Passing the PNPT: 39 Hours, 70 Pages, and a 15-Minute Debrief

My experience taking and passing TCM Security's Practical Network Penetration Tester (PNPT) certification.

I officially passed the Practical Network Penetration Tester (PNPT) certification from TCM Security.

The PNPT isn’t a multiple-choice exam where you memorize enough material, pick the right answers, and walk away with a certification. It is designed around performing a penetration test, documenting what you found, and then explaining your work.

For me, that meant 39 hours to compromise the network, a 70-page penetration testing report, and a 15-minute live debrief explaining my findings.

It was a blast!

The Exam

Going into the PNPT, one of the things I was most excited about was the format.

You’re given a target environment and an objective. From there, it’s up to you to figure out how to approach it.

There isn’t a checklist telling you which technique to use next. You have to enumerate, develop leads, determine which ones are worth pursuing, recognize when something isn’t working, and adjust your approach.

That made the exam feel much closer to an actual engagement than a traditional certification exam.

I ultimately compromised the network in approximately 39 hours.

That number includes sleep and spending time with my family. I didn’t lock myself in a room for 39 straight hours and stare at Kali.

I intentionally approached the exam in a way that was sustainable. I worked the assessment, stepped away when I needed to, spent time with my family, slept, and came back to it.

In some ways, stepping away was part of the process. There were several times when looking at a problem with fresh eyes was more useful than continuing to hammer away at it.

Compromising the Network Was Only Part of the Job

Getting the technical objective wasn’t the end of the PNPT.

Then came the report.

I spent a considerable amount of time turning my notes, screenshots, evidence, attack path, findings, and remediation recommendations into a professional penetration testing report.

The finished report came in at approximately 70 pages.

Writing it reinforced something that is easy to overlook when practicing penetration testing:

Finding a vulnerability isn’t enough.

A penetration tester needs to be able to explain what happened, demonstrate the impact, preserve evidence, communicate the attack path, and provide useful recommendations for fixing the underlying problems.

A technically impressive attack that can’t be clearly communicated isn’t nearly as valuable to a client.

The reporting portion was something I took especially seriously this time around. When I attempted the PJPT for the first time, I actually failed because of my report, not because I couldn’t complete the technical portion of the exam. That experience taught me pretty quickly that compromising a network is only part of the job.

Going into the PNPT, I wasn’t going to make that mistake again. I spent a considerable amount of time making sure my findings were clearly documented, the attack path was easy to follow, the evidence supported what I was saying, and the remediation recommendations were useful.

In a way, failing the PJPT because of my report ended up being one of the better lessons I could have learned before attempting the PNPT. It completely changed how seriously I approached documentation and reporting this time around.

The Debrief

The final piece was the live debrief.

I had approximately 15 minutes to explain my findings and walk through the compromise.

This might have been my favorite part of the entire certification.

Instead of simply submitting a report and waiting for a score, I had to actually talk through what I found and demonstrate that I understood the attack path.

That’s an important skill.

In a real engagement, eventually someone is going to ask:

  • What happened?
  • How did you get in?
  • What did you gain access to?
  • Why does this matter?
  • What should we fix first?

Being able to answer those questions clearly is just as important as knowing the commands that got you there.

Four Years, Five Cybersecurity Certifications

Passing the PNPT also marks another milestone for me.

This is my fifth cybersecurity certification and seventh certification overall in the last four years.

My cybersecurity certification progression now looks like:

Security+ → CySA+ → CISSP → PJPT → PNPT

Each certification has represented a different stage in my career.

Security+ helped establish the foundation.

CySA+ pushed further into defensive security and analysis.

CISSP forced me to think about security much more broadly, beyond individual technologies and vulnerabilities.

PJPT was my first real step into practical penetration testing.

And now the PNPT took that practical offensive-security work considerably further.

The biggest change isn’t really the certifications themselves, though. It’s how differently I approach a network today compared with four years ago.

I’m increasingly interested in understanding both sides of security: how we build and defend systems, and how an attacker can chain seemingly small weaknesses together to compromise them.

That perspective directly affects how I approach my day-to-day work protecting SMB and local-government environments.

Preparation

I didn’t prepare for the PNPT by trying to memorize every tool or command I might possibly need.

A lot of my preparation came from simply spending time attacking networks.

TCM Security’s training provided the foundation, and Hack The Box gave me environments where I could repeatedly practice enumeration, exploitation, privilege escalation, pivoting, and Active Directory attacks.

Labs like Dante were especially useful because they forced me to think beyond compromising a single machine.

I also documented much of that practice here on MidwestSec.

Writing walkthroughs turned out to be part of the preparation itself. Explaining an attack forces you to understand why something worked rather than simply remembering that a particular command worked once.

That became extremely valuable when it was time to write the PNPT report.

The Most Important Lesson

If I had to reduce the entire experience to one lesson, it would be this:

Enumeration wins.

The flashy part of penetration testing is exploitation.

The important part is understanding the environment well enough to know what should be exploited.

When I got stuck during the exam, the answer usually wasn’t some obscure exploit or magical tool I hadn’t heard of.

It was usually that I needed to look harder at information I already had, enumerate something more thoroughly, or reconsider an assumption I had made.

That lesson applies far beyond the PNPT.

A Shoutout to My Wife

None of this happens in a vacuum.

Studying for certifications, spending mornings in labs, writing walkthroughs, disappearing into an exam environment, and then spending hours putting together a 70-page report takes a lot of time. And when you have a family, that time has to come from somewhere.

So I need to give a huge shoutout to my wife. While I was buried in the exam, she was taking care of the kids and carrying more of the day-to-day load at home so I could stay focused. That continued while I worked through the reporting process and prepared for the debrief.

Passing the PNPT might have my name on the certification, but getting there was absolutely a team effort. I’m incredibly thankful that she continues to support me through the studying, exams, and all the time that comes with chasing these goals.

I definitely couldn’t keep doing this without her.

What’s Next?

The PNPT isn’t the finish line.

It’s another step.

My next major certification goal is the OSCP.

Before jumping straight into the exam, I’m planning to continue working through TCM Academy and Hack The Box, with additional focus on the areas where I want more depth, particularly web application testing, Linux and Windows privilege escalation, Active Directory, and operating efficiently in larger environments.

For now, though, I’m going to enjoy this one.

The PNPT was challenging, practical, occasionally frustrating, and super fun.

That’s exactly what I wanted from it.

39 hours. 70 pages. 15-minute debrief. PNPT complete.