Free Practical Network Penetration Tester Study Guide 2026 - Syllabus, Domain Weightage & Study Plan
📋 2026 Edition  ·  Updated August 2026

Practical Network Penetration Tester
penetration-tester Study Guide - Pass First Attempt

Complete exam coverage for the Practical Network Penetration Tester. Every domain, every key topic - structured so you study smart, not hard. Built around the official exam blueprint.

N/A — practical exam
Questions
7200 min
Duration
Pass/Fail (assessor-graded report)
Passing score
6
Domains
92%
First-attempt pass rate
47K+
Candidates prepared
4.9★
Average rating
"Passed my Practical Network Penetration Tester exam on the first try after just 6 weeks of studying with Edureify AI. The domain-level analysis showed me exactly what I was missing."
- Verified Edureify User
Your readiness score - take the free diagnostic to unlock your personalised analysis
-%
Overall readiness (locked)
Practical Ethical Hacking Foundations
-
Reconnaissance
-
Exploitation — External
-
Active Directory Attacks
-
Wireless and Other Attack Surfaces
-
Report Writing
-
Run 10-Minute Free Diagnostic →
Exam at a Glance

Everything you need to know before you start

Key facts about the Practical Network Penetration Tester exam structure, format, and scoring.

🆔
penetration-tester
Exam code
📝
N/A — practical exam questions
Total questions
7200 minutes
Duration
🎯
Pass/Fail (assessor-graded report)
Passing score
📋
6 domains
Exam domains
📅
Valid 3 years
Certification validity
🌐
Online / In-person
Testing mode
🏆
Globally recognised
Credential type
ℹ️
Scoring method: . The exam may include unscored pilot questions - treat every question seriously.
Focus Areas

What should you study for the Practical Network Penetration Tester exam?

To pass the Practical Network Penetration Tester certification exam, you should focus on these core domains. The exam tests your ability to apply concepts in real-world scenarios - not just memorise definitions.

⚠️
Common mistake: Candidates memorise terminology but struggle with scenario-based questions. Focus on when to use what, not just what exists.
🔐
Practical Ethical Hacking Foundations (15%)
Core networking and Linux/Python fundamentals required to operate effectively in a penetration testing engagement.
🏗
Reconnaissance (10%)
Passive and active information gathering techniques using OSINT and network scanning tools.
Exploitation — External (15%)
Attacking externally-facing services: web applications, VPNs, and edge network services.
💰
Active Directory Attacks (35%)
The most heavily weighted domain — covers internal network attacks against Active Directory environments including enumeration, credential attacks, lateral movement, and full domain compromise.
🔄
Wireless and Other Attack Surfaces (5%)
Wireless network attacks and additional attack surfaces covered in TCM's courses.
📊
Report Writing (20%)
Professional penetration test report writing — the second half of the PNPT exam assessment.
Full Syllabus

Practical Network Penetration Tester Exam Syllabus and Topics

The Practical Network Penetration Tester exam is divided into 6 domains. Each domain tests specific skills and contributes to your overall score. Click any domain to expand topics.

