Skip to content

Course Assessment & Learning Checklist

By the end of this lesson, you will be able to:

  • Evaluate your readiness for the Cloud Penetration Tester learning path.
  • Confirm your lab environment is fully prepared.
  • Validate your foundational knowledge.
  • Build a personalised learning plan.
  • Understand the expectations for the remainder of the course.

Congratulations!

You have completed the Start Here section of the Cloud Penetration Tester learning path.

Before moving into technical modules, take time to ensure you are fully prepared.

Professional penetration testers never begin an assessment without preparation.

Similarly, successful students prepare their environment, tools and mindset before beginning practical labs.


Throughout the Start Here module, you have explored:

  • Welcome to the Course
  • Career Roadmap
  • Course Overview
  • Lab Environment Setup
  • Required Knowledge
  • Learning Methodology
  • Cloud Penetration Testing Lifecycle
  • Rules of Engagement
  • Portfolio Development

These lessons provide the foundation for everything that follows.


Knowledge
Lab Environment
Cloud Skills
Hands-on Practice
Enterprise Projects
Professional Reporting
Career Readiness

Each stage builds upon the previous one.


Answer the following questions honestly.

Can you explain:

  • Shared Responsibility Model?
  • Cloud Regions?
  • Availability Zones?
  • Virtual Networks?
  • IAM?
  • Object Storage?
  • Compute Services?

Assessment:

  • Yes
  • Needs Improvement

Can you explain:

  • TCP/IP
  • DNS
  • HTTP
  • HTTPS
  • Routing
  • Firewalls
  • NAT
  • VPN
  • Load Balancers

Assessment:

  • Yes
  • Needs Improvement

Can you confidently use:

  • SSH
  • Bash
  • File permissions
  • Package management
  • Process management
  • Networking commands

Assessment:

  • Yes
  • Needs Improvement

Have you used:

  • AWS
  • Azure
  • Google Cloud

Assessment:

  • Yes
  • Needs Improvement

Do you understand:

  • Docker Images
  • Containers
  • Dockerfiles
  • Registries
  • Volumes
  • Networking

Assessment:

  • Yes
  • Needs Improvement

Can you explain:

  • Pods
  • Deployments
  • Services
  • Namespaces
  • RBAC
  • Secrets
  • ConfigMaps
  • Network Policies

Assessment:

  • Yes
  • Needs Improvement

Do you understand:

  • Authentication
  • Authorization
  • Encryption
  • Risk
  • Vulnerability
  • Threat
  • Security Controls

Assessment:

  • Yes
  • Needs Improvement

Confirm your environment is ready.

  • AWS account
  • Azure account
  • Google Cloud account

  • Visual Studio Code
  • Git
  • Python
  • Docker Desktop
  • kubectl
  • Helm

  • AWS CLI
  • Azure CLI
  • Google Cloud CLI

  • Virtual Machine Software
  • Kali Linux
  • Ubuntu (optional)

  • GitHub Account
  • Markdown Editor
  • Terraform
  • VS Code Extensions

  • Nmap
  • Burp Suite Community Edition
  • Trivy
  • ScoutSuite
  • Prowler
  • kube-bench
  • Kubescape
  • kube-hunter

Before moving forward, ensure you have created your portfolio structure.

Cloud-Pentest-Portfolio/
├── README.md
├── Labs/
├── Projects/
├── Reports/
├── Scripts/
├── Terraform/
├── Architecture/
├── Evidence/
├── Screenshots/
└── Notes/

Checklist:

  • Portfolio created
  • GitHub repository created
  • README written
  • Folder structure organised

A consistent schedule is more valuable than occasional long study sessions.

Activity Hours
Lessons 3–4
Hands-on Labs 5–8
Projects 3–5
Documentation 2
Revision 2

Suggested total:

15–20 hours per week

Adjust this based on your availability and experience.


Throughout this course, you are expected to:

  • Complete every lesson.
  • Finish every lab.
  • Perform every enterprise project.
  • Read every runbook.
  • Maintain your portfolio.
  • Take notes.
  • Repeat practical exercises.
  • Ask questions when needed.

Lesson
Knowledge Check
Hands-on Lab
Enterprise Project
Runbook
Documentation
Portfolio Update
Revision

Follow this workflow throughout the learning path.


As a future Cloud Penetration Tester:

Always:

  • Respect legal boundaries.
  • Follow Rules of Engagement.
  • Protect confidential information.
  • Document findings accurately.
  • Recommend practical remediations.
  • Continue learning.

Never:

  • Test systems without authorisation.
  • Share customer information.
  • Publish sensitive credentials.
  • Ignore business impact.
  • Skip documentation.

