The eJPT is the certification most people sit first when they want to prove they can actually break into a network, not just talk about it. If you are searching for how to pass the eJPT in 2026, the timing matters more than usual this year, because INE rebuilt the exam on 31 March 2026. The practical is now longer, the web application content is heavier, and there is a brand new offensive AI module in the learning path.
This guide gives you the current exam facts and a realistic week-by-week study plan to pass the new 45-question eJPT on your first attempt. It is written for beginners, so no prior pentesting experience is assumed, only a willingness to spend time in the lab.
What Is the eJPT and Who Is It For?
The eJPT (eLearnSecurity Junior Penetration Tester) is an entry-level, fully hands-on penetration testing certification issued by INE Security, the training company that absorbed the old eLearnSecurity brand. That is why the "e" still sits at the front of the name.
There is no multiple-choice theory paper here. You are dropped into a virtual lab, told to compromise a network, and asked to answer questions based on what you find. It sits at the very start of the offensive security ladder, below tougher practical exams like the CompTIA PenTest+, HTB CPTS and the OSCP.
The eJPT is a strong fit if you are:
- A complete beginner who wants a first practical cert on your CV.
- A student or career changer moving into a junior pentester or SOC role.
- A Security+ holder who wants to prove hands-on skill, not just theory.
- Someone testing whether you actually enjoy offensive work before committing to the OSCP.
Exam Tip: The eJPT is issued by INE Security, not eLearnSecurity. When you buy a voucher or search for study material, look for INE. Old eLearnSecurity links and dumps often describe the retired v1 exam and will mislead you.
What Changed in the 2026 eJPT Update?
On 31 March 2026, INE launched an updated eJPT. This is the single most important thing to understand before you build a study plan, because most guides online still describe the older version.
The headline changes are:
- The exam grew from 35 questions to 45 questions.
- 21 new assessment questions were added on web application testing.
- 12 new assessment questions were added on reconnaissance.
- A new course, Offensive AI: Generative AI for Pentesters, joined the learning path.
- Five new videos and three new labs were added to the training.
The practical takeaway is simple. Web application testing and reconnaissance now carry far more weight than they used to. If you study from a 2024 or 2025 plan that treats web apps as an afterthought, you will be underprepared for a big chunk of the new question set.
eJPT 2026 at a Glance
| Feature | Detail |
|---|---|
| Issuing body | INE Security |
| Format | Fully practical, virtual lab |
| Questions | 45 (increased from 35 in March 2026) |
| Time limit | 48 hours |
| Pass mark | 70% overall |
| Cost | 249 US dollars (standalone voucher) |
| Retake | One free retake, within 14 days of a fail |
| Voucher validity | 180 days from purchase |
| Prerequisites | None |
| Renewal | None, the cert does not expire |
Exam Tip: The eJPT does not expire and has no continuing education requirement. Once you pass, it is yours for life, which is rare among security certifications and makes the 249 dollar fee good value.
How the eJPT Exam Is Scored
The eJPT does not use a single flat pass mark across all questions. It is divided into scored areas, and the newer format keeps a domain-weighted approach where different sections demand different minimum scores. Historically the breakdown has run along these lines:
- Assessment Methodologies: a high threshold, around 90%.
- Host and Network Auditing: around 80%.
- Host and Network Penetration Testing: around 70%.
- Web Application Penetration Testing: around 60%.
You need 70% overall to pass. The important lesson is that reconnaissance and enumeration questions are where most points live, and they are the easiest to get right if you are methodical. Do not rush past the scanning phase to reach the "exciting" exploitation part. In the eJPT, careful enumeration is what earns the marks.
The Tools You Must Master
The eJPT rewards fluency with a small set of core tools rather than deep knowledge of exotic exploits. Master these and you cover the vast majority of the exam:
- Nmap for port scanning, service detection and NSE scripts. This appears in almost every scenario.
- Metasploit for exploitation, Meterpreter, payloads and pivoting. The exam leans heavily on it.
- Gobuster or Dirb for web directory and file brute forcing.
- Burp Suite for intercepting and testing web applications, now more important than ever.
- Hydra and John the Ripper for brute forcing logins and cracking hashes.
