CPENT · ● Active · Professional · EC-Council
Exam facts
| Field | Value |
|---|---|
| Cost | $999–$1,199 (exam + 90-day practice range); retake ~$499 |
| Duration | 24 hours (optionally two 12-hour sessions) |
| Questions | 100% practical, hands-on; total score 2500 points |
| Passing | 1750/2500 (70%) |
| Format | Live cyber range; network penetration testing + report submission |
| Delivery | EC-Council remote proctored environment |
| Languages | English |
| Valid | 2 years |
| Renewal | Mandatory recertification every 2 years |
| Prerequisites | 2+ years information security experience recommended; CEH or equivalent knowledge preferred |
| Released | 2020 (current iteration); CPENT V2 blueprint released April 2025 |
| Retiring | N/A |
Vendor source — EC-Council Certified Penetration Testing Professional ↗
Official exam page — CPENT Certification ↗
Exam blueprint — CPENT v1 Exam Blueprint PDF ↗ · CPENT v2 Exam Blueprint PDF ↗
About
CPENT is a 24-hour, fully practical, hands-on penetration testing certification that evaluates your ability to conduct a complete full-scope penetration test against a simulated enterprise network. Unlike theory-based exams, CPENT places you in a live cyber range where you must perform reconnaissance, identify vulnerabilities, exploit systems, pivot across network segments, bypass filters, escalate privileges, and deliver a professional penetration testing report. Released in 2020 and significantly updated in 2025, CPENT is the successor to EC-Council's Certified Ethical Hacker (CEH) for professionals seeking advanced, real-world offensive security validation. Holders scoring ≥90% also earn the Licensed Penetration Tester (LPT) Master credential simultaneously.
Domain context — Security
Penetration testing and ethical hacking — vendor-neutral offensive security practice. Validates capability to identify vulnerabilities, exploit systems responsibly, and communicate findings to organizations. Core IT security specialization for red teamers, security researchers, and senior security engineers.
Topics covered
CPENT v1 and v2 exam blueprints cover the following high-level domains:
- Penetration Testing Methodologies, Scoping & Engagement (~5%) — engagement types, ROE, timeline, quoting, ethical considerations, NIST methodology
- Reconnaissance & Information Gathering (~8%) — OSINT, passive/active scanning, social engineering, threat modeling
- Vulnerability Scanning & Assessment (~12%) — scanning tools, vulnerability databases, risk rating, manual validation
- Network Penetration Testing (~28%) — LAN/WAN targeting, lateral movement, AD exploitation, pivoting, firewall bypass, protocol attacks
- Web Application Penetration Testing (~16%) — OWASP Top 10, API testing, filtered network access, injection, authentication bypass
- Wireless & IoT Penetration Testing (~7%) — WiFi cracking, Bluetooth attacks, firmware analysis, embedded system exploitation
- Operational Technology (OT) & SCADA (~6%) — Modbus protocol interception, PLC communication, industrial control system attacks
- Binary Exploitation & Advanced Techniques (~11%) — reverse engineering, exploit writing, shellcode, privilege escalation
- Reporting & Post-Exploitation (~7%) — documentation, evidence collection, recommendations, professional communication
Source: EC-Council CPENT v1 Exam Blueprint ↗, CPENT v2 Exam Blueprint ↗
Common skills at Security · Professional
- Deep-dive system exploitation and post-exploitation techniques
- Network segmentation bypass and multi-hop lateral movement
- Active Directory enumeration, kerberoasting, and domain compromise
- Web application vulnerability discovery and exploitation chains
- Wireless network cracking and rogue access point deployment
- Embedded firmware extraction and IoT device exploitation
- Proficiency in penetration testing tools (Metasploit, Burp Suite, Cobalt Strike, etc.)
- Report writing and evidence documentation for legal compliance
- Threat modeling and attack path prioritization
- Secure, responsible disclosure and client communication
Recommended courses at Security · Professional
| Provider | Title | Cost | URL |
|---|---|---|---|
| EC-Council iClass (official) | Certified Penetration Testing Professional (CPENT) | $2,199 | ↗ |
| EC-Council iLearn (self-study) | CPENT Video Course with iLabs | $2,199–$2,800 | ↗ |
| EC-Council Accredited Training Centers | Instructor-Led CPENT Bootcamp | $2,000–$2,800 | EC-Council ATC Directory ↗ |
| TrainingCamp | CPENT Certification Bootcamp | $1,499–$1,999 | ↗ |
| Udemy (various) | CPENT Prep Courses | $10–$100 | Search "CPENT" on Udemy |
Course-selection rule: CPENT requires hands-on lab access to simulate the 24-hour exam environment. EC-Council's official iLearn/iClass includes 110+ labs, live cyber ranges, and CTF challenges. Third-party bootcamps supplement; ensure they offer live range access.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| EC-Council Store | CPENT Exam + 90-Day Practice Range | $999–$1,199 | ↗ |
| Whizlabs | CPENT Practice Tests | $99 | ↗ |
| MeasureUp | EC-Council CPENT Practice Exam | $165 | ↗ |
| TryHackMe | Penetration Testing Pathways | $20–$30/month | ↗ |
| HackTheBox | Pro Membership + Labs | $20/month | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| Certified Penetration Testing Professional (CPENT) Exam Guide | Rahul Deshmukh | BPB Online | 2023 | 978-9355514028 | ↗ |
| EC-Council CPENT Exam Prep: 500 Practice Questions and Explanations | Steve Brown | Self-Published | 2023 | 9798343370898 | ↗ |
| CPENT Textbook (Official EC-Council) | EC-Council | EC-Council Press | 2023 | N/A | ↗ |
| Penetration Testing: Security Analysis | EC-Council Press | Cengage Learning | 2013 | 978-1435483668 | ↗ |
Book rule: Most CPENT-specific study materials are recent (2023–2024). The EC-Council Press textbook is official but primarily video-based; the Deshmukh guide provides structured domain walkthrough; Brown's 500-question book offers exam-style practice. No single "definitive" vendor textbook; use iLearn video content + supplementary books.
Typical job titles at Security · Professional
Penetration Tester · Senior Penetration Tester · Red Team Operator · Security Researcher · Vulnerability Assessor · Application Security Engineer · Incident Response Analyst (advanced) · Security Consultant
(Job titles drawn from current job-board postings listing CPENT or equivalent as required/preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $116,888–$206,119 (mid-career); up to $265,211 (top 10%) | Glassdoor ↗ · PayScale ↗ |
| ZAR | R658,337–R757,106 (senior, 8+ years) | PayScale ZA ↗ |
| GBP | £80,000–£140,000 (mid-senior roles) | IT Jobs Watch ↗ |
Salary rule: CPENT-specific salary ranges are merged with "Penetration Tester" general roles, as most job boards don't isolate by certification. Senior penetration testers (CPENT + 5+ years experience) command the top quartile. Geographic variation is significant (US > UK > ZA); experience and specialization (cloud pentesting, API security) drive higher ranges.
Skills validated
- OSINT & reconnaissance — passive information gathering, domain enumeration, metadata harvesting
- Network architecture targeting — subnet mapping, firewall rule identification, DMZ lateral movement
- Active Directory exploitation — enumeration, Kerberos attacks, Golden Ticket, DCSync, pass-the-hash
- Metasploit & payload generation — multi-staged shellcode, encoders, stagers, meterpreter persistence
- Web application security — SQL injection, XSS, CSRF, XXE, insecure deserialization, API auth bypass
- Wireless penetration testing — WPA2/WPA3 cracking, evil twin deployment, client isolation bypass
- IoT/firmware exploitation — UART extraction, binary analysis, emulation, custom exploit development
- OT/SCADA attack surface — Modbus protocol communication, PLC interaction, sensor manipulation
- Privilege escalation — kernel exploits, privilege abuse, UAC bypass, systemd enumeration
- Pivoting & tunneling — multi-hop lateral movement, DNS tunneling, VPN bypass, firewall evasion
- Post-exploitation & reporting — evidence preservation, proof-of-concept videos, executive summary, remediation guidance
Related certifications
- Prerequisite: EC-Council Certified Ethical Hacker (CEH) ↗ (recommended entry point before CPENT)
- Stacks with: GIAC Penetration Tester (GPEN) ↗ · CompTIA PenTest+ ↗
- Equivalent at this level: Offensive Security Certified Professional (OSCP) ↗ — OSCP is entry-level practical, CPENT is mid-career advanced; both require 24-hour hands-on exams
- Advanced progression: GIAC Exploit Researcher & Advanced Penetration Tester (GXPN) ↗ · Offensive Security Web Expert (OSWE) ↗
- Dual credential: CPENT scorers ≥90% earn Licensed Penetration Tester (LPT) Master simultaneously
- Vendor overview: EC-Council Overview ↗
Sources
- EC-Council CPENT Official Page ↗
- EC-Council Certification Database ↗
- CPENT v1 Exam Blueprint ↗
- CPENT v2 Exam Blueprint (April 2025) ↗
- EC-Council iClass CPENT Course ↗
- EC-Council CPENT Store ↗
- Glassdoor Penetration Tester Salary Data ↗
- PayScale US Penetration Tester ↗
- PayScale ZA Penetration Tester ↗
- EC-Council Career Guide 2026 ↗
- CPENT vs OSCP Comparison ↗
Last verified: 2026-05-01
Parent ecosystem: Penetration Testing & Ethical Hacking
Parent domain: Security
Vendor overview: EC-Council Overview