Skip to main content

Command Palette

Search for a command to run...

The Road to CPTS - From Almost Nothing to Certified

Updated
•11 min read•View as Markdown
The Road to CPTS - From Almost Nothing to Certified

Almost Nothing

When I started my journey into the field of cybersecurity, I had very little knowledge of the field itself, hence why the title states "Almost Nothing". When I finished my degree in Computer Science and Information Technology, I only had a few network concepts down, as networking was never the main focus. I then did my honours year and chose cybersecurity as one of my main subjects. A few weeks into my honours year, while gaming with some friends, one of them brought up the show Mr. Robot. I had no idea about the show, and after he convinced me to watch it because it "had a lot to do with computers", I decided to give it a shot.

I think most of you reading this have at least heard of the show itself or have even seen it. This show made me realize the power of hacking and cybersecurity, and I became obsessed with it. I downloaded Kali and started by hacking my own phone, sniffing and inspecting packets on my home network, and even cracking passwords (my own, of course). I was constantly watching YouTube videos about hacking and cybersecurity, trying to learn more.

Looking back at it now, I had the motivation but had no direction or any sort of roadmap. At that time, I thought this was something my cybersecurity class would provide, but it never did. Don't get me wrong, the class was still really informative, as it went over encryption, the CIA triad, and some minor malware analysis, but never anything close to actual "hacking".

So, when I finished my honours year, I took a small break and then instantly found a job as a... software developer. Yeah, I know what you are thinking - what about the cybersecurity "obsession"? Well, the answer is that I wanted to start earning an income, and as I never received any answers from the cybersecurity firms where I applied, I just decided to start with software development. As time went on, I just lost interest in cybersecurity because I could never keep up with it. I always wanted to do it but never had the time, as this time in my life was crazy - from getting married, to moving to Germany (immigration is no joke and will test your sanity), to starting with freelance web development.

Starting Again

So, in the middle of 2025, I decided that software development, even if it is interesting, is not really what I wanted to do. I wanted to work in the cybersecurity field. I told my wife and family, and they were all super supportive, which, in all honesty, gave me the motivation to start learning again.

I started learning about networking concepts like subnetting, the OSI model, and different protocols like HTTP, FTP, SMTP, etc. But I quickly realised I was running into the same problem I had at university: I had no roadmap or starting point. It was time to use those research skills I obtained during my honours year, and I started researching like a conspiracy theorist trying to find evidence of cryptids.

Finally, I found that starting with a platform like TryHackMe was a great starting point. I instantly signed up and started learning, which I found amazing, as TryHackMe incorporated theory with practical work. I started with the normal Cyber Security 101 course and moved to the Jr. Penetration Tester path, as the idea of being an ethical hacker just sounded awesome. I use the term "ethical hacker" because most of my friends still make fun of me for trying to become a "penetration" tester.

Beginner CTFs were next on my list, and I cannot tell you the rush I got after I rooted my first machine without using a guide. It was awesome. After about two months on TryHackMe, I looked a bit more into Hack The Box, which was considered by most to be the harder platform, because I wanted to get my first certification to get my foot in the door.

Trust me when I tell you, the amount of research I did and the number of videos I watched comparing different certifications was A LOT.

I knew from my time at university that the GOLD STANDARD for getting a job as a pentester has always been the OSCP. So now you might be thinking, "Why the CPTS and not the OSCP?" And I have a very good answer for that question, as I thought long and hard about it...

It is just too expensive for me.

Here is a small table of the prices, in ascending order, of different certifications and their training material:

Certification Provider 2026 Price (USD) Level
PJPT TCM Security $249 Beginner
eJPT INE \(250 exam / \)299 bundle Beginner
PT1 TryHackMe ~$340 Beginner
CPTS Hack The Box $490 Intermediate
PNPT TCM Security $499 Intermediate
OSCP / OSCP+ OffSec $2,749/year Intermediate / Advanced

So, taking all of this into account, I decided to go with Hack The Box's Certified Penetration Testing Specialist (CPTS) certification. The best part of all this was that when I decided to get a plan on HTB's platform, they had a special going on because their new certification, the Certified Junior Cybersecurity Associate (CJCA), had just been released. I decided to grab the Silver membership, as that included all the training I needed, as well as an exam voucher for both the CPTS and the CJCA.

CJCA

I first decided to start with the CJCA, as it was seen as the easier certification to obtain. Going into the CJCA course, the knowledge I had obtained from TryHackMe helped a lot in the earlier stages, but I quickly realised that I was way more comfortable with the red team part of the course than I was with the blue team part, as at that time I had mostly only done red team stuff.

