Field Notes — What Test-Takers Report
Every other page on this site teaches you the material or the method. This one asks a narrower question: what did individual people who actually sat the exam choose to publish afterwards? For the Certified DevSecOps Professional (CDP) the answer is unusually generous — this course found nine real, named, first-hand write-ups spanning 2020 to 2024, several of them on the authors' own domains rather than on a content farm. That is a thick record by certification standards, and most of it is genuinely useful. But it comes with a single, load-bearing defect that this page has to put before everything else: every single one of those accounts that states a duration describes a twelve-hour hands-on exam, and Practical DevSecOps' own current pages say six. Seven of the nine state one; the other two, to their credit, published no format numbers at all. The format was shortened after mid-2024, and nobody went back to edit the blog posts. So read these accounts for technique, which transfers completely — and never for the clock, which is now off by a factor of two in every one of them that mentions it.
Imagine nine people wrote reviews of the same cooking test. The reviews are detailed and honest and full of good advice: taste as you go, read all the recipes before you turn the oven on, take a photo of the finished dish before the kitchen closes. Brilliant. But every one of those reviews was written back when the test gave you twelve hours, and the test now gives you six. So the advice about how to cook is still perfect. The advice about how long you can spend on the soup would ruin you. Same page, two kinds of sentence — and telling them apart is the whole skill.
Part One — a thick record with a broken clock
☺ Like you're 10: Lots of people wrote about this test, which is lucky. All of them wrote before it changed size, which is not.
The usual problem with a field-notes page is scarcity: a young credential, two or three write-ups, and an honest admission that there isn't much to go on. The CDP has the opposite problem. There is a real shelf of testimony here — nine accounts published between May 2020 and July 2024, from people in different countries with different day jobs, several of whom disagree with each other, and one of whom actively dislikes the product he passed. That variety is what makes the record trustworthy. What makes it dangerous is that all of it predates a silent format change, and the internet has not caught up.
What the vendor guarantees — the only part of this page that isn't testimony
Before a single blog post, anchor on the vendor. Practical DevSecOps' exam and certification page and its CDP course page agree with each other, which is the minimum bar for treating a number as current. Everything in the table below is their published claim, quoted so you can recognise it — not this course's assertion, and not a promise it is still accurate on the day you read this.
| What Practical DevSecOps publishes | Stated as | Why it matters to this page |
|---|---|---|
| Exam shape | An online, task-oriented exam in which you solve 5 challenges (tasks) | Five is the only sanctioned count. Do not repeat a sub-task number you read in a write-up as if it were a spec. |
| Hands-on window | 6 hours | This is the number every published account that states one contradicts. The vendor's own pages are the authority; the blogs are history. |
| Report window | About 24 hours after the exam to submit the report on the internal portal | The one figure that has stayed stable across the whole record — every source that states a report window says 24 hours, bar a single 2020 outlier, and the earliest of them said it in 2020. |
| Pass mark | At least 80 points (80%) | Higher than its own siblings. The CDE (Expert) exam is stated at 70% over a 24-hour window, and the CDL at 70% too. |
| Result turnaround | Certificate by email within 72 hours of passing | One 2020 account reports receiving it the next day — faster than the stated ceiling, which is the harmless direction to be wrong in. |
| Prerequisites | Basic Linux command knowledge and a foundational understanding of application security concepts such as the OWASP Top 10; no prior Dev or DevOps tool experience stated as necessary | Several accounts flatly disagree in practice — see the baseline page, which exists precisely because of that gap. |
| Validity | Described as a lifetime credential | No renewal period is published. Do not let any third-party site sell you one. |
| Package | 3 years of video access, 60 days of browser-based labs, 100+ guided lab exercises, a PDF manual, checklists, 24/7 learner support through Mattermost, and a single exam attempt | "Single attempt" is why the retake price below matters, and why the accounts obsess about preparation rather than about trying again. |
| Price and credit | Listed at US$899, with 36 CPE points advertised; a retake is listed separately at US$100, with no attempt cap or waiting period stated | Volatile. A 2020 account records the same course at US$799, and discounting is frequent. Confirm at checkout, always. |
Everything in Part One that is not marked official comes from independent write-ups published between 2020 and mid-2024 by individual people describing individual sittings. Exam form, timing, tooling, portal mechanics and pricing have already changed once during the life of that record and can change again. Practical DevSecOps' exam and certification page, its CDP course page and its retake page are the only authority. Where this page and the vendor disagree, the vendor wins.
