C)PEH logo
Focused certification exam prep
Start practice

C)PEH Certification

TL;DR
  • C)PEH is Mile2's Certified Professional Ethical Hacker credential, valid for three years, and unrelated to GAQM CPEH-001 or EC-Council CEH.
  • The written exam is 100 multiple-choice questions in roughly two hours, with a 70% minimum passing grade.
  • The eleven curriculum headings (Module 00 plus Modules 01-10) are unweighted preparation topics, not official exam domains with percentages.
  • The Exam Combo shows a $500 sale price against $795 list; confirm the live checkout amount before buying.

What the C)PEH Certification Actually Is

The C)PEH credential, short for Certified Professional Ethical Hacker, is issued and administered by Mile2. It is a vendor-specific penetration-testing-foundations certification: it validates that a candidate understands how attackers think and operate, and how to apply that knowledge in authorized, documented security assessments. If you want a plain-language definition first, see What Is C)PEH Certification? and What Does C)PEH Stand For?.

The source for the scope described in this article is Mile2's undated seven-page "CPEH Web Outline" PDF, currently linked from the official C)PEH course outline page. That document lists a Course Introduction plus ten substantive modules, a five-day training format, 40 course CEUs, and 16 substantive labs with setup. Those training details describe the course. They do not describe the exam's length, and they do not add extra exam sections.

Training versus testing: The five-day course, the 40 CEUs and the 16 labs belong to the optional training package. The exam itself is a separate written assessment. Mile2 expressly allows candidates to test without purchasing its course, so hands-on lab hours are a preparation choice rather than an exam gate.

Credentials You Should Not Confuse It With

The acronym circulates widely, and several unrelated credentials use similar letters. This page covers only Mile2's C)PEH. It is not GAQM's CPEH-001, not EC-Council's CEH, and not Mile2's own C)PTE or C)PTE-A, which are separate certifications with their own outlines. Mixing up sources is the fastest way to study the wrong material or budget for the wrong fee.

CredentialIssuerRelationship to C)PEH
C)PEHMile2The subject of this article
C)PTE / C)PTE-AMile2Different Mile2 penetration-testing certifications; not interchangeable with C)PEH
CEHEC-CouncilDifferent issuer, different exam; do not reuse its fees or domain lists
CPEH-001GAQMDifferent issuer and exam code; not covered here

Older reseller and academy pages sometimes show 16-module lists. Those legacy lists are not the currently linked outline and are not used here. When comparing study resources, check that the module titles match the eleven headings later in this article. For help with name confusion, the C)PEH Meaning article covers it directly.

Exam Format and Delivery: What Is Confirmed

The credential PDF specifies a written exam of 100 multiple-choice questions, approximately two hours, with a minimum passing grade of 70%. It is delivered online through Mile2's learning-management system. Mile2's Course and Exam Security page identifies LearnDash as the platform and describes a two-hour timed window that cannot be paused, so plan to sit the exam in one uninterrupted block. Mile2 does not publish how many items are scored versus unscored. For a deeper look at the cut score, read C)PEH Passing Score 2026.

There is no verified separate hands-on performance exam in this C)PEH specification. You will not be asked to compromise a live range as part of the credential exam, although the training labs build exactly the skills that make multiple-choice scenarios easier to reason through.

The proctoring and open-book question

This is the area where Mile2's published sources do not fully agree, and an honest guide should say so rather than guess:

  • The Frequently Asked Questions page says most standard exams can start on demand without a live-proctor appointment, and names C)ISSO-A and C)PTE-A as exceptions.
  • The Policies and Procedures document (dated May 26, 2026) describes LearnDash delivery, an open-book exam, live camera and screen proctoring scheduled at least 48 hours ahead, randomized items, the ability to return to skipped questions, and immediate results.
  • Within that same policy, Section G says some exams require a proctor while Section M describes proctored administration more generally. How this applies to the standard C)PEH product is not reconciled.
Do not assume either way: Do not promise yourself an unproctored session, a live-proctored session, or unrestricted use of notes and references. Confirm the delivery mode, any scheduling lead time, and the permitted-resources rule at the moment you book. The general policy also covers identification requirements, accommodations, and a 30-day wait before a third attempt. No C)PEH-specific adaptive-testing or calculator rule was verified.

Because open-book conditions, if they apply, never substitute for understanding, prepare as though you will be working from memory. Our difficulty guide explains why scenario-style questions punish shallow recall even when references are available.

The Eleven Curriculum Headings, Explained

The outline presents eleven headings: Module 00 (Course Introduction) and Modules 01 through 10. Treat them as an unweighted preparation curriculum. No official percentage allocation was verified, so no heading can be called the heaviest or the most tested. For a section-by-section companion, see C)PEH Exam Domains 2026: Complete Guide to All 11 Content Areas.

Course Introduction and Introduction to Ethical Hacking

Orientation, then the professional frame for everything else: what an ethical hacker is permitted to do and why authorization defines the line between assessment and attack.

  • Written scope and rules of engagement as the legal basis for testing
  • Phases of an engagement from planning through reporting
  • The difference between a vulnerability assessment and a penetration test

Cybersecurity Foundation

The shared vocabulary and network fundamentals that later modules assume you already own.

  • Confidentiality, integrity and availability, and how attacks map to each
  • Core protocols, ports and how traffic flows between hosts
  • Defensive controls you will be probing, such as firewalls and segmentation

Reconnaissance & Enumeration

Gathering information before touching a target, then actively extracting detail from discovered services.

  • Passive versus active information gathering, and why the distinction matters legally and operationally
  • Enumerating hosts, services, banners and user or share information
  • Turning raw findings into a prioritized target list

Cryptography

Not an exercise in math, but in recognizing where cryptographic choices fail in practice.

  • Symmetric versus asymmetric schemes and what each is used for
  • Hashing, integrity checks and why weak or unsalted hashes are exploitable
  • Certificates, key management and common implementation mistakes

Vulnerability Scanning & Analysis

Running scanners is easy; interpreting them is the skill. Expect questions about judgment rather than tool syntax.

  • Distinguishing true positives from false positives
  • Prioritizing findings by exploitability, exposure and business impact
  • Using standardized weakness and vulnerability references to describe issues consistently

Web and Application Attacks

The attack surface where most modern engagements land, including API-related weaknesses.

  • Injection, broken authentication and session-handling flaws
  • OWASP-style risk categories and CWE-style weakness classification
  • API-specific issues such as excessive data exposure and broken access control

Exploitation and Post-Exploitation

What happens after a weakness is confirmed, always within the authorized scope.

  • Matching an exploit to a verified vulnerability rather than firing blindly
  • Privilege escalation, lateral movement and persistence concepts
  • Cleanup, evidence handling and avoiding collateral damage on production systems

Social Engineering

The human layer of the attack surface.

  • Phishing, pretexting and physical-access techniques
  • Why authorization and client approval are even more critical when people are the target
  • Defensive awareness measures an assessor can recommend

Wireless Pentesting

The outline's cover spells this "Wireless Pentesting," while its detailed section prints "Wireless Pen testing"; both refer to the same module.

  • Wireless standards, encryption modes and their known weaknesses
  • Rogue access points and evil-twin scenarios
  • Safe, scoped testing so neighboring networks are never affected

Reporting & Ethics

The deliverable is the product. A clear report and a defensible ethical stance are what clients actually pay for.

  • Writing findings with evidence, risk rating and actionable remediation
  • Separating executive-level summary from technical detail
  • Confidentiality, disclosure and handling sensitive data discovered during testing

Pricing and Purchase Mechanics

Cost is where candidates most often conflate products, so it is worth separating them carefully. For the full breakdown, see C)PEH Certification Cost 2026: Complete Pricing Breakdown. The essentials from Mile2's public listings:

ItemWhat it isPrice signal
C)PEH Exam ComboExam, simulator/practice resource, preparation guide, and two attempts$500 sale versus $795 original list in Mile2's public search index
C)PEH Electronic Book KitPreparation material only; not the exam feeIndexed at $400; checkout amount not independently confirmed
Full course packagesTraining with labsPriced separately; not the same as the Exam Combo
Third-party training providersAuthorized classes and bundlesTheir prices are not Mile2's exam fee
Confirm before you pay: The retrieved dynamic product pages did not expose a price in their body text, so the $500 and $795 figures come from the official public search index. Check the live checkout amount. No member versus nonmember pricing tier is published. If you use both included attempts, the FAQ states that further attempts require another retail purchase.

Note the term limits too: Ultimate Combo course access and its included exam voucher are generally valid for one year, which is distinct from the three-year life of the credential. Cyber Range access may carry a shorter separate term. Plan your study calendar so the voucher does not lapse before you sit the exam.

Preparation Suggestions and Requirements

Mile2 suggests that candidates hold any one of the following: the Mile2 C)SP credential, 12 months of IT experience, or 12 months of networking experience. These are suggestions, not a verified mandatory degree, reference, training-hour or experience gate. In practice, that means a motivated newcomer can attempt the exam, but the curriculum clearly assumes comfort with networking basics. A fuller discussion lives in C)PEH Requirements 2026: Eligibility, Prerequisites & How to Qualify.

When you are ready to test your recall under realistic conditions, our C)PEH practice tests are built around the eleven headings above. A note of caution applies to any third-party question bank: such banks are not authenticated real exam content, and a vendor's pass "guarantee" is a marketing statement, not a credential pass rate. Mile2 does not publish a pass rate that we could verify; the C)PEH pass rate article explains how to treat the numbers you will see online.

Validity and Renewal Rules

The credential is valid for three years, with no annual membership requirement. Current central renewal guidance describes the CEU route like this:

  1. Document 60 qualifying CEUs during the three-year cycle, commonly expressed as 20 per year.
  2. Purchase the applicable renewal product.
  3. Answer seven Code of Ethics questions and agree to current policies.

