About the CPENT
EC-Council is rewriting the standards of penetration testing skill development with the Certified Penetration Testing Professional, the CPENT certification program. What makes this program unique is our approach that allows you to attain two certifications with just one exam. The key philosophy behind the CPENT is simple – a penetration tester is as good as their skills; that’s why we urge you to go beyond Kali Linux and go beyond tools.
Not that we don’t believe in the OS or tools, but candidates with an over-reliance on Kali tools find it incredibly difficult to adapt to the multi-disciplinary approach of the real-world penetration testing engagements. We urge you to go beyond and explore the vast horizons of penetration testing that differentiate the great from the good. Ergo, the knowledge, skills, and abilities you learn from the CPENT program will allow you to challenge network types and not just one or two specialties. What makes the CPENT different is the requirement to display skills across multiple disciplines, forcing the candidate to “think on their feet.” It makes CPENT the first of its kind in the list of Pen testing programs! Our research shows that knowledge-based certifications alone do not necessarily equate to well-rounded skillsets when the candidates are put on a complex cyber range. In fact, many do not even have the skills to create routing tables, which is the first step to pivot invisible networks. Without the use of an automated tool, most pen testers struggled, then when simple stateless filtering was present, the few that had added the correct networking details stalled, and only a few ever got past the first hurdle. In short, no one made it through all of the hurdles, leading to the creation of the CPENT.
The Purpose of the CPENT
Years of research showed us that most pentesting candidates have gaps in their skills when it comes to multiple disciplines. Furthermore, the metrics revealed that when the targets are not located on either the same or a directly connected and reachable segment, a few can perform as well as they do it when on a direct or a flat network.
That’s why, for the first time in the industry, the assessment for the Certified Penetration Tester (CPENT) will be about multiple disciplines and not just one or two specialty types. Everything presented in the course is through an enterprise network environment that must be attacked, exploited, evaded, and defended. EC-Council’s CPENT provides the industry with the capability to assess a Pentester’s skills across a broad spectrum of “network zones.” What makes the CPENT different is the requirement to be provided a variety of different scopes of work so that the candidate can “think on their feet.” The result of this is that different zones represent various types of testing. Anyone attempting the test will have to perform their assessment against these different zones.
- Penetration Testers
- Ethical Hackers
- Information security Consultant
- Security Testers
- Security Analysts
- Security Engineers
- Network Server Administrators
- Firewall Administrators
- System Administrators
- Risk Assessment Professionals
CPENT is a fully online, remotely proctored practical exam, which challenges candidates through a grueling 24-hour performance-based, hands-on exam, categorized into 2 practical exams of 12-hours each, which will test your perseverance and focus by forcing you to outdo yourself with each new challenge. Candidates have the option to choose either two 12-hour exams or one 24-hour exam depending on how straining they would want the exam to be.
Exam features:
- Choose your challenge! Either two 12-hour sessions or a single 24-hour exam!
- Join the league of extraordinary pen testers by scoring more than 90% and becoming an LPT (Master)!
We strongly recommend candidates to attempt the CEH (Practical) and/ or ECSA (Practical) prior to attempting the CPENT Challenge.
Blue PrintPassing Criteria:
In order to maintain the high integrity of our certification exams, EC-Council Exams are provided in multiple forms (i.e., different question banks). Each form is carefully analyzed through beta testing with an appropriate sample group under the purview of a committee of subject matter experts that ensure that each of our exams not only have academic rigor but also have “real world” applicability. We also have a process to determine the difficulty rating of each question. The individual rating then contributes to an overall “Cut Score” for each exam form. To ensure each form has equal assessment standards, cut scores are set on a “per exam form” basis. Depending on which exam form is challenged, cut scores can range from 60% to 85%.
Clause: Age Requirements and Policies Concerning Minors
Minors are not permitted to take the EC-Council exam without a written consent/indemnity letter signed by their parent or legal guardian, along with a supporting letter from their institution of learning. Only candidates from a nationally accredited institution of learning shall be considered.
Minor/Adult legal ages are defined by the country of residence/origin for the candidate. For further clarification or to submit a letter of consent, please contact [email protected]. EC-Council reserves the right to revoke the certification status of candidates in case of non-compliance with this policy.
Disclaimer (Certification vs. Licensure)
- The terms “Licensed Penetration Tester (LPT)” and “LPT (Master)” refer to a professional certification designation awarded by EC-Council upon successful performance in the CPENT examination framework.
- This designation is not a government-issued professional license.
- The certification does not confer statutory authority, or regulatory permissions required to practice in any jurisdiction.
- EC-Council certification reflects successful completion of EC-Council’s credentialing requirements only.