The finding that reframes everything else: the clock moved
Seven of the nine named accounts state a hands-on window, and an eighth source — an unattributed review — corroborates them. Line all eight up against today's specification and the pattern is not subtle: four years, several countries, complete agreement with each other and complete disagreement with the vendor's current page.
| Source | Date published | Hands-on window reported | Report window reported |
|---|---|---|---|
| Joshua Jebaraj | May 2020 | 12 hours | 12 hours — the single outlier in the whole record |
| Ishaq Mohammed | May 2020 | 12 hours | 24 hours |
| Najib Radzuan | Aug 2020 | 12 hours | 24 hours |
| Ayoub Najim | Jan 2023 | 12 hours | 24 hours |
| Vinit Patil | Jul 2023 | 12 hours | 24 hours |
| An unattributed review on less-secure.com | Jan 2024 | 12 hours | 24 hours |
| Mikayel Mardanyan Petrosyan | May 2024 | 12 hours | 24 hours |
| Diogo Pereira | Jul 2024 | 12 hours | 24 hours |
| Practical DevSecOps, current published spec | today | 6 hours | 24 hours |
Two accounts are missing from that table for honest reasons. Sanjeev Jaiswal reviewed the course and exam in May 2020 but published no format numbers at all, so he neither corroborates nor contradicts. Tess Sluijter declined to give exam specifics on the grounds of the non-disclosure agreement — which, as it turns out, made hers the account that aged best, because she published almost no numbers to go stale. The one number she does give cuts in this table's favour rather than against it: she reports losing 11 hours of work when her GitLab was reprovisioned, which only makes sense inside a window longer than eleven hours. Writing in March 2021, the one author who refused to state the format quietly corroborates it anyway.
A corroborating detail nobody planted deliberately
There is a small piece of arithmetic that quietly confirms the change and dates it. Practical DevSecOps advertises 36 CPE points for the CDP. Twelve plus twenty-four is thirty-six. That figure is exactly the old format's total contact time, and it is still sitting on the current page beside a six-hour exam window. The most economical explanation is that the hands-on window was halved and the CPE line was never revisited. The latest first-hand account in the record is Diogo Pereira's, published 1 July 2024, still describing twelve hours — so the change lands somewhere after that date.
Treat 36 CPE as evidence about the past, not as a promise about the present, and do not repeat the phrase "a 36-hour exam" that several third-party sites still carry. It describes a format that has been retired. If CPE credit matters to your employer or your professional body, get the current figure from the vendor in writing before you book.
What the drift actually costs you if you miss it
This is not a pedantic correction. It is the difference between a plan and a wreck. Vinit Patil published the most careful time plan in the entire record: roughly two hours and fifteen minutes per challenge, plus a forty-five-minute documentation buffer. Against twelve hours that is sensible, even conservative. Against six it is a fantasy — two and a quarter hours per challenge is eleven and a quarter hours of work inside a six-hour window. And Patil's actual experience was worse than his plan: challenge one took four hours, including a deliberate break to reset his head. Under the current clock, that single challenge is the entire exam, minus the two hours you would need for the other four.
Ayoub Najim independently reports the same shape — he passed on his first attempt, but burned roughly three and a half hours on challenge one and finished the remainder under real pressure. Two people, two years apart, both losing the front third of a twelve-hour exam to the first task. Halve the window and that failure mode does not halve with it; it becomes the whole story. Everything in How to Study for the Exam about timed reps, and everything in the CDP study plan about rehearsing inside the real window, exists because of exactly this.
When you read any CDP write-up — including the ones linked from this page — mentally tag every sentence as either technique or arithmetic. "Read all five challenges before you start" is technique: it is true at any window length, and it gets more valuable as the window shrinks. "I gave myself two hours per challenge" is arithmetic: it is a number derived from a window that no longer exists. Technique survives the format change untouched. Arithmetic does not survive it at all.
The nine accounts, and what each one is actually good for
These are ordered by publication date. Every one is a real, named, reachable write-up by a person describing their own sitting. None of the numbers in the third column should be treated as a specification.
