The eJPT is INE Security's entry-level, hands-on penetration testing certification, built around four weighted domains: host and network penetration testing, assessment methodologies, host and networking auditing, and web application penetration testing. You need an INE subscription plus a voucher; regular vouchers expire 180 days after purchase, with a free retake inside 14 days and both attempts due before expiry. This guide maps the objectives to study tasks, explains the process, and includes a timing drill so you can schedule both attempts safely. Question count, time limit and passing score are not stated on the page checked, so confirm them in your dashboard before booking.
What the eJPT certifies
The eJPT is INE Security's entry-level, hands-on certification validating the knowledge, skills and abilities for a junior penetration tester role, and it leads toward the Certified Professional Penetration Tester (eCPPT).
INE Security describes the eJPT as a hands-on, entry-level Red Team certification that simulates skills used during real-world engagements. The stated purpose is to validate that a candidate can fulfill a junior penetration tester role. The exam simulates real-world scenarios rather than testing recalled definitions alone.
The issuer positions it for people with little to no cybersecurity experience who have a basic understanding of networks and systems. It names starting profiles such as systems administrators, security analysts, engineers and developers, but states that anyone can attempt the exam. Those roles are positioning, not eligibility conditions.
The certification also has a stated place in a progression: the issuer presents it as an entry point to its Red Team certifications, with the Certified Professional Penetration Tester (eCPPT) as the named next step after passing.
The four exam domains and their weights
The current page evaluates four weighted domains: Host and Network Penetration Testing at 35%, Assessment Methodologies at 25%, Host and Networking Auditing at 25%, and Web Application Penetration Testing at 15%.
This four-domain outline replaces the older topic lists you may still see in study material. Treat the live certification page as the operative map, and read the full objective list there, because the table below shows only representative objectives.
The weights tell you where depth pays off. Host and Network Penetration Testing carries the largest share, so skills named there, such as exploit modification, pivoting and credential attacks, deserve the largest block of practice time. The other three domains are far from optional: together they cover how you scope a target, how you extract information from machines you reach, and how you test web applications.
| Domain | Weight | Representative objectives |
|---|---|---|
| Host and Network Penetration Testing | 35% | Identify and modify exploits; conduct exploitation with Metasploit; demonstrate pivoting by adding a route and by port forwarding; conduct brute-force password attacks and hash cracking |
| Assessment Methodologies | 25% | Locate endpoints on a network; identify open ports, services and the operating system of a target; gather company, email and technical information from public sources; identify vulnerabilities and evaluate their criticality or impact |
| Host and Networking Auditing | 25% | Compile and enumerate network, system and user account information from files on a target; transfer files to and from a target; gather hash and password information |
| Web Application Penetration Testing | 15% | Identify vulnerabilities in web applications; locate hidden files and directories; conduct brute-force login attacks; conduct web application reconnaissance |
Vouchers, subscriptions and the exam process
You need both an INE subscription and an exam voucher. Regular vouchers expire 180 days after purchase, the included free retake must happen within 14 days of a failed attempt, and both attempts must be submitted before the voucher expires.
New candidates can buy a bundle that includes the voucher, such as the eJPT + Prep bundle or the Fundamentals annual subscription with novice-level training. If you already hold an active INE subscription, you can purchase the eJPT voucher on its own. Pick the route that matches how much training access you actually need.
After purchase, the process runs through your my.ine account. Your exact voucher expiration date is always visible in the Certifications Dashboard, which makes it the single place to check before you schedule either attempt.
Results are auto-graded and typically delivered within a few hours. The score report includes performance breakdowns across each section, which tells you where to focus if you need the retake.
- Purchase a certification voucher and access it from the certifications page in your my.ine account.
- Note that regular vouchers expire 180 days after purchase; verify your exact date in the Certifications Dashboard.
- If you do not pass, complete the included free retake within 14 days.
- Submit both attempts before the voucher expiration date.
- Expect auto-graded results within a few hours, with a per-section performance breakdown.
Preparation decisions that follow from the objectives
Build depth in a small, reliable toolset, practise each named objective against machines in an isolated lab you own, and keep notes detailed enough to answer questions from them alone.
The objectives are practical by design: they name actions such as locating endpoints, identifying services, pivoting through a route or port forward, cracking hashes, and finding hidden web directories. For each objective, a useful study target is being able to perform it and explain what the output told you, not merely recognize the term. Arrange your practice in the order the domains imply: reconnaissance and scanning first, then enumeration of identified services, then exploitation and post-access information gathering, then web applications.
One habit that serves every domain is writing down why each action worked. After you identify a service or obtain a credential, record what evidence produced that result. As general study advice, notes that reconstruct your activity make it easier to review what you practised and spot weak objectives before exam day, and many candidates find them valuable in any scenario-based assessment.
Be honest about what the certification page does and does not say. The page checked for this guide states the domain weights and policies but does not state a question count, time limit or passing score. Check your Certifications Dashboard and confirm current exam conditions with INE before booking, rather than relying on figures from older third-party guides.
A voucher timing drill
The 14-day retake window and the 180-day voucher expiry are separate limits, and expiry can cut the retake window shorter than 14 days.
Most scheduling mistakes with this exam come from treating the two deadlines as one. The drill below uses only the policies stated on the current certification page, with explicit dates so the answer is unique.
Practice drill
A regular eJPT voucher expires at noon on day 180 after purchase. Your first attempt is submitted and marked failed at noon on day 170. Both attempts must be submitted before voucher expiry, and the included retake is allowed within 14 days. Which deadline limits the retake in this example?
Show answer
Voucher expiry limits the retake. It must be submitted before noon on day 180, less than ten days after the stated failure time.
The 14-day limit would extend past the voucher expiry. The earlier deadline governs, so the retake must finish before the day-180 cutoff. Use the exact expiry shown in the INE dashboard for your voucher; this paper example supplies its timestamps explicitly.
Final checklist before you book
Confirm the current objectives and your voucher dates, choose your subscription route, and complete your hands-on practice inside an authorized lab.
Use this list as your pre-booking routine. Everything on it traces back to the certification page, so re-check it if time has passed since you first read this guide.
- Read the current domains and objectives on the INE Security eJPT certification page.
- Decide between a bundle that includes the voucher and a standalone voucher with your existing subscription.
- Check your voucher's exact expiration date in the Certifications Dashboard.
- Schedule the first attempt early enough that the free retake fits before expiry.
- Practise every objective hands-on in an isolated lab you own or are explicitly authorized to test; never run scans or exploits against systems without permission.
- Expect auto-graded results within a few hours and use the per-section breakdown to target a retake if needed.
Official sources
Facts checked:
