- C)PEH is Mile2's Certified Professional Ethical Hacker credential, not a GAQM or EC-Council product.
- The written exam has 100 multiple-choice questions, roughly two hours, and a 70% minimum passing grade.
- The curriculum has 11 headings (Module 00 plus Modules 01-10); none carry published exam weights.
- The credential is valid for three years, and renewal routes should be confirmed with Mile2 before expiry.
What a C)PEH Actually Is
C)PEH stands for Certified Professional Ethical Hacker. It is a cybersecurity certification governed and administered by Mile2, and "C)PEH" is the official designation the issuer uses. The credential targets people who need to understand how attackers think and operate so they can find weaknesses in systems before someone malicious does. The word "ethical" carries real weight here: every technique in the curriculum is framed around authorization, scope, and responsible reporting.
If you have seen the term in job postings, vendor catalogs, or forum threads and wondered what it means, the short version is this: it is a knowledge-based certification built around a five-day training course and a 100-question written examination. Related explainers on this site cover the naming from different angles, including what C)PEH stands for and the meaning of the acronym, but this article focuses on what the credential contains and how it works in practice.
Credentials It Gets Confused With
The letters CPEH are shared, or nearly shared, by several certifications, and this is the single biggest source of bad information online. To be clear about what C)PEH is not:
- It is not GAQM's CPEH-001.
- It is not EC-Council's CEH, the Certified Ethical Hacker.
- It is not Mile2's own C)PTE (Certified Penetration Testing Engineer) or its C)PTE-A variant.
Because of this overlap, practice questions, price quotes, and pass-rate claims found through a casual search may describe a different exam entirely. If you are weighing the credential against the EC-Council option, the right approach is to compare the issuer outlines side by side rather than relying on a forum summary. For difficulty expectations specific to the Mile2 exam, see How Hard Is the C)PEH Exam?
The Eleven Curriculum Headings
The Mile2 course outline lists a course introduction followed by ten substantive modules. That produces 11 headings, which this site treats as content areas. They are preparation-curriculum headings, not 11 officially weighted exam domains, and the outline is not an exhaustive exam blueprint. Mile2 has not published a percentage allocation per area in the sources reviewed, so no one can honestly tell you which heading is "worth the most." For a deeper walk through each area, see the complete guide to all 11 content areas.
| # | Content Area | What It Covers in Practice |
|---|---|---|
| 1 | Course Introduction | Orientation to the course and its objectives (Module 00) |
| 2 | Introduction to Ethical Hacking | The attacker mindset, legal and authorized testing context |
| 3 | Cybersecurity Foundation | Core security concepts the later modules build on |
| 4 | Reconnaissance & Enumeration | Gathering information about targets and mapping services |
| 5 | Cryptography | Protecting and attacking confidentiality and integrity |
| 6 | Vulnerability Scanning & Analysis | Finding, interpreting, and prioritizing weaknesses |
| 7 | Web and Application Attacks | Common web flaws, including OWASP, CWE, and API topics |
| 8 | Exploitation and Post-Exploitation | Using a foothold and understanding what follows |
| 9 | Social Engineering | Human-targeted attack techniques and defenses |
| 10 | Wireless Pentesting | Assessing wireless network security |
| 11 | Reporting & Ethics | Documenting findings and professional conduct |
One small detail worth knowing: the outline's cover spells the wireless module "Wireless Pentesting," while the detailed section prints "Wireless Pen testing." Same module, inconsistent spelling in the source document.
Exam Format and Delivery
The written exam consists of 100 multiple-choice questions with a time allowance of approximately two hours, and the minimum passing grade is 70%. It is delivered online through Mile2's learning-management system, which is LearnDash according to the Course and Exam Security page. That page also describes a timed window that cannot be paused, so plan to sit the exam in one uninterrupted block. Mile2 does not publish how many items are scored versus unscored.
Two things the sources do not establish are worth stating plainly:
- No separate hands-on exam. The 16 labs and setup in the course are training activities. No verified performance-based practical is part of this C)PEH specification.
- The five-day course and 40 course CEUs describe training, not the exam. They are not extra exam time or additional domains.
The policy also covers identification requirements, accommodations, and a 30-day wait before a third attempt. For a closer look at scoring thresholds, read what you need to pass, and for scheduling logistics see testing windows and scheduling.
Registration, Fees and Attempts
Suggested preparation is any one of the following: the Mile2 C)SP credential, 12 months of IT experience, or 12 months of networking experience. These are suggestions, not a verified mandatory degree, reference, training-hour, or experience gate, and Mile2 expressly permits testing without purchasing its course. Our requirements guide goes deeper on eligibility.