- The certification does not replace or constitute any legal licensure that may be required by local, state, national, or international regulations.
Policy and Enforcement
- EC-Council reserves the right to impose additional restrictions to comply with its policies.
- EC-Council reserves the right to modify certification policies without prior notice.
- EC-Council reserves the right to revoke the certification of any individual found to be in breach of its policies.
- There are no predefined eligibility criteria for those interested in attempting the CPENT exam. You can purchase the exam dashboard code here
- You will receive access to practice range and Exam access code.
- You can purchase the access validity in either 30 days, 60 days, and 90 days at the time of purchase.
- 30 days from the date of activation.
- It is an EC-Council portal where you can access your package inclusions. All the EC-Council practical exams can be scheduled and launched from this portal.
- The Aspen Dashboard access code is valid for 1 Year from the date of receipt. You have to redeem the code within this period.
- The Aspen Dashboard access is valid for 30 days from the date it is unlocked. Within this 30-day access period, the candidate must complete the exam and submit the required report.
- If you need additional time, you may request a one-time 7-day extension by paying a fee of USD 100. We encourage candidates to request the extension before the initial 7-day deadline if more time is needed. If the report is not submitted within the original timeframe or the approved extension period, the exam attempt will be marked as unsuccessful, and the exam will need to be retaken.
The Dashboard consists of:
- Detailed Instruction guide.
- Exam scheduling service.
- Exam launching service.
- Exam progress tracking.
- Sample report templates.
- Report submission.
- Status of the report.
- The CPENT exam is a 100% practical exam. The candidate is required to submit the pen-testing report to complete the exam.
- Yes, it’s an open book exam.
- The exam duration is 24 hours. You can opt either for two sessions of 12 hours each or one session for 24 hours.
- In order to maintain the high integrity of our certifications exams, EC-Council Exams are provided in multiple forms (I.e. different question banks). Each form is carefully analyzed through beta testing with an appropriate sample group under the purview of a committee of subject matter experts that ensure that each of our exams not only have academic rigor but also have “real world” applicability. We also have a process to determine the difficulty rating of each question . The individual rating then contributes to an overall “Cut Score” for each exam form. To ensure each form has equal assessment standards, cut scores are set on a “per exam form” basis. Depending on which exam form is challenged, cut scores can range from 60% to 85%.
EC-Council exams use multiple exam forms, each with its own cut score based on question difficulty. Because of this, the pass score varies by exam form and can range from 60% to 85%.
Certification levels are awarded as follows:
- Score at or above your exam form’s cut score up to 89%: CPENT
- Score 90% and above: CPENT + LPT (Master)
- Yes, you will get two certifications CPENT and LPT (Master) in your Aspen account.
- Sessions should be booked at least 3 days in advance of the desired exam date.
- No, the CPENT exam sessions are proctored by the EC-Council directly through the RPS (Remote Proctoring Services).
Once you are ready to proceed with your exam, you need to ensure you understand the below points:
- Cancellation requests are to be made 24 hours in advance.
- Rescheduling is possible 72 hours before the exam session.
- Candidate has a grace period of 15 minutes to show up for the exam session.
- After three no-show cases, the candidate will be required to seek special permission from the Director of Certification in order to proceed with their next attempt.
- If you need technical support or assistance, please contact us at [email protected]
- FAQs on exam proctoring will be available at https://proctor.examspecialists.com/User/FAQ.aspx
- Please write to [email protected]
- Retake exam requests can only be purchased by writing to [email protected], should a candidate fail the exam.
- Yes, the CPENT is a part of the EC-Council Continuing Education Scheme.
- Yes, the CPENT is a part of the Continuing Professional Education Scheme.
- Earn 120 ECE (EC-Council Continuing Education) credits within the three-year ECE period.
- Stay current with the annual Continuing Education (CE) fees.
- Earn 120 CPE (Continuing Professional Education) credits within the three-year CPE period.
- Stay current with the annual Continuing Education (CE) fees.
- USD 250 per annum.
- No
- It will not be affected. The existing certified members will continue to be certified as long as they maintain the CPE credits in their Aspen account and pay the annual Continuing Education fee.
- These are two different programs. You will have to purchase the CPENT program separately.
- ECSAv10 exam will remain available for the next 6 months from the date of C|PENT launch i.e. till end of 15th May 2021.
- You can use a ping test which should have a result of 10.100.1.4. If you cannot ping this then disconnect and re-connect to the VPN. Also, ensure you’re connected on the machine that your tools are on and not on the virtual host machine.
