This article covers everything you need to know about the CPTA exam - how it works, how it's graded, and what happens if you need to resit.
Getting Started
Clients enrolled in the Certified Penetration Testing Associate (CPTA) course can begin their practical assessment at any time within their 12 month Exam Access period.
The exam consists of 3 separate 8 hour assessment labs, giving you 24 hours of total assessment time. Each lab can be scheduled independently, so you do not need to complete all three consecutively.
Before sitting the exam, we recommend completing all course materials, labs, quizzes, and activities to ensure you’re fully prepared.
Exam Format
The Certified Penetration Testing Associate (CPTA) exam is a practical assessment consisting of three separate assessment labs:
- Infrastructure (INFRA) Lab (8 hours): Multi host network discovery, Active Directory enumeration and attacks, Linux and Windows privilege escalation, and lateral movement.
- Web Application Lab (8 hours): Identifying and exploiting web vulnerabilities across multiple web applications.
- Cloud (AWS) Assessment Lab (8 hours): Identifying cloud exposure, S3 bucket and IAM misconfigurations, and AWS privilege escalation paths.
You can take the three labs in any order and schedule them individually throughout your 12 month Exam Access period. You do not need to complete them back to back, within 24 hours, or on consecutive days.
-
Overall Deadline: 12 Month Exam Access Window
- Once you activate your certification training, you have 12 months of total Exam Access.
- All three assessment labs must be completed within this 12 month period.
-
You can space the labs out however you prefer, for example by taking one lab per week or month.
-
Rules Once a Specific Lab Is Started
- Each individual exam lab has an 8 hour duration.
- Once you click Start Exam for a specific lab, the 8 hour countdown begins and runs continuously. It cannot be paused, stopped, or reset once started.
- When the 8 hours end, the answers and flags submitted during that session are locked in.
Exam Rules
Important:
The use of AI tools, including but not limited to ChatGPT, Gemini, Copilot, or any similar AI assistant, is strictly prohibited.
Seeking help from AI or other individuals is considered cheating and may result in disqualification.
Before sitting the exam, please review the CPTA Exam NDA for the full exam rules.
Submission and Grading
The exam is graded immediately upon submission, and you'll receive feedback on incorrectly answered questions.
- A score of 70% or above in each of the three labs is required to pass the certification overall and earn the silver challenge coin.
- A score of 90% or above in every lab on your first attempt earns the gold challenge coin.
Feedback on incorrect answers is intended to give you a general understanding of where you went wrong and help you prepare if a resit is required.
For full details on how submissions are graded, see Exam Marking Policy.
Exam Result Review
If you’d like your submission rechecked after your results are released, you can request a manual review from the Exam Marking Team.
Reviews are independent of the original marking and may increase your score, but will never lower it.
See Exam Result Review Policy & Marking Timeframes for full details on eligibility, timeframes, and how to request a review.
Resit Policy
The CPTA exam consists of three independent penetration testing labs. Each lab is treated separately for resit purposes.
- Two Exam Attempts Included: Each CPTA purchase includes two attempts for each lab.
- Second Attempt (Retake): If you fail a lab, you're eligible for a second attempt at no additional cost.
- Independent Resits: You only need to resit the lab you failed, not the labs you've already passed.
- Resit Restrictions: You must wait at least 10 days after a failed attempt before resitting that lab.
For full details on Exam Access and extensions, see Certification and Exam Access.
Still Need Help?
Submit a support ticket and our team will be happy to help.