1.1 eJPT Exam Blueprint, Lab Architecture & Strategy
Key Takeaways
The eJPT by INE Security features a 48-hour continuous hands-on engagement consisting of 35 scenario-driven dynamic questions requiring an overall 70% passing threshold with domain-level competency.
Candidates connect to an isolated, multi-subnet lab environment either through an in-browser virtual desktop or via a dedicated OpenVPN connection to their local attack machine.
Multi-homed pivot hosts separate the initial DMZ target network from internal corporate subnets, making network enumeration, route configuration, and pivoting mandatory assessment components.
Success relies on structured operational time management: avoiding rabbit holes, enforcing disciplined note-taking with Obsidian or CherryTree, preserving terminal logs and screenshots, and systematically tracking flags and credentials.
1.1 eJPT Exam Blueprint, Lab Architecture & Strategy
The eLearnSecurity Junior Penetration Tester (eJPT) certification, administered by INE Security, represents one of the industry's premier entry-level practical offensive security credentials. Unlike traditional certifications that assess candidate competence through theoretical multiple-choice questionnaires, the eJPT evaluates your capabilities within a dynamic, realistic virtual corporate network. Understanding the operational structure of the examination, the topology of the testing environment, and proven time-management methodologies is critical to achieving a passing score.
Examination Blueprint & Assessment Structure
The eJPT examination is structured as a continuous 48-hour hands-on penetration testing engagement. From the moment you activate your exam voucher in the INE assessment portal, you are granted full access to a private, dedicated laboratory network containing multiple simulated target systems and network segments.
Core Assessment Parameters
The examination is graded dynamically through 35 scenario-based questions. These are not abstract knowledge checks; rather, they require you to actively compromise hosts, enumerate services, crack cryptographic hashes, decipher web application vulnerabilities, and extract specific system artifacts from within the lab.
| Exam Specification | Detail / Requirement |
|---|---|
| Administering Body | INE Security (eLearnSecurity) |
| Assessment Format | 100% Practical Hands-on Lab Engagement |
| Testing Window | 48 Continuous Hours (Timer runs continuously once started) |
| Question Format | 35 Scenario-Based Dynamic Questions |
| Passing Threshold | 70% Overall (Minimum 25 out of 35 correct answers) |
| Domain Competency | Minimum threshold requirements across all 4 core domains |
| Delivery Mechanism | In-browser virtual desktop (Guacamole/NoVNC) or OpenVPN connection |
| Resource Allowance | Open-book, open-notes, internet access permitted |
| Free Retake Policy | One complimentary retake attempt included per exam voucher |
Domain Breakdown and Scoring Requirements
The eJPT syllabus is divided into four distinct technical domains, each contributing a specific weight to your final evaluation:
- Assessment Methodologies (25% Weight): Encompasses information gathering, open-source intelligence (OSINT), active host discovery, port scanning, service version detection, and vulnerability identification.
- Host and Network Auditing (25% Weight): Evaluates your ability to audit discovered services (such as SMB, FTP, SSH, and database servers), enumerate local Linux and Windows operating system configurations, identify privilege escalation vectors, extract password hashes, and stage file transfers.
- Host and Network Penetration Testing (35% Weight): Focuses on active exploitation using the Metasploit Framework, manual exploit modification, payload delivery, post-exploitation navigation with Meterpreter, network pivoting across segmented subnets, and cracking authentication credentials.
- Web Application Penetration Testing (15% Weight): Tests your capability to identify and exploit common web vulnerabilities, including SQL injection, cross-site scripting (XSS), directory traversal, file inclusion, and authentication bypasses, leveraging tools such as Burp Suite, Gobuster, and SQLMap.
To pass the examination, you must achieve both an overall composite score of at least 70% (25/35 questions) and satisfy minimum performance standards across each individual domain. Scoring 100% in network exploitation will not compensate for a complete failure in web application penetration testing or host auditing.
