C)PEH logo
Focused certification exam prep
Start practice

C)PEH Exam Domains 2026: Complete Guide to All 11 Content Areas

TL;DR
  • The 11 C)PEH content areas are Mile2 curriculum headings (Modules 00-10), not officially weighted exam domains.
  • The written exam is 100 multiple-choice questions, roughly two hours, with a 70% minimum passing grade.
  • No official percentage per area is published, so no single area can be called the heaviest.
  • C)PEH is Mile2's credential, distinct from EC-Council CEH, GAQM CPEH-001, and Mile2 C)PTE.

What the 11 Content Areas Actually Are

Search for "C)PEH exam domains" and you will find confident lists with percentages attached. Be skeptical. The Certified Professional Ethical Hacker credential is governed and administered by Mile2, and its public outline, a seven-page PDF linked from Mile2's C)PEH course outline page, organizes the material as a cover module plus ten substantive modules. That gives eleven headings: Module 00 (Course Introduction) and Modules 01 through 10.

Those eleven headings are preparation-curriculum headings. They are not eleven officially weighted exam domains, and they are not an exhaustive exam blueprint. Mile2 has not published a percentage allocation for them, and no current exam-version identifier was verified in the sources behind this guide. So any claim that "Web Attacks is 25% of the test" or that a specific area is the highest-weighted one is unsupported, and this guide does not make it.

What you can do with an unweighted outline is still valuable: it tells you the full territory a candidate is expected to be fluent in, in the order Mile2 teaches it. For the broader prep picture, pair this guide with our C)PEH study guide.

Confirming You Are Studying the Right Credential

The acronym is shared by several unrelated credentials, and mixing them up is the most expensive mistake a candidate can make. Everything in this article refers to Mile2's Certified Professional Ethical Hacker. It is not EC-Council's CEH, not the GAQM CPEH-001 exam, and not Mile2's own C)PTE or C)PTE-A penetration testing certifications.

CredentialRelationship to this guide
Mile2 C)PEH (Certified Professional Ethical Hacker)The subject of this article
EC-Council CEHDifferent issuer and curriculum; do not apply its domains or fees here
GAQM CPEH-001Different issuer; not covered by this guide
Mile2 C)PTE / C)PTE-ASeparate Mile2 certifications; the A-suffixed variant has distinct policy treatment

If a practice question references an issuer, exam code, or module list that does not match the eleven headings below, you are probably looking at a different credential's material. Older reseller pages sometimes list a 16-module version of the course; this guide intentionally sticks to the currently linked outline. For a plain-language primer on the name itself, see what C)PEH stands for and what C)PEH certification is.

The Exam Format Behind the Curriculum

The credential PDF describes a written exam of 100 multiple-choice questions, approximately two hours, with a minimum passing grade of 70%. It is delivered online through Mile2's learning-management system, and Mile2's general exam-security page identifies the platform as LearnDash and describes a two-hour timed window that cannot be paused. The split between scored and unscored questions is not published.

Two clarifications matter for how you read the curriculum:

  • No separate hands-on exam was verified. The course includes 16 substantive labs plus setup, but those belong to training. The credential specification does not describe a practical performance exam.
  • The five-day course and 40 course CEUs describe training, not testing. They are not extra exam domains or additional exam time.

Because the exam is multiple-choice, labs are best understood as a way to make concepts stick rather than as something you will be asked to perform. For a deeper look at what 70% means in practice, see the C)PEH passing score guide.

Modules 00-03: Orientation and Foundations

Domain 1: Course Introduction (Module 00)

Module 00 is orientation: what the course covers, how the lab environment is set up, and what is expected of you. It is the thinnest area technically, but it frames the course around authorized, professional testing.

  • Know the course scope and lab setup expectations
  • Understand that the course is built around authorized security work

Domain 2: Introduction to Ethical Hacking

This area establishes what ethical hacking is, how it differs from malicious intrusion, and the vocabulary used across the rest of the curriculum.

  • Distinguish authorized testing from criminal intrusion by scope, permission, and intent
  • Recognize the phases of a typical engagement and how they map to later modules
  • Be comfortable with terms such as vulnerability, threat, exploit, and risk

Domain 3: Cybersecurity Foundation

Foundation material is where the "12 months of IT or networking experience" suggestion earns its keep. Mile2 suggests any one of its C)SP certification, 12 months of IT experience, or 12 months of networking experience. These are suggestions, not a verified mandatory gate; our C)PEH requirements guide covers this in detail.

