Prove You Can Execute — In a Real Environment
Most certifications measure what you know. CACP proves what you can execute — inside live infrastructure, under real conditions, with no hints and no safety nets.
You operate across the full cybersecurity lifecycle — offense and defense, connected as a system.
48 hours. Two phases.
Phase 1 — 24-Hour Live Examination
Operate inside infrastructure that mirrors real networks and defenses. Exploit systems, move laterally, achieve objectives, analyze alerts, investigate traffic, and respond to active incidents.
Phase 2 — 24-Hour Report Submission
Document your methodology, findings, and attack chain reconstruction to the standard of a real engagement deliverable. Execution without documentation does not pass.
No multiple choice. No exam dumps. The environment changes every time. You are evaluated on what you accomplish — not what you memorized.
Both red and blue. Built by practitioners. Held to industry standards.
99,00 € Original price was: 99,00 €.89,00 €Current price is: 89,00 €.
No — prior completion of the 15-course pathway is not a requirement. The certification is open to penetration testers, SOC analysts, self-taught practitioners, and anyone else who believes they have the skills. However, if you are new to the field, the pathway is strongly recommended as preparation, since the exam tests full-spectrum operational capability with no hints or safety nets.
You are placed inside a live infrastructure that mirrors real enterprise networks, complete with active defenses and monitoring systems. You must identify attack paths, exploit vulnerabilities, escalate privileges, move laterally across segmented systems, and achieve defined objectives — all while evading detection. You also face defensive scenarios: analyzing SIEM alerts, investigating traffic with Wireshark, and performing memory forensics on compromised hosts. There are no hints, walkthroughs, or second chances.
After the 24-hour exam, you have a further 24 hours to submit a professional written report. It must cover your full methodology, evidence of each objective completed, attack chain reconstruction, forensic findings, and remediation recommendations. The report is evaluated to the same standard used in real penetration testing and incident response engagements — not just as a summary, but as a deliverable you would hand to a client. Both phases must be passed to earn certification.
Most certifications test either offense or defense — not both. CACP is a full-spectrum assessment: you are evaluated on exploitation and evasion alongside detection, forensics, and incident response in the same exam. There are no multiple-choice questions at any stage. Because the environment is live and changes, there is no way to prepare through memorization — only genuine capability gets you through. Passing requires you to prove you can execute under pressure and document your work to a professional standard.
Yes, retakes are available. Each additional attempt is available for purchase separately. We recommend reviewing your report feedback carefully before reattempting, as the report phase is a common area where candidates fall short even after strong technical performance.