PJPT Exam Review: What to Expect From TCM Security’s Practical Junior Penetration Tester…
When I attempted PJPT, I was still earlier in my security journey and didn’t have the same level of real-world exposure I have now.
PJPT Exam Review: What to Expect From TCM Security’s Practical Junior Penetration Tester Certification
You’re probably reading this for one of two reasons:
- You’re thinking about buying the PJPT and want to know if it’s worth it.
- You’re mid-exam, slightly dehydrated, staring at your notes like they owe you money.
If it’s #2, stay calm. Take a short break, drink water, and come back. You may find something useful here or you may not, but either way… it’s not the end of the world. Good luck. You’ve got this.
I passed the PJPT (Practical Junior Penetration Tester) last year, and at the time I had way less experience than I do now. That’s also why it became my stepping stone toward my next goal, the PNPT (which I later went for). This post is the “earlier me” perspective, written for people who are still building the fundamentals.
I’ll be linking this PJPT review from my PNPT blog for anyone who wants the full progression story.

What PJPT is in a nutshell
PJPT is TCM Security’s junior/associate-level practical pentesting exam that’s meant to feel like a real internal assessment, not a CTF speedrun. To pass, you’re expected to:
- Use Active Directory exploitation skills to move laterally/vertically and ultimately compromise the exam Domain Controller
- Submit a detailed, professionally written report
A few key traits that shape the experience:
- It’s not a CTF (seriously)
- Zero flags to capture
- No multiple-choice questions
If you’re looking for something that tests “can you actually do junior pentest work and write it up properly,” this is much closer to that.
A little about me (at the time)
When I attempted PJPT, I was still earlier in my security journey and didn’t have the same level of real-world exposure I have now. I knew the basics, I could follow methodology, and I could research effectively, but I was still building confidence and consistency.
My mindset back then was simple: get solid at fundamentals, then aim for PNPT next.
Networking was definitely the hardest part for me combined with navigating inside the AD. I had also never written a pentest report before this.
Exam format
Officially, the PJPT gives you:
- 2 days to complete the practical assessment
- 2 additional days to write the report
Your voucher/training access is valid for 12 months, and it includes one free retake.
This is a big deal for beginners, because the first attempt often teaches you how to take the exam as much as it tests your skills.
Who PJPT is for (and why that matters)
TCM describes PJPT as an associate-level intro. You should have basic computer/network familiarity, but previous pentesting experience isn’t required.
Translation: you don’t need to be a wizard. You just need to be methodical, calm, and willing to do the unsexy work (enumeration, notes, screenshots, reporting).
TCM also states that PJPT is built from their Practical Ethical Hacking (PEH) material and lists the domains it covers, including methodology, recon, scanning/enumeration, exploitation basics, Active Directory pentesting, and report writing.
What felt different compared to labs
Most beginner practice encourages “try tool → get result → move on.” PJPT rewards something else:
- Methodology over magic (skipping basics hurts later)
- Documentation as part of the exploit chain (you’ll thank yourself)
- Report writing as a real deliverable, not an afterthought
When you’re new, the hardest part isn’t always a technical block. It’s the mental loop of “I’m missing something obvious” versus “I’m actually stuck.” PJPT teaches you how to handle that loop professionally.
My high-level approach
1) Build an attack narrative early
Even during enumeration, I kept a living note of:
- What I know
- What I think is true (and why)
- What I tried
- What worked
- What evidence I captured
It made the report dramatically easier.
2)Timebox rabbit holes
If something doesn’t move after a focused chunk of time, park it. Return to enumeration. Come back with fresh context. This habit alone saves hours.
3) Notes + screenshots like you’re billing hours
“I’ll screenshot it later” is a lie. Screenshot it now.
4) Start the report while you’re still testing
Even if it’s just headings and a skeleton, it removes the “blank page panic” later. The report is a required pass condition, so treat it like one.
I use OneNote for taking notes but Obsidian and Notion are also great options. Ensure that these notes are properly organized.

Don’t skip any detail
Report writing: the part people underestimate
TCM makes it clear the report is a required part of passing. My advice: treat reporting as a parallel track during the exam, not something you “start later.”
What I did (simple and effective):
- Used a straightforward structure: Executive Summary → Attack Path Summary → Findings → Remediation
- Organized screenshots by host and by finding (so I wasn’t digging through chaos later)
- Wrote short notes as I went, then cleaned them up during the report window
A strong PJPT-style report usually needs:
- Executive summary (business impact in plain language)
- Attack path summary (how initial access became AD compromise)
- Technical findings (evidence + steps + remediation)
- Prioritized remediation (what to fix first and why)
The frustration factor (and why it’s useful)
PJPT has moments where you feel stuck. That’s normal. Real pentests include dead ends, false assumptions, and “wait… why isn’t this working?” moments.
The best move is boring but effective:
- Take a 10-minute break
- Re-check assumptions
- Return to enumeration
- Confirm what you actually proved vs what you assumed
Beginner me learned this the hard way. And I’m glad I did, because that exact skill transfers directly into PNPT and real work.
I remember getting stuck because I kept trying to force progress with “more tools” instead of stepping back and validating my assumptions. The fix was boring: re-enumerate, re-check what I actually knew, and build the next step from evidence instead of vibes.

Additional Resources I found helpful
https://benheater.com/active-directory-attack-map/
Final thoughts
If you’re a beginner or early-career pentester, PJPT is a very fair “prove you can do the job” style exam. It forces you to practice the parts that matter outside labs: method, evidence, and communication.
For me, passing PJPT was a confidence checkpoint. It told me, “Okay, you can do the fundamentals for real.” And at the time, my next goal was very clear: PNPT.
If you’re reading this from my PNPT blog, this was the step that made PNPT feel like a progression instead of a leap.
PJPT definitely gave me the much-needed confidence boost to keep going on this journey. I used to see AD as a giant mythical beast at the time which I had to slay using my plain old steel sword but that’s definitely not the case if you have sincerely followed Heath’s course and have the notes prepared.
If this helped even a little, I’m genuinely glad. Don’t overthink it. Stay methodical, take breaks, document everything, and keep going.
메타데이터
- post_id
- 257dd8a104df
- slug
- pjpt-exam-review-what-to-expect-from-tcm-securitys-practical-junior-penetration-tester-257dd8a104df
- url
- https://medium.com/@vulnkraft/pjpt-exam-review-what-to-expect-from-tcm-securitys-practical-junior-penetration-tester-257dd8a104df
- canonical_url
- https://medium.com/@vulnkraft/pjpt-exam-review-what-to-expect-from-tcm-securitys-practical-junior-penetration-tester-257dd8a104df
- author_url
- https://medium.com/@vulnkraft
- status
- ok
- fetched_at
- 2026-06-20 20:29:01