Case No. 053 2026.08.22 Cyber Certificateใบเซอร์ 5 minutes views

KLCP Certification Review and Guideline

Kali Linux Certified Professional

Certificate
KLCP Certification Review and Guideline

Present a certificate : Link

ทักทายกันหน่อย

สวัสดีครับทุกคน บล็อกนี้ผมจะมารีวิว KLCP หรือ Kali Linux Certified Professional ของค่าย OffSec ครับ ตัวนี้จะแปลกกว่าเซอร์ตัวอื่นๆ ที่ผมเคยรีวิวไปนิดนึง เพราะมันไม่ใช่ข้อสอบลงมือเจาะระบบเหมือน eJPT หรือ OSCP แต่เป็นเซอร์ที่วัดความเข้าใจตัว Kali Linux ซึ่งเป็นดิสโทรที่พวกเราสายเจาะระบบใช้เป็นเครื่องมือคู่ใจกันอยู่แล้วนั่นเองครับ

KLCP exam result · 71/80 (88.8%) · PASSED

KLCP คืออะไร

KLCP เป็นใบเซอร์อย่างเป็นทางการตัวแรกของ Kali Linux ครับ ออกโดย OffSec (เจ้าเดียวกับที่ทำ OSCP) จุดประสงค์ของมันคือวัดว่าเราเข้าใจตัวระบบปฏิบัติการ Kali จริงๆ ไม่ใช่แค่เปิดเครื่องมาเรียกใช้ tool เป็นอย่างเดียว แต่รวมไปถึงเรื่องการตั้งค่า การปรับแต่ง การจัดการแพ็กเกจแบบ Debian การ build ISO เอง ไปจนถึงการดูแล Kali หลายเครื่องในระดับองค์กรครับ

เนื้อหาทั้งหมดอ้างอิงจากหนังสือ Kali Linux Revealed หรือคอร์ส PEN-103 ซึ่งข้อดีสุดๆ คือ ฟรีทั้งหนังสือและคอร์สเลยครับ แค่สมัครบัญชี OffSec ก็เข้าไปเรียนได้ มีเนื้อหารวมกันกว่า 181 ชั่วโมง

รายละเอียดคอร์ส PEN-103 : Link บทความแนะนำ KLCP จากทาง Kali : Link

TIP

ทาง Kali เคยบอกไว้ว่าคนที่เข้าคอร์ส PWK (ทางไป OSCP) โดยคุ้นเคยกับ Kali และ Linux มาก่อน มักจะทำได้ดีกว่าในสนามจริง ดังนั้น KLCP เลยเหมาะมากกับคนที่เพิ่งเริ่มสาย Cyber แล้วอยากปูพื้นให้แน่นก่อนไปต่อครับ

รูปแบบการสอบ

ข้อสอบ KLCP จะต่างกับ eJPT หรือ OSCP ที่เป็นแนวลงมือเจาะจริงเลยครับ ตัวนี้เป็นข้อสอบปรนัยล้วนๆ สรุปสั้นๆ ได้ประมาณนี้

  • เป็นข้อสอบแบบ Multiple Choice จำนวน 80 ข้อ
  • เวลาสอบ 90 นาที
  • มีผู้คุมสอบ (proctor) ตลอดการสอบ
  • ห้ามเปิดหนังสือหรือเปิดเน็ตหาคำตอบ (closed-book)
  • ส่งข้อสอบเสร็จรู้ผลทันที
  • ที่ผมชอบสุด คือ ใบเซอร์ตัวนี้ไม่มีวันหมดอายุ ต่างจาก eJPT ที่มีอายุ 3 ปี

รายละเอียดการสอบ (KLCP Exam Guide) : Link

กว่าจะได้สอบ proctor เข้มเอาเรื่อง

มาถึงพาร์ทที่ผมอยากเล่ามากที่สุดครับ 555 คือเรื่องความเข้มของ proctor

เพราะเป็นข้อสอบแบบมีคนคุม ก่อนเริ่มสอบเลยต้องยืนยันตัวตน แล้วเปิดกล้องส่องรอบห้องให้ดูก่อนว่าไม่มีอะไรผิดปกติ กติกาคือ