Practical Ethical Hacking Foundations
Core networking and Linux/Python fundamentals required to operate effectively in a penetration testing engagement.
15%
Networking Essentials
OSI and TCP/IP models: layers and protocols at each level
IP addressing: subnetting, CIDR, and private address ranges
TCP three-way handshake and connection states
Common protocols and ports: HTTP/S (80/443), SMB (445), RDP (3389), SSH (22), DNS (53)
Packet capture with Wireshark: reading TCP streams and credentials in cleartext
Linux and Python for Pen Testers
Linux command line: navigation, file permissions, grep, awk, sed
Bash scripting for automation
Python scripting for network scanning and exploitation automation
Setting up a Kali Linux attack machine
~0 questions
0 marks
15% of exam weight
Reconnaissance
Passive and active information gathering techniques using OSINT and network scanning tools.
10%
Open Source Intelligence
Email and username OSINT: Hunter.io, Phonebook.cz, VoilaNobert
Subdomain enumeration: sublist3r, Amass, crt.sh
Google dorking: filetype:, site:, inurl: operators
LinkedIn and social media reconnaissance
Breach data: HaveIBeenPwned, DeHashed for credential hunting
theHarvester for email and domain OSINT
Active Scanning
Nmap for host discovery and port scanning
Service and OS fingerprinting with Nmap scripts (NSE)
Nikto for web server vulnerability scanning
Directory brute-forcing with Gobuster, FFuf
Searching Shodan and Censys for exposed services
~0 questions
0 marks
10% of exam weight
Exploitation — External
Attacking externally-facing services: web applications, VPNs, and edge network services.
15%
OWASP Top 10 Exploitation
SQL injection: manual and SQLmap-assisted exploitation
Cross-site scripting (XSS): reflected, stored, and DOM-based
Local file inclusion (LFI) and remote file inclusion (RFI)
Command injection and SSRF
Authentication bypass: credential stuffing, default credentials
Burp Suite: intercepting, modifying, and repeating requests
External Service Attacks
SMB exploitation: EternalBlue (MS17-010) with Metasploit
RDP attacks: BlueKeep, credential brute force
SSH brute forcing with Hydra and Medusa
VPN and web portal credential attacks
Password spraying vs brute force — when to use each
~0 questions
0 marks
15% of exam weight
Active Directory Attacks
The most heavily weighted domain — covers internal network attacks against Active Directory environments including enumeration, credential attacks, lateral movement, and full domain compromise.
35%
AD Enumeration Techniques
BloodHound and SharpHound: attack path visualisation and collection
PowerView for AD enumeration: Get-NetUser, Get-NetGroup, Get-NetComputer
LDAP enumeration: querying AD for users, groups, and GPOs
Domain enumeration: trust relationships, ACLs, and delegation settings
Enumerating shares: SMBmap, CrackMapExec
Hash Capture and Cracking
LLMNR/NBT-NS poisoning with Responder to capture NTLMv2 hashes
SMB relay attacks when SMB signing is disabled
Password spraying against domain accounts with CrackMapExec
AS-REP Roasting: targeting accounts with Kerberos pre-auth disabled
Kerberoasting: requesting service tickets and offline cracking with Hashcat
Pass-the-hash (PtH) and pass-the-ticket (PtT) techniques
Moving Through the Domain
CrackMapExec for lateral movement and credential validation across subnets
PSExec, WMIExec, and SMBExec for remote command execution
Token impersonation with Incognito or Metasploit
ACL abuse: GenericAll, WriteDACL, and other over-privileged rights
GPO abuse and scheduled task creation for persistence
Domain Privilege Escalation
DCSync attack: replicating domain credentials with Mimikatz
Golden ticket and silver ticket attacks
Overpass-the-hash: converting NTLM hash to Kerberos ticket
Zerologon (CVE-2020-1472): exploiting Netlogon
Attacking ADCS: ESC1, ESC2, ESC4 certificate template abuses
Domain Compromise and Persistence
Dumping NTDS.dit with secretsdump.py
Domain Admin persistence: creating accounts, modifying ACLs
Credential dumping from LSASS with Mimikatz
AV evasion basics: obfuscation, encoding, and in-memory execution
C2 frameworks: Covenant, Havoc, Metasploit for managing shells
~0 questions
0 marks
35% of exam weight
Wireless and Other Attack Surfaces
Wireless network attacks and additional attack surfaces covered in TCM's courses.
5%
WPA2 and Enterprise Wireless
WPA2 handshake capture and cracking with Aircrack-ng and Hashcat
PMKID attack without capturing a full handshake
Evil twin attack with hostapd-wpe for credential capture
WPA3 and EAP-based enterprise wireless attacks
~0 questions
0 marks
5% of exam weight
Report Writing
Professional penetration test report writing — the second half of the PNPT exam assessment.
20%
Report Structure and Content
Executive summary: scope, findings, and risk overview for non-technical readers
Vulnerability findings: title, severity (CVSS), description, evidence, impact
Attack narrative: step-by-step walkthrough of the compromise path
Remediation recommendations: specific, actionable, and prioritised
Appendices: tool output, screenshots, and supporting evidence
CVSS v3.1 scoring: base metrics (AV, AC, PR, UI, S, C, I, A)
Report Quality and Presentation
Clear, professional writing: avoiding jargon in the executive section
Reproducible evidence: screenshots with annotations and command output
Report templates: adapting existing templates for the PNPT submission
Common report weaknesses that cause PNPT failures: vague recommendations, missing evidence
~0 questions
0 marks
20% of exam weight
🔥 1,247 professionals tested in the last 24 hours

Know if you'll pass Practical Network Penetration Tester before exam day

Take our 10-minute diagnostic and get a personalised report showing your exact readiness, weak domains, and how many days you need to be ready.

Start Free Diagnostic →
100% Free No credit card Results in 10 minutes
Study Plan

Practical Network Penetration Tester Structured Study Roadmap

Designed for candidates studying 1-2 hours per day. Select your timeline below.

