Skip to main content

Penetration testing within an authorised scope

Look for the flaws of a system you are mandated to test, and get them fixed.

Block code
CYBER-OFF
The format

Three months, two hours a day.

  • Certificate programme · 128 h
  • Two hours a day
  • 250,000 F — the same fee for all sixty
  • All in the same format, at the same fee.
The qualification

A CQP under MINEFOP accreditation.

  • Leads to the CQP — Certificat de Qualification Professionnelle, which the ministry used to call the AQP.
  • Awarded under MINEFOP accreditation.
  • The full programme for the same profession remains open to anyone aiming for the complete qualification.
Sessions

A new session opens every quarter.

Next intake: Monday 5 October, with enrolment open until 2 October. The following one starts on 4 January 2027.

  • First-quarter intake — enrolment closes on 2 October5 Oct.
  • Second-quarter intake — 20274 Jan.
Objectives

What you will be able to do.

  • Know what Cameroonian law says about access to an information system

  • Establish a mandate: scope, intervention window, emergency contacts

  • Refuse what is never done, even when authorised: real data, denial of service

  • Map an organisation's public footprint and technical perimeter

  • Keep a test log that records every action, with its date

  • Exploit the most common application vulnerabilities in an isolated lab

  • Score a vulnerability, write a report and support remediation

Programme

Four modules.

  1. Module 0132 h

    Legal framework, mandate and rules of engagement

  2. Module 0232 h

    Reconnaissance and scope mapping

  3. Module 0332 h

    Application exploitation in the lab

  4. Module 0432 h

    Reporting, severity and supporting remediation

Who it is for

Who it is aimed at.

  • Access subject to prior successful completion of the Endpoint and network security technician block and to signing a commitment charter: the techniques taught are only ever practised within a scope authorised in writing. This is not boilerplate — it is what separates an audit from an offence.
Afterwards

Where it leads.

  • Junior penetration tester, technical auditor, application security consultant. Enrolment in this certificate programme is subject to prior successful completion of the Endpoint and network security technician block and to signing the commitment charter: the techniques taught are only ever practised within a scope authorised in writing.
Method

How it works.

  • Systematic alternation between short theory sessions and practical work, with most of the time spent on practice

  • Progression from simple to complex: each module builds on what was learnt in the previous one

  • Realistic role-plays drawn from Cameroonian business cases

  • Considered use of generative AI as a working tool, in line with the common core

  • Regular formative assessments and a final integrative project drawing on all four modules

Assessment

How you are assessed.

  • Formative assessment at the end of each module (graded role-play and practical exercises)

  • Practical work assessed against competency sheets

  • Final integrative project, presented and defended before the trainer

  • One graded assignment per module in the online course space

Tools

What you work with.

  • Kali Linux in a strictly isolated lab

  • Deliberately vulnerable applications: DVWA, Juice Shop, VulnHub

  • Nmap, Burp Suite Community, enumeration tools

  • CVSS scoring grid and penetration test report template

  • Mandate and rules of engagement template

Join the next session

Ready to get started?

Sessions open every quarter. Apply now or request the detailed brochure — our advisers will get back to you.