Dynamic Flags and Target Verification
Many exam questions require you to submit specific proof-of-exploitation strings known as flags. Flags are typically stored in sensitive file system locations—such as /root/flag.txt, /home/user/flag.txt, C:\Users\Administrator\Desktop\flag.txt, or within protected web database tables. In addition to flags, questions frequently require submitting:
- The exact service version string extracted from an enumerated daemon
- The plaintext password recovered from a cracked NTLM or SHA-512 crypt hash
- The internal IP address of a hidden host discovered behind a network pivot
- The operating system build number extracted during privilege enumeration
- The specific user account name with administrative privileges on a compromised domain controller
Because the lab environment generates certain dynamic values per exam instance, candidates must perform the actual exploitation rather than attempting to rely on unverified community answer keys.
Lab Architecture & Multi-Subnet Network Topology
The eJPT lab is architected to mirror an authentic small-to-medium enterprise (SME) infrastructure. You will not find all target systems clustered within a single flat /24 subnet. Instead, the environment is deliberately segmented into multiple isolated subnets separated by firewalls and multi-homed systems.
Multi-Subnet Architecture and Pivoting
Upon establishing network connectivity, your attack machine is assigned an IP address on an initial entry subnet (often referred to as the perimeter or DMZ segment). The machines directly visible on this initial subnet represent your primary attack surface.
However, several critical targets and high-value exam objectives reside in secondary and tertiary internal subnets that have no direct routing to your attack host. Accessing these internal segments requires network pivoting:
- You must identify and fully compromise a multi-homed system located on the initial subnet that possesses an additional network interface attached to an internal subnet.
- Once root or administrative access (or a stable Meterpreter session) is obtained on the dual-homed machine, you must inspect its routing table and interface list (
ip a,ifconfig, oripconfig /all). - You then configure routing through that compromised session—using Metasploit's
post/multi/manage/autoroutemodule, the Metasploitroute addcommand, or an SSH/SOCKS proxy tunnel—to route scan packets and exploit payloads directly into the hidden internal network.
Failing to understand routing tables and pivot mechanics is the primary technical roadblock encountered by candidates who struggle on the exam.
Lab Access Models: Browser vs. OpenVPN
INE provides two distinct mechanisms for connecting to the testing environment: an in-browser virtual desktop and a dedicated OpenVPN connection file.
| Evaluation Metric | In-Browser Virtual Desktop (Guacamole/NoVNC) | Dedicated OpenVPN Configuration (Local Machine) |
|---|---|---|
| Deployment Effort | Zero configuration; launches directly within any modern web browser | Requires importing .ovpn profile into Kali Linux or Parrot OS |
| System Resource Impact | Minimal local resource usage; suitable for low-spec laptops | Consumes local host CPU, RAM, and storage for virtualization |
| Interface Responsiveness | Subject to browser rendering latency and occasional display compression | Native graphical and terminal responsiveness with zero stream latency |
| Customization & Tools | Restricted to pre-installed tools; personal scripts must be redownloaded | Full access to candidate's custom toolchains, aliases, wordlists, and IDEs |
| Connection Stability | Lab state persists automatically on server during local connection drops | Local VPN disconnect drops active shells; routes must be re-established |
| File Transfer & Logging | Clunky clipboard integration; challenging to export terminal logs and images | Seamless local file management, native copy-paste, and instant screenshot capture |
| Recommended Strategy | Excellent emergency fallback if local virtualization software fails | Strongly recommended primary method for maximum agility and evidence capture |
Connecting via OpenVPN to a local, fully configured Kali Linux virtual machine is overwhelmingly the preferred approach for professional candidates. It grants unrestricted use of custom wordlists (such as SecLists), private automation scripts, multi-monitor terminal layouts, and local note-taking platforms.
Operational Strategy & Time Management Framework
The 48-hour testing window provides an extraordinary advantage if managed with discipline. Forty-eight hours is more than sufficient time to complete all 35 objectives, provided you maintain an organized methodology and avoid cognitive exhaustion.