The current FAQ gives a U.S. standard CEU-route renewal price of $200, with eligible developing-region pricing potentially as low as $100, subject to checkout or issuer confirmation. Exam-based renewal, including passing the latest relevant exam, is published as an alternative path and may cost more. CEU evidence requirements are on Mile2's qualifying-CEUs page.

Known source conflicts: The C)PEH course PDF describes both a current-exam pass and annual CEUs as requirements, while the central renewal pages present them as alternative paths. The May 2026 policy also mentions a recertification assessment and completion within seven days of expiry; Section I says that after that period the full certification exam is required without CEUs, while Section M uses permissive wording. An unspecified recertification assessment is not the same thing as the full 100-question exam or the seven-question ethics acknowledgment. Confirm your applicable route and deadline well before expiry, and do not rely on a universal seven-day grace period.

Also note that Mile2's policy specifically identifies C)ISSO-A and C)PTE-A as ANAB-accredited offerings. It does not establish that accreditation for the standard C)PEH, so avoid claiming it in a resume or proposal without confirmation.

Careers, Salary Claims and Reading Them Honestly

The outline advertises an annual salary potential of $80,077. Treat that carefully: the document is undated, and it provides no credential-holder sample or methodology. It is issuer marketing, not a verified 2026 average for C)PEH holders and not evidence that the certification causes a pay premium. Real compensation depends on location, seniority, prior experience and the role. Our C)PEH Salary Guide and ROI analysis walk through how to weigh a certification cost against realistic outcomes.

The credential maps most naturally to entry and intermediate offensive-security and assessment roles: junior penetration tester, vulnerability analyst, security analyst with testing duties, and red-team support. It also helps IT and network staff demonstrate attacker-side awareness. Browse role ideas in C)PEH Jobs, and see C)PEH Training for provider options. Authorized training providers appearing in search results include Mile2 itself, OpenExamPrep, Hudson, Compendium CE and Fast Lane; their course prices are their own and are not Mile2's exam fee.

C)PEH versus the credentials people compare it to

Comparisons with CEH are common but should be made carefully, since the issuers, exam structures and fee schedules differ. Likewise, C)PEH and C)PTE are distinct Mile2 products with different outlines. Choose based on the outline you can verify, the employer language in the postings you are targeting, and your budget, not on a generic ranking. The C)PEH Certification overview and the main practice test site are good starting points for assessing fit.

Sequencing Your Preparation Around the Curriculum

Because the headings are unweighted, spread effort by dependency rather than by guessed exam emphasis. Foundations feed reconnaissance; reconnaissance feeds scanning; scanning feeds exploitation. Reporting and ethics should be touched early and revisited, since every other module ends in a documented finding. For the broader method, see the C)PEH Study Guide and the C)PEH Cheat Sheet.

Week 1

Frame and foundations

  • Introduction to Ethical Hacking and Cybersecurity Foundation
  • Memorize the engagement phases and the role of written authorization
Week 2

Find and enumerate

  • Reconnaissance & Enumeration, then Vulnerability Scanning & Analysis
  • Practice ranking findings by exploitability and impact
Week 3

Attack surfaces

  • Cryptography, Web and Application Attacks, Wireless Pentesting
  • Map each weakness to a category and a remediation
Week 4

Exploit, communicate, simulate

  • Exploitation and Post-Exploitation, Social Engineering, Reporting & Ethics
  • Take timed 100-question practice sets within a two-hour window

Key Takeaway

Rehearse the exam's real conditions: 100 questions, about two hours, no pausing, and a 70% target. Treat scenario questions as small engagement decisions and ask what is authorized, what is verified, and what should be reported. For timing guidance, check C)PEH Exam Dates 2026 and confirm how your session will be delivered.

Frequently Asked Questions

Who issues the C)PEH certification?

Mile2 governs and administers it. It is distinct from GAQM CPEH-001, EC-Council CEH, and Mile2's C)PTE and C)PTE-A credentials, so make sure any study material or price you rely on refers to Mile2's Certified Professional Ethical Hacker.

How many questions are on the exam and what score do I need?

The credential PDF specifies 100 multiple-choice questions in approximately two hours, with a minimum passing grade of 70%. Mile2 does not publish the scored versus unscored split, and the two-hour window cannot be paused.

Is the C)PEH exam open book or proctored?

Mile2's sources are not fully reconciled. The FAQ says most standard exams start on demand without a live-proctor appointment, while the May 2026 policy describes open-book, live-proctored delivery scheduled 48 hours ahead. Confirm the current rule when you book rather than assuming either.

Do I have to buy the Mile2 course to take the exam?

No. Mile2 expressly permits testing without purchasing its course. The Exam Combo (shown at $500 sale against $795 list, subject to live checkout confirmation) includes an exam, simulator, preparation guide and two attempts, but it is not the full training package.

How long does the certification last and how do I renew?

It is valid for three years. The CEU route involves 60 documented qualifying CEUs, a renewal purchase and seven Code of Ethics questions; exam-based alternatives also exist. Sources differ on some details, so confirm your route and deadline with Mile2 before expiry.

Ready to pass your C)PEH exam?

Put this into practice with free C)PEH questions across every exam domain.