Exam Structure & Requirements

Practical Certification Standard

Seven days to prove how you operate.

Every Encrypted Syntax certification uses a remote, hands-on exam built around realistic objectives and a professional report. You are evaluated on technical judgment, evidence, impact, and communication—not memorized commands.

7 Consecutive DaysDedicated Lab EnvironmentSelf-Paced Within the WindowPDF Report Required
The Candidate Journey

Know exactly what happens from activation to result.

Your seven-day window includes both technical work and report writing. Once activated, the clock runs continuously for 168 hours.

PHASE 01

Activate

Receive access details, scope, objectives, and the official reporting requirements.

PHASE 02

Operate

Work independently inside your dedicated environment and capture evidence as you progress.

PHASE 03

Report

Convert technical work into a professional PDF with impact, evidence, and recommendations.

PHASE 04

Submit

Deliver the report before the exam window closes for manual technical review.

Three Exams • Three Missions

The deliverable changes with the role.

CEPT
Enterprise Penetration Testing

Compromise exposed and internal systems, attack Active Directory, pivot through networks, escalate privileges, and prove business impact.

  • Full penetration-test report
  • Reproducible attack paths
  • Evidence and remediation
CDOE
Defense Operations & DFIR

Analyze alerts, logs, memory, disk, and network evidence; reconstruct attacker activity; contain the incident; and improve detections.

  • Incident-response report
  • Evidence-backed timeline
  • Containment and hardening
CCES
Cloud Exploitation

Enumerate cloud identities and services, abuse misconfigurations and trust, escalate privileges, move laterally, and demonstrate exposure.

  • Cloud assessment report
  • Attack-path evidence
  • Risk ratings and mitigation
How You Are Evaluated

Passing requires both execution and communication.

01

Technical Objectives

Your completed objectives, quality of evidence, methodical reasoning, command and tool understanding, and ability to demonstrate meaningful impact.

  • Accurate scope handling
  • Defensible screenshots, logs, and commands
  • Understanding of how and why the result occurred
02

Professional Reporting

Your report structure, technical accuracy, reproducibility, stakeholder clarity, risk explanation, and practical remediation or hardening guidance.

  • Clear executive communication
  • Complete technical evidence
  • Actionable recommendations
You must meet the minimum standard in both technical performance and reporting quality to pass.
Candidate Readiness

Prepare the environment before the clock starts.

Technical Setup

  • Stable, reliable internet connection
  • Modern Linux, Windows, or macOS system
  • Ability to use the supplied VPN client
  • Hardware capable of running your tools and optional local VMs

Preparation Materials

  • Your own notes, cheat sheets, and mind maps
  • Standard pentesting, cloud, or DFIR tools
  • Official vendor documentation
  • General non-interactive technical references

Important Responsibility

You are responsible for your local operating system, hardware, internet connection, and home-network configuration during the exam window.

Review How to Prepare →
Tools, Integrity & Scope

Use resources—without outsourcing your judgment.

Allowed

  • Your own notes, scripts, tools, and reference material
  • Official vendor documentation and general technical articles
  • Generic helper code that you understand and can explain
  • Independent research on non-exam-specific techniques
  • AI for generic helper code or non-exam-specific text clarification

Not Allowed

  • Collaboration, live coaching, pair-hacking, or screen sharing
  • Sharing exam hosts, IPs, screenshots, configurations, or solutions
  • Sending exam-specific information to an AI service
  • Using AI or another person to solve the environment or write substantial report content
  • DoS/DDoS, intentional system damage, or activity outside authorized scope

Academic integrity protects the value of your credential.

You must understand and take responsibility for every command, script, conclusion, and report statement you submit. Integrity violations or deliberate attacks against grading, VPN, hypervisor, or out-of-scope infrastructure can result in immediate disqualification and loss of future exam eligibility.

The Required Deliverable

Your report is part of the exam.

Submit one PDF using the official Encrypted Syntax report template before the seven-day window closes. Late reports are accepted only when an extension was granted in writing before the deadline.

Executive summary
Scope and methodology
Tools and technical approach
Screenshots, logs, and commands
Impact and risk explanation
Reproducible findings
Remediation or hardening
Professional organization
Attempts & Retakes

A clear path forward after every result.

ATTEMPT 01Included

Your initial seven-day practical exam and report submission.

ATTEMPT 02Complimentary

One free retake after an unsuccessful first attempt. It must begin immediately or within seven days of the result and uses the same exam version.

ATTEMPT 03+$150 Voucher

Additional attempts require a new voucher and may use the same or a different exam version at the Institute’s discretion.

After Submission

Every result is manually reviewed.

Technical ReviewYour objectives, evidence, reasoning, and report are evaluated together.
Result & FeedbackYou receive a pass/fail result with general feedback for your next step.
Credential IssuanceSuccessful candidates receive a digital certificate and verification details.
Prepare With Confidence

The exam should feel demanding—not mysterious.

Review the preparation roadmap before activating your window, organize your evidence workflow, and reserve enough time to produce a professional report.

Open the Preparation Guide