All the resources and information you need to complete the exam are in the modules of the CWES path itself. The tricky part in the exam comes when you have to chain multiple vulnerabilities together.
Do all the skills assessments at the end of the modules, together at once, after completing the path.
One preparation method I discovered was to get the user flag on HTB machines, because many of them have web apps with varied vulnerabilities for initial access. That’ll help you identify and enumerate an unknown vuln without the handheld guidance of the module labs, where you know what the vulnerability is. There is even a CWES track on HTB dedicated to this: CWES HTB track
During the exam, make sure to keep a notes section (I used Obsidian), separate from your report section, to record which methods you have already tried and what their results were. This will save you from wasting time on exhausted attack vectors, and might also help during report writing.
If you found an exploitable path or vulnerability, be sure to take note of the payloads used and concerned endpoints.
Screenshots are a must during the exam itself; don’t leave them for the last. Most importantly, label each of them properly. This will help you greatly during report writing.
For report writing, I used Sysreptor with the available CWES template. It is very easy to fill in once you have the hang of it.
And don’t forget to take breaks during the exam, especially when you’re stuck somewhere. Most of the time you’ll come back with a clear head and cross that blockade.
All the best to anyone taking the exam in the future!