  • บนโต๊ะห้ามมีอุปกรณ์อิเล็กทรอนิกส์อื่นเลย เหลือได้แค่เครื่องที่ใช้สอบเครื่องเดียว
  • ห้ามมีจอต่อพ่วงเพิ่ม ถ้ามีจอไหนต่ออยู่ ต้องแชร์ให้ proctor เห็นทุกจอ
  • ระหว่างสอบต้องเห็นหน้าเราตลอด ลุกไปไหนไม่ได้

ที่ตลกคือ ตอนเปิดกล้องส่องห้อง ผมมีทีวีวางไว้ด้านหลัง proctor เห็นปุ๊บก็บอกเลยว่าให้ยกทีวีออกไปจากห้องด้วยครับ เพราะกติกาคือในกล้องห้ามมีจอภาพใดๆ โผล่มาให้เห็นเลย ถึงมันจะเป็นทีวีที่วางไว้เฉยๆ และผมไม่ได้แตะมันเลยตลอดการสอบก็ตาม สุดท้ายผมเลยต้องยกทีวีออกไปไว้นอกห้องกันจริงๆ 555 เข้มขนาดนั้นเลยครับ

NOTE

พอมองย้อนกลับไปก็เข้าใจได้นะครับว่าทำไมเขาถึงเข้มขนาดนี้ เพราะจอทุกจอมันเอาไปเปิดสูตรได้หมด การที่เขายอมให้เรามีจอได้แค่จอเดียวคือจอสอบ ก็ตัดโอกาสโกงไปได้จริงๆ แต่ตอนแบกทีวีออกนี่ก็ขำตัวเองอยู่เหมือนกัน

เตรียมตัวยังไงดี

Guideline ของผมง่ายๆ เลยครับ อ่าน Kali Linux Revealed ให้จบ เพราะข้อสอบออกจากในนี้เกือบทั้งหมด แล้วมันก็ฟรีด้วย ไม่มีเหตุผลที่จะไม่อ่าน ผมขอแยกหัวข้อที่ควรเก็บให้แน่นเป็นกลุ่มๆ ตามที่เจอมา จะได้เห็นภาพว่าต้องโฟกัสตรงไหนบ้าง

  • พื้นฐาน Linux และการใช้งานทั่วไป เรื่องสิทธิ์ไฟล์ การจัดการ user และ group รวมถึงการเพิ่ม user เข้ากลุ่ม sudo, โครงสร้าง directory ตามมาตรฐาน FHS, การหา help ด้วย man และ apropos และการจัดการ process กับงานเบื้องหลัง
  • การจัดการแพ็กเกจแบบ Debian ตัว dpkg ทั้งการดูไฟล์ในแพ็กเกจ หาว่าไฟล์มาจากแพ็กเกจไหน และติดตั้งไฟล์ .deb, การใช้ apt กับ sources.list, การสร้างแพ็กเกจเองด้วย dpkg-buildpackage แก้ changelog ด้วย dch และพวก maintainer script, การเปิดใช้หลาย architecture และการทำ repository เองด้วย reprepro
  • systemd และการจัดการ service การใช้ systemctl สั่ง start stop และดูสถานะ, การดู log ด้วย journalctl, ตำแหน่งของไฟล์ service และเครื่องมือตรวจ log
  • Storage และการเข้ารหัส เรื่อง LUKS กับ cryptsetup, การ mount partition และการดูดิสก์กับ USB ที่ต่ออยู่
  • เครือข่ายและ firewall iptables โดยเฉพาะความต่างระหว่าง ACCEPT, DROP และ REJECT, การจัดการฐานข้อมูล PostgreSQL และเครื่องมือกัน brute-force อย่าง fail2ban
  • เรื่องเฉพาะของ Kali พวก metapackage อย่าง kali-tools-wireless กับ kali-tools-forensics, desktop เริ่มต้นอย่าง Xfce, custom kernel ที่รองรับ wireless injection, การติดตั้งอัตโนมัติด้วย preseed และการตรวจ checksum ของ ISO
  • ระดับองค์กร การดูแล Kali หลายเครื่องด้วย SaltStack ทั้งฝั่ง master และ minion และการ build kernel เอง
  • แนวคิดความปลอดภัยพื้นฐาน ประเภทของช่องโหว่และการโจมตี เช่น DoS, file inclusion, SQL injection, การประเมินความเสี่ยงจาก likelihood กับ impact และประเภทของการทำ pentest
TIP