| Author & date | What makes it worth reading | Where to be careful | Link |
|---|---|---|---|
| Sanjeev Jaiswal ("Jassics") 1 May 2020 | The earliest full course-and-exam review. Reports about 30 days of preparation at one to two hours a day over four weeks, with the labs repeated two or three times. Recommends arriving with prior Docker, GitLab CI/CD and SSH familiarity plus DevSecOps basics — the practical prerequisite list the vendor's own page does not give you. | States no exam-format numbers at all, so it cannot corroborate anything about timing. See the note below on why its prep-duration sentence turns up again in two later posts. | Medium |
| Ishaq Mohammed 21 May 2020 | Contains the single best operational warning in the entire record: lab access ends when your exam time ends, so take backups, screenshots and saved output as you go. Also describes the exam as five challenges each carrying sub-challenges, and records the course price at US$799 at the time. | Twelve-hour framing throughout, and a price that has since moved. The warning itself is format-independent and, under a six-hour clock, more urgent rather than less. | ishaqmohammed.me |
| Joshua Jebaraj 26 May 2020 | Confirms five tasks and makes the sharpest point about what is being tested: the exam rewards the practical work rather than memory. Also notes that the course material deliberately includes broken tasks so that troubleshooting becomes part of the training, and reports his certificate arriving the following day. | The only account in the record claiming a 12-hour report window. Eight other sources and the vendor all say 24. Treat it as an outlier or an early-format detail, not as a live possibility. | joshuajebaraj.com |
| Najib Radzuan 12 Aug 2020 | By a distance the most concrete account of what the report has to contain: step-by-step instructions, the actual configuration files (GitLab CI/CD YAML, Ansible playbooks), screenshots, and machine-readable scanner output in JSON or XML. Also the origin of the read-everything-first tactic, on the grounds that the challenges interconnect. | Twelve-hour framing. The report requirements are the part to lift; treat the specific tool names as that year's exam rather than a permanent list. | Medium · devops4me |
| Tess Sluijter 4 Mar 2021 | The most disciplined account and, because of that discipline, the one that has aged best. Declines exam specifics citing the NDA, and instead gives the framing that matters: expect scanners other than the ones the labs used, expect more advanced features of the ones they did, and expect languages you did not practise on. Compares the required mindset to the OSCP — the concepts are familiar, the research happens live. Advice: document as you go — a line she credits to John Strand, not to herself — and clone the exam repository locally, pulling updates regularly. | Deliberately gives you no exam timings or task details. The single number in the post is incidental and appears in Part One above: 11 hours of work lost to a GitLab reprovision, which implies a window longer than eleven and so places her in the twelve-hour era without her ever saying so. The restraint is a feature. Do not go looking for specifics here; go looking for posture. | kilala.nl |
| Ayoub Najim 12 Jan 2023 | Cites the 80-out-of-100 pass mark, confirms five challenges, and reports roughly 60 days of preparation at two to three hours a day over eight weeks. Passed first time. Most usefully, he is candid that challenge one ate about three and a half hours and the rest were finished under pressure. | Twelve-hour framing; the pressure he describes at the end is what the front of a six-hour exam now feels like. See the note below on the shared prep-duration phrasing. | Medium |
| Vinit Patil 27 Jul 2023 | The best time-management account, and the reason the schematic above exists. Publishes both his plan and his actuals, hour by hour, and names the working stack he met: GitLab CI/CD, SCA, SAST and DAST tooling, Docker, Ansible, InSpec, Linux hardening and DefectDojo. | Every single number in it is drawn against a twelve-hour window. Read the structure of the plan — segment the window, budget documentation explicitly, protect the tail — and rebuild the numbers yourself against six. | Medium |
| Mikayel Mardanyan Petrosyan 8 May 2024 | The dissent, and the most valuable account on this page for anyone deciding whether to buy. He passed, and then published a detailed critical review of the course, the platform and the credential's positioning. Part Three below covers it properly rather than reducing it to a sentence. | It is a review of the 2024 product on the 2024 platform; some of the interface complaints may have been fixed since. His structural criticism about where evidence-gathering happens in the clock has, if anything, got sharper. | Medium |
| Diogo Pereira 1 Jul 2024 | The most recent verified first-hand account, and the calmest. Describes the sitting as relaxed on the strength of thorough preparation, and reports something no other account does: he hit minor technical problems at the start and Practical DevSecOps extended his time by an hour to compensate. Advice: build personal cheatsheets of code snippets in advance, read the PDF manuals alongside the videos, and plan the time split before starting. | Still twelve hours. The one-hour extension is one candidate's experience of support responsiveness, not an entitlement — do not build a plan that assumes you can get time back. | diogo-pereira.com |
Three of these are less independent than they look
Nine accounts is only nine accounts if they were written independently, and three of them share a suspiciously specific sentence template about preparation duration — the "it took me around N days, studying X hours a day for W weeks, repeating the labs two to three times" construction. Jaiswal's is the earliest (May 2020); Najim's (2023) and Patil's (2023) closely echo its phrasing. Their other content differs substantially, and Patil's hour-by-hour breakdown is unmistakably his own work, so all three remain usable and all three stay in the table above. But the honest reading is one template plus two variations, not three independent corroborations of a prep-duration figure.
This is the general failure mode of certification research, and it is worth learning here where the stakes are low. Repetition is not corroboration. Three posts saying the same thing might be three people who each sat the exam, or one person who sat it and two who read his post. Before you weight a claim by how often you have seen it, check whether the versions are independently phrased. Where they are not, count them once.
