← CWAP PrepEngagements · No Flags · Timed

Full Machines

Full, realistic applications run as timed pentest engagements — practice for the CMWAP exam.

How each engagement runs:
  1. Qualify. A 50-question CWAP knowledge quiz — score 70% or you can't start.
  2. Plan (90 min). Write and submit a pentest plan. The target stays locked until it's in — no plan, no access.
  3. Hack (24 h). Once the plan is submitted, a 24-hour clock starts to compromise the app and find every critical issue.
  4. Report & debrief. Write it up, then record your own ≤10-minute debrief video (your CMWAP deliverable) and paste the link on the machine's debrief page.

There are no flags. Read the full engagement path for how to plan, report, and debrief.

The range

Logistics & freight-management platform

TransLog

Full application, multiple critical vulnerabilities, no flags.

/full-translog/
Telecom / ISP customer & network portal

NetSpire

Full application, multiple critical vulnerabilities, no flags.

/full-netspire/
E-government citizen-services portal

GovDesk

Full application, multiple critical vulnerabilities, no flags.

/full-govdesk/
SaaS DevOps / internal admin console

OpsNest

Full application, multiple critical vulnerabilities, no flags.

/full-opsnest/