The exam environment is artificial (predictable vulnerability patterns) - It does not test web application security in depth (limited to basic web exploits) - The Active Directory component, while improved, does not cover advanced AD attacks - Report writing is graded but the standards are lower tha