  • Networking fundamentals: addressing, common protocols, and how traffic flows
  • Core security principles: confidentiality, integrity, availability, and defense in depth
  • Basic operating system and service concepts that later attacks depend on

Candidates who skip this area because it feels basic often lose points later. Reconnaissance output, scan results, and exploit descriptions all assume you can read a network diagram and recognize what a port or service implies.

Modules 04-05: Reconnaissance, Enumeration and Cryptography

Domain 4: Reconnaissance & Enumeration

Reconnaissance is information gathering; enumeration is the more active step of extracting specifics such as hosts, services, accounts, and shares. The conceptual line matters on a multiple-choice exam: passive recon avoids touching the target, while enumeration generally involves direct interaction.

  • Differentiate passive and active information gathering, and know why each carries different detection risk
  • Understand what enumeration is meant to reveal and how it feeds vulnerability analysis
  • Be able to reason from an output snippet to what it tells an attacker

A useful way to think about it: reconnaissance answers "what is out there?" and enumeration answers "what exactly is running, and who can talk to it?" Questions often present a scenario and ask which step of that progression you are in.

Domain 5: Cryptography

Cryptography is the area where memorizing definitions without understanding purpose backfires. Expect to match a tool to a goal.

  • Symmetric versus asymmetric encryption: shared-key speed versus key-pair convenience
  • Hashing as integrity checking, and why it is not encryption
  • Digital signatures, certificates, and the role of trust in public key infrastructure
  • How weak algorithms, poor key management, and misconfiguration undermine otherwise sound designs
Why the pairing makes sense: Recon and enumeration tell you what a target exposes; cryptography tells you what protects it and where that protection can fail. Many exam scenarios chain the two, such as identifying a service during enumeration and then reasoning about whether its encryption is adequate.

Modules 06-07: Vulnerabilities and Web/Application Attacks

Domain 6: Vulnerability Scanning & Analysis

Scanning finds candidate weaknesses; analysis decides which ones matter. The skill being tested is prioritization, not tool operation.

  • Know what a vulnerability scanner can and cannot tell you, including false positives and false negatives
  • Prioritize by exploitability, exposure, and business impact rather than by raw severity score alone
  • Understand how scan findings become inputs to exploitation planning and to the final report

A scanner reporting "critical" on an internal, non-routable test server and "medium" on an internet-facing authentication portal is a good example of why analysis exists. Expect questions that make you choose what to fix or test first.

Domain 7: Web and Application Attacks

This area connects to widely used reference frameworks such as OWASP, CWE, and API security topics. Concepts matter more than payload syntax on a multiple-choice exam.

  • Injection-style flaws: untrusted input interpreted as commands or queries
  • Broken authentication and session handling, and broken access control
  • Cross-site scripting and request forgery at a conceptual level: who is being tricked, and by what
  • API-specific weaknesses, including excessive data exposure and weak authorization
  • Using CWE-style weakness categories to name the root cause rather than only the symptom

The recurring theme: nearly every web flaw is a failure to treat user-controlled data as untrusted, or a failure to enforce who is allowed to do what. If you can classify a scenario along those two lines, you can usually eliminate half the answer choices.

Modules 08-10: Exploitation, Social Engineering and Wireless

Domain 8: Exploitation and Post-Exploitation

Exploitation is gaining a foothold; post-exploitation is what you do with it. On the exam this is mostly about sequence and purpose.

  • How an exploit turns a vulnerability into access, and what limits its success
  • Privilege escalation, persistence, and lateral movement as post-exploitation goals
  • Why authorized testers document and clean up rather than leave artifacts behind

Domain 9: Social Engineering

Social engineering targets people instead of systems, and it is a conceptual area where understanding psychology beats memorizing lists.

  • Common pretexts and channels, such as phishing, impersonation, and physical tailgating
  • The levers attackers pull: authority, urgency, familiarity, and helpfulness
  • Defenses that actually work: verification procedures, awareness training, and reporting culture

Domain 10: Wireless Pentesting

Mile2's cover page spells this "Wireless Pentesting," while the detailed section prints "Wireless Pen testing"; both refer to the same module.

  • Wireless security protocol generations and why older ones are weak
  • Typical wireless attack categories, such as rogue access points and credential capture
  • Why wireless testing needs especially tight authorization, since signals do not stop at property lines

Reporting and Ethics

Domain 11: Reporting & Ethics

The final area is where the credential's name earns its meaning. Technical skill without disciplined reporting and ethical conduct is not professional ethical hacking.

