CPTS Study Plan

A 10-day marathon through an enterprise network. A free, day-by-day CPTS schedule built from the official HTB Academy: Penetration Tester Job Role Path syllabus, scaled to your exam date and weekly hours.

Approx. cost
$490–$1,260
Difficulty
♥♥♥♥♥
Study time
about 391h
Start level
Junior

▶ Build my CPTS plan

> How long does CPTS take?

The plan assumes about 391 study hours. Here is how that stretches across different weekly schedules.

Hours per weekTime to finish
5 hoursabout 79 weeks (18.2 months)
10 hoursabout 40 weeks (9.2 months)
15 hoursabout 27 weeks (6.2 months)
20 hoursabout 20 weeks (4.6 months)
30 hoursabout 14 weeks (3.2 months)

> CPTS exam format

Hack The Box · HTB Academy: Penetration Tester Job Role Path

  • 10 days total: the hacking and the report both fit in the window
  • Capture at least 12 of 14 flags
  • Commercial-grade penetration test report required
  • 100% of the Penetration Tester path required first
  • Covers external, web, internal & Active Directory

Official CPTS page ↗

> CPTS syllabus and study hours

Every topic in the plan, in order, with its baseline hours. The planner shrinks or stretches these to fit your dates.

Recon & Foundations

Methodology, enumeration and footprinting.

  • Penetration Testing Process8h · learn
  • Getting Started13h · learn
  • Network Enumeration with Nmap7h · learn
  • Footprinting12h · learn
  • Information Gathering - Web Edition10h · learn
  • Vulnerability Assessment9h · learn

Exploitation Toolkit

Shells, transfers, passwords and pivots.

  • File Transfers6h · learn
  • Shells & Payloads9h · learn
  • Using the Metasploit Framework8h · learn
  • Password Attacks14h · learn
  • Attacking Common Services10h · learn
  • Pivoting, Tunneling, and Port Forwarding10h · learn

Active Directory

The biggest single module in the path.

  • Active Directory Enumeration & Attacks26h · learn

Web Gauntlet

Proxies, fuzzing and the web vuln classes.

  • Using Web Proxies8h · learn
  • Attacking Web Applications with Ffuf7h · learn
  • Login Brute Forcing7h · learn
  • SQL Injection Fundamentals9h · learn
  • SQLMap Essentials6h · learn
  • Cross-Site Scripting (XSS)6h · learn
  • File Inclusion6h · learn
  • File Upload Attacks6h · learn
  • Command Injections7h · learn
  • Web Attacks10h · learn
  • Attacking Common Applications18h · learn

Privilege Escalation

From user to root / SYSTEM.

  • Linux Privilege Escalation15h · learn
  • Windows Privilege Escalation18h · learn

Reporting & Capstone

Write it up, then attack a full network.

  • Documentation & Reporting6h · learn
  • Attacking Enterprise Networks16h · lab

Training Grounds

Reinforce the path with real boxes.

  • Retired HTB boxes (CPTS-style)30h · lab
  • Multi-host network practice (e.g. Pro Labs)30h · lab
  • Active Directory chains20h · lab

Final Boss Prep

The exam rewards stamina and reporting.

  • Build module cheat sheets & methodology10h · review
  • Report practice (SysReptor / template)10h · review
  • 10-day exam game plan4h · review

> Where to practise for CPTS

Each task in your plan lists practice labs for its own topic. These are the best places to put in extra hands-on hours:

> CPTS exam-day checklist

General logistics for exam week. The official exam guide always takes priority if it differs.

One to two weeks before

  • Schedule your exam and add the start time, time zone and deadline to your calendar
  • Read the official exam guide end to end: rules, allowed and banned tools, and what counts as proof
  • Plan your 10-day window: set a daily schedule and leave days for the report
  • Track flags as you go: you need at least 12 of 14
  • Complete a full-length timed practice run on your exam setup
  • Finalize your note-taking setup and templates (see the notes starter below)
  • Build and review your cheat sheets and command references
  • Arrange time off, tell people you will be unavailable, and plan your meals ahead

Machine and network

  • Charge and test a backup device or phone hotspot, and know how to contact support if your connection drops
  • Plug in your laptop and turn off sleep, updates and notifications for the exam
  • Test the VPN or lab connection early and know how to reconnect after a drop
  • Update your attack VM, take a clean snapshot and keep a spare
  • Install and test every tool you plan to use, and check none of them are banned
  • Test your screenshot hotkeys and make sure you have plenty of free disk space

During the exam

  • Sleep well the night before, and skip last-minute cramming
  • Prepare food and water, and set timers for break reminders
  • Read the brief and scope carefully before you touch anything
  • Write notes and capture proof as you go, not at the end
  • Time-box each target and move on when stuck. You can come back later
  • Stop new attacks with enough time left to verify your evidence

Report and submission

  • Copy your report template and fill in the easy parts (scope, methodology) while you work
  • Check every finding has reproducible steps and screenshots
  • Proofread: could someone else follow each step?
  • Export in the exact format and naming the exam guide requires
  • Submit with a buffer before the deadline and confirm it was received

Suggested exam-day rhythm

  • Day 1. Read the brief, set up notes and enumerate everything. Do not rush into exploitation.
  • Days 2 to 8. Fixed daily rhythm: two or three focused blocks of about 3 hours, breaks between them, and a proper stop at night.
  • End of each day. Update notes, list your next three ideas and back up your evidence.
  • Last 2 days. Stop new attacks. Verify every finding, then write and proofread the report.
  • Submission. Submit with a buffer before the deadline and confirm it was received.

▶ Open the interactive CPTS exam kit

The kit lets you tick items off, download a notes starter and report template, and see a readiness score from your plan progress.

> Passed CPTS with PWN PATH

No CPTS debriefs yet

Passed a cert? A short debrief helps the next learner plan their own run, and it only takes a couple of minutes.

▶ Share my debrief

Debriefs are self-reported. See all pass stories.

> Frequently asked questions

How long does it take to prepare for CPTS?

PWN PATH builds the CPTS plan on about 391 study hours. At 10 hours a week that is roughly 40 weeks, and at 20 hours a week roughly 20 weeks. Your own timeline depends on how much of the material you already know.

What is the CPTS exam like?

10 days total: the hacking and the report both fit in the window. Capture at least 12 of 14 flags. Commercial-grade penetration test report required. 100% of the Penetration Tester path required first. Covers external, web, internal & Active Directory.

How hard is CPTS?

We rate CPTS 4 out of 5. It suits people who want the deepest pentest curriculum for the money and a report-heavy exam. Comfortable in Linux and networking. A lot of reading and note-taking ahead.

How much does CPTS cost?

HTB Academy subscription plus a $210 exam voucher. Silver Annual is about $490–550 with a voucher included; some advanced paths need Gold. Prices are approximate, in US dollars unless a currency is shown, and change often. Confirm with the vendor before you buy.

What should I study first for CPTS?

Start with the "Recon & Foundations" phase: Penetration Testing Process, Getting Started, Network Enumeration with Nmap. The planner puts topics in a sensible order and scales the hours to the time you have.

What are the prerequisites for CPTS?

Comfortable in Linux and networking. A lot of reading and note-taking ahead.

What should I do the week before the CPTS exam?

Re-read the official exam guide for rules and banned tools, test your machine, network and VPN or lab connection, finish a full timed practice run, finalize your notes and cheat sheets, and plan your meals, breaks and sleep. The exam-day checklist on this page covers it step by step.

How should I handle breaks and sleep during the CPTS exam?

Day 1: Read the brief, set up notes and enumerate everything. Do not rush into exploitation. Days 2 to 8: Fixed daily rhythm: two or three focused blocks of about 3 hours, breaks between them, and a proper stop at night. End of each day: Update notes, list your next three ideas and back up your evidence. Last 2 days: Stop new attacks. Verify every finding, then write and proofread the report.

What should I take after CPTS?

Common next steps are OSCP+, CAPE, CWEE. See the roadmap to compare them.

Is the PWN PATH study planner free?

Yes. There are no accounts and no sign-up. Your plan and progress are saved in your browser, and you can export a backup file, add the schedule to your calendar or print it.

> Plan your path

Good stepping stones before CPTS:

Where it leads:

More in network pentesting:

Not sure CPTS is right for you? Take the one-minute cert quiz.