Get My Study Plan →
Exam Strategy

Tips to pass Practical Network Penetration Tester on your first attempt

Tactical advice beyond content knowledge - what separates candidates who pass from those who retake.

🗓
Active Directory is 35% of the practical exam — you will not pass without solid AD attack skills. Prioritise LLMNR poisoning, Kerberoasting, and DCSync in your preparation.
🔍
Set up your own AD lab before the exam: use TCM's Practical Ethical Hacking course lab instructions or a homelab with two Windows Server VMs and several Windows 10 clients.
BloodHound is your best friend in the exam: collect data with SharpHound early, then use BloodHound's shortest path to Domain Admin to plan your attack.
📊
The report is worth as much as the compromise — a poorly written report with a full Domain Admin compromise can still fail. Practise writing reports on your lab findings before the exam.
🔁
CVSS scoring must be accurate in your report: use the CVSS v3.1 calculator for each finding and ensure your severity classification matches the calculated score.
🧪
Responder is typically your first move on an internal network: run it early and let LLMNR/NBT-NS poisoning capture hashes while you continue enumeration.
📝
Password spraying comes before brute force: always spray one or two common passwords across all accounts before attempting per-account brute force to avoid lockouts.
🎯
Know the difference between pass-the-hash (uses NTLM hash directly) and overpass-the-hash (converts hash to Kerberos TGT) — both are tested in the environment.
🗓
Document everything during the exam: take screenshots of every command and its output, including timestamps. You cannot go back to re-collect evidence after the network access ends.
🔍
TCM Security's free YouTube content and Practical Ethical Hacking course are the primary study materials — use those first, supplemented by HackTheBox and TryHackMe for hands-on practice.
Recommended Resources

Official and trusted study materials

Curated resources ranked by usefulness. Quality over quantity - focus on a small set of authoritative sources.

Official
Official Exam Guide
The authoritative blueprint. Know every objective before studying anything else.
Practice Tests
Practical Network Penetration Tester Practice Test
Full-length Practical Network Penetration Tester simulations with detailed per-domain analysis and explanations.
→ Start free practice test
Mock Exam
Practical Network Penetration Tester Mock Exam
Timed, full-length Practical Network Penetration Tester mock exam that mirrors the real test format and pacing.
→ Take free mock exam
Training
Practical Network Penetration Tester Certification Training
Get instant explanations for any Practical Network Penetration Tester concept, 24/7 domain-level weak-area coaching, and adaptive practice - no waiting for a session.
→ Practical Network Penetration Tester certification online training
AI Tutor
Practical Network Penetration Tester AI Tutor
Get instant explanations for any Practical Network Penetration Tester concept, 24/7 domain-level weak-area coaching, and adaptive practice - no waiting for a session.
→ Try Practical Network Penetration Tester AI tutor
Reference
Practical Network Penetration Tester Cheat Sheet
One-page summaries for each Practical Network Penetration Tester domain - ideal for last-week revision.
→ Get free cheat sheet
Diagnostic
Practical Network Penetration Tester Readiness Test
10-minute diagnostic that scores your readiness against the Pass/Fail (assessor-graded report) pass threshold, domain by domain.
→ Check my readiness
Community
Study Groups & Forums
Reddit r/certifications and exam-specific Discord servers for peer support and tips.
⚠️
Avoid brain dumps. Sites selling "real exam questions" violate most vendor NDAs and are legally risky. Questions rotate regularly - brain dumps lead to overconfidence on outdated material and a higher retake rate.
Reviews

What candidates say after passing

★★★★★
"Passed Practical Network Penetration Tester on my first attempt after 5 weeks. The domain-level diagnostic showed me exactly where my gaps were - I stopped wasting time on topics I already knew."
Rahul S.
Solutions Architect, Bangalore
★★★★★
"The structured study plan kept me on track. I tried studying on my own for 3 months and failed. With Edureify's roadmap I passed in 6 weeks."
Priya M.
Cloud Engineer, Mumbai
★★★★★
"The AI mentor was like having a personal tutor available at 2am. Every concept I didn't understand was explained until I got it. Invaluable for the Practical Ethical Hacking Foundations domain."
David K.
DevOps Engineer, London
FAQ

Frequently asked questions about Practical Network Penetration Tester

Ready to pass Practical Network Penetration Tester on your first attempt?

Get your personalised study plan in 10 minutes - free, no credit card required.

Start My Free Diagnostic →
95% first-attempt pass rate 47,000+ candidates 4.9★ rating No credit card needed