Skip to main content

6 MONTHS OFF YOUR ANNUAL PLAN - THIS WEEK ONLY

31hr
:
06min
:
58sec
BUSINESS • 7 min read

THM PT1 vs CompTIA Security+ vs HTB CBBH: which certification path fits your team

Choosing a first cyber security certification for a team is less about picking a "best" credential and more about matching the credential to the direction the team is actually growing in. TryHackMe's Junior Penetration Tester (PT1), CompTIA's Security+, and HackTheBox's (HTB) Certified Bug Bounty Hunter (CBBH, recently renamed to HTB CWES, or Certified Web Exploitation Specialist) all sit near the entry point of the market, but they validate quite different things and prepare a hire for quite different work.

This guide compares the three on format, scope, and where each one fits inside a team plan, so a security leader can pick the credential that supports what the team is trying to do next.

In short:

  • CompTIA Security+ is a broad, vendor-neutral theory credential with performance-based questions. It signals baseline knowledge across security domains and remains one of the most reliably recognized entry-level names on a CV.
  • TryHackMe PT1 is a 48-hour practical exam that simulates a real client penetration testing engagement across web applications, network infrastructure, and Active Directory (AD), with a graded professional report.
  • HackTheBox CBBH (now HTB CWES) is a practical web-focused credential aimed at bug bounty hunters and web penetration testers.
  • The three sit at different points of the "learn, practice, validate, get hired" model TryHackMe uses for its offensive path. The right choice depends on whether a team needs breadth, offensive readiness across the full stack, or a web-application specialism.

What are the two kinds of cyber security certification?

There are two kinds of cyber security certification: those that test whether a candidate understands concepts, and those that test whether a candidate can apply them.

Theory-based certifications ask a candidate to sit a timed exam, answer multiple-choice questions with a small number of performance-based questions (PBQs), and receive a score. These credentials signal breadth of knowledge, satisfy employer checklists, and appear reliably in HR filtering systems.

Practical certifications work differently. They place a candidate inside a live environment and require them to complete real tasks over an extended window: compromise a system, exploit a vulnerability, or write a professional report. The evidence produced is closer to a work sample, which many hiring managers reference during technical interviews.

Both kinds have real value. The useful question for a team is which one fits the role being hired for and the direction the team is heading.

What does CompTIA Security+ actually cover?

Security+ is CompTIA's entry-level, vendor-neutral security credential. It covers a broad range of security domains through up to 90 questions in 90 minutes, primarily multiple choice with a small number of performance-based questions. Passing score is 750 on a 100 to 900 scale. Renewal is every three years through Continuing Education Units.

Security+ is designed to validate that a candidate understands security concepts across the field: threats and attacks, architecture and design, implementation, operations and incident response, governance, risk, and compliance. Recommended experience is CompTIA Network+ plus around two years in a security or systems administrator role, though the credential is widely taken earlier as a first cyber security qualification.

For a team, Security+ tends to be most useful as an HR-visible baseline. A candidate holding Security+ can reliably clear automated screening and demonstrate that they have studied the field broadly. It is less useful as evidence that a candidate can perform specific offensive work, which is where a practical credential typically sits alongside it.

What does TryHackMe PT1 actually cover?

TryHackMe PT1 (Junior Penetration Tester) is a 48-hour practical exam simulating a real client penetration testing engagement. In TryHackMe's own words, PT1 offers "full-stack testing across AppSec, NetSec, and Active Directory" and is "the closest certification to real penetration testing experience." Candidates operate methodically across all three domains, then deliver "a client-ready report that highlights your communication and technical skills."

The certification's preparation route was rebuilt for 2026 and now runs through "89 rooms, 17 modules" on the Jr Penetration Tester path, covering roughly 70 to 90 hours of hands-on lab work. TryHackMe describes the path as "the canonical study route" for PT1, structured around a "learn, practice, validate, get hired" progression, with "every module, every capstone challenge, and every skill area designed in lockstep with what the certification tests."

The path includes a dedicated 9-room Active Directory module covering "Kerberos, NTLM relay, lateral movement, credential harvesting from LSASS and SAM" alongside a rewritten web security section covering SQL injection, XSS, CSRF, SSRF, IDOR, broken authentication, directory traversal, command injection, and API testing. Three full kill-chain capstone challenges are, in TryHackMe's description, "designed to mirror what real junior pentester interviews and assessments look like."

The exam includes three months of premium access to the Cyber Security 101 and Jr Penetration Tester paths, plus a free retake if the first attempt is unsuccessful.

Practitioners describe the experience directly. Mathias Detmers, a Security Analyst who took PT1, writes that it "is a well-designed certification that truly tests your thoroughness and methodology. If you're looking for a hands-on exam that reflects real-world scenarios, PT1 delivers." Lucas Campos, a Junior Penetration Tester, adds that "every interactive scenario forced me to think like a real attacker instead of just memorizing commands."

For a team, PT1 tends to be most useful as evidence that a hire can execute an end-to-end penetration testing engagement across web, network, and Active Directory, and produce the professional report a real assessment requires. TryHackMe positions it as the logical preparation stage before more advanced offensive credentials.

What does HackTheBox CBBH actually cover?

