C)PEH logo
Focused certification exam prep
Start practice

C)PEH Training

TL;DR
  • C)PEH means Certified Professional Ethical Hacker from Mile2, not GAQM CPEH-001, EC-Council CEH, or Mile2 C)PTE.
  • The curriculum runs Module 00 (Course Introduction) plus ten substantive modules, from Introduction to Ethical Hacking through Reporting & Ethics.
  • The written exam is 100 multiple-choice questions in roughly two hours, with a 70% minimum passing grade.
  • Mile2 permits testing without buying its course, so training is a choice rather than a gate.

What "C)PEH Training" Actually Covers

When people search for C)PEH training, they usually mean one of three different things: a structured course that walks through the ethical hacking curriculum, a set of self-study materials such as an e-book and practice resources, or a combination of both aimed at passing the written exam. Those are not interchangeable, and the difference affects both your budget and your schedule.

The Certified Professional Ethical Hacker credential is governed and administered by Mile2, and its official designation is C)PEH. The training associated with it is a curriculum on penetration-testing fundamentals delivered as a five-day course with 16 substantive labs plus lab setup, and 40 course CEUs. Importantly, those numbers describe training. They do not describe how long the exam lasts or add extra exam domains. Keeping that distinction clear will save you from planning around a hands-on performance test that, based on the available specification, does not exist for this credential.

If you are still orienting yourself, the explainer on what C)PEH certification is covers the basics, and the C)PEH study guide goes deeper on preparation strategy. This article focuses on the training side specifically: what you will learn, which format fits you, and how to avoid common purchasing mistakes.

Making Sure You Are Training for the Right Credential

Several certifications share similar acronyms and similar-sounding names, and search results blend them together. Before you spend money on any course or practice material, confirm that it targets Mile2's Certified Professional Ethical Hacker. This credential is not:

  • GAQM's CPEH-001 exam
  • EC-Council's CEH (Certified Ethical Hacker)
  • Mile2's own C)PTE (Certified Penetration Testing Engineer) or C)PTE-A

The practical consequence is that exam fees, question counts, module lists, and renewal rules differ across these programs. A study resource written for a different ethical hacking certification may cover overlapping subject matter, but it will not mirror the C)PEH module structure or the way Mile2 frames its objectives. If you are weighing it against the better-known alternative, read the C)PEH difficulty guide for context on what the exam demands, and treat any "CPEH vs CEH" comparison skeptically unless it clearly identifies which CPEH it means.

Check the issuer first: A legitimate C)PEH training product should reference Mile2, the C)PEH designation, and the Mile2 module outline. If a listing only says "CPEH" and cites a different certifying body, it is for another credential.

The Curriculum Map: Modules 00 Through 10

The current Mile2 outline, a seven-page PDF linked from the official C)PEH course outline page, lists Module 00 (Course Introduction) followed by ten substantive modules. This site presents those as 11 headings. It is worth being precise about what they are: unweighted preparation-curriculum headings. They are not 11 officially weighted exam domains, and the outline is not an exhaustive exam blueprint. No official percentage allocation was published, so no domain can honestly be called the "most heavily tested." Anyone claiming otherwise is guessing.

The headings, in order:

  1. Course Introduction
  2. Introduction to Ethical Hacking
  3. Cybersecurity Foundation
  4. Reconnaissance & Enumeration
  5. Cryptography
  6. Vulnerability Scanning & Analysis
  7. Web and Application Attacks
  8. Exploitation and Post-Exploitation
  9. Social Engineering
  10. Wireless Pentesting
  11. Reporting & Ethics

A note on a small inconsistency: the outline's cover spells the wireless module "Wireless Pentesting," while the detailed section prints "Wireless Pen testing." Same topic, different spelling. You may also encounter older reseller or academy listings that describe a 16-module version of the course. Those older lists are not the currently linked curriculum, so check any third-party syllabus against Mile2's current outline before relying on it. For a section-by-section walk through each heading, see the C)PEH exam domains guide.

Training Versus Testing: Course, Labs, and the 100-Question Exam

The single most useful mental separation in C)PEH preparation is this: the course teaches you through lectures and labs, and the exam measures you through a written multiple-choice test. They are related but distinct.

AspectTraining (Course)Exam
FormatFive-day course with 16 substantive labs and lab setup100 multiple-choice questions
TimeCourse delivery over several days; 40 course CEUsApproximately two hours
Hands-on elementYes, in labsNo separate performance exam verified in this specification
Passing standardNot applicableMinimum 70%
DeliveryPer provider (self-paced or instructor-led)Online through Mile2's learning-management system

The scored versus unscored question split is not published, so do not assume every item counts or that none of them are experimental. Plan to answer all 100 carefully. For more on the threshold itself, the C)PEH passing score guide explains the 70% line, and the pass rate article explains why vendor "success guarantees" from third parties should not be mistaken for an official pass rate.

Training Options and What Each One Includes

You have several routes, and the right one depends on your background and how you learn.

