eWPTv2 Experience — 2024
Hi Everyone,
eWPTv2 Experience — 2024

It’s true
Read for free: https://medium.com/@y3t1_sec/ewptv2-experience-2024-f9a84eb9ade4?source=friends_link&sk=8f0da1d345b4d215111d2277b1cc00f8
Hi Everyone,
I shared my journey with the eJPT exam back in January, and it received a positive response. Today, I’d like to recount my experience with the eWPTv2 exam, which I recently passed.
My Background:
Prior to writing this test, I worked as a system administrator for 10 years and have worked in cybersecurity for the last two. I have a rather extensive blue team skillset, performing OS and network hardening, incident response, SOC team, and forensics. The chances are that most people writing this exam don’t have this background, but I have tried to write this to be beneficial to everyone looking to write the exam.
Introduction
After completing the eJPT exam, I found myself still struggling with web vulnerabilities and compromising websites. This gap led me to focus on enhancing my red teaming skills, particularly with web applications.
Given that most of my IT experience is in system administration, my interactions with websites have been limited to hosting and server configuration rather than development. To build my skills in web application security, I took the following steps:
- Completed the Web Fundamentals learning path on TryHackMe.
- Finished all the PortSwigger apprentice labs.
- Enrolled in the Web Application Penetration Tester course from INE.
I set my sights on the eWPTv2 exam as a more achievable goal within a few months compared to the BSCP exam.
The Course
Many of you are likely familiar with the first two steps but might want more information on the eWPT course. While the course is not a requirement for the eWPTv2 certification, here’s my take on it:
For the cost, I didn’t find the course worthwhile. If you’ve completed the eJPT, you might expect a similar quality, but in my experience, the eJPT course was more effective. The eWPT course covers vulnerabilities at a high level and encourages self-study. It mainly uses DVWA, BWAPP, and Mutillidae labs — free, vulnerable web applications that you can host yourself.
While Alexis Ahmed (HackerSploit) highlights the importance of these resources for understanding core concepts, I found that the course often lacked in-depth explanations on identifying vulnerabilities. The focus was more on exploiting vulnerabilities rather than understanding the underlying code issues. Additionally, a significant portion of the course covers very basic web application concepts, which I do not believe is necessary for those attempting this exam.
If you’re funding this certification yourself, you might want to skip the course. However, if your company is covering the cost, it could serve as a supplementary resource, though it shouldn’t be your sole study tool.
Tips for Successful Studying
- Diversify Your Resources: The course alone may not be enough. Utilize PortSwigger labs, DVWA, Mutillidae, and BWAPP in your home lab. These resources offer practical experience that complements the course content.
- Track Your Progress: I found it frustrating at times to gauge my improvement. Engage in Capture The Flag (CTF) challenges and bug bounties to measure your progress and see tangible results.
- Embrace Failure: The eWPTv2 exam is less documented than others, making it harder to assess your readiness. Use the two attempts included with your exam voucher to learn from your mistakes and improve.
- Practice API Testing: API testing is a crucial part of web services. Focus on breaking APIs, understanding API authentication, and practicing without tools like Postman, as it won’t be available during the exam.
Additional Tips for Passing the Exam
The eWPTv2 exam involves testing multiple sites, so familiarity with the Web Security Testing Guide (WSTG) is essential. While the eJPT checklist was helpful, OWASP provides an even better one. Use it extensively in your labs and CTFs to become proficient.
Sometimes things won’t go as planned. I faced issues with my lab environment, which impacted my exam experience. Don’t get discouraged; keep pushing through and research extensively when needed.
Also, take regular breaks. During my eJPT exam, I didn’t take enough breaks, which I regretted. This time, I set a timer to remind me to stand up, walk away, and document my findings every hour.
Conclusion
While the eWPT certification may not have the same reputation as the BSCP, it’s a valuable credential for those interested in web application security. Over the past six months, focusing on web applications has been a rewarding experience, and I’m pleased with my decision to pursue this certification, even if it’s not currently in high demand from employers.
As with my eJPT experience, my notes from the course are available for download here: https://github.com/y3t1sec/ewpt-study-notes
메타데이터
- post_id
- f9a84eb9ade4
- slug
- ewptv2-experience-2024-f9a84eb9ade4
- url
- https://medium.com/@y3t1_sec/ewptv2-experience-2024-f9a84eb9ade4
- canonical_url
- https://medium.com/@y3t1_sec/ewptv2-experience-2024-f9a84eb9ade4
- author_url
- https://medium.com/@y3t1_sec
- status
- ok
- fetched_at
- 2026-07-23 06:53:59