Skip to main content

WEB1 Exam Guide

Everything you need to know about the WEB1 exam format, preparation, results, and certification.

Written by BigFawn

Exam Format & Duration

The WEB1 exam is a 48-hour, non-proctored, hands-on assessment. It consists of 3 sections across deployable web applications, available 24/7 once started. Candidates choose which vulnerability titles to attempt and may switch freely between sections at any time. No paid tool licence is required.


Exam Sections

  • Blackbox Exploitation - 20% of total score (200 points, 1 flag). Attack web applications with no source access, exploiting authentication, session, and access-control flaws as an external attacker.

  • Whitebox Exploitation - 20% of total score (200 points, 1 flag). Work with source code access to discover and exploit complex server-side vulnerabilities including request smuggling, race conditions, insecure deserialisation, and SSRF.

  • Greybox Exploitation - 60% of total score (600 points, 5 flags at 120 points each). Work the full injection and client-side spectrum with partial knowledge of the target, covering SQL, NoSQL, LDAP, ORM, command, XXE, SSTI, XSS, CSRF, CORS misconfiguration, and prototype pollution.

Total: 1,000 points. Passing mark: 700 points (70%).

You can read more about the topics covered in the exam here.


Tooling & Environments

Each exam instance is a deployable web application, cloned in isolation with its own data and a unique flag injected at deploy - no candidate ever affects another. Attack from the TryHackMe AttackBox or your own VPN-connected machine. All you need is a browser and your usual web testing toolkit. No paid tool licence (e.g. Burp Suite Pro) is required to sit the exam.


Prerequisites & Preparation

WEB1 is not an entry-level certification. It is a focused web specialisation running well into intermediate territory, covering techniques such as HTTP request smuggling, race conditions, insecure deserialisation, and prototype pollution. A working knowledge of core web technologies, HTTP, and basic security concepts is recommended before starting the preparation path.

The Web Application Pentesting Learning Path is the source of all exam content and is included free with TryHackMe Premium. It covers every vulnerability class tested in the exam, from authentication and JWT security through injection and client-side attacks to advanced server-side techniques. 3 months of TryHackMe Premium is bundled with the exam purchase.


Results & Grading

Flag-based exploitation components are scored automatically and objectively. Written components (attack description and remediation guidance) are graded against a published rubric. A human appeal path is available for written scores. The passing mark is 700 of 1,000 points (70%).


Verification

Your WEB1 credential includes a verifiable digital certificate with a unique verification ID, a shareable Credly badge, LinkedIn integration, a QR code for instant verification, a public verification portal for employers, and per-vulnerability reports as portfolio evidence.


Pricing & What's Included

The WEB1 exam is priced at $299, with a 15% discount for active TryHackMe Premium subscribers. The purchase includes one free retake, a 48-hour exam window, and 3 months of TryHackMe Premium.


How WEB1 Relates to PT1

WEB1 sits before PT1 in the TryHackMe learning path, serving as focused pre-preparation. Where WEB1 builds deep, specialised web application security skills, PT1 covers a broader penetration-testing scope. Completing WEB1 first gives you a strong web foundation heading into PT1.


Still got more questions?

You can reach out to [email protected] or ask in our Discord server or Subreddit for further assistance.

TryHackMe

Did this answer your question?