SA-APEX · eligibility check

Find out before you pay us anything.

This is a qualification tool, not a lead-capture quiz. It can tell you that you are not the intended level, and it will. That is more useful to you than a result engineered to make you apply.
  • No email required
  • Runs in your browser
  • Nothing is submitted
  • Honest outcomes

Your answers never leave this browser. The scoring runs locally — there is no submission, no email box and no follow-up sequence. If you decide to apply, you can choose to attach the one-line summary. The answers themselves stay with you either way.

Offensive experience

How many years of authorized offensive work have you actually done?

Paid or formally authorized red-team, penetration-testing, application-security or exploit-development work. Study time does not count.

Have you owned an engagement end to end?

Scoping, safe execution, evidence collection, the report, the remediation conversation and the retest.

Have you found a vulnerability that no scanner and no CVE would have told you about?

Derived from code, architecture, state or runtime behaviour. Business logic, authorization, race, tenancy, parser, trust boundary.

Have you written exploit code yourself, from scratch?

Software engineering

In how many languages have you shipped something real?

Something someone else depended on. Not a tutorial. Count across scripting, systems and application development.

Can you trace untrusted input through unfamiliar code to a trust boundary without running it?

Infrastructure you can build

Could you build the estate you attack — cloud, virtualisation, routing, VPN, firewall, directory, endpoints?

The exam has you build it, then attack somebody else’s. This question is the single biggest predictor of how the exam goes.

BGP and OSPF — configured, or read about?

Could you stand up a working VoIP platform — signalling, media, trunking, provisioning?

Voice is required. It is not waived by any prior credential.

Managed Apple and Android devices — enrollment, policy, the lot?

AI engineering

Have you built something on top of a model beyond a chat wrapper?

Typed tools, scoped agents, retrieval with provenance, policy enforcement, evaluation sets.

On client work, how do you currently keep client data out of public models?

There is no wrong answer here that ends your application. There is one that ends the exam.

When a model tells you something is exploitable, what happens next?

0 of 13 answered