C)PEH logo
Focused certification exam prep
Start practice

C)PEH Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • C)PEH here means Mile2's Certified Professional Ethical Hacker, not GAQM CPEH-001, EC-Council CEH, or C)PTE.
  • The written exam is 100 multiple-choice questions, about two hours, with a 70% minimum passing grade.
  • The 11 outline headings are unweighted curriculum headings, not official exam domains with published percentages.
  • Confirm live checkout price, proctoring method, and renewal route before paying or booking; sources conflict.

Identity Check: Which C)PEH This Sheet Covers

Several credentials share similar acronyms, and mixing them up is the most common way candidates waste prep time. This cheat sheet covers one credential: the Certified Professional Ethical Hacker, designation C)PEH, governed and administered by Mile2. It is not GAQM's CPEH-001, it is not EC-Council's CEH, and it is not Mile2's own C)PTE or C)PTE-A, which are separate credentials with separate objectives.

If you landed here searching for a practice question dump from another vendor's exam, stop and verify the certifying body first. For background on the name itself, see our explainers on what C)PEH certification is and what C)PEH stands for.

Scope note: Everything below is anchored to Mile2's currently linked seven-page CPEH Web Outline (an undated PDF) and Mile2's public policy pages. Older reseller lists describing 16 modules are a different packaging of the material and are deliberately not mixed in here.

The Exam in One Glance

ItemWhat the sources support
Certifying bodyMile2
Questions100 multiple-choice
TimeApproximately two hours; the general exam-security page describes a timed window that cannot be paused
Passing gradeMinimum 70%
DeliveryOnline through Mile2's learning-management system (LearnDash)
Hands-on practical examNone verified in this C)PEH specification
Scored vs. unscored splitNot published
Credential validityThree years

Two clarifications save confusion. First, the five-day course, the 40 course CEUs, and the 16 substantive labs describe the training, not extra exam components. Second, the outline names no exam-version identifier and no percentage allocation, so any site claiming a "most heavily weighted domain" is inventing it. For deeper analysis of the score line, read our C)PEH passing score guide, and for realistic expectations on difficulty, see how hard the C)PEH exam is.

The 11 Curriculum Headings, Decoded

The outline preserves Module 00 (Course Introduction) plus ten substantive modules. Treat them as eleven study headings of unknown relative weight. Prepare all of them; do not skip any based on a rumor about emphasis.

#HeadingOne-line job description
1Course IntroductionOrientation to the program and its objectives
2Introduction to Ethical HackingWhat authorized testing is and why scope matters
3Cybersecurity FoundationCore concepts every later heading assumes
4Reconnaissance & EnumerationDiscovering what exists before touching it
5CryptographyProtecting data and recognizing weak implementations
6Vulnerability Scanning & AnalysisFinding, validating, and prioritizing weaknesses
7Web and Application AttacksWeb, API, and application-layer flaws
8Exploitation and Post-ExploitationGaining access, then showing impact
9Social EngineeringAttacking people and process, not code
10Wireless PentestingAssessing wireless networks (printed "Wireless Pen testing" in the detailed section)
11Reporting & EthicsTurning findings into deliverables, within professional limits

Our complete guide to all 11 content areas expands each row.

Technical Core: What You Must Be Able to Explain

A multiple-choice exam rewards candidates who can explain why a technique is chosen, not just name it. Use the blocks below as a self-quiz: if you cannot explain a line in your own words, that is your study gap.

Reconnaissance & Enumeration

The central distinction is passive versus active. Passive reconnaissance gathers information without sending traffic to the target; active reconnaissance interacts with target systems and can be logged or detected.

  • Know why recon precedes any scanning: you are narrowing the attack surface and validating scope.
  • Understand enumeration as moving from "this host exists" to "this service, version, and account list exists."
  • Be able to say which activities require explicit written authorization because they touch the target directly.

Cryptography

Expect conceptual questions rather than math. Know the roles, not the algorithms' internals.

  • Symmetric versus asymmetric: speed and key distribution trade-offs, and why real protocols combine both.
  • Hashing versus encryption: hashes are one-way integrity tools; encryption is reversible with a key.
  • Digital signatures and certificates: what they prove (integrity, origin) and what they do not (confidentiality).
  • Why weak or outdated implementations, not just weak algorithms, create exploitable gaps.

