Free shipping on orders over $99 · Use code LEARN26 for 10% off
Free Trial available for 5 days!4.9 star average ratingFree chapter every monthShipping to 120+ countries Free Trial available for 5 days!4.9 star average ratingFree chapter every monthShipping to 120+ countries
Support · Partner
Get the full year subscription for unlimited reading — 2 months freeBuy a 3-book bundle — 20% off each book!
Back to the blog
PenTest+9 min read

Nobody Fails PenTest+ on the Hacking. They Fail on the Paperwork.

The exam candidates fear the technical questions and neglect the rest. Then they fail on scoping, rules of engagement, and reporting — the professional spine that separates a penetration tester from a criminal.

Ask a room of PenTest+ candidates what worries them and they will point at the technical content — the exploitation, the tools, the attack techniques. Ask the people who train them where candidates actually fail, and you get a completely different answer. They fail on the parts they dismissed as bureaucracy: scoping, authorisation, legal frameworks, and reporting. They fail on the paperwork.

This is not an accident of exam design. It is the exam correctly reflecting the profession, where the paperwork is not the boring wrapper around the real work — it is the work that makes the rest legal, useful, and professional.

The myth of the technical exam

The myth goes like this: penetration testing is about breaking into systems, so the exam must be mostly about breaking into systems. Candidates prepare accordingly, drilling exploitation and tooling, and treat engagement management and reporting as a light read the night before. Then they meet an exam where a substantial share of the questions are about exactly those neglected areas, weighted just as heavily as the technical ones.

Engagement Management 17% Recon & Enumeration 21% Vulnerability Discovery 17% Attacks & Exploits 35% Reporting & Communication (woven throughout) 10%
Even the "hacking" domains assume you scoped the work legally and can report it. Non-technical judgement runs through the whole exam.

Attacks and exploits is the largest single domain, yes — but it is barely a third of the exam. The rest rewards a completely different skill set: knowing what you are allowed to do, planning the engagement, and communicating what you found. A candidate who is brilliant at the third and hopeless at the rest does not pass.

Here is the distinction the exam is really testing, and it is the most important one in the whole field. The exact same action — scanning a network, exploiting a vulnerability, extracting data — is either a well-paid profession or a serious crime, and the only thing that separates the two is authorisation. A signed agreement, a defined scope, and a clear set of rules are what make you a penetration tester instead of a criminal.

The line you cannot cross

Testing one IP outside your agreed scope is not a technicality. It is unauthorised access — a crime in most jurisdictions — regardless of your good intentions or the value of what you found. The paperwork is what keeps you on the right side of that line.

This is why the exam will not let you skip engagement management. A tester who does not understand authorisation, legal boundaries, and compliance frameworks is dangerous no matter how skilled they are technically. The certification is, in part, a promise to clients that the holder understands where the line is — and that promise is worthless if the exam does not test it hard.

Get PenTest+ certified — first try, no resitAll-in-One Study Guide. Ebook $29.99, only $26.99 with code LEARN26.
Claim your discount

Scope: the document that keeps you out of court

The rules-of-engagement document is the unglamorous heart of a professional engagement. It defines what you may test, when, how aggressively, what is explicitly off-limits, who to call if something breaks, and what happens if you stumble onto something sensitive. Every clause exists because someone, somewhere, learned the hard way what happens without it.

The exam asks about scope because getting it wrong in reality is catastrophic. Test outside the agreed targets and you have committed a crime. Test too aggressively and take down production, and you have caused real damage. Fail to define an emergency contact and a routine test becomes a midnight crisis with nobody to call. Understanding scope is not memorising a template — it is understanding that your authorisation is precisely bounded, and stepping outside those bounds undoes everything.

The deliverable that is the actual product

Finally, the report — the thing candidates most underestimate and clients most value. The client did not hire you to get a shell. They cannot see your shell, they do not care about your shell, and a screenshot of it changes nothing about their security. They hired you for the report: a clear, prioritised, actionable account of what is wrong and how to fix it. That document is the entire product. Everything else is the process that produces it.

1 You exploit the fun, invisible part 2 You document findings + evidence 3 You prioritise by real risk 4 They fix the actual outcome
The client experiences none of the hacking and all of the report. Guess which one the exam weights.

A brilliant finding buried in an unreadable report is a finding that never gets fixed, which in business terms is a finding you failed to deliver. The exam tests reporting because the profession lives or dies on it. So if you are preparing for PenTest+, invert your instinct. Give the exploitation the study time it needs — and then give scoping, authorisation, and reporting equal time, because the exam does, and because the job does. Nobody fails PenTest+ on the hacking. They fail on the parts that turn hacking into a profession.

How to prepare for the parts you dread

If the non-technical domains are where candidates fail, they are also where a little deliberate study yields the biggest score gains, precisely because everyone else is neglecting them. Do not read the engagement-management material passively. Learn what each clause of a rules-of-engagement document protects against and why it exists. Understand the major legal and compliance frameworks not as acronyms to memorise but as the real-world constraints that shape what a tester may do. Read actual penetration test reports — many good examples are published — and study what makes a finding clear, a severity rating defensible, and a remediation actionable. This material is genuinely learnable in a way that expert-level exploitation is not; you can master professional scoping and reporting in a couple of focused weeks, whereas deep offensive skill takes years. That asymmetry is a gift to the exam candidate: the domains you fear most are the ones you can improve fastest, and they count for just as much.

So invert the instinct that the exam is a hacking test. It is a professionalism test with a hacking component, and the candidates who internalise that — who give scoping and reporting the same respect they give exploitation — are the ones who pass, and the ones clients trust with real engagements. The paperwork is not what stands between you and the interesting work. The paperwork is what makes the interesting work a career instead of a crime.

Zero Trust, actually implemented — launching soon

What zero trust means once you have to build it: identity, segmentation, least privilege. Get notified at launch and save 20%.

Notify me — save 20%