  • Structure of a useful report: scope, method, findings, evidence, risk rating, and remediation guidance
  • Writing for two audiences: executives who need business impact and engineers who need reproduction steps
  • Staying within authorized scope, handling discovered data responsibly, and disclosing findings properly
  • Why ethics is not a footnote: Mile2 also ties renewal to a Code of Ethics acknowledgment
Test-day pattern: When two answer choices are both technically plausible, the one that respects authorization, scope, and responsible handling of data is usually the intended answer. Treat ethics as a tie-breaker across the whole exam, not only this area.

Sequencing the Areas Across Your Prep

Since no area is officially weighted, spread effort by dependency rather than by guessed percentage. One suggested order, assuming four weeks:

Week 1

Foundations first

  • Modules 00-03: terminology, networking, security principles
  • Fill any networking gaps now; later areas depend on them
Week 2

Discovery and protection

  • Modules 04-06: reconnaissance, enumeration, cryptography, vulnerability analysis
  • Practice reading scan and enumeration output
Week 3

Attack paths

  • Modules 07-10: web and application attacks, exploitation, social engineering, wireless
  • Classify each flaw by root cause
Week 4

Reporting and review

  • Module 11-style reporting and ethics review, then timed practice
  • Revisit weak areas using our practice tests

For the full approach, see the C)PEH study guide, and for a quick refresher near test day use the C)PEH cheat sheet. If you are wondering how demanding the material is overall, read how hard the C)PEH exam is.

Policy Details to Verify Before You Book

Several delivery and renewal details are described inconsistently across Mile2's own documents, so confirm them directly rather than relying on forum posts or third-party summaries.

  • Proctoring and open-book rules. Mile2's FAQ says most standard exams can start on demand without a live-proctor appointment, while its broader May 2026 Policies and Procedures describes open-book delivery with live camera and screen proctoring scheduled at least 48 hours ahead. How this applies to the standard C)PEH product is not reconciled, so do not assume either arrangement or an unrestricted resource policy without booking confirmation.
  • Price. The official public search index shows the C)PEH Exam Combo at $500 sale versus $795 list, including an exam, simulator, preparation guide, and two attempts. Checkout amounts were not visible in the retrieved product pages, so confirm the live price. The separate $400 electronic book kit is study material, not the exam fee. See the C)PEH certification cost breakdown.
  • Retakes. After both included attempts, a further attempt requires another retail purchase, and the general policy describes a 30-day wait before a third attempt.
  • Validity and renewal. The credential is valid for three years. Central renewal guidance describes 60 documented CEUs over the cycle, a renewal product purchase, and seven Code of Ethics questions, with exam-based alternatives also published. The course PDF and May 2026 policy word the options differently, so confirm your route and deadline before expiry rather than assuming a universal grace period.

Mile2 expressly permits testing without purchasing its course, but that is a decision about training, not about content. If you self-study, the eleven areas above are your map. Training providers also vary in pricing, and their fees are not Mile2's exam fee. For questions about outcomes, note that no official pass rate was verified; read what the pass-rate data shows before trusting any figure you see advertised.

Frequently Asked Questions

Are the 11 areas official, weighted exam domains?

No. They are the headings of Mile2's published C)PEH preparation curriculum (Modules 00-10). Mile2 has not published percentage weights, so no area can be identified as the most heavily tested.

How many questions are on the C)PEH exam, and what score passes?

The credential PDF describes 100 multiple-choice questions in approximately two hours, with a minimum passing grade of 70%. The scored versus unscored split is not published.

Does C)PEH include a hands-on practical exam?

No separate performance exam was verified in the specification. The course includes labs for training, but the credential exam is the written multiple-choice assessment.

Is C)PEH the same as CEH or the GAQM CPEH-001?

No. Mile2's Certified Professional Ethical Hacker is a separate credential from EC-Council's CEH and from GAQM's CPEH-001, and also differs from Mile2's C)PTE. Do not mix their domains, fees, or policies.

Can I take the exam without buying the Mile2 course?

Yes. Mile2 expressly permits testing without purchasing its course. Suggested preparation is any one of C)SP, 12 months of IT experience, or 12 months of networking experience, but these are suggestions rather than a verified mandatory gate. See the requirements guide and exam scheduling overview for more.

Ready to pass your C)PEH exam?

Put this into practice with free C)PEH questions across every exam domain.