What this course found and deliberately did not use
Being explicit about the discards is part of being trustworthy about the inclusions. Four categories of source turned up in the search and were left out on purpose.
| Source | Why it was excluded |
|---|---|
| A January 2024 review on less-secure.com | A real post with a correct-for-its-time 12-plus-24 format and five tasks, but no author name appears on the page and it is uniformly positive with no criticism whatsoever. It reads promotional. It appears in the drift table above purely as format corroboration, labelled as unattributed, and is cited for nothing else. |
| A LinkedIn Pulse article by Mukhtiar Khan | The article exists, but LinkedIn blocks retrieval, so nobody on this course has read it. Nothing is attributed to it. An unreadable source is not a source, however plausible its title. |
| Trustpilot, G2, TeamBlind | Vendor-review sites and career chat, not exam-experience accounts. TeamBlind's one substantive remark — that the credential carries weight with conservative, regulated clients but less so in large product-engineering organisations — is anonymous, unverifiable and about hiring markets rather than about sitting the exam. |
| practicetestgeeks.com, mentorcruise.com and similar | Aggregator and SEO pages with no first-hand sitting behind them. These are the pages most likely to still be repeating "a 36-hour exam" — they are where stale numbers go to be laundered into fact. |
Part Two — the techniques that survive the format change
☺ Like you're 10: Now the good bit. Everything the nine people said about how to work is still exactly right — and the shorter exam makes most of it matter more, not less.
Strip out every number and what remains is a remarkably consistent playbook, arrived at independently by people who mostly were not reading each other. Six habits recur. Every one of them is format-independent, and four of the six get more valuable when the window halves.
1. Read all five challenges before you touch anything
This is Najib Radzuan's lead tactic and the one with the clearest mechanism behind it: the challenges interconnect. Something you build in challenge two may be what challenge four expects to already exist, and discovering that at hour five is a different experience from knowing it at minute five. Spending the opening minutes reading rather than typing feels wasteful when the clock is visibly running — which is exactly why people skip it, and exactly why it pays.
Under a six-hour window the calculation gets sharper, not looser. A ten-minute read of all five is under 3% of the exam and converts an unknown pile into a ranked queue: which one is cheapest, which one is a prerequisite for another, which one you should attempt last because you are weakest there and partial work is better than none. The triage playbook is the drilled version of this; the challenge bank is where you rehearse it against material you have not seen.
2. Document as you go, because the environment dies with the clock
Two independent accounts converge on this and one of them states the mechanism outright. Ishaq Mohammed's warning is the most operationally useful sentence in the record: you lose access to the exam lab when your exam time ends, so keep taking backups, screenshots and saved output while you still can. Tess Sluijter reduces it to three words — document as you go — but the three words are not hers, and she says so: As John Strand always says: "Document as you go!" It is one of several concrete tactics she gives despite the NDA; its companion — clone your exam repository locally and pull updates regularly — is in her row of the table above.
Think about what that actually means against the published spec. You get roughly 24 hours afterwards to write the report. You do not get the environment back during those 24 hours. So every screenshot you did not take, every scanner output you did not save, every command you ran but cannot reproduce from memory is a point you cannot claim — no matter how correctly you fixed the thing. The fix and the proof of the fix are two separate deliverables, and only one of them has a second chance.
# The evidence habit, run at the close of every single sub-task — not at the end. # Four artefacts per fix. If any one is missing, the fix is not finished. EV=~/exam-evidence/challenge-2/task-3 mkdir -p "$EV" # 1. THE FINDING — proof the problem was real, before you touched it semgrep --config auto --json --output "$EV/01-before.json" ./src # screenshot the failing pipeline run / the vulnerable response / the open port # 2. THE CHANGE — the actual artefact you wrote, not a description of it cp .gitlab-ci.yml "$EV/02-pipeline.yml" cp policies/require-scan.rego "$EV/02-policy.rego" git -C . diff > "$EV/02-change.patch" # 3. THE PROOF IT WORKED — the same check, re-run, now clean or now blocking semgrep --config auto --json --output "$EV/03-after.json" ./src # screenshot the pipeline FAILING on purpose if the task was to add a gate # 4. THE NOTE — four sentences, written now, while it is still in your head cat > "$EV/04-note.md" <<'NOTE' Finding: what was wrong, and how I proved it was wrong. Evidence: 01-before.json, screenshot-01.png Change: what I altered and why this control and not another. Proof: 03-after.json, screenshot-02.png — gate now blocks on fixable HIGH. NOTE # Sanity check before moving on: four things, or you are not done. ls -1 "$EV"
This is Petrosyan's structural criticism and it deserves its own box, because it is the point most candidates miss. Gathering evidence and writing notes happens inside the hands-on window, not inside the 24-hour report window — the report window is for assembling and formatting what you already captured. So the usable working slack is smaller than the headline figure suggests. Under the old twelve-hour format that was an annoyance. Under six hours it is a planning constraint: budget documentation time explicitly, per task, the way Patil did with his forty-five-minute buffer, and accept that some of your six hours is spent typing prose rather than fixing things.
