Skip to content

BurpSuite Certified Practitioner Exam Review

Published: at 03:22 PMSuggest Changes

Introduction

I recently cleared the Burp Suite Certified Practitioner exam, and it was quite the journey! In this post, I’ll share my experiences, tips, and key takeaways to help those of you planning to take the exam or explore the PortSwigger Academy challenges. Let’s dive in!

Just a dirt background…

It’s been quite a journey for almost 4 months completely and let me explain you how i wasted my first 2 months while preparing for this certification actually.. Before even portswigger announced there certification back in time, I’ve completed the several labs like XSS, SQL injection, Access control, Business logics and most of the other labs.. But often ignored the hard things actually or took the shortcut paths like looking into the solution and solving directly..

Looking into the solution is fine but without understanding the context of exploitation like how the bug works? and how to exploit? and these things i don’t understand

But recently my organization provided with the opportunity to take this exam actually and I thought why can’t we do like reboot our web security knowledge like starting from scratch… Like entered into the pre-planning phase like making todolist of all the labs and day to day, I started solving the ones I was comfortable with rather than learning something hard.. Why I say hard things? Hard things are the ones you will learn something new and rather than getting comfortable with easy ones and eventually you won’t learn because in my perspective when after completing half of the easy labs like XSS, Access control, File uploads.. I lost interest in solving hard challenges like Blind SQLi, Request smuggling and deserialization just because it’s tough

Let’s have a look into how did I prepare in last few months and things that helped me out

Well, How did I prepare?

Useful Resources

Things to remember


Next Post
Reveal Hidden risks using Securityhub