Practical Network Penetration Tester Study Guide 2026: Syllabus, Exam Topics & Study Plan -Edureify
๐Ÿ“‹ 2026 Edition  ยท  Updated September 2026

Practical Network Penetration Tester Study Guide 2026

Complete exam coverage for the Practical Network Penetration Tester: syllabus, domains, key topics, study plan and practical exam preparation strategy.

N/A — practical exam
Questions
7200 min
Duration
Pass/Fail (assessor-graded report)
Passing score
6
Domains
95%
First-attempt pass rate
47K+
Candidates prepared
4.9โ˜…
Average rating
"Passed my Practical Network Penetration Tester exam on the first try after just 6 weeks of studying with Edureify AI. The domain-level analysis showed me exactly what I was missing."
- Verified Edureify User
Your readiness score - take the free diagnostic to unlock your personalised analysis
-%
Overall readiness (locked)
Practical Ethical Hacking Foundations
-
Reconnaissance
-
Exploitation — External
-
Active Directory Attacks
-
Wireless and Other Attack Surfaces
-
Report Writing
-
Run 10-Minute Free Diagnostic โ†’
Exam at a Glance

Practical Network Penetration Tester Exam Overview

Key facts about the Practical Network Penetration Tester exam structure, format and scoring.

๐Ÿ†”
penetration-tester
Exam code
๐Ÿ“
N/A — practical exam questions
Total questions
โฑ
7200 minutes
Duration
๐ŸŽฏ
Pass/Fail (assessor-graded report)
Passing score
๐Ÿ“‹
6 domains
Exam domains
๐Ÿ†
Certification
Credential type
โ„น๏ธ
Scoring method: . The exam may include unscored pilot questions - treat every question seriously.
Focus Areas

What should you study for the Practical Network Penetration Tester exam?

Start with the domains that make up the Practical Network Penetration Tester exam. Use the detailed syllabus below to work through the individual topics.

โš ๏ธ
Common mistake: Candidates often memorise terminology but struggle with scenario-based questions. Focus on when to use what, not just what exists.
🔐
Practical Ethical Hacking Foundations (15%)
Core networking and Linux/Python fundamentals required to operate effectively in a penetration testing engagement.
🏗
Reconnaissance (10%)
Passive and active information gathering techniques using OSINT and network scanning tools.
Exploitation — External (15%)
Attacking externally-facing services: web applications, VPNs, and edge network services.
💰
Active Directory Attacks (35%)
The most heavily weighted domain — covers internal network attacks against Active Directory environments including enumeration, credential attacks, lateral movement, and full domain compromise.
🔄
Wireless and Other Attack Surfaces (5%)
Wireless network attacks and additional attack surfaces covered in TCM's courses.
📊
Report Writing (20%)
Professional penetration test report writing — the second half of the PNPT exam assessment.
Full Syllabus

Practical Network Penetration Tester Exam Syllabus and Topics

The Practical Network Penetration Tester exam is divided into 6 domains. Each domain covers specific skills and topics. Expand a domain to see the detailed syllabus.

