CPTA: A Practical Pathway Into Offensive Cybersecurity
Offensive cybersecurity can be difficult to know where to start.
There are countless tools, techniques and areas of security to explore, from understanding networks and operating systems to identifying vulnerabilities, exploiting weaknesses and learning how attackers move through an environment. Knowing which skills to build first, and how they fit together, isn’t always straightforward.
For anyone looking to develop offensive security skills, having a clear path through those fundamentals can make the learning process much more manageable.
That’s why we’ve developed the Certified Penetration Testing Associate (CPTA), designed to give you a structured, practical way to build offensive cybersecurity skills.
Who Is CPTA For?
CPTA is designed to help you build the practical skills needed to carry out penetration testing. It can support you at different stages of your cybersecurity career, whether you’re:
- Aspiring penetration testers and ethical hackers looking to build practical offensive security skills and work towards an offensive role
- SOC analysts, threat hunters, detection engineers and incident responders looking to gain greater insight into attacker mindset, tools, techniques and procedures
- Existing penetration testers, security consultants and red team operators looking to broaden their knowledge across different technologies and attack techniques
You don’t need years of offensive security experience to get started. CPTA builds from the technical foundations through to practical penetration testing techniques, with 0 to 3 years of experience recommended.
What You’ll Learn in CPTA
With over 20 domains, CPTA takes you through the skills and techniques used across a penetration testing engagement, from understanding the technologies you’re testing to identifying and exploiting vulnerabilities. You’ll develop skills across:
- Technical foundations: networking, Linux, Windows and Python
- Discovery and vulnerability assessment: identifying hosts, services, operating systems and potential vulnerabilities
- Exploitation: password attacks, vulnerability exploitation and gaining access to systems
- Privilege escalation and lateral movement: building on initial access, gaining greater privileges and moving between systems
- Active Directory: understanding enterprise domains and exploring common enumeration, credential and authentication attacks
- Web applications: testing for vulnerabilities including IDOR, XSS, CSRF, SQL injection and command injection
- AWS: discovering public assets, exploring IAM and identifying potential exposure across EC2, S3 and Lambda
- Red teaming: an introduction to command and control and red team operations
Rather than treating these as isolated skills, CPTA helps you understand how they fit together as you work through the different stages of a penetration test.
Build Practical Offensive Security Skills
Understanding techniques is one thing. Being able to apply them is another.
Hands on practice are central to CPTA. You’ll work through practical labs and realistic scenarios where you can apply what you’re learning across infrastructure, Active Directory, web applications and AWS environments.
You’ll put techniques such as network discovery, vulnerability assessment, exploitation, privilege escalation and lateral movement into practice, helping you build experience as you progress through the certification.
Learn the Penetration Testing Process
Technical testing is only one part of a professional penetration test. CPTA takes you through the wider engagement, so you’ll learn about:
- Scoping and rules of engagement
- Setting expectations with clients
- Planning and conducting an engagement
- Reporting and communicating your findings
- Remediation and retesting
This gives you an understanding of how a penetration test is managed from start to finish, not just the technical skills used during testing.
Put Your Skills Into Practice
Throughout CPTA, you’ll apply what you’re learning through labs and realistic scenarios, building experience across the different techniques and environments covered in the course.
At the end of CPTA, you’ll complete a three-part practical exam covering infrastructure, web and cloud assessments, putting your skills to the test across three different environments.
By the time you reach the exam, you won’t just have learned about penetration testing techniques. You’ll have spent your time applying them and building a broader understanding of how they come together.
Get Started With CPTA
CPTA includes 20+ domains, 600+ lessons, activities and quizzes, and more than 60 hands-on labs, giving you plenty of opportunities to build and apply your skills throughout the course.
The course takes an average of 100 hours to complete, with four months of on-demand access, before you put what you’ve learned into practice across three eight-hour realistic exam labs.
The CPTA course is available to buy from 8th September 2026. You can join the waitlist here.