Vulnerability Scanning & Analysis

A scanner output is a lead list, not a verdict. The exam-relevant skill is judgment.

  • False positives versus false negatives, and why validation matters before reporting.
  • Prioritization: severity, exploitability, exposure, and asset value together, rather than a raw score alone.
  • Credentialed versus uncredentialed scanning and what each can and cannot see.

Web and Application Attacks

Know the vulnerability classes and the vocabulary used to catalog them, including OWASP categories, CWE-style weakness naming, and API-specific risks.

  • Injection, broken authentication, broken access control, and misconfiguration as recurring themes.
  • Why APIs deserve separate thought: object-level authorization failures and excessive data exposure are not the same as page-rendering bugs.
  • Root cause versus symptom: input handling and trust boundaries underlie most entries.

Exploitation and Post-Exploitation

Exploitation is one step, not the goal. Post-exploitation demonstrates business impact and then stops where the rules of engagement say to stop.

  • Privilege escalation, lateral movement, and persistence as concepts, with the ethical constraint on each.
  • Why cleanup and documentation of every action are part of professional practice.

Social Engineering, Wireless, and Reporting & Ethics

  • Social engineering: pretexting, phishing, and physical approaches work by exploiting trust and urgency; defenses are training and verification procedures.
  • Wireless: know encryption/authentication generations and why weak configurations, rogue access points, and captured handshakes matter.
  • Reporting & ethics: authorization, scope, confidentiality of findings, responsible disclosure, and writing for two audiences: executives and technical remediators.
Authorized lab work only: Practice every offensive technique inside an isolated lab you own or a platform that explicitly permits it. The exam tests professional judgment, and "was this authorized?" is a recurring theme across the whole outline.

Fees, Bundles, and Attempts

Pricing language on the web is messy, so separate the products:

  • C)PEH Exam Combo: the public search index shows $500 sale against a $795 original list price. The retrieved dynamic product page did not expose the figure in its body, so confirm the live checkout amount before purchasing.
  • What the Combo includes: an exam, a simulator/practice resource, a preparation guide, and two attempts. It is not the full training course.
  • C)PEH Electronic Book Kit: separately indexed at $400. That is preparation material, not the examination fee, and its live price was not independently confirmed either.
  • Retakes: the FAQ states that two additional attempts require another retail purchase once both included attempts are used. The general policy also describes a 30-day wait before a third attempt.
  • Tiers: no member/nonmember pricing is published.

Training-provider course prices (resellers and authorized academies) are a different cost from Mile2's exam fee. Do not add or compare them as though they were the same line item. Our C)PEH certification cost breakdown lays out how to total the real spend.

Prerequisites are suggestions: Mile2 suggests any one of its C)SP credential, 12 months of IT experience, or 12 months of networking experience. These are not a verified mandatory gate, and Mile2 expressly permits testing without purchasing its course. Details are in our C)PEH requirements guide.

Proctoring and Open-Book: What Is Not Settled

This is the single most important "verify before you book" item, because Mile2's own documents do not reconcile cleanly:

  • The FAQ says most standard exams can start on demand without a live-proctor appointment, naming C)ISSO-A and C)PTE-A as exceptions.
  • The May 26, 2026 Policies and Procedures describes LearnDash delivery, an open-book exam, live camera/screen proctoring scheduled at least 48 hours ahead, randomized items, the ability to return to skipped questions, and immediate results.
  • Within that policy document, one section says some exams require a proctor while another describes proctored administration generally. How it applies to the standard C)PEH product is not stated.

So do not assume either "unproctored" or "live-proctored," and do not assume an unrestricted open-book resource policy. Get written confirmation of your specific booking, including identification requirements and any accommodations process. If you want a rehearsal under realistic time pressure, run timed sessions on our practice test platform so the two-hour clock feels familiar regardless of delivery mode. For scheduling questions, see C)PEH exam dates and scheduling.

