learners to identify and exploit real-world vulnerabilities across computers, network se...

Exam PEN-200Level ProfessionalDifficulty AdvancedCost $1,699
Enumeration and information gatheringVulnerability scanning and assessmentEncryption and cryptographyXSSCommand InjectionDirectory Traversal
Official certification page

Put this course to work for your team

Every plan includes this course plus the full library, virtual labs, and practice exams — or talk it through with sales.

For IT leaders

What IT leaders need to know before assigning this course

Security teams need repeatable penetration testing skills to find exploitable weaknesses before they become incidents, audit findings, or emergency contractor work. This advanced PEN-200 course fits IT Practitioners moving into offensive security, security engineers who support vulnerability validation, and Team Leads building an internal red-team capability. The visible curriculum alone is about 33 hours, plus additional skills, so IT Directors should plan roughly a full training week per learner and allow extra practice time for OSCP+ readiness.

Because the course covers offensive tooling and techniques — including Metasploit, password attacks, antivirus evasion, tunneling, and exploitation of Windows, Linux, and web applications — assign it within clear rules of engagement and approved lab or test environments. CBT Nuggets Playlists can help Training Managers sequence the rollout, while Team Reporting helps leaders track progress across assigned learners.

Team Impact

How this training helps your team succeed

IT teams complete this training to turn vulnerability data into actionable security validation. The curriculum moves from reconnaissance and scanning into exploitation, post-exploitation, enumeration, tunneling, and web application assessment, giving security teams a practical workflow for controlled penetration testing.

  • Validate exposure with tools and methods such as Nmap scanning, Nessus active scanning, OpenVAS, and passive vulnerability discovery.
  • Assess web applications for common attack paths, including XSS, directory traversal, file inclusion, command injection, and SQL exploration.
  • Investigate Windows and Linux systems through enumeration, insecure services, file permissions, DLL injection concepts, and library file abuse.
  • Practice controlled exploitation workflows with Metasploit, payloads, post-exploitation, password attack methodology, port forwarding, tunneling, and traffic inspection.

After completion

Capabilities your team walks away with

Knowledge

  • Penetration testing lifecycle concepts, including reconnaissance and vulnerability discovery.
  • How exploit resources, Metasploit fundamentals, payloads, and post-exploitation fit into an authorized test.
  • Differences between active scanning, detailed Nessus scanning, OpenVAS usage, and passive scanning approaches.
  • Common web application weaknesses, including XSS, directory traversal, file inclusion, command injection, and SQL-related issues.
  • Windows and Linux enumeration concepts, including services, file insecurity, library files, and DLL injection topics.

Ability

  • Run structured reconnaissance and scanning activities using tools covered in the course, including Nmap, Nessus, and OpenVAS.
  • Use Burp Suite and other web assessment tools to investigate web application attack paths.
  • Apply Metasploit workflows for exploitation, payload handling, automation, and post-exploitation practice in authorized environments.
  • Evaluate password attack methodology and related tools, including physical attack considerations.
  • Analyze tunneling, port forwarding, deep packet inspection, antivirus evasion, and memory corruption exploit concepts.

Readiness check

Confirm prerequisite knowledge before training begins

A short placement assessment on the CBT Nuggets assessments platform measures whether a learner already has the foundation this course assumes. IT Directors use it to put the right people in the right training — and any learner can take it right now to make sure they'll get full value from day one.

  • Questions generated from this course's own video transcripts — what gets measured is exactly what gets taught
  • Instant, per-learner results that show whether the prerequisite foundation is in place
  • Results roll up into team readiness reporting, so training hours go where they change outcomes
Runs on assessments.cbtnuggets.com — sign in with an Adept account so results roll up into team readiness reporting. Need one?
.

If gaps show up, start here

Kali Linux Revealed (PEN-103)

Master Kali Linux, earn your KLCP certification, and prepare for the the PEN-103 exam. This associate-level Kali Linux Certified Professional course dives deep into penetration testing, perfect for cybersecurity pros like pentesters and network secur...

~6h

This course is included with every subscription

Unlock this one course, or get one learner — or your whole team — access to all 287 courses, virtual labs, and practice exams.

Course Unlock

Just need this course?

$225one time

No subscription

One year of access to OSCP

  • Every skill in this course
  • Its virtual labs and practice exam
  • Ask IT Trainerbot about it — free

CBT Nuggets Individual

IT Trainerbot Pro

$49per month

Billed annually

Every course, for one learner

See Individual pricing
For IT teams

CBT Nuggets Teams

IT Trainerbot for Teams

$59per seat / mo

Billed annually

From 1 learner seat · unlimited admin seats

Checking your access

Need tenant hosting, reseller terms, or payment plans on a larger agreement? Book a Demo to discuss an Enterprise contract.

See plans and pricing for your team

Trusted by 23,000+ organizations

Frequently Asked Questions

Is the PEN-200 exam really that hard?

Yes, the PEN-200 exam is notoriously difficult, but this OSCP training is designed to make it manageable. You’ll face a 24-hour hands-on challenge that tests your stamina as much as your technical skill. This OSCP course is taught by real-world cybersecurity professional and CBT Nuggets trainer Erik Choron. He'll break down the complex exam content into digestible 10-15 minute lessons, and provide you with virtual labs to build the muscle memory you need on exam day.

How much can I earn with an OSCP certification?

Most OSCP holders command salaries ranging from $90,000 to over $130,000 depending on their role and experience level. Because the exam is famously difficult, employers view the credential as a gold standard, often making it a requirement for high-paying senior penetration testing and security consulting positions.

How much does the OSCP+ cost?

The official OffSec certification bundle for PEN-200 starts at $1,749. This price includes official course materials, 90 days of lab access, and one attempt at the OSCP+ exam. By using this CBT Nuggets training as a resource first, you can master the difficult technical concepts at a better price point before you commit to the full expense of the official OffSec bundle (and start your 90-day lab clock). With an exam this expensive, it's definitely worth it to be fully prepared before you schedule your exam.

What is the difference between the OSCP and OSCP+?

The main difference is that the OSCP+ is the version of the certification that requires maintenance through Continuing Professional Education (CPE) credits, or recertification every three years. While the core technical skills tested in the PEN-200 are the same, the "+" indicates that your credential is active and your skills are up-to-date. Passing the PEN-200 exam earns you an OSCP+ certification. If your OSCP+ expires, it will become a traditional OSCP, which is valid for life and does not expire.

Does this OSCP training include unlimited virtual labs?

Yes, this course contains integrated virtual labs designed by cybersecurity expert Erik Choron. This will allow you to practice exploits in a live, sandboxed environment directly through your browser. You'll be able to perform enumeration, privilege escalation, and Active Directory attacks on real targets without having to configure your own local virtual machines. These labs are specifically designed to build the muscle memory you need to succeed during the 24-hour PEN-200 exam.

Ready to upskill your team?

Talk to our sales team to find the right plan for your organization.