C)PEH logo
Focused certification exam prep
Start practice

What Is A C)PEH?

TL;DR
  • C)PEH is Mile2's Certified Professional Ethical Hacker credential, not a GAQM or EC-Council product.
  • The written exam has 100 multiple-choice questions, roughly two hours, and a 70% minimum passing grade.
  • The curriculum has 11 headings (Module 00 plus Modules 01-10); none carry published exam weights.
  • The credential is valid for three years, and renewal routes should be confirmed with Mile2 before expiry.

What a C)PEH Actually Is

C)PEH stands for Certified Professional Ethical Hacker. It is a cybersecurity certification governed and administered by Mile2, and "C)PEH" is the official designation the issuer uses. The credential targets people who need to understand how attackers think and operate so they can find weaknesses in systems before someone malicious does. The word "ethical" carries real weight here: every technique in the curriculum is framed around authorization, scope, and responsible reporting.

If you have seen the term in job postings, vendor catalogs, or forum threads and wondered what it means, the short version is this: it is a knowledge-based certification built around a five-day training course and a 100-question written examination. Related explainers on this site cover the naming from different angles, including what C)PEH stands for and the meaning of the acronym, but this article focuses on what the credential contains and how it works in practice.

Scope note: This article describes the Mile2 Certified Professional Ethical Hacker credential only, based on the currently linked seven-page course outline and Mile2's public policy pages. Older third-party course listings sometimes describe different module counts, so treat the issuer's own materials as the reference point.

Credentials It Gets Confused With

The letters CPEH are shared, or nearly shared, by several certifications, and this is the single biggest source of bad information online. To be clear about what C)PEH is not:

  • It is not GAQM's CPEH-001.
  • It is not EC-Council's CEH, the Certified Ethical Hacker.
  • It is not Mile2's own C)PTE (Certified Penetration Testing Engineer) or its C)PTE-A variant.

Because of this overlap, practice questions, price quotes, and pass-rate claims found through a casual search may describe a different exam entirely. If you are weighing the credential against the EC-Council option, the right approach is to compare the issuer outlines side by side rather than relying on a forum summary. For difficulty expectations specific to the Mile2 exam, see How Hard Is the C)PEH Exam?

The Eleven Curriculum Headings

The Mile2 course outline lists a course introduction followed by ten substantive modules. That produces 11 headings, which this site treats as content areas. They are preparation-curriculum headings, not 11 officially weighted exam domains, and the outline is not an exhaustive exam blueprint. Mile2 has not published a percentage allocation per area in the sources reviewed, so no one can honestly tell you which heading is "worth the most." For a deeper walk through each area, see the complete guide to all 11 content areas.

#Content AreaWhat It Covers in Practice
1Course IntroductionOrientation to the course and its objectives (Module 00)
2Introduction to Ethical HackingThe attacker mindset, legal and authorized testing context
3Cybersecurity FoundationCore security concepts the later modules build on
4Reconnaissance & EnumerationGathering information about targets and mapping services
5CryptographyProtecting and attacking confidentiality and integrity
6Vulnerability Scanning & AnalysisFinding, interpreting, and prioritizing weaknesses
7Web and Application AttacksCommon web flaws, including OWASP, CWE, and API topics
8Exploitation and Post-ExploitationUsing a foothold and understanding what follows
9Social EngineeringHuman-targeted attack techniques and defenses
10Wireless PentestingAssessing wireless network security
11Reporting & EthicsDocumenting findings and professional conduct

One small detail worth knowing: the outline's cover spells the wireless module "Wireless Pentesting," while the detailed section prints "Wireless Pen testing." Same module, inconsistent spelling in the source document.

Exam Format and Delivery

The written exam consists of 100 multiple-choice questions with a time allowance of approximately two hours, and the minimum passing grade is 70%. It is delivered online through Mile2's learning-management system, which is LearnDash according to the Course and Exam Security page. That page also describes a timed window that cannot be paused, so plan to sit the exam in one uninterrupted block. Mile2 does not publish how many items are scored versus unscored.