The 48-Hour Tactical Pacing Schedule
A disciplined tactical timeline separates successful candidates from those who succumb to fatigue:
- Hours 0 to 4: Reconnaissance and Network Mapping
- Download the OpenVPN configuration, verify IP reachability, and initialize your terminal logging suite.
- Perform comprehensive host discovery sweeps across the provided initial scope using
arp-scanornmap -sn. - Execute full TCP port scans (
-p-) and initial UDP scans against identified live hosts. - Document all active hosts, open ports, and detected service banners in your note-taking workspace.
- Hours 4 to 16: Perimeter Exploitation and Initial Footprints
- Enumerate web applications, hidden directories, SMB shares, and database daemons identified on the perimeter.
- Correlate service versions with public vulnerability disclosures (CVEs) and Exploit-DB entries.
- Execute targeted exploits to gain initial low-privilege and administrative access across perimeter machines.
- Answer corresponding exam questions as flags and artifacts are discovered.
- Hours 16 to 24: Mandatory Rest and Mental Reset
- Disconnect from the lab and sleep for 6 to 8 hours.
- Cognitive fatigue severely degrades analytical reasoning, leading to overlooking obvious misconfigurations and mistyping commands. Sleeping allows your brain to synthesize information, often leading to immediate breakthroughs upon return.
- Hours 24 to 36: Pivoting, Internal Enumeration, and Privilege Escalation
- Query network configurations on compromised hosts to discover secondary subnets.
- Configure Metasploit routing or SOCKS proxies and initiate discovery on internal hosts.
- Conduct privilege escalation on newly discovered systems using LinPEAS, WinPEAS, or manual auditing.
- Recover deep flags, decrypt stored passwords, and resolve internal-network exam questions.
- Hours 36 to 44: Objective Reconciliation and Verification
- Systematically review all 35 questions in the exam portal.
- Double-check answers against raw terminal logs and captured screenshots.
- Re-visit any stubborn questions that were deferred during earlier phases.
- Hours 44 to 48: Submission and Final Audit
- Verify that every question has a selected or entered answer.
- Export and archive your complete examination notes, logs, and screenshots for your personal professional portfolio.
- Submit the examination through the portal.
Open-Book Methodology and Preparation
The eJPT is entirely open-book. You are encouraged to reference technical manuals, command cheat sheets, official documentation, and vulnerability databases throughout the assessment.
To maximize efficiency during the exam, assemble a curated cheat sheet prior to launching the lab:
- Port Scanning: Standard Nmap combinations for rapid discovery (
-T4 -sS -p- --min-rate 1000), version detection (-sV -sC), and UDP auditing (-sU --top-ports 100). - Web Enumeration: Syntax for Gobuster directory brute-forcing (
gobuster dir -u <URL> -w <wordlist> -x php,txt,html), Nikto web scans, and Feroxbuster commands. - Reverse Shell One-Liners: Reliable Bash, Python, PHP, and PowerShell reverse shells pre-configured for copy-paste modification.
- Pivoting Commands: Metasploit
autoroutesyntax (run autoroute -s <subnet>/24), Proxychains configuration steps, and Chisel reverse port forwarding flags. - Credential Cracking: Hashcat and John the Ripper invocation commands for MD5, NTLM, SHA-256, and SHA-512 hashes.
Note-Taking Structures and Artifact Preservation
Disciplined documentation is the hallmark of a professional penetration tester. Attempting to track multiple compromised hosts, active sessions, discovered credentials, and flags in disorganized terminal tabs will inevitably lead to confusion and lost progress.
Use structured hierarchical note-taking applications such as Obsidian or CherryTree. Establish a dedicated folder for the exam with a standardized organizational structure:
- Root Node: Exam Overview, Scope IP ranges, DNS servers, and credential dump.
- Host Nodes (one per discovered IP address):
01-Reconnaissance: Raw Nmap scan files, open ports, service banners, and software versions.02-Vulnerabilities: Identified CVEs, Exploit-DB IDs, and web findings.03-Exploitation: Exact commands and exploit modules used to gain initial access.04-Privilege-Escalation: Internal enumeration outputs, local exploits, and administrative access proof.05-Artifacts-and-Flags: Full terminal screenshots displayingwhoami,ipconfig/ifconfig, and flag text.