Networking Essentials
OSI and TCP/IP models: layers and protocols at each level
IP addressing: subnetting, CIDR, and private address ranges
TCP three-way handshake and connection states
Common protocols and ports: HTTP/S (80/443), SMB (445), RDP (3389), SSH (22), DNS (53)
Packet capture with Wireshark: reading TCP streams and credentials in cleartext
Linux and Python for Pen Testers
Linux command line: navigation, file permissions, grep, awk, sed
Bash scripting for automation
Python scripting for network scanning and exploitation automation
Setting up a Kali Linux attack machine
~0 questions
0 marks
15% of exam weight
Open Source Intelligence
Email and username OSINT: Hunter.io, Phonebook.cz, VoilaNobert
Subdomain enumeration: sublist3r, Amass, crt.sh
Google dorking: filetype:, site:, inurl: operators
LinkedIn and social media reconnaissance
Breach data: HaveIBeenPwned, DeHashed for credential hunting
theHarvester for email and domain OSINT
Active Scanning
Nmap for host discovery and port scanning
Service and OS fingerprinting with Nmap scripts (NSE)
Nikto for web server vulnerability scanning
Directory brute-forcing with Gobuster, FFuf
Searching Shodan and Censys for exposed services
~0 questions
0 marks
10% of exam weight
OWASP Top 10 Exploitation
SQL injection: manual and SQLmap-assisted exploitation
Cross-site scripting (XSS): reflected, stored, and DOM-based
Local file inclusion (LFI) and remote file inclusion (RFI)
Command injection and SSRF
Authentication bypass: credential stuffing, default credentials
Burp Suite: intercepting, modifying, and repeating requests
External Service Attacks
SMB exploitation: EternalBlue (MS17-010) with Metasploit
RDP attacks: BlueKeep, credential brute force
SSH brute forcing with Hydra and Medusa
VPN and web portal credential attacks
Password spraying vs brute force — when to use each
~0 questions
0 marks
15% of exam weight
AD Enumeration Techniques
BloodHound and SharpHound: attack path visualisation and collection
PowerView for AD enumeration: Get-NetUser, Get-NetGroup, Get-NetComputer
LDAP enumeration: querying AD for users, groups, and GPOs
Domain enumeration: trust relationships, ACLs, and delegation settings
Enumerating shares: SMBmap, CrackMapExec
Hash Capture and Cracking
LLMNR/NBT-NS poisoning with Responder to capture NTLMv2 hashes
SMB relay attacks when SMB signing is disabled
Password spraying against domain accounts with CrackMapExec
AS-REP Roasting: targeting accounts with Kerberos pre-auth disabled
Kerberoasting: requesting service tickets and offline cracking with Hashcat
Pass-the-hash (PtH) and pass-the-ticket (PtT) techniques
Moving Through the Domain
CrackMapExec for lateral movement and credential validation across subnets
PSExec, WMIExec, and SMBExec for remote command execution
Token impersonation with Incognito or Metasploit
ACL abuse: GenericAll, WriteDACL, and other over-privileged rights
GPO abuse and scheduled task creation for persistence
Domain Privilege Escalation
DCSync attack: replicating domain credentials with Mimikatz
Golden ticket and silver ticket attacks
Overpass-the-hash: converting NTLM hash to Kerberos ticket
Zerologon (CVE-2020-1472): exploiting Netlogon
Attacking ADCS: ESC1, ESC2, ESC4 certificate template abuses
Domain Compromise and Persistence
Dumping NTDS.dit with secretsdump.py
Domain Admin persistence: creating accounts, modifying ACLs
Credential dumping from LSASS with Mimikatz
AV evasion basics: obfuscation, encoding, and in-memory execution
C2 frameworks: Covenant, Havoc, Metasploit for managing shells
~0 questions
0 marks
35% of exam weight
WPA2 and Enterprise Wireless
WPA2 handshake capture and cracking with Aircrack-ng and Hashcat
PMKID attack without capturing a full handshake
Evil twin attack with hostapd-wpe for credential capture
WPA3 and EAP-based enterprise wireless attacks
~0 questions
0 marks
5% of exam weight
Report Structure and Content
Executive summary: scope, findings, and risk overview for non-technical readers
Vulnerability findings: title, severity (CVSS), description, evidence, impact
Attack narrative: step-by-step walkthrough of the compromise path
Remediation recommendations: specific, actionable, and prioritised
Appendices: tool output, screenshots, and supporting evidence
CVSS v3.1 scoring: base metrics (AV, AC, PR, UI, S, C, I, A)
Report Quality and Presentation
Clear, professional writing: avoiding jargon in the executive section
Reproducible evidence: screenshots with annotations and command output
Report templates: adapting existing templates for the PNPT submission
Common report weaknesses that cause PNPT failures: vague recommendations, missing evidence
~0 questions
0 marks
20% of exam weight
๐Ÿ”ฅ 1,247 professionals tested in the last 24 hours

Know if you'll pass Practical Network Penetration Tester before exam day

Take our 10-minute diagnostic and get a personalised report showing your readiness, weak domains and where to focus next.

Start Free Diagnostic โ†’
100% FreeNo credit cardResults in 10 minutes
Study Plan

Practical Network Penetration Tester Structured Study Roadmap

Choose a preparation timeline based on how much time you have available. For a plan based on your actual readiness and weak domains, use the personalised Edureify study experience. Get My Training Plan โ†’

Weeks 1-2
Core Services + Highest-Weighted Domain
Deep-dive into the most heavily tested domain. Spend more time here when its exam weight is significantly higher.
Official exam guideDomain 1 completeCore conceptsPractice questions
Week 3
Domain 2 - Hands-on Practice
Focus on scenario-based study and reinforce concepts through practical application where applicable.
Domain 2Scenario walkthroughsHands-on practicePractice questions
Week 4
Domain 3 - Deeper Concepts
Work through complex concepts and decision scenarios.
Domain 3Scenario drillsPractice examReview
Week 5
Remaining Domains + Weak Area Targeting
Identify your weaker domains and spend focused time closing those gaps.
Remaining domainsDiagnosticTargeted reviewStudy notes
Week 6
Full Simulations + Final Preparation
Use timed simulations to test your preparation and review the reasoning behind incorrect answers.
Full mock examsWrong-answer reviewFinal reviewExam logistics
Exam Strategy

Tips to pass Practical Network Penetration Tester on your first attempt

Practical advice for applying what you know, managing questions and preparing for exam conditions.

