Study Guide

PNPT Study Guide: What the Exam Asks and How to Prepare

PNPT exam guide: what the five-day assessment, written report, and live debrief require, plus cost, eligibility, and preparation from TCM Security's page.

Updated September 20267 min readStudy GuideCEH Exam
Gabrielle Wallace

Gabrielle Wallace

CEH Exam Editorial Team

Prepare for all PNPT deliverables: a five-day practical assessment, two additional days for a professional report, and a live 15-minute debrief. Use the included training and authorized labs to develop the assessed skills and practise explaining your results. TCM permits AI-enabled tools and requires disclosure of how tools were used in the report.

What the PNPT certification assesses

The PNPT is TCM Security's practical penetration testing exam: five days of engagement, two days of report writing, and a live debrief, with no multiple-choice questions and no capture flags.

The Practical Network Penetration Tester (PNPT) is a professional-level certification from TCM Security. Rather than a quiz, you carry out a network penetration test that the issuer designed to mirror paid client work.

You get five full days in the exam environment and an additional two days to write the report. TCM Security is explicit that this is not a capture-the-flag exercise: there are zero flags to capture and no multiple-choice questions.

TCM lists open-source intelligence, Active Directory exploitation, antivirus and egress bypassing, lateral and vertical movement, and compromising the exam Domain Controller among the assessment requirements. Prepare these skills through the included authorized labs alongside reporting and presentation.

Sources: Practical Network Penetration Tester (PNPT) - TCM Security — PNPT certification page, certifications.tcm-sec.com/pnpt

Eligibility, cost, and how long your access lasts

Anyone in any country can sit the exam, with parental consent required under 18. The $499 bundle includes the voucher, one free retake, and 12 months of training access; the certification itself no longer expires.

TCM Security states that any individual from any country is eligible, and that candidates under 18 must submit a Parental Consent Form before purchasing. There are no formal prerequisites to buy the voucher.

The standard bundle costs $499 and includes the exam voucher, one free retake, and 12 months of access to the on-demand training the exam is based on. The retake matters: the issuer includes it deliberately so a first attempt is not your only chance.

Two clocks run from purchase. Your exam voucher and your training access are each valid for 12 months. The certification itself, however, does not expire; TCM Security made it permanently valid as of April 17, 2023.

Current and former military, first responders, students, and teachers can request a 20% discount by emailing the issuer's support address with proof of status. If you have no professional hacking experience, the issuer recommends starting with its PJPT certification before attempting the PNPT.

Sources: Practical Network Penetration Tester (PNPT) - TCM Security — PNPT certification page, certifications.tcm-sec.com/pnpt

The engagement alone does not earn the certification

Completing the network assessment is only the first requirement. You must also submit a professional report and pass a live 15-minute debrief with assessors.

TCM lists technical assessment, a detailed written report and a live 15-minute debrief as parts of the certification process. Reaching the technical objective does not replace the other deliverables.

The issuer permits completing the engagement objectives before the five-day environment window ends. Keep the additional two-day report period visible in your plan rather than treating documentation as an optional task.

For the debrief, practise giving a clear account of a completed course lab within 15 minutes. Use your notes to explain the observations and result. This rehearsal is optional preparation, not an additional published examination requirement.

  • Perform open-source intelligence (OSINT) to gather the intelligence needed to attack the network.
  • Use Active Directory exploitation skills for antivirus and egress bypassing, lateral and vertical movement, and ultimately compromising the exam Domain Controller.
  • Provide a detailed, professionally written report.
  • Perform a live 15-minute report debrief in front of the assessors.

Sources: Practical Network Penetration Tester (PNPT) - TCM Security — PNPT certification page, certifications.tcm-sec.com/pnpt

Tools, monitoring, and the disclosure rule

All tools are allowed, including AI-enabled ones, provided you disclose how you used them in your report. There is no proctor, but the exam network is monitored for cheating.

TCM explicitly allows AI-enabled tools and requires disclosure of how tools were used in the report. Keep a record of their role while working so your account is accurate; the page does not publish a separate scoring allocation for disclosure.

The exam is not proctored and requires no monitoring software on your machine. TCM Security states that it monitors network traffic in the exam environment and has detection mechanisms for cheating, so the openness of the tool rule comes with verification behind the scenes.

On the practical side, the published system requirements are an 8GB RAM machine with a 256GB drive, an up-to-date operating system and browser, and a stable internet connection, since the exam environment is cloud-hosted.

