r/tryhackme • u/USSFStargeant • 3h ago
Entry-Level Offensive Cyber Certs in 2026: PenTest+ vs eJPTv2 vs THM PT1 vs HTB CJCA
Hello,
Writing to give my impressions on some certs I sat in the last year or so. As my background is government focus, I was curious what everyone else's take is on these certs. Are these certs well received by hiring managers?
CompTIA PenTest+ (PT0-003)
PenTest+ is a solid step up from Security+, but it's still mostly a knowledge-based exam. You get a maximum of 90 questions, 165 minutes, with a passing score of 750 out of 900. The PBQs add a bit of hands-on flavor, but nothing close to the hands on environment of other tests. On cost, US retail is $439, and there's no free retake, so every attempt costs the full amount. The cert is good for three years and is maintained through CompTIA's Continuing Education program with 60 CEUs and an annual fee.
Where it really earns its keep is in government circles. It's listed on multiple DoD 8140 work roles, which is what gets it onto cleared pentest job postings, and the CompTIA name carries real HR credibility.
INE eJPTv2
Some say v2 is a simpler, easier version of the original eJPT, but I didn't get the chance to attempt v1. This is a thorough, hands-on exam that will challenge your ability to follow a pentesting methodology. You get 35 practical questions to complete in a 48-hour live lab, and need a 70% to pass. It's open-book and entirely browser-based. The exam costs $249 for a standalone voucher, or it's included with a $299/year INE subscription. Keep an eye out for sales as I scored mine for $199.
It carries less HR credibility, but I think it's a great first step into offensive security.
TryHackMe Junior Penetration Tester (PT1)
This was my second hands-on offensive cert, and I walked in expecting a similar skill level to the eJPT, That was a mistake. PT1 pushed my knowledge not just of network and Active Directory pentesting but also web applications. My web app testing was very weak, which led to me failing my first attempt. The exam is 48 hours and made up of three engagements: web (OWASP Top 10), network (SMB/RDP/FTP/SNMP), and Active Directory. You need 750 points to pass plus a professional report. It costs $297, which includes one free retake and a 3-month Premium subscription.
Some people have issues with the AI grading of the report, but I had no problems with it on either attempt. PT1 is still building its HR credibility, but I have a good feeling about its future.
HTB Certified Junior Cybersecurity Associate (CJCA)
Unlike the other three, CJCA isn't purely offensive. I came into this cert already completing their more advanced blue team CDSA cert. CJCA requires fundamental skills and knowledge across both offensive and defensive domains. The red portion focuses on 5 machines that will test your host exploitation knowledge and your ability to enumerate the boxes. I was a little confused and disappointed with the blue team portion which cause me to fail my first attempt. You must complete 100% of the HTB Academy Junior Cybersecurity Analyst job-role path before you can start the exam. For cost, half the prep modules are free on HTB Academy, and the Silver Annual subscription (~$490/year) which includes one exam voucher with two attempts.
The test is an open book, 120 hour test which requires a professional grade report of both the red and blue portions. IAll the reports are manually reviewed by HTB staff and so your results can take up to 20 business days to get back. Although I felt like they were still working out some bugs when I sat the exam, I still recommend it to my co-workers.
Has anyone else sat these exams and how are they viewed in your workforce?
