Thoughts on the eJPT cert

Thoughts on the eJPT cert

I was on my way out the door for a multi-month hiking trip when I realized my eLearnSecurity Junior Penetration Tester (eJPT) voucher would expire before I returned. Guess what that means -- a quick attempt at the exam!

Welp, I passed...so let me share some thoughts on this one.

First, I loved it. Like literally, loved it. Everything about this exam was fun. Now, I'm an educator so my idea of fun compared to yours might differ -- but seriously this is one fun exam. From the scenario presented to the exam questions to the lab environment itself, everything was cleanly designed and well structured. Go into this thing expecting to have some fun and you will.

Second, I have quite a few years experience paired with extensive education and dozens of related certifications -- so my viewpoint is from that perspective. Keep that in mind as you read my notes. While I attempted to "think" like a beginner...I'm still seeing this exam from my own jaded view.

THE EXAM

The exam itself is just a series of 20 multiple choice questions. All of these questions are based on information and details you discover within the lab environment. While, you could in theory take a guess, you'd likely get every question wrong if you don't do the work to find the information. You can move back and forth within the questions and answer them in whatever order you please. It's easy to tell which ones you've answered as well, so going back to one you've missed is super simple.

You can use the questions to guide your actions in the lab environment. But I recommend instead following your pentesting methodology, and then answering the questions at the end. Why? Because having a methodical approach to a pentesting engagement is incredibly important. This is a chance to perfect your technique, take solid notes, and practice for the real deal. If you miss something in your approach...it's easy to jump back in, pwn the machine again, and grab the details you missed. You'll also learn to add some steps into your process for the future.

When you're in the thick of it, doing recon, mapping, discovery, and exploitation -- don't forget to take breaks and allow yourself time to think. You have tons of available time, seriously tons. You can look things up, try different tools, go back and forth between systems, and just in general take your time. 

When I pressed the submit button on my exam, the system showed I had launched the lab environment 8.5 hours earlier. During that time, I walked my dogs, ate dinner with my family, took two mentorship calls, watered my garden, and pwned every box and answered every question. I even had to do "research" in the middle for a particular process I was having trouble with. So, seriously -- you have time!

1) This isn't a beginner to IT/Security cert...build your foundation:

  • Basic Computer Skills: open files, run programs, command line, network settings
  • Networking: TCP/IP Model, IPv4, Subnetting, DNS, DHCP, NAT, Ports and Services
  • Linux Skills: command line, distros, bash, ssh, openvpn, permissions, accounts
  • Packet Analysis: Wireshark, tshark, TcpDump, sniffers, protocol analyzers
  • Virtualization: WMware or VirtualBox
  • Security Concepts: PKI, Kerberos, SSL/TLS, IDS/IPS, Firewalls
  • Notes: You must have some sort of notetaking and organization process

2) Do the Penetration Testing Student (PTS) course on INE


 

Temisan Ebireri

Penetration Testing | Digital Forensics | Network Defense | Fullstack Development

2 年

Very helpful post Mic Merritt. I am currently preparing for the eJPT exam and I have been wondering how best to prepare. This post provided lots of insight. Thank you

Ally Petitt

Security Researcher | US Women's Cyber Team | OSCP | Discovered 8 CVEs

2 年

Hi! I have a quick question. Are there any required documents for the test to verify identity?

回复
Scott Gardner

Passionate about networking and security

2 年

Hello, and thank you for this blog. How would you say this cert and other certs from eLearningSecurity are viewed in the industry? I'm considering doing the OSCP courses instead, but eLS courses are less expensive and seem to be well liked by the people who take them. Thank you for your sacrifice. -Scott

回复
Kavya Bothra

Founder - BindCat | Tech Community & Education

3 年

Thanks for Opinion, This will help us to prepare...

回复

Will ejpt help me to land my first job as an entry level pentester...... because I don't hace enough money for the oscp exam ..so I need to get a job first to save funds for the future

回复

要查看或添加评论,请登录

Mic Merritt的更多文章

  • Fueling Engagement and Motivation

    Fueling Engagement and Motivation

    In a world that's becoming more digital by the minute, cybersecurity has become a crucial concern for everyone, from…

    5 条评论
  • Level 3 -- The Amateur

    Level 3 -- The Amateur

    Finally! Here we are at the next step in our learning journey with Level 3 -- The Amateur. At this point, you must have…

    5 条评论
  • Digital Forensics & the Court of Law

    Digital Forensics & the Court of Law

    Let's chat about digital forensics - you know, that super cool field that's been making huge strides in recent years…

    19 条评论
  • Understanding APTs

    Understanding APTs

    Cyber attacks are getting more difficult to detect and more sophisticated in our world today. Advanced Persistent…

    14 条评论
  • The Potential of Penetration Testing

    The Potential of Penetration Testing

    In the dynamic world of cybersecurity, it is imperative for your organization to remain vigilant against potential…

    2 条评论
  • How to Start a Threat Assessment

    How to Start a Threat Assessment

    Starting a threat assessment can be a complex process, as it involves numerous steps and precautions. If a threat…

    22 条评论
  • Threats - Detecting and Hunting

    Threats - Detecting and Hunting

    We live in a truly digital world! All of these technological advancements have given both enterprises and individuals…

    5 条评论
  • How to be a Better Penetration Tester

    How to be a Better Penetration Tester

    Penetration testing is a crucial security practice for organizations of all sizes. It primarily involves finding…

    29 条评论
  • We Are Hackers...not Criminals

    We Are Hackers...not Criminals

    In the age of emerging technology, the term "hacker" has become increasingly prominent in our lives. From accessing…

    19 条评论
  • Understanding the Insider Threat

    Understanding the Insider Threat

    The age of cybercrime has seen a surge in malicious actors invading corporate networks. Companies must remain vigilant…

    9 条评论

社区洞察

其他会员也浏览了