The HTB CPTS exam is a hands-on, intermediate assessment. Once you start, you have 10 days to collect flags from the lab targets and upload a commercial-grade report in English, and that window covers both the lab work and the report. To qualify, you must complete 100% of the Penetration Tester job role path and hold an exam voucher. Prepare by treating each path module as part of a connected attack chain and by practicing written reproduction steps and evidence after every lab machine you solve.
What the CPTS credential covers
CPTS is Hack The Box's intermediate, hands-on penetration testing certification. It assesses practical testing and ethical hacking skill across infrastructure, web entry points and Active Directory, and it expects a commercial-grade, actionable security report.
Hack The Box's help center describes CPTS as validating comprehensive, hands-on penetration testing at an intermediate level, with candidates learning to assess complex infrastructure risk and to compose commercial-grade, actionable reports. There is no multiple-choice paper: the exam runs inside an isolated lab network.
Comparing adjacent HTB credentials helps you confirm this is the right exam. The table summarizes how the help center positions each one. If your goal is broad, end-to-end penetration testing proficiency, CPTS is the broad intermediate option; web depth or Active Directory specialization have their own credentials.
| Credential | Primary focus | Level per HTB | Best fit when... |
|---|---|---|---|
| CPTS | Infrastructure penetration testing, web entry points, Active Directory, risk assessment, reporting | Intermediate | You want broad pentesting job proficiency end to end |
| CJCA | Foundational offensive and defensive skills, SIEM-assisted monitoring, log analysis | Entry-level foundational | You are starting and want a hybrid skill base |
| CWES | Web application penetration testing and bug bounty work | Intermediate | You want web-specific depth |
| CAPE | Advanced Active Directory attack paths, Kerberos and NTLM abuse, component misconfigurations, C2 use | Advanced | You already test infrastructure and want AD specialization |
Eligibility: finish the path, hold a voucher
To sit the exam you must achieve 100% completion of the chosen role path and have a valid exam voucher. Yes, that means the entire Penetration Tester path, not just the modules you find useful.
Choose a current subscription or module-purchase route that covers the Penetration Tester path and a CPTS voucher. HTB describes annual plans with bundled access and vouchers, and a monthly route where modules and the exam voucher are purchased separately. Check the inclusions for the particular plan before purchasing.
Starting the exam consumes one attempt immediately through a mandatory confirmation dialog, so only click it when you are ready to begin. You also cannot start another exam while one is in progress or under review, so plan around the voucher expiry date if you hold more than one.
The 10-day window includes your report
CPTS gives you 10 days total for the lab environment and the report together. The countdown starts the moment you confirm exam entry and runs uninterrupted, so report writing is not extra time afterwards.
To pass, you must meet two milestones before your deadline: collect enough target-system flags to reach your exam's point threshold, and upload a detailed, commercial-grade penetration testing report in English that maps your attack methodology and remediation steps.
Check the current CPTS point requirements in your exam instructions. The general help article gives 70 out of 100 for intermediate paths as an example; this guide does not establish that example as the current CPTS cut score.
Budget accordingly: if you spend nine days testing, you have one day left for a document that a technical reviewer must be able to replay. Writing findings as you go is the practical way to protect that time.
Connecting to the lab: one route at a time
You can reach the exam network either through a local VPN configuration file in your own virtual machine or through the browser-based Pwnbox, but never both at once. Running both connection models simultaneously drops your active sessions.
If you use Pwnbox, note that a browser instance stays online for a maximum of four continuous days, after which the system wipes the container. That four-day lifespan is separate from your 10-day exam deadline, and any exam files stored in Pwnbox are lost when it expires, so keep notes and evidence somewhere durable.
If you use the VPN file instead, your exam instance spawns on the VPN server you selected and returns an entry point. You can reset or stop the instance at any time and add more time to it once it drops below 100 minutes remaining.
The exercise below rehearses the single-route rule, since it is one of the few exam mechanics you can fully prepare on paper.
Practice task
You plan to recon the exam network from a browser Pwnbox while your local virtual machine stays connected through the downloaded VPN configuration file, so you can switch between them without waiting. What happens if you run both connections at once, and how should you work instead?
Show answer
Running both at once will drop your active sessions. Use only one connection route at a time: either the local OpenVPN configuration in your virtual machine or an active browser Pwnbox, never both simultaneously.
The HTB help center describes two connection models for the exam lab and applies a strict single-route policy: connecting locally while an active browser Pwnbox is running drops active sessions. Plan for the switch by stopping or letting one route lapse before starting the other, and remember that a Pwnbox instance lasts at most four continuous days and wipes stored exam files at expiry, which is separate from the 10-day exam deadline.