Mile2's Official Exam Combo

The official public search index shows the C)PEH Exam Combo at a $500 sale price against a $795 original list price. The retrieved product-page body did not expose prices directly, so treat these as indexed figures and confirm the live checkout amount. The Combo includes an exam, a simulator or practice resource, a preparation guide, and two attempts. It is not the full training package. If you want the instructor-led course experience, that is a separate purchase. Pricing details and comparisons are laid out in the C)PEH certification cost breakdown.

The Electronic Book Kit

A separately indexed C)PEH Electronic Book Kit appears at $400. That is preparation material, not the examination fee, and its current checkout amount was not independently confirmed. Do not confuse it with exam registration.

Authorized and Third-Party Training Providers

Several organizations offer Mile2 C)PEH training or preparation resources, including Hudson, Compendium CE, Fast Lane, and OpenExamPrep (a practice-question site). Provider course prices are not Mile2's examination fee, and they bundle different things such as instruction time, lab access, and materials. Treat third-party question banks with particular care: they are not authenticated real exam content, and a bank that claims to contain "actual exam questions" should raise a red flag rather than inspire confidence.

Self-Study Without the Course

Mile2 expressly allows candidates to test without purchasing its course. Suggested preparation is any one of Mile2 C)SP, 12 months of IT experience, or 12 months of networking experience. These are suggestions, not a verified mandatory degree, training-hour, or experience gate. If you already work in IT or networking, self-study plus the Exam Combo's practice resources can be a reasonable path. Details on eligibility live in the C)PEH requirements article.

Course ≠ requirement: Because the exam can be taken without Mile2's course, the real question is not "do I need training?" but "how much structure do I need to learn this material efficiently?" Be honest about your starting point.

Deep Dives on the Topics That Trip Candidates Up

Rather than restating every heading, here are the areas where understanding, not memorization, makes the difference on a multiple-choice test.

Reconnaissance & Enumeration

Reconnaissance gathers information about a target; enumeration actively extracts details such as hosts, services, and accounts. Exam questions often hinge on telling passive collection (no direct contact with the target) from active probing (traffic that the target can observe).

  • Know why passive techniques are lower risk of detection but yield less detail.
  • Understand what service and version information reveals and how it feeds later vulnerability analysis.
  • Be able to reason about which technique fits a scenario, not just name tools.

Cryptography

This module rewards conceptual clarity. Know the roles of symmetric versus asymmetric encryption, hashing, and digital signatures, and why each is used where it is.

  • Hashing is one-way and used for integrity; encryption is reversible with the right key.
  • Understand how weak or misapplied cryptography becomes an attack surface.
  • Expect scenario questions asking which primitive solves a stated problem.

Vulnerability Scanning & Analysis

Scanning finds potential weaknesses; analysis decides which ones matter. The skill being tested is prioritization: not every finding is equally exploitable or equally damaging.

  • Distinguish a scanner's raw output from a validated, prioritized finding.
  • Understand false positives and why verification is part of the process.
  • Weigh severity against context such as exposure and the value of the affected asset.

Web and Application Attacks

Expect coverage of common web weakness categories, referenced through frameworks such as OWASP and CWE, and attention to API-related issues. The emphasis is on recognizing the vulnerability class from a description and knowing the defensive control that addresses it.

  • Map attack descriptions to weakness categories.
  • Understand why input handling and authentication flaws recur so often.
  • Know the general mitigation pattern for each class.

Exploitation and Post-Exploitation

Exploitation gains a foothold; post-exploitation covers what an assessor does next, including understanding access, assessing impact, and maintaining scope discipline. Think in terms of a sequence of phases, and be able to say which phase a described action belongs to.

Social Engineering and Wireless Pentesting

Social engineering questions focus on human-factor manipulation and the organizational controls that blunt it. Wireless questions focus on protocol weaknesses and how assessors evaluate wireless networks within an authorized scope.

Authorized Lab Work and Reporting Ethics

Every hands-on exercise in ethical hacking training rests on one rule: you test only systems you are explicitly authorized to test. The labs bundled with training are designed so that practicing offensive techniques happens inside a sanctioned environment. Building your own practice lab on equipment you own, or using a provider's lab, keeps you on the right side of the law and of the credential's code of ethics.

The final module, Reporting & Ethics, deserves more attention than candidates usually give it. Findings that are not communicated clearly are findings that do not get fixed. A strong report states the issue, its evidence, its business impact, and a remediation path, and it is written for the audience that must act on it. Ethics questions on the exam test judgment: what to do when you discover data outside scope, how to handle sensitive findings, and why disclosure and confidentiality obligations matter. Renewal also touches ethics directly, since the renewal process includes seven Code of Ethics questions and agreement to current policies.

Key Takeaway

Do not treat Module 10 as an afterthought. Reporting and ethics questions are often the most "reasonable-sounding" distractors on the exam, so practice choosing the response that is both technically sound and professionally responsible.

Sequencing Your Training Around the Modules

Because no official weighting exists, a sensible plan gives every module real attention while spending extra time where your background is thinnest. Here is one way to sequence an eight-week preparation window; adjust to your experience, and see the C)PEH cheat sheet for a condensed review once you have finished.

Weeks 1-2

Foundations

  • Introduction to Ethical Hacking and Cybersecurity Foundation: terminology, phases, and the legal and ethical frame.
  • Do these first because every later module assumes this vocabulary.
Weeks 3-4

Discovery and Cryptography

  • Reconnaissance & Enumeration, then Cryptography.
  • Pair recon with lab practice; give cryptography time for concept review since it is less hands-on.
Weeks 5-6

Assessment and Attack

  • Vulnerability Scanning & Analysis, Web and Application Attacks, then Exploitation and Post-Exploitation.
  • These build on each other, so keep them adjacent.
Weeks 7-8

Human, Wireless, Reporting, and Review

  • Social Engineering, Wireless Pentesting, and Reporting & Ethics.
  • Finish with timed practice sets to rehearse a 100-question, roughly two-hour sitting.

Spaced review beats cramming here: revisit earlier modules briefly each week so that reconnaissance and scanning concepts stay fresh when you reach exploitation.

Fees, Delivery Policy, and What to Verify Before Buying

Several details in the available sources are not fully reconciled, so verify them directly rather than assuming.

  • Price: Confirm the live checkout amount for the Exam Combo and any course purchase. Indexed prices may differ from what you see at checkout.
  • Attempts: The Combo includes two attempts. Per the current FAQ, two additional attempts require another retail purchase after both included attempts are used. The general policy also describes a 30-day wait before a third attempt.
  • Access windows: Course access and the included exam voucher in bundled offerings are generally one year, which is separate from the three-year credential validity. Cyber Range access can have a shorter, separate term.
  • Proctoring: The FAQ says most standard exams can start on demand without a live-proctor appointment, naming other products as exceptions. The broader Policies and Procedures document describes live camera and screen proctoring scheduled at least 48 hours ahead. How this applies to the standard C)PEH product is not clearly reconciled, so do not assume either arrangement until your booking confirms it.
  • Open-book status: The general policy mentions an open-book exam, but do not rely on an unrestricted resource policy without current confirmation.
  • Timing: Mile2's security page describes a two-hour timed window that cannot be paused, so plan an uninterrupted block of time.

For a fuller treatment of scheduling, see the C)PEH exam dates guide.

Open-book does not mean easy: Even if reference materials are permitted, a two-hour window across 100 questions leaves little time to look things up. Treat the exam as closed-book in your preparation and consider any permitted resources a safety net.

After Training: Validity, Renewal, and Career Context

The credential is valid for three years. Current central renewal guidance describes 60 documented qualifying CEUs across the cycle (commonly expressed as 20 per year), purchase of the applicable renewal product, seven Code of Ethics questions, and agreement to current policies. The FAQ gives a U.S. standard CEU-route renewal price of $200, with eligible developing-region pricing potentially as low as $100, subject to confirmation at checkout. There is no annual membership requirement. Renewal paths also include an exam-based alternative.

The sources conflict on some renewal specifics. The course PDF describes both a current-exam pass and annual CEUs as requirements, while central renewal pages present alternative paths, and the May 2026 policy describes a recertification assessment with a seven-day post-expiry window whose exact scope is unclear. Do not assume a universal grace period or equate an unspecified recertification assessment with either the full exam or the ethics acknowledgment. Confirm your applicable route and deadline well before expiry.

On careers: the Mile2 outline advertises $80,077 as annual salary potential, but it is undated and gives no sample or methodology, so treat it as issuer marketing rather than a verified average or proof that the credential causes higher pay. For a more careful look, read the C)PEH salary guide, the C)PEH jobs overview, and the worth-it analysis. Also note that the policy identifies C)ISSO-A and C)PTE-A as ANAB-accredited offerings; it does not establish that accreditation for the standard C)PEH.

When you are ready to test your knowledge against exam-style questions, the C)PEH practice test site offers a place to rehearse the format.

Frequently Asked Questions

Do I have to take Mile2's course to sit the C)PEH exam?

No. Mile2 expressly permits testing without purchasing its course. Suggested preparation is Mile2 C)SP, 12 months of IT experience, or 12 months of networking experience, but these are suggestions rather than a verified mandatory gate.

Is there a hands-on practical exam as part of C)PEH?

A separate hands-on performance exam is not verified in the C)PEH specification. The written exam is 100 multiple-choice questions in about two hours with a 70% minimum. The 16 labs belong to the training course, not the exam.

What does the Exam Combo include?

The Exam Combo includes an exam, a simulator or practice resource, a preparation guide, and two attempts. It is not the full training package, and the live checkout price should be confirmed before purchase.

Is the C)PEH the same as EC-Council's CEH?

No. C)PEH is Mile2's Certified Professional Ethical Hacker credential. It is distinct from EC-Council's CEH, GAQM's CPEH-001, and Mile2's own C)PTE and C)PTE-A, each of which has its own requirements and fees.

Which module should I study first?

Start with Introduction to Ethical Hacking and Cybersecurity Foundation, since later modules such as Reconnaissance & Enumeration and Exploitation and Post-Exploitation assume that vocabulary. No official weighting identifies a single most important module.

Ready to pass your C)PEH exam?

Put this into practice with free C)PEH questions across every exam domain.