CMWAP Practice Path
Practice for the Certified Modern Web App Pentester exam (certs.thexssrat.com/cmwap). Prove how you think, not how many payloads you can spray: a 24-hour window, a written report (≤90 min), and a ≤10-minute debrief video — scored on methodology.
The CMWAP engagement, step by step
Every full machine on this path runs this exact flow — the same shape as the exam.
0 — Qualify
A 50-question web-app knowledge check gates each engagement. Score 70% or you can't start — the exam assumes you know the fundamentals cold.
1 — Plan (90 min)
Before you touch the target, write and submit a plan: scope, rules of engagement, methodology, tooling, objectives. No plan, no access — exactly like a real engagement.
2 — Test (24 h)
Work the plan. Map the whole surface, then go class by class. Validate every finding with the exact request that proves it. Deliberate, targeted testing — audit logs show how you worked.
3 — Report & debrief
Write the report (exec summary, findings with severity + repro + impact + remediation), then record a ≤10-minute debrief video. In the exam the debrief is where you're scored.
What the debrief is scored on
The CMWAP debrief video (≤10 min) is graded on five dimensions — practice hitting them on every machine.
1 · Scoping
What you chose to test and why.
2 · Approach & structure
Your methodology — not a payload spray.
3 · Finding validation
How you proved each issue is real, and how you present it.
4 · Time allocation
Transparency about where the 24 hours went.
5 · Reflection
What you'd improve about your process next time.
The Two Modules
Warm up on the bug classes, then run the full no-flag engagements.
Web-App Vulnerability Fundamentals
Before the full engagement, drill each core web-app bug class in isolation. These are small, single-vulnerability labs (with flags) so you can prove the technique cold — the CMWAP exam assumes you know these.
- Broken Access Control — IDOR & function-level authz
- Stored / blind XSS with out-of-band exfil
- CSRF — forging state-changing requests
- Business logic abuse
- Secrets exposure & content discovery
Full Engagements — the CMWAP format
No-flag machines run exactly like the CMWAP exam: pass a 50-question qualifier (70%), write a plan in 90 minutes, get 24 hours to compromise a full application, then record a debrief. Nothing to capture — you are graded on how you think and what you deliver.
- Scoping & rules of engagement
- Methodology-driven testing (not payload spraying)
- Finding validation & evidence
- Report writing within the 90-minute budget
- ≤10-minute debrief video — the 5 scored dimensions
No flags. On these machines you don't submit a flag — you submit a pentest plan + report and a debrief video on the machine page. That's the deliverable, exactly like CMWAP.
Ready for the real thing? Book the CMWAP exam →