This article explains what CPTA covers, who it's designed for, what you'll learn, and what you can expect from the course and practical exam.
If you're looking to build practical offensive cybersecurity skills, CPTA provides a structured pathway through the fundamentals of penetration testing and shows you how individual techniques fit together across a real engagement.
What is CPTA?
The Certified Penetration Testing Associate (CPTA) is our offensive cybersecurity certification designed to give you a structured, practical way to build penetration testing skills.
Offensive security can be difficult to know where to start. There are countless tools, techniques, and areas to explore, from networking and operating systems to vulnerability assessment, exploitation, and understanding how attackers move through an environment.
CPTA brings these areas together into a structured learning path. Rather than treating offensive security techniques as isolated skills, you'll learn how they fit together across the different stages of a penetration testing engagement.
The course is hands on, with practical labs and realistic scenarios across infrastructure, Active Directory, web applications, and AWS environments.
Who is CPTA For?
CPTA is designed for people at different stages of their cybersecurity journey, including:
- Aspiring penetration testers and ethical hackers looking to build practical offensive security skills and work towards an offensive role
- SOC analysts, threat hunters, detection engineers, and incident responders looking to better understand attacker mindset, tools, techniques, and procedures
- Existing penetration testers, security consultants, and red team operators looking to broaden their knowledge across different technologies and attack techniques
Prerequisites
CPTA is recommended for people with 0 to 3 years of cybersecurity experience, although you don't need previous offensive security experience.
The course builds from technical foundations through to practical penetration testing techniques, making it suitable for people coming from different areas of cybersecurity.
You should have a baseline understanding of networking, Linux, and Windows. If you need to refresh these skills before starting, we have free foundational courses available.
What You'll Learn
CPTA covers more than 20 domains and takes you through the skills and techniques used throughout a penetration testing engagement.
- Technical foundations: networking, Linux, Windows and Python
- Discovery and vulnerability assessment: identifying hosts, services, operating systems and potential vulnerabilities
- Exploitation: password attacks, vulnerability exploitation and gaining access to systems
- Privilege escalation and lateral movement: building on initial access, gaining greater privileges and moving between systems
- Active Directory: understanding enterprise domains and exploring common enumeration, credential and authentication attacks
- Web applications: testing for vulnerabilities including IDOR, XSS, CSRF, SQL injection and command injection
- AWS: discovering public assets, exploring IAM and identifying potential exposure across EC2, S3 and Lambda
- Red teaming: an introduction to command and control and red team operations
An estimated 100 hours of study time, although the time required varies depending on your experience and learning pace. Beyond the technical skills, CPTA also covers the wider penetration testing process, including:
- Scoping and rules of engagement
- Setting expectations with clients
- Engagement planning and execution
- Reporting and communicating findings
- Remediation and retesting
Build Practical Offensive Security Skills
Understanding a technique is one thing. Being able to apply it is another.
Hands on practice is central to CPTA. Throughout the course, you'll work through practical labs and realistic scenarios where you can apply what you're learning across infrastructure, Active Directory, web applications, and AWS environments.
Rather than learning techniques in isolation, you'll build your understanding progressively and see how they come together across the different stages of a penetration test.
What's Included?
When you purchase CPTA, you'll receive:
- 4 months of on demand access to the course
- 20+ domains with 600+ lessons, activities, and quizzes
- 60+ hands on labs across infrastructure, Active Directory, web applications, and AWS
- 100 lab hours
- 2 exam attempts that must be used within 12 months of starting
- A three part practical exam covering infrastructure, web, and cloud assessments across three realistic eight hour exam labs
- A Credly digital badge and certificate on successful completion
The course is designed to give you plenty of opportunities to learn, practise, and apply your skills before putting them to the test in the practical exam.
Ready to Take the Next Step?
You can explore the full details on the main CPTA certification page or try the free CPTA demo to get a feel for the content before committing.
Still need help?
Submit a support ticket and our team will be happy to help.