ถ้าใครใช้ Kali เป็นเครื่องหลักอยู่แล้วแบบผม เนื้อหาหลายส่วนจะคุ้นมากจนอ่านผ่านๆ ได้เลย ส่วนที่ผมว่าคนมักไม่ค่อยได้จับจริงจังคือเรื่องการทำแพ็กเกจเองกับการ build ISO ครับ ตรงนั้นแหละที่ควรลงมือทำตามหนังสือดูสักรอบ

สรุป

โดยรวมผมว่า KLCP เป็นเซอร์ที่คุ้มค่ามากสำหรับคนเริ่มต้นครับ ของฟรีทั้งหนังสือทั้งคอร์ส เสียแค่ค่าสอบ ได้ใบเซอร์ที่ไม่มีวันหมดอายุ แล้วยังได้ปูพื้น Kali กับ Linux ให้แน่นก่อนไปลุยเซอร์สายเจาะระบบตัวอื่นต่อ

ถ้าถามว่าจำเป็นสำหรับคนที่อยู่ในสายมานานแล้วไหม อาจจะไม่ถึงกับต้องมี แต่ถ้าอยากได้อะไรมายืนยันว่าเราเข้าใจเครื่องมือที่ใช้อยู่ทุกวันจริงๆ ตัวนี้ก็ตอบโจทย์ดีครับ

จบแล้วครับสำหรับรีวิว KLCP หวังว่าจะเป็นประโยชน์กับคนที่กำลังสนใจเซอร์ตัวนี้อยู่ ขอบคุณที่อ่านจนจบครับ :)

A quick hello

Hi everyone. In this blog I am reviewing KLCP, the Kali Linux Certified Professional from OffSec. This one is a little different from the other certs I have reviewed, because it is not a hands-on hacking exam like eJPT or OSCP. Instead it measures how well you understand Kali Linux itself, the distribution the rest of us in offensive security keep on our desk as a daily driver.

KLCP exam result · 71/80 (88.8%) · PASSED

What is KLCP

KLCP is the first official certification for Kali Linux. It is issued by OffSec (the same people behind OSCP), and the goal is to confirm that you really understand the Kali operating system, not just that you can open it and run a tool. That means configuration and customisation, Debian-style package management, building your own ISO, all the way up to running multiple Kali machines at enterprise scale.

Everything is drawn from the Kali Linux Revealed book, also known as the PEN-103 course, and the best part is that both the book and the course are completely free. Sign up for an OffSec account and you can start learning, with more than 181 hours of material.

PEN-103 course details : Link Kali’s own KLCP announcement : Link

TIP

Kali has said that people who enter the PWK program (the road to OSCP) already comfortable with Kali and Linux tend to do better in the real exam. So KLCP is a great fit for anyone new to Cyber who wants a solid foundation before moving on.

The exam format

KLCP is nothing like the hands-on eJPT or OSCP exams. This one is pure multiple choice. Here is the short version.

  • 80 multiple-choice questions
  • 90 minutes
  • Proctored the whole way through
  • Closed-book, no opening notes or the internet to look up answers
  • Instant result once you submit
  • My favourite part: the certification never expires, unlike eJPT which is valid for 3 years

KLCP Exam Guide : Link

Getting to the exam, where the proctor got serious

This is the part I most wanted to tell you about. The proctoring was strict.

Because it is a proctored exam, before you start you have to verify your identity and then turn the camera around to show the whole room so they can confirm nothing is out of place. The rules were:

  • No other electronic devices on the desk at all, only the machine you are taking the exam on
  • No extra connected monitors, and if any display is plugged in you have to share every single one with the proctor
  • Your face has to stay visible the entire time, no getting up and walking off

The funny part: during the room scan I had a TV sitting behind me. The moment the proctor saw it, they told me to carry the TV out of the room, because the rule is that no screen of any kind may appear in the camera, even a TV just sitting there that I would never touch during the exam. So I actually ended up hauling it out of the room. That strict.

