I just happened to be doing this today myself, here's what I'm putting together (based on recommendations from the book "Hacking with Kali" which is free if you have an ACM membership).
Practice tools/lab environments:
1. https://github.com/SpiderLabs/MCIR
2. https://www.offensive-security.com/metasploit-unleashed/Requ...
3. http://sourceforge.net/projects/mutillidae/
Install that stuff in a VM:
* https://www.virtualbox.org/wiki/Downloads
Metasploitable2 is a pre-packaged pentesting environment with plenty of vulnerabilities. You could run a CTF by just picking out things from the exploitability guide that comes with it (read down the page a bit) and defining victory conditions based on that.