3. Expect tools, features and languages the labs never showed you
Tess Sluijter's framing is the most quoted-worthy thing in the record and the one most likely to save your exam. Her expectation-setting is threefold: expect scanners other than the ones the course labs used; expect more advanced features of the ones they did use; and expect programming languages other than the ones you practised on. Her comparison is to the OSCP — the concepts are the same, but you research on the job.
That is a specific instruction about how to prepare, and it is not "learn more tools." It is learn the category well enough to drive an unfamiliar member of it. If you only know Semgrep, you know one SAST tool; if you understand what SAST does, what a ruleset is, how findings are triaged and how exit codes drive a pipeline gate, you can pick up a scanner you have never seen from its --help output. Same for SCA, DAST, IaC scanning and policy engines. Pipeline security, static analysis, dynamic analysis and SCA in depth are all written category-first for exactly this reason, and the tools hub is deliberately a catalogue of interchangeable options rather than a shrine to one favourite.
The language point is the one people under-rate. A SAST challenge against a Python codebase and the same challenge against a Java or Go codebase are different afternoons if you can only read one of them. You do not need fluency — you need to be able to open an unfamiliar repository, find where dependencies are declared, find where the build happens, and read a stack trace without panicking. If that sounds like a gap, the baseline page is where it gets closed. And if the OSCP framing appeals, the OSCP page and offensive security for DevSecOps cover the research-under-pressure mindset in more depth.
4. Build the cheatsheet before exam day, not during it
Diogo Pereira's central piece of advice is to prepare personal cheatsheets of code snippets in advance, and to read the vendor's PDF manuals alongside the videos rather than treating video as the primary channel. This is the highest-leverage habit on the page for a shortened exam, because a cheatsheet converts recall time into paste time — and recall time is what you no longer have.
The trap is building a cheatsheet that is really a textbook. A useful one is short, invocation-shaped, and contains only things you have actually run. The command and tool reference on this site is the raw material; your version should be a tenth of its length and written in your own hand, because the act of choosing what goes in is most of the value.
# A cheatsheet worth having: one screen per category, invocations only. # Rule — nothing goes in that you have not personally run at least twice. ## SAST — fail the build on a real finding semgrep --config auto --error --json --output sast.json . semgrep --config p/owasp-top-ten --severity ERROR --error . ## SECRETS — history matters more than the working tree gitleaks detect --source . --report-format json --report-path secrets.json trufflehog git file://. --only-verified --json > verified-secrets.json ## SCA — a gate, not a report trivy fs --scanners vuln --severity HIGH,CRITICAL --ignore-unfixed --exit-code 1 . syft packages dir:. -o cyclonedx-json=sbom.json && grype sbom:sbom.json --fail-on high ## CONTAINER — same tool, image target, plus config trivy image --severity HIGH,CRITICAL --exit-code 1 "$IMAGE" trivy config --severity HIGH,CRITICAL --exit-code 1 ./deploy ## IaC — two engines, because the exam may not hand you your favourite checkov -d . --compact --quiet --output json --output-file-path iac.json tfsec . --format json --out tfsec.json --minimum-severity HIGH ## DAST — the baseline scan is the one that fits in an exam window zap-baseline.py -t "$TARGET_URL" -J zap.json -r zap.html ## POLICY AS CODE — the gate that rejects, with a reason conftest test deploy/ --policy policies/ --output json opa eval -i input.json -d policies/ "data.main.deny" --format pretty ## COMPLIANCE — machine-readable output the report can quote inspec exec profile/ --reporter cli json:compliance.json ## TRIAGE — get findings somewhere a report can cite them curl -s -H "Authorization: Token $DD_TOKEN" -F "scan_type=Trivy Scan" \ -F "file=@trivy.json" -F "engagement=$ENG_ID" \ "$DD_URL/api/v2/import-scan/" ## THE THREE FLAGS THAT DECIDE WHETHER A GATE IS REAL # --exit-code 1 / --error → the pipeline actually fails # --severity → it fails on the right things # --ignore-unfixed → it fails on things somebody can act on
Write your own version of the block above from a blank file, with no reference open, and then verify every line by running it against a scratch repository. Anything you could not produce from memory goes into Know It Cold for drilling; anything that failed when you ran it goes into your mistake log with the corrected invocation beside it. Do this once now and once again a fortnight later — the second pass is where you find out which lines you actually own. When both passes are clean, run Mock Exam · Set 1 using only your own cheatsheet.
5. Challenge one is the time sink in every account that breaks down its hours
Two of the nine published an hour-by-hour account, and both lost the front of the exam to the first task: Najim at roughly three and a half hours, Patil at four. Neither was incompetent — both passed. The pattern is about how the first task feels: unfamiliar environment, adrenaline, a natural reluctance to abandon the thing you have already sunk an hour into, and no data yet about how hard the other four are.