Practice decision

Your PNPT exam notes show that you used Tool A for network discovery and AI-enabled Tool B to help interpret command output. The report lists Tool A but says no AI-enabled tools were used. Under TCM's published tool-disclosure rule, what needs correcting?

Show the answer

Describe how both tools were used, including Tool B's role, and remove the inaccurate statement that no AI-enabled tools were used.

Permission to use a tool and the obligation to disclose its use are separate parts of the published rule. Accurate disclosure addresses the omission in this example; it does not establish that every other exam requirement has been met.

Sources: Practical Network Penetration Tester (PNPT) - TCM Security — PNPT certification page, certifications.tcm-sec.com/pnpt

Preparing with the included training and labs

Your voucher includes 45+ hours of on-demand training and hands-on labs for 12 months, covering ethical hacking fundamentals, privilege escalation, OSINT, and external penetration testing.

The $499 bundle is built around five courses: Practical Ethical Hacking, Windows Privilege Escalation for Beginners, Linux Privilege Escalation for Beginners, Open-Source Intelligence (OSINT), and the External Pentest Playbook. Together they provide over 45 hours of on-demand video, and the voucher also includes hands-on local labs for practice.

The issuer's own difficulty guidance is blunt, and it is worth planning around. If you are a beginner, the exam will be very difficult and the issuer strongly recommends completing the included training first. Junior penetration testers should expect it to be difficult, possibly needing extra training. Mid-to-senior pentesters can expect moderate difficulty. This is the issuer's framing, not an independent rating.

You are not preparing alone. The bundle includes 24/7/365 course support and access to the issuer's community Discord, and TCM Security also sells live instruction options, such as its Ethical Hacker Bootcamp, if you want scheduled teaching on top of the on-demand material. Check the current course durations in the academy itself, since published figures have changed over time.

Sources: Practical Network Penetration Tester (PNPT) - TCM Security — PNPT certification page, certifications.tcm-sec.com/pnpt

Prepare the assessment, report and debrief together

Use the included authorized labs to connect technical practice with a clear written and spoken account of the work.

The five included courses cover practical ethical hacking, Windows and Linux privilege escalation, open-source intelligence and external penetration testing. Work through their lab instructions and compare your results with the explanations provided. The current certification page establishes the assessment requirements; the older training overview is supporting course context.

As an optional study routine, choose one completed course lab and write a short account with its objective, the relevant observations, the demonstrated result and any limits to the conclusion. Keep the supporting evidence beside each claim. If the course provides remediation guidance, distinguish that recommendation from a remediation you have actually tested.

Use that same account for a spoken rehearsal. Explain the path and result from your notes, then check whether the written account would make sense to someone who had not watched the lab. This prepares the report and debrief without prescribing one universal technical attack sequence.

Sources: Practical Network Penetration Tester (PNPT) - TCM Security — PNPT certification page, certifications.tcm-sec.com/pnpt

A final preparation checklist

Check the assessment requirements, reporting plan and access dates before starting.

  • Confirm your device meets TCM's published system requirements.
  • Review the included training and use its authorized labs to address your gaps.
  • Plan for the five-day assessment, additional two report days and live debrief.
  • Keep accurate notes on tool use, including AI-enabled tools, for report disclosure.
  • Check the voucher and training expiry dates before choosing your attempt date.

Sources: Practical Network Penetration Tester (PNPT) - TCM Security — PNPT certification page, certifications.tcm-sec.com/pnpt

Where to confirm details before you book

Treat TCM Security's PNPT certification page as the authority for current pricing, durations, and policies, and contact their support for discounts or the parental consent form.

Exam pages change: prices, course lineups, and training options are all adjustable by the issuer. Before purchasing, re-check the PNPT page for the current bundle contents and confirm any discount by emailing the support address listed there with your proof of status. If you are under 18, request the Parental Consent Form from the same address.

Choose a purchase date that leaves usable study time within the 12-month access window. Review the included material and your practice results before starting the exam. Live instruction is an optional training choice, not a prerequisite added by this guide.

Sources: Practical Network Penetration Tester (PNPT) - TCM Security — PNPT certification page, certifications.tcm-sec.com/pnpt

Sources

Key facts checked:

Next steps

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for TCM Security Practical Network Penetration Tester (PNPT).

Keep Reading

Related Study Guides

Explore related guides and preparation topics.