Submitting the report
Reports must be written entirely in English and uploaded through the exam dashboard as an unencrypted PDF document or a compressed ZIP archive, with no password protection and a maximum size of 20MB.
You can use the official downloadable report template included with your exam or the Sysreptor HTB template system. The platform only accepts submissions through the official exam web dashboard.
The final submission is irreversible. Clicking it terminates your live lab connection and formally closes your exam window, and once committed the file cannot be changed, modified or swapped. Upload early enough to review the file before you commit.
Even if you fail to reach the required points, you must still submit a report to be eligible for a second attempt. No report on the first attempt means no second attempt.
Results, feedback and second attempts
Review takes up to 20 business days and results arrive by email. If you fail, you can start a second attempt right away, but you must start it within 14 days of receiving feedback or you lose it.
Your exam history and feedback appear on the History tab. Compare the feedback with your first report and the corresponding course material before using the second attempt.
Because you cannot run two exams at once and vouchers have expiry dates, plan your calendar around the review period before booking anything else.
What the Penetration Tester path trains
The current Penetration Tester path contains 28 modules. It takes you from the testing process and enumeration through infrastructure and web assessment to documentation and reporting.
The path opens with the penetration testing process, including pre-engagement steps such as contracting criteria with a client, then builds enumeration skill with Nmap, footprinting of common enterprise services and web reconnaissance across active and passive techniques.
A vulnerability assessment module distinguishes assessments from penetration tests and covers interpreting and reporting results, which feeds directly into the exam's report deliverable. Foothold modules cover shells and payloads, the Metasploit Framework, password attacks, attacking common services and login brute forcing. Post-exploitation work spans pivoting, tunneling and port forwarding plus Linux and Windows privilege escalation.
Active Directory gets a dedicated enumeration and attacks module, reflecting the domain environments enterprise testers face. Web attack modules cover web proxies, directory brute forcing, SQL injection, cross-site scripting, file inclusion, file uploads, command injection, verb tampering, IDOR, XXE and common applications. The path closes with documentation and reporting and a full simulated engagement in Attacking Enterprise Networks, which is the closest preview of the exam's format.
The official module list is exhaustive, so use the Academy page for section-level detail and treat the groups above as a study map rather than a substitute for the path itself.
Sources: Penetration Tester Job Role Path | HTB Academy — Path overview and module list
Turn a completed lab into a reportable finding
Use the path exercises to practise keeping a clear record of what you observed and how it supports a finding.
The Documentation & Reporting module emphasizes keeping thorough notes during an engagement and assembling evidence for a report. Attacking Enterprise Networks then brings the testing process together in a simulated engagement. These are useful places to connect technical practice with the report deliverable.
As an optional review routine, choose one completed course lab and explain its starting conditions, the observations you recorded and the result you demonstrated. Compare that account with the actual course walkthrough. Mark any claim for which you cannot find supporting evidence rather than filling the gap from memory.
Keep all practice within the selected lab instructions. The path covers password attacks, pivoting and other techniques, but its module descriptions do not prescribe trying a discovered credential against every service or following one fixed attack sequence.
Sources: Penetration Tester Job Role Path | HTB Academy — Path overview and module list
AI use and exam integrity
Using AI to solve exam content directly violates Hack The Box's certification terms, but local reference and debugging help is permitted. Never paste exam targets into public AI models, never have AI write your report, and never use autonomous agents to solve machines for you.
The permitted category is narrow: asking how a Linux command works or checking the syntax for a script is allowed. The prohibited categories are specific: leaking raw exam targets or code into public AI models breaches confidentiality terms, AI-generated reports violate the not-your-own-work rule, and automated solving counts as cheating.
The support team can help with platform issues but cannot give hints or guidance on actual exam tasks, so build your problem-solving practice into lab work rather than expecting rescue during the exam.
Your next steps
Finish the path, confirm your exam requirements and prepare both the lab work and report within the same deadline.
- Confirm full Penetration Tester path completion and a valid CPTS voucher before starting.
- Choose one connection route and keep a durable copy of notes and evidence outside an expiring Pwnbox.
- Check the current exam instructions and deadline; leave time to check and upload the report.
- Review one complete lab finding against the Documentation & Reporting material.
Sources: Penetration Tester Job Role Path | HTB Academy — Path overview and module list; Academy Certifications | Hack The Box Help Center — CPTS sections: certification description, exam process, deadlines, report submission, results, AI policy
Sources
Facts checked:
