C)PEH logo
Focused certification exam prep
Start practice

C)PEH Study Guide 2026: How to Pass on Your First Attempt

TL;DR
  • C)PEH is Mile2's Certified Professional Ethical Hacker credential, not GAQM's CPEH-001 or EC-Council's CEH.
  • The written exam is 100 multiple-choice questions, roughly two hours, with a 70% minimum passing grade.
  • The 11 curriculum headings are unweighted, so spread preparation evenly instead of chasing a "highest-weighted" domain.
  • Mile2 permits testing without buying its course, but confirm proctoring and open-book rules at booking.

Confirm Which C)PEH You Are Studying For

The acronym causes real confusion. This guide covers the Certified Professional Ethical Hacker credential administered by Mile2, with the official designation C)PEH. It is not GAQM's CPEH-001, it is not EC-Council's CEH, and it is not Mile2's own C)PTE or C)PTE-A, which are separate penetration-testing credentials. If you pull a study resource that lists a different certifying body, different fees, or a different module count, set it aside. Candidates routinely waste weeks on material written for the wrong exam.

If you are still deciding whether this is the right credential at all, see our explainers on what C)PEH certification is and what C)PEH stands for. For a side-by-side view of how it relates to the other certifications people mention in the same breath, the difficulty guide frames what this particular exam actually asks of you.

Watch for legacy module lists: Older reseller and academy pages describe a 16-module version of the course. The currently linked Mile2 outline is a seven-page PDF organized as a course introduction plus ten substantive modules. Build your plan from the current outline, and treat older lists as background only.

Exam Mechanics and Registration You Need Before You Study

Knowing the format shapes how you prepare. Here is what the issuer's materials support:

ItemWhat is supported
Question count100 multiple-choice questions
TimeApproximately two hours; the general exam-security page describes a timed window that cannot be paused
Passing gradeMinimum 70%
DeliveryOnline through Mile2's learning-management system (LearnDash)
Hands-on componentNo separate performance exam verified in the C)PEH specification
Scored/unscored splitNot published
ValidityThree years

At 70% on 100 questions, you need roughly 70 correct answers. That is a meaningful margin for error but not a forgiving one, since the curriculum spans everything from cryptography to wireless attacks. For a deeper look at the threshold, read our C)PEH passing score breakdown.

Prerequisites are suggestions, not gates

Mile2 suggests that candidates have any one of the following: the Mile2 C)SP credential, 12 months of IT experience, or 12 months of networking experience. These are recommendations, not a verified mandatory degree, training-hour, or reference requirement. Mile2 also expressly permits testing without purchasing its course. Our requirements guide covers how to assess your own readiness against that suggested baseline.

Pricing: separate the exam from the training

The cost picture is easy to misread, so keep these three items distinct:

  • Exam Combo: Mile2's public search index shows $500 on sale against a $795 original list price. It includes an exam, a simulator/practice resource, a preparation guide, and two attempts. It is not the full training package. The live product page did not expose the price in retrieved text, so confirm the checkout amount before buying.
  • Electronic Book Kit: Indexed at $400. This is preparation material, not an exam fee, and its checkout amount was also unconfirmed.
  • Third-party training: Authorized providers sell instructor-led courses at their own prices. Those are tuition, not the issuer's examination fee.

Once both included attempts are used, the FAQ states that further attempts require another retail purchase. The general policy also describes a 30-day wait before a third attempt. We itemize all of this in the C)PEH certification cost guide.

Proctoring and open-book: confirm before you book. Mile2's FAQ says most standard exams can start on demand without a live-proctor appointment, while the broader May 2026 Policies and Procedures describe an open-book exam with live camera and screen proctoring scheduled at least 48 hours ahead. These sources are not reconciled for the standard C)PEH product. Do not assume either arrangement, and do not assume you may bring unrestricted outside resources. Get written confirmation of your delivery format at booking, and check identification and accommodation rules at the same time.

Scheduling questions are covered in more detail in our exam dates and scheduling guide.

Mapping the 11 Curriculum Headings

The current outline lists a Course Introduction (Module 00) followed by ten substantive modules. These are preparation-curriculum headings. Mile2 has not published percentage weights or confirmed that they function as 11 official exam domains, so any claim that one area is "most heavily tested" is unsupported. The sound response is balanced coverage with extra time on your weakest areas. Our complete domains guide goes deeper on each heading.

