100+ Free HTB CAPE Practice Questions
Prepare for the HTB Certified Active Directory Pentesting Expert exam with instant access — no signup required.
Loading practice questions...
Explore More Hack The Box Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: HTB CAPE Exam
10 days
Lab Duration
Hack The Box
15 modules
Prep Path Length
HTB Academy
ESC1-8
ADCS Attack Classes Covered
CAPE Syllabus
Expert
Difficulty Rating
Hack The Box
Lifetime
Certification Validity
Hack The Box
10+
AD Attack Domains Tested
CAPE Exam Guide
HTB CAPE is a 10-day practical AD lab exam that proves expert-level skills in Active Directory penetration testing. Candidates must enumerate complex AD environments, chain Kerberos attacks, exploit ADCS misconfigurations (ESC1-8), abuse DACL relationships using BloodHound, relay NTLM to LDAP and ADCS endpoints, attack cross-forest trusts, and operate a Sliver C2 framework — all while avoiding detection and submitting a professional report.
Sample HTB CAPE Practice Questions
Try these sample questions to test your HTB CAPE exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1Which PowerView function enumerates all Active Directory users in the current domain?
2What LDAP filter would you use to find all accounts with a Service Principal Name (SPN) set, making them Kerberoasting targets?
3During Kerberoasting, which component of the ticket is cracked offline to recover a service account's plaintext password?
4Which Impacket tool is used to perform AS-REP Roasting against accounts that do not require Kerberos pre-authentication?
5In BloodHound, what relationship edge indicates that a principal has the ability to modify the msDS-KeyCredentialLink attribute of another object, enabling a Shadow Credentials attack?
6What ADCS misconfiguration (ESC1) allows any domain user to enroll in a certificate template and specify an arbitrary Subject Alternative Name (SAN)?
7Which Certipy command is used to find vulnerable ADCS certificate templates and CA misconfigurations in a domain?
8ESC8 in ADCS involves relaying NTLM authentication to which service to obtain a certificate for a privileged account?
9Which tool is most commonly used in HTB CAPE path to perform NTLM relay attacks, including relaying to LDAP and ADCS endpoints?
10What is the purpose of the PetitPotam technique in an NTLM relay attack against AD CS?
About the HTB CAPE Exam
The HTB Certified Active Directory Pentesting Expert (CAPE) is Hack The Box's flagship certification for proving mastery in Active Directory penetration testing. The 10-day practical exam validates advanced skills across the full AD attack lifecycle: from enumeration and Kerberos abuse to ADCS exploitation, DACL manipulation, NTLM relay, cross-forest trust attacks, and C2 operations. This practice bank tests the conceptual knowledge underlying those techniques.
Assessment
Performance-based assessment
Time Limit
10 days lab + report window
Passing Score
Undisclosed
Exam Fee
HTB Academy subscription or standalone voucher (Hack The Box)
HTB CAPE Exam Content Outline
AD Enumeration & LDAP
LDAP filters, PowerView functions, BloodHound data collection and analysis, identifying attack surface from directory data
Kerberos Attacks
Kerberoasting, AS-REP Roasting, Golden and Silver Tickets, Pass-the-Ticket, unconstrained/constrained/RBCD delegation, S4U2Self/S4U2Proxy, Overpass-the-Hash, Diamond Tickets
DACL & ACL Abuse
WriteDacl, GenericWrite, GenericAll, WriteOwner, ForceChangePassword, Shadow Credentials, AdminSDHolder persistence, logon script abuse
NTLM Relay & Coerced Authentication
ntlmrelayx.py, Responder, PetitPotam, Printer Bug, mitm6 with DHCPv6/WPAD, relay to LDAP for RBCD and shadow credentials, relay to ADCS for ESC8
ADCS Attacks
ESC1 through ESC8 CA and template misconfigurations, Certipy enumeration and exploitation, PKINIT-based authentication, UnPAC-the-Hash
AD Trust Attacks
Child-to-parent domain compromise, SID History injection via Extra SIDs, inter-realm ticket forgery, trust key extraction, SID filtering bypass, selective authentication misconfiguration
C2 Operations, Lateral Movement & Reporting
Sliver C2 implant generation and management, SOCKS5 pivoting, execute-assembly for in-memory tool execution, Pass-the-Hash with psexec/wmiexec, professional penetration test report writing
How to Pass the HTB CAPE Exam
What You Need to Know
- Passing score: Undisclosed
- Assessment: Performance-based assessment
- Time limit: 10 days lab + report window
- Exam fee: HTB Academy subscription or standalone voucher
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
HTB CAPE Study Tips from Top Performers
Frequently Asked Questions
What is the HTB CAPE exam format?
CAPE is a 10-day practical Active Directory lab engagement. Candidates connect to a complex enterprise AD environment and must enumerate targets, chain attack techniques (Kerberoasting, ADCS ESC attacks, DACL abuse, NTLM relay, trust attacks), capture flags, and operate a C2 framework. The exam concludes with submission of a professional penetration test report documenting all findings, attack chains, and remediation recommendations.
What is the recommended preparation for HTB CAPE?
HTB recommends completing the Active Directory Penetration Tester job-role path on HTB Academy, which covers 15 modules and 253 sections. Key areas to master include: BloodHound attack path analysis, Kerberos protocol internals and all major attack types, ADCS enumeration and ESC1-8 exploitation with Certipy, NTLM relay with ntlmrelayx.py and PetitPotam/PrinterBug coercion, DACL abuse across all common ACE types, Sliver C2 operations, and professional report writing.
How difficult is the HTB CAPE exam?
CAPE is rated 'Expert' difficulty and is considered one of the most technically demanding AD-focused certifications available. The exam tests chaining multiple techniques together across a complex multi-domain environment while dealing with active defenses like Windows Defender. Candidates report that the ability to chain techniques (not just know them in isolation) and write a comprehensive 200+ page report are the hardest aspects. Starting the report on day 1 rather than waiting until day 8 is strongly recommended.
What tools are central to the CAPE exam?
Core tools include: BloodHound/SharpHound (AD attack path enumeration), PowerView (LDAP/DACL enumeration and manipulation), Rubeus (Kerberos attacks: Kerberoasting, AS-REP roasting, ticket forgery, PtT), Impacket suite (ntlmrelayx, GetUserSPNs, GetNPUsers, secretsdump, getST, psexec), Certipy (ADCS enumeration and ESC exploitation), Sliver C2 (C2 framework), Mimikatz (credential extraction), and Responder with mitm6 (NTLM capture and relay setup).
Does the CAPE exam require a report submission?
Yes. CAPE requires submission of a professional penetration test report within the reporting window after the lab period ends. The report must document all discovered attack paths, exploitation evidence (screenshots, command output, flags), and remediation recommendations. Report quality is a graded component. Experienced CAPE candidates recommend using a structured template and documenting findings in real time during the lab, not after.
Is this practice exam like the real CAPE?
No — this is a multiple-choice knowledge practice exam. The real CAPE is a fully practical hands-on assessment in a live AD environment. This practice bank tests the underlying conceptual knowledge (Kerberos mechanics, ADCS vulnerability classes, DACL abuse paths, C2 framework operations) that informs practical exploitation. To pass CAPE, extensive hands-on practice in HTB Academy labs and Pro Labs (like RastaLabs, Offshore, and Cybernetics) is essential.