← Back to list

My PJPT exam experience 2026

In the last days of 2025, in that magical time between Christmas and New year’s (the period also known as the void) I decided to use my…

Gothos · 2026-01-08 07:49 · 3 claps · 2.4 min read
#cybersecurity #tcm-security #pjpt #cybersecurity-training #penetration-testing
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

My PJPT exam experience 2026

In the last days of 2025, in that magical time between Christmas and New year’s (the period also known as the void) I decided to use my free time and attempt the PJPT exam by TCM Security. The exam consist of an internal penetration test simulation, with the objective of compromising the Active Directory Domain Controller.

The most often repeated advice on the internet is that if you approach this exam as you would a CTF, you will fail. THAT… IS…. CORRECT!

If you’re used to Capture-the-Flag platforms, your brain is trained to overthink:

  • “This can’t be that simple.”
  • “Surely there’s a zero-day here.”
  • “Why would they expect this technique?”

PJPT doesn’t play that game.

There are no magic flags, no deliberately broken logic, no “guess what the author was thinking” moments. Instead, it feels like: “Here’s a network. Go break it like a professional.”

And honestly? That’s far more valuable.

It took me about 9 hours to compromise the DC, this includes several breaks I took to walk my dog and grab a bite to eat. Here is where the next really useful piece of advice comes — Don’t overthink it!

My time could’ve been halved, if I just stuck to the course content, instead of trying anything and everything I could think of. Don’t get me wrong, this is what you should be doing, but you have ample time after you complete your objective. Suppose you go in, compromise the DC in 2–3 hours, what are you going to do for the remainder of your two days ? Go in again and try different approaches. I hit a massive wall 2 hours in, because I expected something tricky, because this is how CTFs have conditioned me…

Think Like a Pentester, Not a Puzzle Solver

Once I stopped treating the exam like a puzzle and started treating it like a job, everything clicked.

  • Enumerate calmly
  • Validate assumptions
  • Exploit deliberately
  • Document clearly

That mindset shift matters more than any tool.

Notes and Reporting Matter More Than You Think

One underrated part of the PJPT is how much it quietly reinforces note-taking and report writing. Keeping clear, structured notes and taking screenshots during the exam saves you from second-guessing yourself and makes the reporting phase a bit easier. In real pentests, finding the bug is only half the job — explaining it clearly is what actually delivers value, and PJPT reflects that reality well.

Credit Where It’s Due: TCM’s Support Team

I also have to call out TCM Security’s support, because they were exceptional. I had an issue accessing the exam portal and they resolved it in about 20 minutes — on freaking December 26th, which is honestly wild. On top of that, even though it was during the holidays, less than 8 hours after I submitted my report for review, I got back this awesome thing:

Final Thoughts

PJPT doesn’t reward overthinking. It rewards competence.

If you’ve done the course, trust it. If something looks straightforward, try it.

Chances are, the right answer is already in your notes.

And that’s exactly why this exam feels less like a game… …and more like the real thing.


메타데이터
post_id
cd23a36ced95
slug
my-pjpt-exam-experience-2026-cd23a36ced95
url
https://medium.com/@GothosFolly/my-pjpt-exam-experience-2026-cd23a36ced95
canonical_url
https://medium.com/@GothosFolly/my-pjpt-exam-experience-2026-cd23a36ced95
author_url
https://medium.com/@GothosFolly
status
ok
fetched_at
2026-06-20 20:29:01