Two things the sources do not establish are worth stating plainly:

  • No separate hands-on exam. The 16 labs and setup in the course are training activities. No verified performance-based practical is part of this C)PEH specification.
  • The five-day course and 40 course CEUs describe training, not the exam. They are not extra exam time or additional domains.
Proctoring and open-book: confirm before you book. Mile2's FAQ says most standard exams can start on demand without a live-proctor appointment, naming C)ISSO-A and C)PTE-A as exceptions. Its broader May 2026 Policies and Procedures describes an open-book exam with live camera and screen proctoring scheduled at least 48 hours ahead. How those two documents apply to the standard C)PEH product is not reconciled, so do not assume either an unproctored session or a live-proctored one, and do not assume unrestricted reference materials. Get the delivery rules in writing from Mile2 when you schedule.

The policy also covers identification requirements, accommodations, and a 30-day wait before a third attempt. For a closer look at scoring thresholds, read what you need to pass, and for scheduling logistics see testing windows and scheduling.

Registration, Fees and Attempts

Suggested preparation is any one of the following: the Mile2 C)SP credential, 12 months of IT experience, or 12 months of networking experience. These are suggestions, not a verified mandatory degree, reference, training-hour, or experience gate, and Mile2 expressly permits testing without purchasing its course. Our requirements guide goes deeper on eligibility.

On cost, there are three distinct products people conflate:

ProductWhat It IsPrice Signal
C)PEH Exam ComboExam, simulator/practice resource, preparation guide, and two attemptsPublic search index shows $500 sale / $795 original list
C)PEH Electronic Book KitPreparation material, not the exam feeIndexed at $400; checkout amount not independently confirmed
Full training courseFive-day instructor-led or bundled trainingVaries by provider; not the issuer's exam fee

The dynamic Mile2 product pages did not expose prices in the retrieved page body, so confirm the live checkout amount before purchasing. The Exam Combo is not the full training package. Per Mile2's FAQ, once both included attempts are used, two additional attempts require another retail purchase. Ultimate Combo course access and its included exam voucher are generally good for one year, which is separate from the three-year life of the credential itself. No member versus nonmember pricing tier is published. Training-provider prices (such as those from authorized training partners) are their own pricing and should never be read as the exam fee. The full breakdown lives in our C)PEH certification cost guide.

Concrete Topics to Master

Knowing the heading names is not the same as knowing what to study. Here is how the more technical areas translate into things a candidate should be able to explain.

Reconnaissance & Enumeration

You should be able to distinguish passive information gathering (collecting data without touching the target) from active probing, and explain what enumeration adds: usernames, shares, services, and versions that turn a vague target into a concrete attack surface.

  • Why recon quality determines everything downstream
  • How discovered service versions connect to known weaknesses
  • Where the line sits between authorized scanning and overreach

Cryptography

Expect to separate symmetric from asymmetric approaches, hashing from encryption, and understand why each exists. The exam-relevant skill is matching a primitive to a security goal rather than memorizing algorithm trivia.

  • Confidentiality versus integrity versus authentication
  • Why hashes are one-way and what that means for password storage
  • How weak or misused cryptography becomes an attack path

Vulnerability Scanning & Analysis

Running a scanner is the easy part. The tested skill is interpreting results: separating true findings from false positives and deciding what to fix first based on exploitability and business impact.

  • Prioritization logic, not just severity labels
  • Why scanner output needs human validation
  • Reading a finding well enough to explain remediation

Web and Application Attacks

This area touches OWASP-style web risks, CWE-style weakness classification, and API security topics. Understand the flaw category, how it arises from unsafe handling of input or access control, and what a defender changes to close it.

  • Injection and broken access control as recurring themes
  • The difference between a weakness class and a specific vulnerability
  • API-specific exposure such as over-permissive endpoints

Exploitation, Post-Exploitation, Social Engineering, Wireless

These areas move from gaining access to understanding what an attacker does next, how people are manipulated rather than machines, and how wireless networks are assessed. Authorization and containment are the through-line: all authorized lab work operates inside a defined scope.

Reporting & Ethics

A finding no one can act on is wasted effort. Know what a defensible report contains, how to communicate risk to non-technical readers, and why handling discovered data responsibly is part of the job, not an afterthought.