In all honesty, the coursework for the CJCA was excellent and helped me build a better foundation and reinforce some of the skills I had already learned. One thing that I want to make clear about HTB is that their course material contains a large amount of information. I also want to make it clear that this is not a bad thing. For me, it was great, as I feel all of the topics and techniques were explained thoroughly.

It also means that you should take breaks while doing the course so you don't get burned out - foreshadowing.

I started the CJCA course at the end of August 2025 and took the exam at the end of January 2026. That was about five months of learning and training. Just note that I did not study for 6–8 hours every day. I took some days off to spend with family, and on other days I just tried doing CTFs. The coursework was awesome, as it goes over both red- and blue-team concepts. I have even seen some people call the CJCA the purple-team certification.

In my personal opinion, for anyone reading this, DO NOT UNDERESTIMATE THIS EXAM. I know, it says "Junior" in the certification's name, but trust me: if you are a complete beginner, this exam will fold you like a lawn chair if you are not prepared. I will go over my experience of the exam in another post, but I can say it was my first time doing a Hack The Box exam, and as difficult as it was, I really enjoyed it. I happened to pass the exam on my first try, and one thing I can say is that I was brimming with self-confidence. I felt that all of that time I had put into learning and practicing had finally paid off. But I knew it wasn't over.

I still had to face the mythical CPTS.

CPTS

Here is where things started to get hard.

The CJCA and CPTS share some of the coursework, so when I started with the CPTS course, I had already completed some of the modules. This sounds like a good thing until you find out that the CPTS course consists of 28 modules, all filled with a lot of content that would take some time to work through. Looking at you, "Password Attacks" module.

Looking back on it now, everything in the CPTS course was super hands-on, and it contained a lot of practical assignments and skill assessments. There were times when stuff felt easy, and there were times when I felt like I wanted to test the structural integrity of the apartment walls using my cranium.

At the end, I got through it, and I started to realise that, in my opinion, this is what the authors of the course actually want. I really think they want you to struggle, to actually use your brain to work through problems, to do your own research, and to find a solution. Yeah, I understand some of you might think, "What is the point of the course if you have to look things up for yourself?" But this really helped me improve my problem-solving skills. My opinion is that, in the last few years, we have become so dependent on throwing our problems at an LLM and hoping it can solve them for us. So having this experience of struggling and doing your own research can only be beneficial for us as pentesters.

Getting back to the CPTS course, everything went smoothly until I hit the "Active Directory" module. This is where I started to experience burnout. I looked back at all the previous modules and thought to myself:

"How am I supposed to remember all of these things?"

I took notes on the previous modules, don't get me wrong, but there was still so much information. At this point, I just took a week off and did other things because I felt I was going to lose my motivation.

This turned out to be the best thing possible because, after the break, I felt ready to learn again.

I continued through the course and attempted the "Attacking Enterprise Networks" module blindly, which I know most people recommend you do.

After completing the whole CPTS course, I did an additional module "CrackMapExec" and then practised using the CPTS Track, which can be found on HTB Labs.

I will write a more detailed post about my whole experience with the CPTS exam, but there is one thing I want to make clear:

The CPTS exam humbled me.

It broke that chip right off my shoulder that I had from passing the CJCA, and I am honest when I say that this exam, from my point of view as a relative newcomer to the cybersecurity field, is damn hard. But don't let that scare you.

Even though the CPTS exam is hard, it made me a way better pentester, and for that, I am truly thankful. The fact that the CPTS exam was so hard for me made it even better when I received an email just after midnight saying that I had passed the exam. In all honesty, I think my wife will remember that moment better, as I almost gave her a heart attack when I shook her awake like a scene straight out of Billy Madison just to tell her that I had passed while she was deep asleep.

Crossing That "Finish Line"... Now What?

Now, with my CPTS in hand, I can finally start applying for jobs, but at the same time, I want to keep learning.

I know there is a lot more to learn, and honestly, that makes me excited. Learning new things and understanding new topics has always been a passion of mine.

The field of cybersecurity is vast, and that is so cool. I am really looking forward to seeing where this journey takes me.

Final Thanks

I want to thank God for all His help, support, and grace. I want to thank my family and friends for all their support and for always motivating me. It is really amazing to have such people in my life. I would also like to thank Hack The Box for giving me a great place to learn and practice. Finally, I would like to thank you, the reader, for reading through this. I hope you enjoyed it.

Just know that I have a lot more coming.