- If you can ping the 10.100.1.4 address, then the network is connected properly. The CPENT consists of a challenging network environment which means you have to let the packets show you the way. Read the network, what is it telling you? Analyze it and Go Deeper. This environment requires you to review the packets and use them as your guide. Again, as long as you can ping the address then the network is functioning as it should.
- In the CPENT, you have to let the network show you the way. If you are running default scans and intense scans of all ports, then the scans could take a long time. Ensure you review what the network is telling you and let the packets show you the way. Go Deeper and get past the challenges that are between you and the scan results. If you follow best practices of scanning against a filtered environment, you will be able to get the required results.
- Let the packets show you the way. Analyze it. Go Deeper and follow the scanning methodology. Testing is a systematic process, so make sure to follow the process. Refer to the scope of work for each zone and proceed as you would in a real test. Determine the best path to follow to get the results you need.
- Yes. The CPENT exam is an open-book exam, so you may use your personal AI toolkit, along with other reference materials and online resources, during the exam. You are responsible for verifying and correctly using any output generated by your AI tools. Your final submission must reflect your own ability to complete the required penetration testing tasks.
- You have to let the packets show you the way. Analyze it, then Go Deeper. If you aren’t getting results from a system scan, then change your mindset and look at what the network is telling you. This requires you to analyze it. The best method is to observe the network traffic using a protocol analyzer and read the network, then take what the network gives.
- In a highly filtered environment you have to let the packets show you the way. Analyze the protocols and see if this matches what you expect. Once you have done that Go Deeper and look for weaknesses. Once you discover that, leverage it to gain access
- There are protections in place that prevent the effective ID from gaining you root privileges, so you have to write a program or change the shell code to bypass the protections. Look at the escalation process and Go Deeper.
- To solve this you have to identify the PLC, then the communication stream and interpret it. Let the packets show you the way. Analyze it and Go Deeper! The first step is to get access to the OT network.
- As with any network you have to identify the targets, then ask “what would I see in Active Directory environment?” Once you have done, that Go Deeper and analyze it. Take what the network can give. Then look for Kerberos weaknesses and see if you can compromise a ticket.
- Check the syntax and make sure you have entered the options correctly. Ensure you have privileges to write to the folder that you are extracting the firmware file system to. Review the error message and see if you can figure it out, then Go Deeper.
- This is not required to get the answers to the questions. You can obtain them without booting the image and corresponding file system. In other words, you can do static analysis and get the required information to score points.
- You need to notice the ports that you are using. The egress ports need to be ports that are not normally proxied, so the question to ask is what ports are going to egress out? The ports 80 and 443 are poor choices since they are normally proxied. Again, Go Deeper!
- The zones include a directly connected zone which is the 172.25.X.X network. When it is a 192.168.X.X network it should have a DMZ where the servers/machine reside. Like most zones there is one or more weaknesses that have to be discovered by mapping the attack surface through the filter which is step one. The firewall only allows a certain number of ports and that is where you need to start. The ICMP protocol should not be allowed in an enterprise from the outside world. The key is to determine the ports that are allowed and then use that to map the attack surface. From there, look for other networks from that position and for a way to gain access. You accomplish this by reading what the packets tell you and taking what the network provides and Go Deeper. Not all subnets are visible from the 172.25.X.X network, some will require access to a 192.168.X.X first.
- The OT network is NEVER reachable, so you have to find the weak machine in the IT network and use it to access the OT network. There is one weak machine that is connected to the OT network where an operator uses it to monitor the dashboards of the OT network. Once you gain access to that machine you can do recon FROM that machine to see the OT network traffic between the sensors and the PLC. No ICMP is allowed across the public to the other networks and limited ports for attack surface. In an enterprise level OT network there should never be traffic allowed from the OT network out. Read the network packets and take what it gives then, Go Deeper to obtain the required data.
- You have to read what the network is telling you, then you can identify the targets. As mentioned in the scope and guide, in an enterprise there will be some type of filtering in place, so you have to read the results and Go Deeper to extract information. Since this is the OT scope, you also have to think of how an OT network is designed. In the scenario it is explained that there is one machine on the IT side that an engineer is using to get data from the OT side, so once you identify that then you have to look for the network communication from the OT network.
- In the AD zone, there is one or more weak machine and that is the vector by which you need to gain access. Once you gain access by discovering and finding a weakness in a machine, the AD forest will be there. Again, this is basic defense for an AD environment; therefore, you have to take what the network provides and “Go Deeper” to gain access.
- It is not down. You have to find the weak machine and then from that machine you can see the forest. Think how a network is designed; the Domain Controller should not be directly reachable, this is defined in the exam guide. There should be more machines up, but if you cannot ping them, you have to Go Deeper and use other methods.