🗓
Active Directory is 35% of the practical exam — you will not pass without solid AD attack skills. Prioritise LLMNR poisoning, Kerberoasting, and DCSync in your preparation.
🔍
Set up your own AD lab before the exam: use TCM's Practical Ethical Hacking course lab instructions or a homelab with two Windows Server VMs and several Windows 10 clients.
BloodHound is your best friend in the exam: collect data with SharpHound early, then use BloodHound's shortest path to Domain Admin to plan your attack.
📊
The report is worth as much as the compromise — a poorly written report with a full Domain Admin compromise can still fail. Practise writing reports on your lab findings before the exam.
🔁
CVSS scoring must be accurate in your report: use the CVSS v3.1 calculator for each finding and ensure your severity classification matches the calculated score.
🧪
Responder is typically your first move on an internal network: run it early and let LLMNR/NBT-NS poisoning capture hashes while you continue enumeration.
📝
Password spraying comes before brute force: always spray one or two common passwords across all accounts before attempting per-account brute force to avoid lockouts.
🎯
Know the difference between pass-the-hash (uses NTLM hash directly) and overpass-the-hash (converts hash to Kerberos TGT) — both are tested in the environment.
🗓
Document everything during the exam: take screenshots of every command and its output, including timestamps. You cannot go back to re-collect evidence after the network access ends.
🔍
TCM Security's free YouTube content and Practical Ethical Hacking course are the primary study materials — use those first, supplemented by HackTheBox and TryHackMe for hands-on practice.
Recommended Resources

Practical Network Penetration Tester Study Resources

Use a focused set of resources alongside the study guide rather than trying to study from everything available.

Official
Official Exam Guide
Start with the authoritative exam objectives and blueprint.
Practice Tests
Practical Network Penetration Tester Practice Test
Practice questions with explanations and domain-level performance analysis.
โ†’ Start free practice test
Mock Exam
Practical Network Penetration Tester Mock Exam
Timed preparation under realistic exam-style conditions.
โ†’ Take free mock exam
Training
Practical Network Penetration Tester Certification Training
Structured preparation with personalised learning support and adaptive practice.
โ†’ Practical Network Penetration Tester certification online training
AI Tutor
Practical Network Penetration Tester AI Tutor
Get help understanding concepts and work on weak areas with AI-powered learning support.
โ†’ Try Practical Network Penetration Tester AI tutor
Reference
Practical Network Penetration Tester Cheat Sheet
Quick-reference summaries for final revision.
โ†’ Get free cheat sheet
Diagnostic
Practical Network Penetration Tester Readiness Test
Assess your preparation and identify weaker exam domains.
โ†’ Check my readiness
โš ๏ธ
Avoid brain dumps. Sites selling real or stolen exam questions may violate certification-provider rules and can leave candidates studying outdated material.
Reviews

What candidates say after passing

โ˜…โ˜…โ˜…โ˜…โ˜…
I tried two other prep platforms beforeEdureify AI. The difference is thatEdureify AI made me think through scenarios instead of just picking from answer choices. That's what the Penetration Tester actually tests, and that's what the platform actually trains.
Michael T.
VP Engineering
โ˜…โ˜…โ˜…โ˜…โ˜…
The voice-first format was the only reason I could prepare at all while managing a demanding client project. I studied during commutes, lunch breaks, and evening walks. By exam day, I'd covered more practice scenarios than most candidates do in a traditional prep course.
Shweta B.
Agile Coach
โ˜…โ˜…โ˜…โ˜…โ˜…
BootSelf AI's diagnostic found my CVSS scoring gap in the first session. I'd been ignoring it because it felt conceptually familiar. Turns out familiarity and exam-readiness are completely different things. The targeted practice on that gap changed my score trajectory.
Fatima H.
Security Lead
โ˜…โ˜…โ˜…โ˜…โ˜…
I appreciated thatEdureify AI didn't treat the Penetration Tester as a memorization exercise. Every scenario forced me to reason through the question the way the exam expects - weighing context, applying frameworks, eliminating wrong answers systematically. That's a trainable skill and the platform trains it well.
Amelia P.
Portfolio Manager
FAQ

Frequently asked questions about Practical Network Penetration Tester

Most candidates with relevant background can structure their preparation over several weeks, depending on their existing knowledge, available study time and exam difficulty. Use the study roadmap above as a starting point and use the readiness diagnostic to identify where you need more preparation.
The guide covers the exam overview, domains, detailed syllabus and topics, study roadmap, exam preparation tips and links to practice, mock, readiness, cheat-sheet, AI Tutor and training resources.
The guide is designed to organize your preparation around the exam syllabus. You should combine it with practice questions and timed simulations so that you can test both your knowledge and your ability to apply it.
Yes. Start with the exam overview and domain breakdown, then work through the detailed topics using the study roadmap. Candidates with less experience may need additional time for foundational concepts.
Take the Edureify readiness diagnostic to assess your preparation and identify the domains where you need to focus more.
Edureify AI can help explain concepts, identify weaker areas from practice performance and support a more personalised preparation process.

Ready to prepare for Practical Network Penetration Tester?

Find your weak areas and build a more focused preparation plan.

Start My Free Diagnostic โ†’
95% first-attempt pass rate47,000+ candidates4.9โ˜… ratingNo credit card needed
Keep Learning

Related Cybersecurity Certification Study Guides

Explore related certification study guides within this category.