On cost, there are three distinct products people conflate:
| Product | What It Is | Price Signal |
|---|---|---|
| C)PEH Exam Combo | Exam, simulator/practice resource, preparation guide, and two attempts | Public search index shows $500 sale / $795 original list |
| C)PEH Electronic Book Kit | Preparation material, not the exam fee | Indexed at $400; checkout amount not independently confirmed |
| Full training course | Five-day instructor-led or bundled training | Varies by provider; not the issuer's exam fee |
The dynamic Mile2 product pages did not expose prices in the retrieved page body, so confirm the live checkout amount before purchasing. The Exam Combo is not the full training package. Per Mile2's FAQ, once both included attempts are used, two additional attempts require another retail purchase. Ultimate Combo course access and its included exam voucher are generally good for one year, which is separate from the three-year life of the credential itself. No member versus nonmember pricing tier is published. Training-provider prices (such as those from authorized training partners) are their own pricing and should never be read as the exam fee. The full breakdown lives in our C)PEH certification cost guide.
Concrete Topics to Master
Knowing the heading names is not the same as knowing what to study. Here is how the more technical areas translate into things a candidate should be able to explain.
Reconnaissance & Enumeration
You should be able to distinguish passive information gathering (collecting data without touching the target) from active probing, and explain what enumeration adds: usernames, shares, services, and versions that turn a vague target into a concrete attack surface.
- Why recon quality determines everything downstream
- How discovered service versions connect to known weaknesses
- Where the line sits between authorized scanning and overreach
Cryptography
Expect to separate symmetric from asymmetric approaches, hashing from encryption, and understand why each exists. The exam-relevant skill is matching a primitive to a security goal rather than memorizing algorithm trivia.
- Confidentiality versus integrity versus authentication
- Why hashes are one-way and what that means for password storage
- How weak or misused cryptography becomes an attack path
Vulnerability Scanning & Analysis
Running a scanner is the easy part. The tested skill is interpreting results: separating true findings from false positives and deciding what to fix first based on exploitability and business impact.
- Prioritization logic, not just severity labels
- Why scanner output needs human validation
- Reading a finding well enough to explain remediation
Web and Application Attacks
This area touches OWASP-style web risks, CWE-style weakness classification, and API security topics. Understand the flaw category, how it arises from unsafe handling of input or access control, and what a defender changes to close it.
- Injection and broken access control as recurring themes
- The difference between a weakness class and a specific vulnerability
- API-specific exposure such as over-permissive endpoints
Exploitation, Post-Exploitation, Social Engineering, Wireless
These areas move from gaining access to understanding what an attacker does next, how people are manipulated rather than machines, and how wireless networks are assessed. Authorization and containment are the through-line: all authorized lab work operates inside a defined scope.
Reporting & Ethics
A finding no one can act on is wasted effort. Know what a defensible report contains, how to communicate risk to non-technical readers, and why handling discovered data responsibly is part of the job, not an afterthought.
Who Uses the Credential and What About Salary
C)PEH fits roles that touch offensive or defensive security understanding: junior penetration testing, vulnerability assessment, security analysis, and IT or network staff moving toward security work. It is an entry-to-intermediate credential in a field where employers often care as much about demonstrable lab skill as about a certificate. Our C)PEH jobs overview looks at role types in more detail.
On pay, be careful. Mile2's own outline advertises an annual salary potential of $80,077, but it is undated and gives no sample or methodology. Treat it as issuer marketing, not a verified 2026 average for credential holders and not proof that the certification causes higher pay. Pay depends far more on role, location, and experience. See the salary guide and the worth-it analysis for how to weigh it sensibly.
Validity and Renewal
The credential is valid for three years, and there is no annual membership requirement. Current central renewal guidance describes 60 documented qualifying CEUs over the three-year cycle (commonly expressed as 20 per year), purchase of the applicable renewal product, seven Code of Ethics questions, and agreement to current policies. The FAQ gives a standard U.S. CEU-route renewal price of $200, with eligible developing-region pricing potentially as low as $100, subject to confirmation at checkout. Exam-based renewal can cost more.
Sequencing Your Preparation
Because Mile2 publishes no weights, spread effort by dependency rather than by guessing at emphasis: later modules assume earlier ones. A reasonable order follows the curriculum itself. Detailed planning advice is in the C)PEH study guide, and a quick-reference companion is the cheat sheet.
Foundations and Recon
- Introduction to Ethical Hacking and Cybersecurity Foundation, so the vocabulary is solid
- Reconnaissance & