CTEM Practitioner Certification

Prove you can run a CTEM cycle end to end. Scope, prioritize, validate, and mobilize with defensible decisions.
The CTEM Practitioner certification is the working-level, free credential from LearnCTEM. It verifies that you can scope a business service, deduplicate discovery inputs, prioritize exposures using business impact and EPSS or KEV signals, reason about attack paths, design safe validation activities, and drive mobilization with clear SLAs. The assessment is 100 scenario MCQs in 42 minutes, 25 seconds per question. 80 percent to pass, with free unlimited retakes.
Who this certification is for
Vulnerability and exposure analysts
Move beyond CVSS. Show you can prioritize with business impact and real threat activity.
Security consultants
Prove you can deliver a repeatable exposure register, prioritization, and validation plan for any client.
Detection, IR, and platform engineers
Show you can validate exposures safely and mobilize fixes without breaking production.
Exam blueprint
| Domain | Weight | What you must prove |
|---|---|---|
| Scoping a Business Service | 15 percent | Define scope by business service, not IP ranges, with clear owners and success criteria. |
| Discovery and Asset Deduplication | 15 percent | Combine scanner, CMDB, cloud, SaaS, and identity sources into a single deduplicated inventory. |
| Prioritization with Business Context, EPSS, KEV | 20 percent | Build a defensible score that reflects impact, exploitability, and active threat. |
| Attack Path Reasoning | 15 percent | Trace how a low-severity finding chains into a high-impact outcome across identity, cloud, and app tiers. |
| Validation with BAS and Safe Reproduction | 15 percent | Choose validation techniques that produce evidence without harming production. |
| Mobilization Workflow and SLAs | 10 percent | Route work to the right owner with the right SLA, and close with proof, not tickets. |
| Metrics and Reporting | 10 percent | Report cycle outcomes in terms of risk reduced, not just tickets closed. |
Question style
Scenario and analytical MCQ with take-home exercises
Every Practitioner question describes a realistic 2026 environment. You will see finding lists that mix CVEs, misconfigurations, exposed secrets, weak SSO policies, cloud IAM issues, and LLM application exposures. You will be asked which exposure to prioritize first, which validation technique is safe, which owner should mobilize, or which metric best represents progress. The three take-home exercises use a sample retail-plus-cloud environment: build the exposure register, rank ten exposures with a defensible score, and write a validation plan for the top three.
Sample questions
You are prioritizing 200 discovered exposures for the checkout service. Two candidates stand out: (A) an internet-facing web app CVE with a CVSS of 9.1 but EPSS of 0.02 and not on KEV, (B) an internal misconfigured OAuth scope that grants a partner SaaS full read on customer records. Which do you prioritize first?
- A.A, because CVSS 9.1 is critical
- B.B, because the business impact is direct customer data exposure and the exposure is actively usable today
- C.Both at the same priority since CVSS is the tiebreaker
- D.Neither. Wait for KEV to add A before acting
During Validation you want evidence that a prioritized exposure in a payment API is exploitable. Which approach is most consistent with CTEM Validation principles?
- A.Run a full production penetration test with no coordination
- B.Use a breach and attack simulation or a scoped safe reproduction in a staging mirror to produce evidence without harming production
- C.Wait until the next quarterly red team engagement
- D.Ask the vendor to confirm the vulnerability without independent evidence
In discovery you have three different inventories: EDR sees 8,400 endpoints, the CMDB lists 6,900, and cloud accounts report 2,100 workloads. Duplicates and orphans are certain. What is the correct next step for a Practitioner?
- A.Report 17,400 assets and move on
- B.Pick the largest source as the source of truth
- C.Reconcile using stable identifiers (cloud instance IDs, MAC, hostname, identity graph) to produce a single deduplicated inventory tied to business services
- D.Delete anything not in the CMDB
A prioritized exposure is fixed. Mobilization is complete when:
- A.The ticket is closed
- B.The remediation team says it is done
- C.Evidence has been re-collected that shows the exposure is no longer reachable or exploitable
- D.The next scan happens on schedule
Preparation path
Grading and retake policy
- MCQ auto-graded on submission. Exercises reviewed within 5 business days.
- 80 percent required to pass. 80 of 100 correct answers.
- Exercises are graded against a public rubric shipped inside the exam.
- Free retakes, with a maximum of 3 attempts per 24 hours. Exercises can be revised and resubmitted.
- Certificate issued with a unique ID and public verification URL.
What the certificate proves
Every certificate carries a unique ID and a public verification URL at learnctem.com/verify.
Frequently asked questions
Who should take the CTEM Practitioner certification?
Security analysts, vulnerability managers, exposure management leads, consultants, and engineers who actively run parts of the CTEM lifecycle. Beginner-level knowledge is expected.
What is the format of the Practitioner exam?
A 100-question scenario-based MCQ exam in 42 minutes, with 25 seconds per question and no going back. 80 percent to pass.
How is the Practitioner exam different from Beginner?
Beginner tests concepts. Practitioner tests decisions. Every scenario describes an environment and asks which action you would take next, using business context, EPSS or KEV signals, attack path reasoning, and safe validation choices.
How long should I prepare for the Practitioner exam?
8 to 12 hours if you already have vulnerability management or security operations experience. 20 or more hours if you are coming straight from Beginner without hands-on exposure management work.
How are the three exercises scored?
Each exercise is graded against a public rubric covering completeness, business alignment, and defensibility. Rubrics are published on this page and inside the exam so there are no surprises.
Can I retake the Practitioner exam?
Yes. Retakes are free, with a maximum of 3 attempts in any 24 hour period. After 3 attempts you can try again once 24 hours have passed. Exercises can be revised and resubmitted after review.
Ready to earn the CTEM Practitioner Certification?
Sign up in seconds. Zero cost. Public verification for every certificate.
