September 4, 2026
CPTS Path & Exam Review
Hello everyone! Before beginning my storytelling, I recommend you subscribe to my Telegram channel where I share my experience in Offensive…
By Annassir Mussin
6 min read
Hello everyone! Before beginning my storytelling, I recommend you subscribe to my Telegram channel where I share my experience in Offensive Security field, covering broad range of knowledge, suggestions, and tips — Cyberspace. Here are also my social media links where you can follow me — LinkedIn, HackTheBox.
I am glad to say that I am one of the CPTS cert holders )
What is my honest opinion on the course?
Personally, I liked how the course material and learning path are structured. The material was very well-written and comprehensive.
The CPTS course is dense and covers many topics, such as Reconnaissance, basic Web Exploitation, Privilege Escalation, and Lateral Movement. Moreover, the course contains all the knowledge you need and explains it thoroughly, so further research on most topics wasn't necessary.
Preparation for the exam was tough, and I have to say that I started it with only basic offensive security knowledge. I want to give Hack The Box credit for such a fabulous course. CPTS teaches all the necessary knowledge that a Penetration Tester should have.
I highly recommend the CPTS learning path to anyone looking to strengthen their penetration testing skills. Even if you don't plan to take the exam itself, the course provides a clear structure for organizing your knowledge and understanding the flow of real-world pentesting engagements. It also helps you develop the ability to recognize patterns, identify vulnerabilities, and approach assessments with greater confidence.
How much time did it take me to finish the path?
I started the Penetration Tester path in late February. At that point, I had already completed around 25–30% of the course, since I had fully completed the CWES path, which focuses on Web Exploitation. Because of that, some of the topics in the CPTS path were already familiar to me, especially when it came to web exploitation. I completed the CPTS path in just two months, starting in late February and finishing at the end of April (roughly from the 20s of February to the 20s of April). Even though I already had some knowledge from the CWES path, there was still a lot of new material to learn, especially when it came to areas like Active Directory and Pivoting.
I have to say that this was quite an intense period for me. During that time, I was doing an internship as a Penetration Tester at TSARKA Group, while also studying in my first year at university. On top of that, I still had to find time for my personal life. Balancing all three was not easy, especially when I wanted to properly understand the material instead of just rushing through the modules. Looking back, completing the path in two months was quite a challenging experience, but it also gave me a much better understanding of how different parts of penetration testing connect with each other.
What did I do to prepare?
I have to say that, unlike many other people who prepare for the CPTS exam, I didn't do much lab-solving outside of the Academy. I didn't complete any Pro Labs either, even though I constantly saw people saying that Dante Pro Lab is a must-have for anyone preparing for the CPTS exam.
In reality, I only did some seasonal Linux machines. So where did I get most of my practical experience? Maybe some of you won't believe it, but almost all of my practice came directly from the Academy itself.
I did a lot of the practice labs throughout the modules, and I went through the Skill Assessments a couple of times each. I also completed the Attacking Enterprise Networks module twice. For me, this module was especially useful because it gives you an environment that partially resembles the CPTS exam, with attack paths and a workflow that are quite similar to what you will experience during the exam. Of course, the number of machines and subnets is smaller, and the overall difficulty is lower than in the actual CPTS exam, but it still gives you a good idea of what to expect.
I also retook the Active Directory module several times. The first time I went through it, the penny simply didn't drop and I struggled a lot with understanding some of the concepts and attack paths. Instead of just moving on, I decided to go through the module again until I actually understood what I was doing. Looking back, this helped me a lot during the exam.
I would also say that having a solid understanding of Pivoting and Lateral Movement plays a significant role in successfully passing the CPTS exam. These are not topics that you can just memorize and forget. You need to understand how to move through a network, identify where you can go next, and recognize how different machines and services are connected. This was one of the areas that I found especially important during my preparation.
What about the exam?
Even though I finished the CPTS path by the end of April, I took the exam itself only in July because I was a broke student at the time :)
By then, my internship had ended, and I had finally earned enough money to afford the CPTS exam voucher. Once I started the exam, it took me around 3 days to complete roughly 85% of it, followed by another 1.5 days to prepare a proper report. So, in total, I spent around 4.5 days on the entire exam, from the 9th of July to the 13th of July.
It didn't take long to receive the results, and I was happy to find out that I had passed the exam on my first attempt. On the 14th of July, I officially received my CPTS certification.
One thing I have to mention is that I was already working full-time at that point, so I had to combine my job with the exam and work on it whenever I had some spare time. Because of that, time management was extremely important during those days. I had to plan my days carefully and make sure I could dedicate enough time to the exam without letting my work suffer.
Honestly, those 4.5 days were quite stressful. Even though I had prepared for the exam beforehand by completing the entire path, being in the actual exam environment is a completely different experience. Having a limited amount of time while also working full-time definitely added another layer of pressure. Still, I managed to get through it on my first attempt, which made receiving the certification on July 14th even more satisfying.
My tips for future CPTS candidates
If I had to give some advice to people who are currently preparing for the CPTS exam, the first and most important thing I would say is: learn to think like a hacker.
The technical knowledge is obviously important, but I believe that the mindset is even more important. During the exam, you will have a lot of information in front of you, and sometimes the solution is already there, you just need to notice it. Always pay close attention to what you find during enumeration. Don't just collect information because you are supposed to. Ask yourself why something is there, how it can be used, and what it can potentially lead to.
I actually learned this lesson the hard way during my own exam. I got stuck on the very first flag for around five hours, simply because I was being inattentive. The information I needed was basically in front of me, but I kept looking for something more complicated instead of properly analyzing what I had already found. After finally noticing what I had missed, I realized that I had wasted several hours for no good reason.
So, if you get stuck, don't immediately assume that you need some crazy technique or that you missed an advanced vulnerability. Sometimes you just need to stop, go back through your notes, re-enumerate something, or look at the information from a different perspective.
Another thing I strongly recommend is to deeply understand Active Directory, Privilege Escalation, and Lateral Movement. These are not topics that I would recommend simply going through once and moving on from. You should understand what is happening, why a particular attack works, and how different techniques can be combined.
In particular, make sure you are comfortable with Active Directory environments. Understand how users, groups, permissions, services, trusts, and different machines interact with each other. You should also be comfortable with privilege escalation and understand how to identify potential paths instead of relying on a single technique.
Finally, don't underestimate the importance of Lateral Movement and Pivoting. Understanding how to move from one compromised machine to another and how to work with different network segments is a major part of the overall penetration-testing workflow.
My biggest advice, however, remains the same: pay attention and develop the hacker mindset. Don't just ask yourself, "What tool should I run next?" Ask yourself, "What do I know right now, what does it tell me, and what can I do with it?" That change in thinking makes a huge difference, not only for the CPTS exam but for penetration testing in general.
Final thoughts
Overall, I can confidently say that CPTS was one of the most useful cybersecurity learning experiences I have had so far. What I liked the most is that the course doesn't just teach you individual techniques. It teaches you how to think during a penetration test and how different techniques connect together.
I also think the CPTS certification has a lot more value when you actually go through the entire learning path instead of treating it as just another certification to add to your CV. Even if you are not planning to take the exam, I would still recommend going through the path if you want to become a better penetration tester. Plus, student subscription costs 8$, not that expensive :)
Was the exam difficult? Yes.
Was the preparation stressful? Definitely.
Was it worth it? Absolutely.
I passed on my first attempt, but more importantly, I finished the path with a much better understanding of penetration testing than I had when I started. And for me, that is the biggest value of CPTS.