- SQLMap for SQL injection against vulnerable web apps.
- enum4linux and smbclient for enumerating Windows SMB shares.
- Netcat for reverse shells and file transfer.
Exam Tip: Pivoting trips up more eJPT candidates than any single exploit. Practise using Metasploit routes and autoroute to reach a second network segment through a compromised host until it is second nature.
A Week-by-Week eJPT Study Plan
This is an eight-week plan built for someone starting from near zero and studying around ten to twelve hours a week. If you already hold Security+ or have IT experience, you can compress it into four to six weeks by moving faster through the early stages.
Weeks 1 to 2: Foundations and Reconnaissance
Work through the Assessment Methodologies section of INE's Penetration Testing Student learning path. Focus on information gathering, footprinting, DNS reconnaissance, subdomain enumeration and port discovery with Nmap.
Because the 2026 update added 12 new recon questions, this is no longer a section to skim. Build a personal Nmap cheat sheet and run every scan type until you understand what each flag actually does.
Weeks 3 to 4: Host and Network Penetration Testing
This is the largest part of the syllabus. Cover system and host-based attacks, network attacks, the Metasploit framework, exploitation and post-exploitation. Spend real time inside Metasploit rather than just reading about it.
Reinforce every concept on external practice ranges. Easy machines on Hack The Box and the relevant rooms on TryHackMe map closely to eJPT skills and cost far less than burning a real attempt.
Weeks 5 to 6: Web Application Penetration Testing
This is where the 2026 exam changed most, so give it the time it now deserves. Learn how to map an application, find directories with Gobuster, intercept requests with Burp Suite, and exploit SQL injection with SQLMap.
Work through the new web application labs in the updated learning path. The 21 added web questions mean weak web skills are now enough to fail the whole exam.
Week 7: Auditing, Pivoting and Offensive AI
Cover Host and Network Auditing, then drill pivoting until you can chain access from one machine to another without notes. Also work through the new Offensive AI: Generative AI for Pentesters course. It is unlikely to dominate the exam, but it reflects where INE is taking the certification and sharpens how you use AI assistants responsibly during an engagement.
Week 8: Full Practice and Note Templates
Sit at least one full mock engagement under time pressure. Build a reporting and notes template now, with sections for each host, open ports, credentials found and flags captured. During the real 48 hours, clean notes are the difference between answering all 45 questions and losing track of what you already compromised.
Common Reasons Candidates Fail the eJPT
Even though the eJPT is entry level, people still fail it. The usual causes are avoidable:
- Poor enumeration. Rushing scanning means missing the open service that holds the answer.
- Weak web skills. With the 2026 update this is now a leading cause of failure.
- No pivoting practice. Candidates get stuck on the first network and cannot reach the rest.
- Messy notes. With 45 questions across 48 hours, disorganised notes cost easy marks.
- Studying the wrong version. Old v1 or 35-question material leaves gaps in the new content.
Exam Tip: You have 48 hours, so you do not need to rush. Most candidates who fail do so through disorganisation, not lack of time. Sleep during the window, then return with fresh eyes to the hosts you could not crack.
Is the eJPT Worth It in 2026?
For beginners, yes. At 249 dollars for a lifetime, fully practical certification, the eJPT is one of the most affordable ways to prove hands-on skill to an employer. It will not, on its own, land a senior pentesting role, but it is a genuine signal that you can do the work, and it is the natural stepping stone before the OSCP or HTB CPTS.
If you are weighing your options, our guides on the CompTIA PenTest+ study plan and PenTest+ vs CEH will help you place the eJPT in a wider career path. For the level above, see our HTB CPTS study plan.
Ready to Start Practising?
The eJPT rewards hands-on repetition, and the fastest way to build exam-day confidence is to test yourself under realistic conditions. CertCrush gives you structured practice questions and study tools that reinforce the exact reconnaissance, exploitation and web application skills the new 45-question eJPT tests.
Create your free CertCrush account to start practising today, or browse our full range of certification courses to plan your route from the eJPT to the OSCP and beyond. Study smart, stay methodical, and you will walk into that 48-hour lab ready to pass.