Validity and Renewal Cheat Lines

TopicCurrent guidance
ValidityThree years (distinct from the roughly one-year course/voucher access window in Ultimate Combo products)
CEU route60 documented qualifying CEUs over the cycle, commonly expressed as 20 per year
Also requiredPurchase of the applicable renewal product, seven Code of Ethics questions, agreement to current policies
Renewal priceFAQ gives a U.S. standard CEU-route price of $200; eligible developing regions may be as low as $100; confirm at checkout
Exam routePublished as an alternative (passing the latest relevant exam); may cost more
Annual membershipNone required

Treat these as open questions to resolve with Mile2 before your expiry date:

  • The C)PEH course PDF describes both a current-exam pass and annual CEUs as requirements, while central renewal pages present them as alternative paths.
  • The May 2026 policy mentions a recertification assessment and a seven-day completion window after expiry, then says the full certification exam is required without CEUs after that period, while another section uses permissive wording.
  • An unspecified "recertification assessment" should not be equated with either the full 100-question exam or the seven-question ethics acknowledgment.

Do not assume a universal seven-day grace entitlement, and do not assume you would need both a full retake and 60 CEUs. Confirm the applicable route and deadline well ahead of expiry.

Salary and Job Claims, Handled Honestly

The outline advertises $80,077 annual salary potential. That figure is issuer marketing: it carries no dated credential-holder sample, no methodology, and no evidence of a causal premium from holding the certification. It is not a verified 2026 C)PEH salary average, so do not quote it as one. The credential's value is more reliably argued through the skills it demonstrates and the roles those skills map to, such as junior penetration testing, vulnerability assessment, and security analysis support.

Anecdotes on forums and Reddit threads about the exam are useful color but are not official policy evidence, and third-party "success guarantees" are not a credential pass rate. Mile2 does not publish a verified pass rate that we could confirm, so see our pass rate analysis for how to interpret the claims you encounter. For the earnings and value discussion, continue to the salary guide and the worth-it ROI analysis.

Key Takeaway

Accreditation language also needs care: Mile2's policy specifically identifies C)ISSO-A and C)PTE-A as ANAB-accredited offerings. It does not establish that accreditation for the standard C)PEH, so avoid repeating it in your resume or marketing copy.

Sequencing the Headings Across Four Weeks

One short, C)PEH-specific plan. The order follows how the outline builds on itself: concepts first, then discovery, then attack chains, then the human and reporting layers. Adjust the pace to your background, and use our full C)PEH study guide for the detailed method.

Week 1

Foundations

  • Course Introduction, Introduction to Ethical Hacking, Cybersecurity Foundation.
  • Front-load vocabulary and the authorization/scope mindset, since every later heading assumes both.
Week 2

Discovery and Protection

  • Reconnaissance & Enumeration, Cryptography, Vulnerability Scanning & Analysis.
  • Pair scanning with prioritization practice so you learn to judge, not just list.
Week 3

Attack Chains

  • Web and Application Attacks, then Exploitation and Post-Exploitation.
  • Do the hands-on lab repetitions here, in an authorized lab only.
Week 4

People, Wireless, Reporting, Review

  • Social Engineering, Wireless Pentesting, Reporting & Ethics.
  • Finish with timed 100-question sets and review every miss by heading.

Be cautious with third-party question banks: they are not authenticated real exam content, so use them to find weak headings rather than to predict questions. Our C)PEH practice tests are built the same way, as a diagnostic aid for the published curriculum.

Quick-Fire FAQ

Is C)PEH the same as CEH?

No. C)PEH is Mile2's Certified Professional Ethical Hacker. CEH is EC-Council's separate credential, and GAQM's CPEH-001 is also a different exam. Verify the certifying body before buying any prep product.

How many questions and what score do I need?

The written exam has 100 multiple-choice questions in roughly two hours, with a 70% minimum passing grade. The scored/unscored split is not published.

Is there a hands-on practical component?

No separate hands-on performance exam was verified in the C)PEH specification. The 16 labs belong to the training course, not the exam.

Which domain is weighted highest?

That cannot be stated. The 11 outline headings are unweighted curriculum headings, and no official percentage allocation was verified. Prepare every heading.

Do I have to buy the Mile2 course to sit the exam?

No. Mile2 expressly permits testing without purchasing its course, and its suggested preparation (C)SP, or 12 months of IT or networking experience) is a recommendation rather than a verified mandatory gate.

Keep this sheet as a verification checklist: identify the right credential, confirm the live price and delivery method, study all 11 headings, and settle your renewal route before the three-year clock runs out. For the jobs side of the picture, see C)PEH jobs.

Ready to pass your C)PEH exam?

Put this into practice with free C)PEH questions across every exam domain.