The countermeasure is a hard flag-and-move rule set before you start, because you will not set one fairly at hour two. Decide your per-challenge ceiling from the current six-hour window and your own documentation budget, write it on paper, and obey it. Partial work left in place is worth more than a fifth task you never opened — and with only five items, one abandoned challenge is twenty percent of the paper. How to Study for the Exam covers building that rule into your practice reps rather than inventing it on the day.
There is a reason challenge one hurts more than its share, and it is not difficulty. It is that at minute one you have no calibration — you cannot yet tell whether four hours is a reasonable price for this task or a disaster, because you have nothing to compare it against. Reading all five challenges first (habit 1) is partly a fix for exactly this: it gives you a rough relative sizing before you commit, so the ceiling you set is informed rather than arbitrary.
6. Support answers during the exam — but do not plan around it
Diogo Pereira reports hitting minor technical problems at the start of his sitting and having his time extended by an hour to compensate. That is a real, citable data point about a real thing candidates worry about: whether anyone is listening if the environment misbehaves. The vendor's package advertises 24/7 learner support through Mattermost, and at least one candidate's experience is consistent with that extending to exam-time incidents.
Two cautions. First, this is one account, and one account is an existence proof, not a policy — nothing in the vendor's published pages promises time compensation, so do not build a plan whose slack depends on getting an hour back. Second, Petrosyan notes that the Mattermost channel tends to answer privately rather than in the open, which means the community channel is less useful as a searchable archive than it looks. Know how to reach support before the clock starts — Exam Day — What to Expect covers the pre-flight checks that stop most of these problems happening at all — and assume you will not need to.
What the report actually has to contain
The vendor publishes a submission window and a portal, but no rubric. Najib Radzuan's account is the closest thing in the public record to a content list, and it is worth treating as a floor rather than a ceiling. He is explicit that screenshots and scan reports are both essential to a CDP report — not one or the other.
| Element | What it looks like in practice | Captured when? |
|---|---|---|
| Step-by-step instructions | What you did, in order, precisely enough that the grader could repeat it without you. Commands with their flags, not "I scanned the repo." | During the hands-on window, at the close of each sub-task |
| The configuration files themselves | The pipeline YAML, the Ansible playbook, the policy file, the profile — the actual artefact, pasted or attached, not a paraphrase of it. | During — copy them out of the lab before it locks |
| Screenshots | The failing state and the fixed state. A gate you added should be shown blocking, because a green pipeline is not proof that a gate exists. | During — impossible to recreate afterwards |
| Machine-readable scanner output | JSON or XML from the tools, saved to files. This is the part that distinguishes "I claim it is clean" from "here is the run that says so." | During — always write to a file, never rely on scrollback |
| Reasoning | Why this control and not another; what the finding actually risked. Not in Radzuan's list explicitly, but the difference between a report that reads as understanding and one that reads as transcription. | Either — but drafting it live is cheaper than reconstructing it |
Everything in that table's right-hand column says the same thing: the report is built during the exam and merely typed up afterwards. Vulnerability management and triage and compliance as code at scale both cover producing machine-readable evidence as a matter of routine; the capstone lab track is where you practise producing it under something resembling exam conditions.
Part Three — the dissent, unsoftened
☺ Like you're 10: One of the nine people passed the test and then wrote a review saying he didn't think much of it. That review is the most useful one on this page, and we're not going to tidy it up.
Eight of the nine accounts are broadly positive. That is normal and slightly suspicious: people who pass write posts, people who fail mostly do not, and people who paid several hundred dollars have a quiet incentive to feel good about it. Mikayel Mardanyan Petrosyan passed the CDP in 2024 and then published a critical review anyway, which makes his the account with the least to gain and therefore the one worth reading most carefully. Reducing it to "one person didn't like it" would be dishonest, so here it is properly.
