PortSwigger Burp Suite Certified Practitioner (BSCP) Exam Review
A fast-paced, highly practical exam where the technical difficulty is entirely manageable, but the clock is relentless. The technical challenge sits at a comfortable 5/10, but the intense time pressure easily bumps the experience up to a solid 7/10.
Here is the breakdown of surviving the clock, avoiding catastrophic rabbit holes, and clearing it smoothly on the next run.
The Experience
- The Ultimate Foe is Time: Four hours fly by incredibly quickly. Failing a first attempt frequently comes down to running out of time on the second application due to a single deep rabbit hole.
- The Second Attempt Blueprint: Once you dial in your time management and methodology, the exam changes completely. It’s entirely possible to breeze through both applications within 2.5 hours, leaving plenty of buffer time.
- Proctoring Caution: The exam requires a proctoring session. While some suggest it is only needed for the initial identity verification, I err-ed on the side of caution and kept the proctoring session active for the entire duration of the exam.
Essential Resources
Preparation relies heavily on PortSwigger’s free web security academy labs, but these two community repositories are goldmines for structured preparation and quick reference during the test:
Use the checklists within these repos to target the most relevant labs, map out your weaknesses, and build your cheat sheets.
Survival Tips & Strategy
Weaponise Your Notes (The Ultimate Time Saver)
- You cannot afford to write payloads by hand during the exam.
- Build highly organized, easy-to-read notes before jumping in.
- Ensure you have ready-to-go payloads for every vulnerability class that you can rapidly copy, paste, and modify to fit the target environment.
- Having this data instantly accessible is the single biggest factor in seamlessly coasting through the stages without burning the clock.
Ditch the Blanket Scanning
- Avoid mindless automated target scanning. Instead, manually map the application to understand its core business logic.
- Pay close attention to subtle functionalities. Treat it like a live, breathing environment: Who else is using this app? What administrative actions might trigger an interaction? How can you abuse multi-user features?
Enforce Hard Timers on Rabbit Holes
1
If you are prone to tunnel vision, strict timeboxes are non-negotiable. With sound methodology and solid notes, each stage should take no more than 30 minutes. If you find yourself staring at the same endpoint for more than 20 minutes without progress, step back, drop it, and pivot to a completely different vector.
Focus on One App at a Time
1
Do not ping-pong between the two applications. Alternating between them fragments your mental context and leads to disaster. It is incredibly easy to lose track of what functionality belongs to which target, causing you to waste hours trying to force an exploit on an application that doesn't even support the vulnerable feature. Finish one completely, or explicitly context-switch only when completely stuck.
Administrative Housekeeping
- Do the Prep Work: The free PortSwigger Mystery Labs and Practice Exams are non-negotiable. Re-run the recommended labs until the exploitation paths become muscle memory.
- Save Your Project Files: Make absolutely certain you are actively saving your Burp Suite project files throughout the exam. PortSwigger may request these files post-exam for verification or review.
Final Verdict
The BSCP is a rewarding sprint that heavily penalises hesitation but deeply rewards a structured approach and strong fundamentals. Do the labs, structure your payloads beforehand, manage your clock aggressively, and enjoy the hunt.
Good luck!