Professionalism is as important as technical ability.


By the end of this learning path, you will be able to:

  • Assess cloud infrastructure.
  • Perform cloud reconnaissance.
  • Evaluate IAM security.
  • Review Kubernetes environments.
  • Identify cloud misconfigurations.
  • Assess cloud storage.
  • Test containers securely.
  • Produce professional penetration testing reports.
  • Communicate technical findings to business stakeholders.
  • Recommend practical security improvements.

To complement this learning path:

  • AWS Certified Cloud Practitioner
  • CompTIA Security+
  • Microsoft Azure Fundamentals (AZ-900)
  • Google Cloud Digital Leader
  • AWS Certified Security – Specialty
  • Microsoft Azure Security Engineer (AZ-500)
  • Google Professional Cloud Security Engineer
  • Certified Kubernetes Security Specialist (CKS)
  • Offensive Security Certified Professional (OSCP)
  • Certified Information Systems Security Professional (CISSP)

Before beginning Module 01, confirm:

  • Lab environment is operational.
  • Cloud accounts are configured.
  • Required software is installed.
  • Portfolio repository is created.
  • Study schedule is planned.
  • Networking fundamentals reviewed.
  • Linux fundamentals reviewed.
  • Cloud fundamentals understood.
  • Docker basics understood.
  • Kubernetes basics understood.
  • Ethical hacking principles understood.
  • Rules of Engagement understood.

Area Status
Cloud Fundamentals ☐ Ready ☐ Review
Networking ☐ Ready ☐ Review
Linux ☐ Ready ☐ Review
AWS ☐ Ready ☐ Review
Azure ☐ Ready ☐ Review
Google Cloud ☐ Ready ☐ Review
Docker ☐ Ready ☐ Review
Kubernetes ☐ Ready ☐ Review
IAM ☐ Ready ☐ Review
Security Fundamentals ☐ Ready ☐ Review
Lab Environment ☐ Ready ☐ Review
Portfolio ☐ Ready ☐ Review

Complete this scorecard honestly to identify any areas requiring additional study.


1. Why is preparation important before starting cloud penetration testing?

Section titled “1. Why is preparation important before starting cloud penetration testing?”

Answer: Preparation ensures you have the necessary knowledge, tools, lab environment and understanding of ethical practices to perform assessments safely and effectively.

2. Why should you maintain a professional portfolio throughout this learning path?

Section titled “2. Why should you maintain a professional portfolio throughout this learning path?”

Answer: A portfolio demonstrates your practical skills, documents your projects and provides evidence of your experience for employers and clients.

3. Why is documentation important during penetration testing?

Section titled “3. Why is documentation important during penetration testing?”

Answer: Documentation records evidence, supports findings, communicates business impact and helps organisations implement effective remediation.

4. Why should you complete every lab and project rather than only reading the lessons?

Section titled “4. Why should you complete every lab and project rather than only reading the lessons?”

Answer: Hands-on practice develops practical skills, reinforces theoretical knowledge and prepares you for real enterprise cloud penetration testing engagements.

5. What should you do if you identify gaps during this assessment?

Section titled “5. What should you do if you identify gaps during this assessment?”

Answer: Review the relevant lessons, strengthen your foundational knowledge, practise in your lab environment and revisit the assessment before progressing.


  • Strong fundamentals lead to stronger penetration testing skills.
  • Hands-on practice is the core of this learning path.
  • Maintain your portfolio from day one.
  • Follow professional standards and ethical guidelines.
  • Learn consistently rather than rushing through the material.
  • Enterprise projects and runbooks simulate real consulting engagements.
  • Continuous improvement is essential for long-term success.

🎉 You have successfully completed the Start Here module.

You now have:

  • A structured learning roadmap.
  • A prepared lab environment.
  • A professional learning methodology.
  • An understanding of the cloud penetration testing lifecycle.
  • Knowledge of ethical and legal responsibilities.
  • A plan for building your professional portfolio.

You are now ready to begin your technical journey into cloud offensive security.


Module 01 — Cloud Offensive Security Foundations

Section titled “Module 01 — Cloud Offensive Security Foundations”

In the next module, you will begin developing the technical foundations required for cloud penetration testing.

You will learn:

  • Cloud Security Fundamentals
  • Shared Responsibility Model
  • Cloud Architecture
  • Cloud Networking
  • Identity & Access Management (IAM)
  • Compute Services
  • Cloud Storage Security
  • Logging & Monitoring
  • Containers
  • Kubernetes Fundamentals

These concepts form the technical foundation for every cloud penetration testing engagement you will perform throughout this learning path.

➡️ Next Module: Module 01 — Cloud Offensive Security Foundations