| His criticism | What it means for you |
|---|---|
| The usable slack is smaller than the headline. Evidence-gathering and documentation happen inside the hands-on window, not in the report window afterwards. | The single most actionable item in his review, and it survives the format change with interest. Budget documentation as exam time, not as homework. This is why habit 2 above is written as a per-sub-task ritual rather than an end-of-day sweep. |
| The content is heavily operational and light on theory. He describes it as strong on doing and thin on the reasoning underneath. | Take it as a scoping statement rather than a complaint. If you want the why — threat models, maturity models, the reasoning behind a control — you will have to get it elsewhere. That is precisely what threat modelling, the maturity models and the secure SDLC pages on this site are for. |
| Production quality is uneven. He reports frequent grammatical errors in the material and an impression of carelessness. | Cosmetic on its own, but it has a practical edge: sloppy material is harder to trust when you are trying to decide whether an instruction is wrong or you are. Verify anything surprising against the tool's own documentation rather than assuming the course is right. |
| The newer platform UI regressed. Dark mode was dropped, and copying text out of the material was blocked or unreliable. | Plan your note-taking around it. If you cannot copy from the platform, your cheatsheet has to be typed by hand — which, as habit 4 argues, is better for retention anyway but considerably slower. Budget for that when you plan your study weeks. It may also have been fixed since May 2024; check before assuming. |
| Support answers privately rather than in the open channel. | The Mattermost community is therefore not a searchable knowledge base of previously-answered questions. Do not count on finding your problem already solved there; ask directly. |
| Process friction. The report template was shared as a link that turned out to be a Word document, which he found awkward on Linux. | Trivial, and exactly the kind of trivial thing that costs an hour at the wrong moment. Open and test every template, portal and upload path before exam day, not during your 24-hour report window. |
| His verdict: an entry-level operational certification he would recommend to beginners, and he would not buy further certifications from the same vendor. | Weigh this against the eight positive accounts rather than instead of them. It is one informed opinion about value for money from someone who completed the thing — which is worth more than any number of five-star reviews from people who have not. |
A single critical review from someone who passed is worth more evidence-weight than several positive ones, and it is worth being clear about why. The positive reviews are consistent with a good product and with survivorship bias — you are only hearing from people whose experience ended well. The critical review from a passer cannot be explained away by either. He got the outcome he paid for and still had objections, which means the objections are about the thing rather than about the result.
None of that is an argument against sitting the CDP. It is an argument for going in with accurate expectations: a hands-on, operational credential that will make you demonstrably competent at running a security toolchain, that will not by itself make you a security architect, and whose material you should treat as a starting point rather than a canon. The certifications page puts it in context against the alternatives, and the CDE page covers the next rung of the same ladder if you decide to keep climbing it.
The silences — what nobody reports, and why that matters
☺ Like you're 10: Sometimes what's missing from every review tells you something. But "nobody mentioned it" is not the same as "it doesn't happen."
Four things are conspicuously absent from the entire nine-account record, and each absence needs a different response.
| The silence | How to read it |
|---|---|
| Nothing about live proctoring, webcams or ID checks. No official page this course could find specifies it, and no account mentions being watched. | The record reads more like lab access plus a submitted report than like a supervised session — but that is inference, not testimony, and this page will not turn it into a claim. The right move is to read your own booking confirmation and ask the vendor directly. Do not walk into an exam having assumed nobody is watching. |
| No first-hand account of the six-hour format exists yet. The most recent verified account predates the change. | This is the one genuinely thin patch on an otherwise thick page. Nobody has published what six hours feels like. Until somebody does, the vendor's spec plus the transferable techniques above are the entire evidence base for pacing, and your own timed rehearsals are worth more than anything you can read. |
| No published report rubric, and no account of how points are split between fixing and documenting. | Since nobody knows the split, treat both halves as fully weighted. The safest assumption is the expensive one: a perfect fix with no evidence and a beautifully-written report about a fix that did not work are both bad outcomes. |
| Almost nothing about failing. Every account in the record is by somebody who passed. | Straightforward survivorship bias, and the reason to read all nine rather than one. You are looking at nine successful strategies with no control group, so treat their advice as "things that were present in passes" rather than "things that cause passes." |
Reading first-hand accounts critically — the general skill
☺ Like you're 10: Three habits that stop a blog post from lying to you by accident.
This page is really a worked example of a skill you will need for every certification you ever sit, and for a good deal of security work besides. Three habits do most of the work.
Date everything, and check what changed since. The CDP record is not wrong because its authors were careless — it is wrong because the exam moved underneath them. An undated claim is an unusable claim. When you find a write-up, find its publication date first and ask what the vendor has changed since. On this page the dates are printed beside every author for exactly that reason.
Separate observation from inference. "My exam ran twelve hours" is an observation and almost certainly true of that sitting. "The exam runs twelve hours" is an inference from a sample of one, and it is now false. The same distinction applies to sub-task counts, tool lists and difficulty ratings: what happened to one person is evidence about one person. How to Study for the Exam makes the same point about your own practice — one clean rep is an observation, not a readiness signal.
Count independent voices, not repetitions. Three posts sharing a phrasing template are one voice with an echo, as Jaiswal, Najim and Patil demonstrate above. And a claim that appears on twenty SEO pages with no named author behind any of them has a source count of zero, however confident the twenty pages sound. That is precisely how "a 36-hour exam" is still circulating years after the format it described was retired.
Foxy: Good news. Nine write-ups, real names, real domains, five years of them. That's a proper record for once.
Timmy: And the bad news, which you're saving for second.
Foxy: Every single one says twelve hours. The vendor's own page says six.
Remy: Wait — all nine? That's not a typo, that's a format change nobody announced loudly enough.