HackTheBox's (HTB) Certified Bug Bounty Hunter (CBBH) is a practical credential aimed at bug bounty hunters and web-focused penetration testers. HackTheBox announced in 2025 that CBBH would evolve into the Certified Web Exploitation Specialist (HTB CWES) from 1 October 2025, with existing CBBH holders automatically transitioned to the new name. The underlying scope focuses on modern web application security, including API-driven systems, single-page applications, and GraphQL endpoints.

The credential is typically pursued by candidates targeting bug bounty programs or web application penetration testing roles specifically, rather than the broader offensive scope covered by PT1. For a team, CBBH tends to be most relevant where the direction is a web-focused specialism.

How do the three credentials compare on format and scope?

Each credential tests different things in different ways:

  • CompTIA Security+. Timed, primarily multiple-choice exam with performance-based questions. Broad coverage across security domains. 90 minutes. Recognized worldwide as an entry-level baseline.
  • TryHackMe PT1. 48-hour practical engagement inside a live environment across web, network, and Active Directory. Includes a graded professional penetration testing report, three months of preparation content, and a free retake.
  • HackTheBox CBBH (now CWES). Practical, web-focused credential covering modern web exploitation, APIs, single-page applications, and related surfaces.

Format alone does not decide fit. The direction the team is heading in tends to be a stronger determinant.

Which certification fits which team direction?

The three credentials map cleanly to three different team plans:

  • A team hiring generalists or first-time security analysts. Security+ is a recognized signal at the hiring stage. It is broadly recognized, satisfies most entry-level checklists, and gives a manager confidence that the candidate has studied across the field. Pairing it with a practical credential during onboarding is a common pattern.
  • A team building offensive capability across the full stack. PT1 tends to be the closer match. Its scope covers web, network, and Active Directory in a single exam and produces a graded professional report. The Jr Penetration Tester path doubles as onboarding material, since the same environment is used for both preparation and practice.
  • A team focused on web application security or bug bounty programs. CBBH (CWES) tends to be the more targeted credential, since its scope is specifically modern web exploitation rather than the broader offensive stack.

For teams that need more than one of the above, most security leaders layer credentials rather than choosing between them.

How do the three fit into the talent lifecycle?

Certifications carry different weight at different stages of the lifecycle:

  • Hiring. Security+ is well recognized name across automated screening and job descriptions. PT1 and CBBH tend to shorten the technical interview, because a hiring manager can reference the candidate's actual exam work.
  • Onboarding. TryHackMe's role-mapped preparation paths double as day-one practice, so a new hire moves through the same environment they will work in. Security+ typically contributes to onboarding indirectly, through study material.
  • Progression. A practical credential such as PT1 produces a graded artifact tied to a specific role, which many managers find easier to reference for promotion decisions than a knowledge exam passed some years earlier.
  • Retention and succession. Visible growth paths tend to help retention. A team using TryHackMe can plan a ladder from foundational content through PT1 and onward to more advanced offensive work inside a single platform.

FAQ

Is PT1 easier or harder than Security+?

They are different kinds of exam rather than points on the same difficulty scale. Security+ is a 90-minute timed exam that is primarily multiple choice with performance-based questions and tests broad knowledge across security domains. PT1 is a 48-hour hands-on practical engagement that tests whether a candidate can execute an end-to-end penetration test across web, network, and Active Directory, and write a professional report. Candidates typically prepare very differently for each.

Is TryHackMe PT1 an alternative to CompTIA Security+?

Not directly. Security+ validates broad conceptual knowledge across security domains, while PT1 validates hands-on offensive ability in a specific role. Many security teams treat them as complementary: Security+ for HR visibility, PT1 for demonstrable ability during a technical interview.

Is HTB CBBH the same as HTB CWES?

HackTheBox announced that CBBH would evolve into HTB CWES (Certified Web Exploitation Specialist) from 1 October 2025, and existing CBBH holders were automatically transitioned to the new certification name. The underlying scope focuses on modern web application security. Search results still commonly reference "CBBH" as the older name.

Which certification is best for a team building a penetration testing capability?

For a team building general penetration testing capability across web, network, and Active Directory, PT1 tends to be the closer match, because a single practical exam covers the full scope and produces a professional report. For teams whose direction is specifically web application security or bug bounty programs, CBBH (CWES) is more targeted. Security+ is best treated as the recognizability layer that sits alongside either.

Where should a security leader start if the team is just getting off the ground?

Start with Security+ for the recognizability baseline, and layer a practical credential (PT1 for broad offensive readiness, CBBH or CWES for a web specialism) as soon as a specific role direction is clear. That combination gives a manager both a recognizable HR signal and graded evidence of ability.

All three credentials can be complementary inside a team plan, each doing a different job at a different stage. Of the three, TryHackMe PT1 tends to produce the most direct, actionable signal of capability, because a 48-hour engagement across web, network, and Active Directory with a graded professional report is the closest exam format to the work itself.

Explore how role-mapped certifications fit into your team's hiring, onboarding, and progression plans on TryHackMe for Business.

authorJoanna Duffy
Aug 6, 2026

Recommended

Get more insights, news, and assorted awesomeness around cyber training.

Join over 640 organisations upskilling their
workforce with TryHackMe