NOTE

Looking back it makes sense why they are this careful, since any screen could be used to pull up cheat notes. Letting you keep exactly one display, the exam machine, really does close the door on cheating. But carrying that TV out still makes me laugh at myself.

How to prepare

My guideline is simple: read Kali Linux Revealed cover to cover, because almost every question comes straight out of it, and it is free anyway, so there is no reason not to. Here are the areas I would group and nail down, so you know where to focus:

  • Linux basics and general usage file permissions, managing users and groups including adding a user to the sudo group, the FHS directory layout, finding help with man and apropos, and handling processes and background jobs
  • Debian package management dpkg for listing a package’s files, finding which package owns a file, and installing .deb files; apt and sources.list; building your own packages with dpkg-buildpackage, editing the changelog with dch, and the maintainer scripts; enabling extra architectures and hosting your own repository with reprepro
  • systemd and services managing services with systemctl (start, stop, status), reading logs with journalctl, where service files live, and log-checking tools
  • Storage and encryption LUKS and cryptsetup, mounting partitions, and inspecting disks and USB devices
  • Networking and firewall iptables, especially the difference between ACCEPT, DROP, and REJECT, managing PostgreSQL, and brute-force defences like fail2ban
  • Kali specifics the metapackages such as kali-tools-wireless and kali-tools-forensics, the default Xfce desktop, the custom kernel with wireless-injection support, unattended installs with preseed, and verifying the ISO checksum
  • Enterprise scale managing many Kali machines with SaltStack (master and minion) and building your own kernel
  • Security fundamentals classes of vulnerability and attack such as DoS, file inclusion, and SQL injection, risk assessment from likelihood and impact, and the types of penetration test
TIP

If Kali is already your daily driver like it is for me, a lot of this will feel familiar enough to skim. The parts most people rarely touch seriously are building your own packages and building an ISO, so those are the ones worth actually doing along with the book at least once.

Wrapping up

Overall I think KLCP is well worth it for beginners. The book and the course are free, you only pay for the exam, you get a certification that never expires, and you come away with a solid Kali and Linux foundation before diving into the more offensive certs.

Is it a must for people who have been in the field for a while? Maybe not strictly. But if you want something that confirms you truly understand the tool you use every single day, this one does the job nicely.

That is the KLCP review. I hope it helps anyone looking at this cert. Thanks for reading.

⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣤⣤⣤⣤⣤⣤⣤⣤⣀⣀
⠀⠀⠀⠀⠀⠀⠀⢀⣤⣶⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣶⣤⡀
⠀⠀⠀⠀⠀⣠⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣄
⠀⠀⠀⢠⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠟⠛⠻⣿⣿⣿⣿⣿⣿⣿⣷⣄
⠀⠀⣰⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⢸⣿⣿⣿⣿⣿⣿⣿⡿⠂
⠀⣸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⣤⣴⣿⣿⣿⣿⣿⡿⠛⠁
⢰⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠛⠁
⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠋⠀⢀⣀
⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠟⠋⠁⠀⠀⠀⣴⣿⣿⣿⣦
⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣦⣀⠀⠀⠀⠀⢿⣿⣿⣿⡟⠀Ar3mus @ KLCP Certification Review and Guideline
⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣦⣄⠀⠉⠉⠁
⠸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⣄⡀
⠀⢻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣶⣄⡀
⠀⠀⠻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⡄
⠀⠀⠀⠙⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠋
⠀⠀⠀⠀⠀⠛⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠋⠁
⠀⠀⠀⠀⠀⠀⠀⠉⠻⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠛⠉
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠉⠙⠛⠛⠻⠿⠿⠟⠛⠛⠋⠉
KLCP Certification Review and Guideline
https://ar3mus.pages.dev/posts/certificate/3/
Author
Ar3mus
Published at
2026-08-22

Related Cases

2026.04.15 Road to OSCP · Review and Exam Tips Cyber Certificateใบเซอร์ 2026.04.12 CPTS Certification Review and Guideline Cyber Certificateใบเซอร์ 2024.11.11 eJPT Certification Review and Guideline Cyber Certificateใบเซอร์
L's ThemeHideki Taniuchi