Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Core

Mobile Application Security and Penetration Testing

Mobile apps hold tokens, keys and personal data on devices you do not control, which changes how you test them. This mobile application penetration testing course covers iOS and Android together, using static and dynamic analysis against apps we provide in the academy lab.

You examine insecure storage, weak transport security, and the platform-specific attack surface of each operating system, then report findings a mobile development team can reproduce and fix under a clear scope.

Duration
8 weeks
Format
Live online, instructor-led
Prerequisites
None required
Class size
Capped at 12 learners
Mobile Application Security and Penetration Testing

What you will be able to do

  • Set up an iOS or Android device for authorized application testing
  • Reverse a mobile app package and find hardcoded secrets and endpoints
  • Bypass root, jailbreak and certificate pinning defences in the lab
  • Inspect local storage for tokens, keys and personal data
  • Verify transport security and find data leaks through logs and backups
  • Assess inter-app communication and platform component misuse
  • Write a mobile finding a developer can reproduce and fix

Course outline

5 modules

  • iOS and Android security models compared
  • Setting up a testing device or emulator
  • Intercepting app traffic
  • Scope and rules of engagement for mobile

What you need before you start

  • Comfort with the command line and reading code
  • Basic understanding of how mobile apps talk to backends
  • A computer able to run an emulator or connect to a test device

Who this course is for

  • Penetration testers adding mobile to their coverage
  • Mobile developers who want to test their own apps
  • Application security engineers reviewing mobile releases
  • Testers preparing for the CompTIA PenTest+ exam

Where this leads

Prepares you for

PenTest+

Awarded by CompTIA

The PenTest+ certification is granted by CompTIA on passing its exam and never by the academy. The scoping, hands-on testing and reporting practised in this mobile course reflect the penetration testing process that PenTest+ assesses.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.