Who Uses the Credential and What About Salary

C)PEH fits roles that touch offensive or defensive security understanding: junior penetration testing, vulnerability assessment, security analysis, and IT or network staff moving toward security work. It is an entry-to-intermediate credential in a field where employers often care as much about demonstrable lab skill as about a certificate. Our C)PEH jobs overview looks at role types in more detail.

On pay, be careful. Mile2's own outline advertises an annual salary potential of $80,077, but it is undated and gives no sample or methodology. Treat it as issuer marketing, not a verified 2026 average for credential holders and not proof that the certification causes higher pay. Pay depends far more on role, location, and experience. See the salary guide and the worth-it analysis for how to weigh it sensibly.

Validity and Renewal

The credential is valid for three years, and there is no annual membership requirement. Current central renewal guidance describes 60 documented qualifying CEUs over the three-year cycle (commonly expressed as 20 per year), purchase of the applicable renewal product, seven Code of Ethics questions, and agreement to current policies. The FAQ gives a standard U.S. CEU-route renewal price of $200, with eligible developing-region pricing potentially as low as $100, subject to confirmation at checkout. Exam-based renewal can cost more.

Renewal sources do not fully agree. The C)PEH course PDF describes both a current-exam pass and annual CEUs as requirements, while Mile2's central renewal pages present CEU-based and exam-based paths as alternatives. The May 2026 policy also mentions a recertification assessment and a seven-day window after expiry, and it is internally inconsistent about whether the full exam is required afterward. That assessment is not the same thing as the full 100-question exam or the seven-question ethics acknowledgment. Confirm your applicable route and deadline with Mile2 before your expiry date rather than relying on any grace period.

Sequencing Your Preparation

Because Mile2 publishes no weights, spread effort by dependency rather than by guessing at emphasis: later modules assume earlier ones. A reasonable order follows the curriculum itself. Detailed planning advice is in the C)PEH study guide, and a quick-reference companion is the cheat sheet.

Weeks 1-2

Foundations and Recon

  • Introduction to Ethical Hacking and Cybersecurity Foundation, so the vocabulary is solid
  • Reconnaissance & Enumeration, since later attacks depend on it
Weeks 3-4

Analysis and Application Layer

  • Cryptography, then Vulnerability Scanning & Analysis
  • Web and Application Attacks, the area with the most named taxonomies to learn
Weeks 5-6

Attack Chain and Wrap-Up

  • Exploitation and Post-Exploitation, Social Engineering, Wireless Pentesting
  • Reporting & Ethics, then timed practice against the 100-question, two-hour format

When you reach the practice stage, use realistic practice questions to rehearse pacing, and keep in mind that third-party question banks are not authenticated real exam content. Likewise, treat vendor "success guarantees" as marketing rather than a credential pass rate; the sources reviewed publish no verified pass rate, which our pass rate article discusses.

Frequently Asked Questions

What is a C)PEH in plain terms?

It is Mile2's Certified Professional Ethical Hacker certification. Candidates demonstrate knowledge of attack techniques and defensive context through a 100-question multiple-choice written exam. Its overall focus is covered further in What Is C)PEH Certification?

Is C)PEH the same as CEH?

No. CEH is EC-Council's Certified Ethical Hacker. C)PEH is a separate Mile2 credential with its own outline, exam, and pricing. Do not use one's materials to prepare for the other.

Do I have to take the Mile2 course to sit the exam?

No. Mile2 expressly permits testing without purchasing its course. The suggested preparation, one of C)SP, 12 months of IT experience, or 12 months of networking experience, is a recommendation rather than a verified mandatory gate.

Is there a hands-on practical portion?

No separate performance exam is verified in this specification. The labs are part of the training course; the credential exam itself is the written multiple-choice assessment.

How long does the certification last?

Three years. Renewal paths and deadlines should be confirmed with Mile2 before expiry because the published sources describe them somewhat differently.

In short, the C)PEH is a focused, Mile2-issued written certification with a clearly defined format, a pricing structure that is easy to misread, and a few policy details worth verifying directly with the issuer. Start from the official outline, keep it distinct from similarly named credentials, and build your preparation around the eleven curriculum headings rather than around claims that the published sources cannot support.

Ready to pass your C)PEH exam?

Put this into practice with free C)PEH questions across every exam domain.