Earning the Hack The Box CPTS: My Experience
On August 31, 2026, I earned the CPTS (HTB Certified Penetration Testing Specialist) certification from Hack The Box.
In this post, I’ll share why I chose CPTS, how I approached the learning process, and what I experienced during the exam. I hope this helps anyone preparing for it.
Why Did I Choose CPTS Before OSCP?
CPTS is a hands-on penetration testing certification issued by Hack The Box. It assesses your ability to conduct penetration tests in an environment designed to simulate real-world systems.
I also considered OSCP, but I decided to pursue CPTS first. My main reasons were affordability and the opportunity to learn.
The Silver Annual Plan I used had a standard price of $490, which included access to the Penetration Tester Path and an exam voucher that could be used for CPTS.
For comparison, OffSec offers two relevant options. At the time of writing, the standalone OSCP+ exam costs $1,699, while the PEN-200 package with 90 days of course and lab access and one exam attempt costs $1,749.
For a simple comparison, using an assumed exchange rate of KRW 1,350 per US dollar, $490 is approximately KRW 660,000, while $1,699 is approximately KRW 2.29 million. The packages differ in content and access duration, but there was a substantial difference in the upfront cost.
Of course, I could have focused on preparing for OSCP from the outset. Instead, I chose to strengthen my penetration testing skills through the more affordable CPTS route first, then build on that experience when pursuing OSCP.
What I Actually Paid—and My Last-Minute Preparation
The amount I actually paid for the Silver Annual Plan was $367.50.
The standard price was $490, but I purchased it during a 25% discount promotion. Using the exchange rate at the time—KRW 1,381 per US dollar—that works out to approximately KRW 500,000.
The Silver Annual Plan included several benefits, but I mainly used it for the Penetration Tester Path and the CPTS exam voucher.
Pricing note: The price for new Silver Annual subscriptions is scheduled to increase to $550 per year on October 12, 2026.
The bigger problem, however, was my time management.
I started studying enthusiastically when I first subscribed and completed roughly half of the Path that year. Then life got busy, I kept putting my studies off, and eventually I even forgot that I still had an active subscription. An email reminder arrived one month before it expired. That was when I rushed to finish the remaining material, finally managing to start the exam just one day before my subscription expired.
The exam voucher included in my Silver Annual Plan was set to expire with the subscription. Fortunately, I started the exam the day before expiration and had no issues continuing afterward. For anyone preparing through a subscription, I recommend keeping track of the voucher’s expiration date, not just your study schedule.
CPTS Prerequisites and Exam Format
To take CPTS, you must complete 100% of the Penetration Tester Path and have a valid exam voucher.
The exam lasts 10 days, including report writing and submission, and the report must be written in English. You need to meet both the required flag threshold and the report assessment criteria. Officially, results can take up to 20 business days.
To be eligible for a retake, you must submit a report for your first attempt as well, and you must begin your second attempt within 14 days of receiving feedback on a failed attempt. To my knowledge, the exam content does not change for the second attempt, so in a sense, you could think of it as having a total of 20 days across two attempts.
Studying the Penetration Tester Path
Working through the Path was more demanding than I expected.
I moved relatively quickly through topics I was already familiar with. However, penetration testing topics such as lateral movement and Active Directory were much less familiar to me, so understanding the concepts and working through the labs took considerable time.
That does not mean the experience was all difficulty and frustration. The unfamiliar topics were also new and interesting, which made the learning process quite enjoyable. Studying them also helped me reconsider the importance of infrastructure design and security policies from an attacker’s perspective. Understanding an individual vulnerability and looking at multiple systems as an interconnected environment are very different experiences—and that distinction particularly stood out to me.
The time needed to complete the Path will vary considerably depending on your existing knowledge and how much time you can invest. Based on my experience, around three months seems like a reasonable target with focused effort, provided you already have some security knowledge and can consistently set aside time after work and on weekends.
If many of the topics are unfamiliar, though, I would recommend allowing more time. I definitely do not recommend leaving everything until just before your subscription expires, as I did.
My Exam Experience
I started the exam the day after completing the Path. I did not set aside any additional time for practice labs or reviewing my notes, though I did refer to the experience shared by Ian, an O4C member who had earned CPTS before me.
When you start the exam, you review the instructions and guidelines, then connect to the exam environment to begin the penetration test.
Overall, I felt that the exam required a solid understanding of the Path material and the ability to adapt it to the situation. Looking at the individual vulnerabilities in isolation, I did not find the exploitation techniques particularly difficult.
What I found more challenging was deciding where to investigate further and connecting the information I had collected to determine my next steps. With multiple targets to analyze, there was a lot of information to examine. Whenever something did not work as expected, going back and checking my assumptions took additional time. In short, there was quite a bit of trial and error.
I had captured 12 flags by day nine. I considered continuing with the remaining objectives, but given the time left, I decided to focus on organizing my evidence and writing the report.
Because I had been taking notes as I worked through the exam, I initially thought the report would not take too long. Once I started putting it together, however, I discovered that more evidence and explanations were missing than I had expected. Steps that had seemed obvious at the time needed to be revisited so I could explain them clearly to someone else. Going back to collect the missing evidence took additional time.
The report requirements were also more detailed and specific than I had anticipated. If I had focused entirely on exploitation and left all the reporting until the very end, I would have been in a difficult position.
Tips for Anyone Preparing
1. Set Aside Time in Advance If You’re Working Full-Time
Ten days may sound generous, but the time you can actually use is limited when you have a full-time job.
Whenever possible, choose a period with fewer overtime commitments or personal plans, and make sure you can dedicate enough time on the weekends as well. In my case, the exam required a substantial portion of my evenings and weekends.
2. Build an Understanding Across the Full Path, Not Just Your Strongest Areas
I spent far more time studying unfamiliar topics than familiar ones.
Moving quickly through your stronger areas is fine, but I think it is important not to rush through unfamiliar material just to mark it as complete. Rather than simply memorizing commands, spend time understanding when to use them and why.
3. Don’t Spend Too Long on a Single Approach
Investing a lot of time in something does not necessarily mean you are heading in the right direction.
Keep a record of the approaches you have tried and their results. If you are not making progress, revisit whether your current hypothesis still makes sense. I found that reorganizing and reviewing information I had already collected was just as important as trying something new.
4. Don’t Leave the Report Until the End
As you solve each problem, organize the information you will need for the report.
Do not rely on screenshots alone. I recommend recording the commands you used, their output, the steps needed to reproduce the result, and why you chose that approach. Even if everything makes sense in the moment, gaps can appear when you try to explain it again a few days later.
I thought I had documented things thoroughly, but I still found plenty of missing details. Treat evidence collection as part of the problem-solving process.
5. Make Good Use of Permitted Tools
Trying to handle every step with scripts you write yourself can leave you short on time.
If an existing tool is suitable for the task, use it—but make sure you understand what it does and verify its results. Deciding what to implement yourself and when to use an existing tool is also part of managing your time effectively.
Final Thoughts
For me, CPTS was more than simply adding another certification to my résumé. It was an opportunity to study areas I was less familiar with and work through a penetration testing engagement from start to finish.
What stood out most was the process of connecting information gathered from multiple systems to guide my analysis, then turning the results into a report that someone else could understand.
Although I initially chose CPTS to keep costs down, I am also very satisfied with what I learned while preparing for and taking the exam.
That wraps up my CPTS experience. I hope this post is helpful to anyone preparing for the certification.