About Exam

The exam formate is pretty much same as of Certified AppSec Pentester (CAPen) exam. you can read about that here.

My Thoughts on the Exam and Some Tips

The exam consists of 15 multiple-choice, and CTF-type questions. Each question is allocated an appropriate score based on its level of difficulty.

I think the exam difficulty was like an easy-rated HTB machine. The following HTB machines are very close to the exam lab environment that I could find.

Make sure to read the above HTB write-ups. You will be using very similar techniques.

The NetExec tool was very useful; make sure to get comfortable using it. During the exam, to use tools like Mimikatz, you will need to transfer them to target machine. Learn some techniques on how to transfer files/tools between your machine and the target machine.

I have observed that the exam lacks dynamic questions. The questions and flags remain the same in every attempt. In my opinion, this is a significant drawback. If the exam questions are leaked, it would undermine the exam’s credibility and reduce its value.


Happy Hacking