100+ Free HTB CPTS Practice Questions
Prepare for the HTB Certified Penetration Testing Specialist exam with instant access — no signup required.
Loading practice questions...
Explore More Hack The Box Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: HTB CPTS Exam
10 days
Exam Duration
Hack The Box
12/14 flags
Minimum Passing Requirement
Hack The Box
~8 machines
Target Machines in Exam
Hack The Box
28 modules
Path Prerequisite
HTB Academy
~$490/yr
Student Subscription
Hack The Box
Report required
Commercial-Grade Report
Hack The Box
HTB CPTS is a 10-day practical penetration testing exam requiring candidates to capture at least 12 of 14 flags across approximately 8 Linux and Windows machines in a simulated enterprise environment (including Active Directory), then submit a commercial-grade report. Prerequisites include completing all 28 modules of the HTB Academy Penetration Tester path. This practice exam covers knowledge areas: Nmap, ffuf, BloodHound, Kerberoasting, Metasploit, SQLi, LFI, privesc, and AD attacks.
Sample HTB CPTS Practice Questions
Try these sample questions to test your HTB CPTS exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1Which Nmap flag performs a TCP SYN (half-open) scan without completing the three-way handshake?
2Which Nmap flag enables service version detection on open ports?
3During footprinting, you want to enumerate all 65,535 TCP ports on a target. Which Nmap flag set achieves this?
4What is the primary purpose of the Nmap Scripting Engine (NSE) category 'vuln'?
5Which ffuf flag specifies the wordlist used for web directory fuzzing?
6You are fuzzing for virtual hosts on a web server. Which ffuf flag tells it to match only responses with a specific HTTP response code?
7What does the 'FUZZ' keyword in an ffuf command represent?
8Which protocol does Kerberoasting attack to retrieve service account ticket hashes for offline cracking?
9Which tool is used to perform Kerberoasting from a Linux host, requesting TGS tickets for all SPNs in a domain?
10AS-REP Roasting is possible when a user account has which specific attribute set?
About the HTB CPTS Exam
The HTB Certified Penetration Testing Specialist (CPTS) is a practical penetration testing certification from Hack The Box that validates skills across network enumeration, web application attacks, Active Directory exploitation, privilege escalation, and pivoting. Unlike multiple-choice exams, CPTS requires compromising real machines in a 10-day black-box enterprise lab environment and submitting a commercial-grade report.
Assessment
Performance-based assessment
Time Limit
10 days (240 hours)
Passing Score
12/14 flags + accepted report
Exam Fee
~$490/year (Student subscription) or standalone voucher (Hack The Box)
HTB CPTS Exam Content Outline
Network Enumeration & Footprinting
Nmap scanning flags, NSE scripts, SMB/SNMP/DNS/LDAP/FTP enumeration, and service version detection
Active Directory Enumeration & Attacks
BloodHound, Kerberoasting, AS-REP roasting, DCSync, Pass-the-Hash, NTLM relay, ACL abuse, and Golden/Silver tickets
Web Attacks
SQL injection, LFI/RFI, command injection, XSS, IDOR, SSRF, XXE, file upload bypasses, and ffuf fuzzing
Linux & Windows Privilege Escalation
SUID abuse, sudo misconfigs, cron jobs, unquoted service paths, SeImpersonatePrivilege, Potato exploits, and LinPEAS/WinPEAS
Password Attacks
Hashcat modes, John the Ripper, credential dumping (SAM/NTDS), password spraying, and Pass-the-Hash
Shells, Payloads & Post-Exploitation
msfvenom, Metasploit modules, Meterpreter commands, shell upgrades, and file transfer techniques
Pivoting & Tunneling
SSH port forwarding, Chisel SOCKS5 proxy, proxychains, and multi-hop network traversal
Pentest Process & Documentation
Pre-engagement scoping, Rules of Engagement, MITRE ATT&CK mapping, CVSS scoring, and professional report writing
How to Pass the HTB CPTS Exam
What You Need to Know
- Passing score: 12/14 flags + accepted report
- Assessment: Performance-based assessment
- Time limit: 10 days (240 hours)
- Exam fee: ~$490/year (Student subscription) or standalone voucher
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
HTB CPTS Study Tips from Top Performers
Frequently Asked Questions
What is the HTB CPTS exam format?
The HTB CPTS exam is a 10-day (240-hour) practical black-box penetration test conducted via VPN against approximately 8 Linux and Windows machines in a simulated enterprise environment including Active Directory. Candidates receive a letter of engagement defining scope. They must capture at least 12 of 14 flags and submit a commercial-grade penetration test report. Both the flag threshold and an accepted report are required for certification.
What are the prerequisites for the HTB CPTS?
Candidates must complete all 28 modules of the HTB Academy Penetration Tester job-role path at 100% before the exam becomes accessible. Each module includes skills assessments that must be completed. The path covers enumeration, web attacks, Active Directory attacks, privilege escalation, pivoting, password attacks, and reporting — approximately 150-300 hours of study.
How should I prepare for the HTB CPTS?
Complete every module in the HTB Academy Penetration Tester path thoroughly, including all skills assessments. Practice on retired HTB machines that match CPTS difficulty (Easy to Medium). Focus especially on Active Directory attacks (BloodHound, Kerberoasting, Pass-the-Hash), web attacks (SQLi, LFI, command injection), and privilege escalation on both Linux and Windows. Practice report writing alongside your technical skills — the report is separately graded.
How does the HTB CPTS compare to the OSCP?
Both are practical penetration testing certifications, but they differ in scope and format. OSCP (24 hours) tests exploitation and AD compromise with a specific scoring structure; CPTS (10 days) provides more time and covers a broader range of web attacks, footprinting, and methodology documentation. CPTS costs less (~$490/year vs $1,699+) and is gaining industry recognition, particularly among HTB community members. Many candidates pursue both.
What does the CPTS professional report require?
The HTB CPTS report must be a commercial-grade penetration test document including an executive summary, methodology description, detailed findings with risk ratings and remediation recommendations, proof screenshots with flag captures, and supporting evidence for each compromise. HTB provides a sample report structure. The report is reviewed by HTB staff and must demonstrate professional technical writing quality in addition to correct findings.
Is this practice exam like the real HTB CPTS?
No — this is a knowledge-prep multiple-choice practice exam. The real HTB CPTS requires actually compromising machines in a live lab environment over 10 days. These practice questions build conceptual knowledge of tools (Nmap, BloodHound, Metasploit), techniques (Kerberoasting, Pass-the-Hash, LFI), and methodology that underpin practical exploitation. Use this alongside hands-on HTB machine practice for complete exam preparation.