Look for the flaws of a system you are mandated to test, and get them fixed.
Next intake: Monday 5 October, with enrolment open until 2 October. The following one starts on 4 January 2027.
Know what Cameroonian law says about access to an information system
Establish a mandate: scope, intervention window, emergency contacts
Refuse what is never done, even when authorised: real data, denial of service
Map an organisation's public footprint and technical perimeter
Keep a test log that records every action, with its date
Exploit the most common application vulnerabilities in an isolated lab
Score a vulnerability, write a report and support remediation
Systematic alternation between short theory sessions and practical work, with most of the time spent on practice
Progression from simple to complex: each module builds on what was learnt in the previous one
Realistic role-plays drawn from Cameroonian business cases
Considered use of generative AI as a working tool, in line with the common core
Regular formative assessments and a final integrative project drawing on all four modules
Formative assessment at the end of each module (graded role-play and practical exercises)
Practical work assessed against competency sheets
Final integrative project, presented and defended before the trainer
One graded assignment per module in the online course space
Kali Linux in a strictly isolated lab
Deliberately vulnerable applications: DVWA, Juice Shop, VulnHub
Nmap, Burp Suite Community, enumeration tools
CVSS scoring grid and penetration test report template
Mandate and rules of engagement template
Sessions open every quarter. Apply now or request the detailed brochure — our advisers will get back to you.