How EC-Council grades the CPENT report
Applies to CPENT.
What the CPENT report must contain, why it is the evidence that makes your range flags count, and how the CPENT and LPT Master score bands work.
- CPENT
- 24h exam (2x12h or 1x24h) + 7-day report
CPENT is scored on a live cyber range — flags captured and objectives reached — and the report is where those achievements get credited. That is the part people miss: a compromise you pulled off but did not document with proof does not count. The report is not paperwork bolted on at the end; it is the evidence layer the range score is read from.
What the report is for
EC-Council does not publish a separate scoring rubric for report quality, so be careful with claims that polish earns points on its own. What is documented is narrower and more useful to know: reporting is a weighted domain of the exam blueprint, and your range results are credited from the evidence you submit. An undocumented flag is an uncredited flag. The report’s first job is to prove, step by step and with screenshots, that you actually did what you claim.
Its second job is to read like a professional deliverable — EC-Council frames the CPENT report as a client-grade consulting document, not a CTF log.
What has to be in it
EC-Council’s own report guidance lists the expected structure: an executive summary, scope of work, findings, recommendations and an appendix. Within the findings, each issue needs steps to reproduce, proof of exploitation, a severity or risk rating, the business impact, and remediation — written to be read by both engineers and non-technical stakeholders. There is no official page count or mandatory template; the standard is professional completeness, not length.
The score bands
CPENT and LPT Master are the same exam, not two. LPT Master is simply the top score band of the CPENT exam, so it carries the same report requirement — there is no extra document for it. The thresholds are where EC-Council’s own pages disagree: the current CPENT page describes a variable cut score that ranges with the exam form (roughly 60–85%), while older pages still state a flat 70%. What is consistent across all of them is that scoring above 90% earns the LPT Master designation. Confirm the current cut on the exam page before you sit — it is not a single fixed number.
How the time works
The exam runs as two 12-hour sessions or one 24-hour session, and the report is due within seven days of your final session. That window is separate from the hacking, but it depends entirely on notes you took during it — evidence you did not capture on the range is not recoverable a week later.
Where people lose it
- Undocumented achievements. A flag captured but never proven with a screenshot or command output, so it cannot be credited.
- A technically correct but thin report. Accurate findings written up too sparsely to read as a client deliverable.
- Treating the report as an afterthought. Leaving it to the seven-day window instead of documenting from the first session.
- No executive summary or business-impact framing. Writing only for engineers, not for the stakeholder the report is supposedly for.
- Missing the seven-day submission window.
CPENT vs OSCP, in one line
OSCP grades the report as a reproducibility instrument — a stranger must be able to replay every command. EC-Council grades it as a client-facing consulting deliverable, weighted toward business impact and remediation for a non-technical reader.
The exams this covers
- what the CPENT exam involvesUnderstand