Course Introduction and Introduction to Ethical Hacking

Orientation plus the conceptual framing of the discipline.

  • What distinguishes authorized testing from unauthorized intrusion
  • Typical phases of an engagement, from scoping to reporting
  • Terminology you will see throughout the rest of the material

Cybersecurity Foundation

The baseline knowledge everything else builds on.

  • Networking fundamentals and common protocols
  • Core security principles and threat concepts
  • How attackers and defenders reason about the same systems

Reconnaissance & Enumeration

Gathering information about a target, then extracting structured detail from discovered services.

  • Passive versus active information gathering
  • Service and host discovery, and what each result implies
  • Turning raw enumeration output into a list of testable hypotheses

Cryptography

How data is protected, and how protection fails.

  • Symmetric versus asymmetric approaches and when each is used
  • Hashing, integrity, and the idea of digital signatures
  • Common implementation and key-management weaknesses

Vulnerability Scanning & Analysis

Finding weaknesses systematically and judging which ones matter.

  • What scanners detect well and where they mislead
  • Validating findings instead of trusting raw output
  • Prioritizing by exploitability and business impact

Web and Application Attacks

Attacks against web applications and their supporting interfaces.

  • Input-handling flaws and authentication/session weaknesses
  • Familiarity with OWASP, CWE, and API-related topics
  • How a weakness class maps to a realistic attack path

Exploitation and Post-Exploitation

Gaining access, then understanding what access means.

  • The logic of choosing an exploit path, not just running tools
  • Privilege escalation and movement after initial access
  • Staying within scope while demonstrating impact

Social Engineering

Attacking people and process rather than software.

  • Common pretexts and psychological levers
  • Why technical controls alone do not close this gap
  • Defensive awareness and policy countermeasures

Wireless Pentesting

Assessing wireless networks and their protections. (The cover of the outline spells it "Wireless Pentesting"; the detailed section prints "Wireless Pen testing.")

  • Wireless security protocols and their known weaknesses
  • How wireless attack scenarios differ from wired ones
  • Authorization boundaries specific to radio-based testing

Reporting & Ethics

Communicating findings and conducting yourself professionally.

  • Structuring findings so a non-technical reader can act on them
  • Rules of engagement, authorization, and disclosure
  • Why the ethics material is a core professional expectation, not filler

Topics That Deserve Original Understanding

Because the exam is multiple-choice, it is tempting to memorize. The better investment is understanding why things work, because scenario-style wording rewards reasoning over recall. Four areas repay that effort.

Reconnaissance as a decision process

Treat recon as a funnel. Passive collection (public records, DNS, search results) leaves little trace on the target; active probing is more informative but more detectable. A common test pattern is to describe a goal and ask which technique fits, so learn the trade-off each technique makes between stealth and detail. Enumeration then converts "a port is open" into "this service, this version, these likely weaknesses."

Cryptography: know the failure modes

Rather than memorizing algorithm names in isolation, organize them by purpose: confidentiality, integrity, authentication, non-repudiation. Then ask how each fails in practice: weak or reused keys, poor randomness, outdated algorithms, misconfigured certificates. Questions often hinge on picking the control that matches the stated need.

Vulnerability prioritization

A scanner reports hundreds of findings; a tester decides which three matter. Practice reasoning about severity as a combination of how easy a flaw is to exploit, what an attacker gains, and what the asset is worth. A "medium" finding on an internet-facing system holding sensitive data can outrank a "high" finding on an isolated test box. Expect to justify an ordering, not just define a term.

Web, OWASP, CWE, and API weaknesses

Learn the difference between a weakness class (the CWE-style idea, such as improper input validation) and a risk category (the OWASP-style grouping). Pair each class with a plain-language description of the attack, the symptom a tester would observe, and the standard mitigation. Include API-specific issues such as broken object-level authorization and excessive data exposure, since modern applications expose functionality through interfaces rather than pages.

Key Takeaway

For every attack technique you study, write one sentence each for: how it works, how you would detect it, and how you would prevent it. That three-part habit matches how both exam scenarios and real reports are framed.

Labs, Practice Questions, and What They Can't Do

The course lists 16 substantive labs plus setup. That describes the training, not the exam: the verified C)PEH specification has no separate hands-on performance test. Still, lab time is valuable because it makes abstract concepts concrete. Do any practical work only in environments you own or have explicit written permission to test. Authorized lab work is the habit the Reporting & Ethics material is trying to instill.

On practice questions, be realistic. Third-party question banks are not authenticated real exam content, and no vendor's "success guarantee" is a credential pass rate. Use practice questions to find weak domains and to rehearse pacing (about 72 seconds per question across 100 items in two hours), not to hunt for memorizable answers. You can try our C)PEH practice tests for domain-organized drills and explanations. If you are curious about what the data does and doesn't show on outcomes, read our pass rate analysis; Mile2 has not published an official pass rate.

A Domain-Ordered Study Schedule

Since the headings are unweighted, order them by dependency: later topics assume earlier ones. This sample runs eight weeks; compress or stretch it to fit your experience.

Week 1

Foundations

  • Course Introduction, Introduction to Ethical Hacking, Cybersecurity Foundation
  • Shore up networking basics if you lack the suggested 12 months of experience
Weeks 2-3

Reconnaissance & Enumeration, then Cryptography

  • Build the passive-versus-active decision framework
  • Organize cryptography by purpose and failure mode
Weeks 4-5

Vulnerability Analysis and Web/Application Attacks

  • Practice prioritizing findings
  • Map OWASP/CWE/API weakness classes to attack, detection, and fix
Week 6

Exploitation, Post-Exploitation, Social Engineering

  • Focus on reasoning about attack paths and scope
  • Cover pretexting and defensive countermeasures
Week 7

Wireless Pentesting and Reporting & Ethics

  • Review wireless protocol weaknesses
  • Draft a mock finding written for a non-technical reader
Week 8

Timed Review

  • Sit full 100-question timed sets and re-study your weakest headings
  • Confirm delivery, proctoring, and ID requirements for exam day

A one-page recap is useful in the final days; see our C)PEH cheat sheet for a condensed review.

After You Pass: Validity, Renewal, and Career Context

Renewal: sources disagree, so verify

The credential is valid for three years. Current central renewal guidance describes 60 documented qualifying CEUs over the cycle (commonly expressed as 20 per year), purchase of the applicable renewal product, and seven Code of Ethics questions with agreement to current policies. The FAQ gives a U.S. standard CEU-route price of $200, with eligible developing-region pricing potentially lower; confirm at checkout. There is no annual membership requirement, and Mile2 also publishes exam-based alternatives.

However, the C)PEH course PDF describes both passing the current exam and annual CEUs as requirements, while the central renewal pages present alternative paths. The May 2026 policy adds a recertification assessment and a seven-day window after expiry, with ambiguous wording about the full exam. Do not equate that recertification assessment with either the full 100-question exam or the seven-question ethics acknowledgment. Confirm your applicable route and deadline well before expiry.

Career context and salary caution

Roles that value this credential generally sit in penetration testing, security assessment, and defensive-security teams; see our overview of C)PEH jobs. On pay, the issuer's outline advertises $80,077 in annual salary potential, but it is undated and lacks a methodology or credential-holder sample. Treat it as marketing, not a verified 2026 average or proof that the certification causes a premium. Our salary guide and the ROI analysis weigh these limits in more detail.

Also note that the general policy identifies C)ISSO-A and C)PTE-A as ANAB-accredited offerings; it does not establish that accreditation for standard C)PEH, so avoid claiming it.

Frequently Asked Questions

How many questions are on the C)PEH exam and what score do I need?

The written exam has 100 multiple-choice questions in approximately two hours, with a minimum 70% passing grade. The scored versus unscored split is not published.

Do I have to buy Mile2's course to take the exam?

No. Mile2 expressly permits testing without purchasing its course. The Exam Combo includes an exam, simulator/practice resource, preparation guide, and two attempts, but not the full training package.

Is the C)PEH the same as CEH or GAQM's CPEH-001?

No. C)PEH is Mile2's Certified Professional Ethical Hacker. It is distinct from EC-Council's CEH, GAQM's CPEH-001, and Mile2's own C)PTE and C)PTE-A.

Which domain carries the most weight?

None can be identified. The 11 headings are unweighted curriculum headings, and no official percentage allocation has been verified. Study all of them, prioritizing your weakest.

Is the exam proctored and open-book?

Sources conflict. The FAQ suggests on-demand starts without a live-proctor appointment, while the broader policy describes open-book delivery with scheduled live proctoring. Confirm the format for your C)PEH booking before exam day.

Ready to pass your C)PEH exam?

Put this into practice with free C)PEH questions across every exam domain.