In addition to hierarchical notes, enable persistent terminal logging. Running the Linux script utility (script -a -f /path/to/exam_terminal.log) records every command entered and all resulting terminal output directly to disk. If your terminal crashes or you need to verify an exact command parameter submitted hours earlier, your persistent log provides an indisputable record.
Critical Exam Pitfalls & Avoidance Strategies
Candidates who encounter difficulty on the eJPT rarely fail due to a lack of technical knowledge; rather, they falter due to tactical missteps and poor lab hygiene.
Pitfall 1: Rabbit Holes and Tunnel Vision
The most prevalent failure mode is fixating on a single stubborn service or host for four to six consecutive hours. Penetration tests frequently present hardened services alongside trivial misconfigurations. If an exploit attempt fails repeatedly or requires complex, custom memory corruption adjustments, pause your efforts. Document what was attempted, step back, and examine other hosts or services on the network. In most cases, alternate access paths, default credentials, or web application vulnerabilities will provide a faster and more reliable foothold.
Pitfall 2: Neglecting Service Version Detection
Running basic port scans without service version detection (-sV) or failing to inspect banners manually with Netcat often leads to deploying exploit payloads against the wrong target software. For instance, assuming port 8080 runs Apache Tomcat when it actually hosts a custom Python API or a Jenkins automation server will waste hours of effort. Always verify service versions before searching for exploits.
Pitfall 3: Indiscriminate Lab Resets
The exam interface allows candidates to reboot individual virtual machines or reset the entire lab environment. While rebooting a specific target machine is helpful if a service daemon crashes or becomes unresponsive during exploit testing, never trigger a full lab reset carelessly. A full environment reset wipes all generated user accounts, uploaded payloads, established SSH keys, and routing configurations across all hosts. Before initiating any reset, verify that all flags, credentials, and scan outputs from every host are safely recorded in your notes.
Pitfall 4: Forgetting the Difference Between Metasploit Routes and System Routes
When using Metasploit's autoroute module, the routing table is maintained strictly within the Metasploit Framework. Running tools outside of Metasploit—such as standard Nmap, Gobuster, or Hydra directly from the Linux bash terminal—will not route traffic through your Metasploit session. To run external command-line tools against an internal subnet, you must establish an auxiliary SOCKS proxy module (auxiliary/server/socks_proxy) in Metasploit and route external commands through proxychains.
What are the core parameters and passing requirements for the INE Security eJPT examination?
A 24-hour theoretical assessment consisting of 50 multiple-choice questions requiring an 85% passing grade
A 48-hour hands-on practical lab featuring 35 scenario-based questions with a 70% overall passing threshold and domain minimums
A 72-hour open-network exercise requiring submission of a written penetration testing report without dynamic questions
A timed 4-hour proctored examination covering 100 questions with no live laboratory environment
When performing an assessment in the eJPT multi-subnet lab environment, what technical mechanism is required to discover and exploit targets residing in isolated internal subnets?
Reconfiguring the local DHCP server on your host machine to broadcast cross-subnet ARP requests
Submitting a support ticket to the INE exam proctor requesting public IP reassignment for internal hosts
Identifying a dual-homed compromised host on the perimeter network and establishing network pivoting through routes or SOCKS proxies
Executing an aggressive ICMP flood from your external attack box to force internal routers to disable firewall rules
Which operational strategy effectively prevents catastrophic progress loss and wasted effort during the 48-hour eJPT examination?
Recording all flags, credentials, and commands in structured notes and backing them up before initiating any machine or lab reset
Focusing continuously on a single unresponsive host until it is compromised before enumerating other available network targets
Relying exclusively on the browser terminal's scrollback buffer rather than recording notes in external tools
Immediately resetting the entire lab environment whenever a custom exploit script fails to return an initial shell
Sections you finish are checked off in the contents.