Timmy: It's also thirty-six CPE points sitting on the page. Twelve plus twenty-four. The arithmetic of an exam that doesn't exist any more.
Recon: Drift detected between stated configuration and observed configuration. Someone changed the resource and did not update the record.
Pip: So do I carry the write-ups or not? I don't carry anything I can't vouch for.
Timmy: Carry the technique, drop the clock. "Read all five before you start" is true at any length. "Two hours per challenge" is true at exactly one length, and it isn't this one.
Ellie: One of them said the lab disappears when the clock stops. That's the one I'd shout about. You can't go back for a screenshot you didn't take.
Rocky: And one of them passed and then wrote that he wouldn't buy from them again. Keep that one in. The pass stories are easy to find; that one isn't.
Foxy: Two people also lost half their morning to challenge one. Same story, two years apart.
Remy: Under six hours, half a morning is the exam. Set the ceiling before you start or you won't set it at all.
Timmy: Then that's the page. Nine honest accounts, one stale number, and a rule for telling which sentence is which.
Once you have read the accounts themselves, come back to the practical pages. The CDP exam guide carries the vendor's current specification with the same warnings as this page; How to Study for the Exam turns the six habits above into a method; Exam Day — What to Expect takes the environment, the report portal and the pre-flight checks in detail; the baseline page closes the gap between what the vendor says it assumes and what these nine people found it actually assumes; and the challenge bank plus the capstone lab track are where you rehearse against a real clock — a real six-hour clock, which is the one thing none of the nine could tell you about.
1. How many published first-hand CDP accounts does this page draw on, and what single fact does every one of them that states it get wrong now? 2. What piece of arithmetic still visible on the vendor's own page corroborates the format change? 3. Vinit Patil spent four hours on challenge one. Why is that anecdote more alarming today than when he published it? 4. Ishaq Mohammed's warning about lab access — what is it, and what does it imply about when evidence must be captured? 5. Three of the nine accounts are described as "less independent than they look." Which three, and what should you do about it? 6. What are Tess Sluijter's three "expect" statements, and what do they tell you about how to study tools? 7. Name three of Mikayel Mardanyan Petrosyan's criticisms, and say which one changes your exam-day plan rather than your purchasing decision. 8. Nothing in the record mentions webcams or proctoring. Why is that not evidence that the exam is unproctored?
Check your answers
- Nine named accounts published between May 2020 and July 2024. Seven of them state a hands-on window and all seven say 12 hours; Practical DevSecOps' current published specification says 6 hours. (Sanjeev Jaiswal published no format figures and Tess Sluijter declined them under the NDA — which is why those two have aged best.) The 24-hour report window, by contrast, matches the vendor in every account that states one except Joshua Jebaraj's, which is the record's lone 12-hour-report outlier.
- The advertised 36 CPE points. Twelve hours of exam plus twenty-four hours of report is thirty-six — the arithmetic of the retired format, still sitting on a page that now states a six-hour window. It is corroboration, not proof, and it also dates the change to after Diogo Pereira's 1 July 2024 account.
- Because four hours was a third of the window he sat and would be two thirds of yours, leaving roughly two hours for the remaining four challenges. Ayoub Najim independently reports about three and a half hours on the same challenge. The pattern is real; the surviving slack is not.
- You lose access to the exam lab when your exam time ends — so backups, screenshots and saved scanner output have to be taken while the clock is still running. The implication is that the 24-hour report window is for assembling evidence, never for collecting it; anything you failed to capture live is unrecoverable regardless of how well you fixed the underlying problem.
- Sanjeev Jaiswal, Ayoub Najim and Vinit Patil share a near-identical prep-duration sentence template, with Jaiswal's the earliest. All three stay in the record because their other content differs and Patil's timing breakdown is clearly his own — but count the prep-duration claim once, not three times. Repetition is not corroboration.
- Expect scanners other than the ones the labs used; expect more advanced features of the ones they did; expect languages you did not practise on. Together they say: study the category — what SAST, SCA, DAST, IaC scanning and policy engines each do, and how a finding becomes a gate — rather than memorising one favourite tool's flags, so you can drive an unfamiliar member of the category from its help output.
- Any three of: documentation happens inside the hands-on window so usable slack is smaller than advertised; the content is operational and thin on theory; the material contains frequent errors; the newer UI dropped dark mode and blocked copying; support answers privately rather than in the open channel; the report template arrived as an awkward Word document. The one that changes your exam-day plan is the first — budget documentation as exam time, per sub-task. The rest inform whether and how you buy, and how you take notes.
- Because absence of mention is not evidence of absence. None of the nine set out to document proctoring arrangements, and the official pages this course could find simply do not specify it either way. Silence in a small, self-selected set of write-ups tells you nothing reliable. Read your own booking confirmation and ask the vendor — and never plan an exam on the assumption that nobody is watching.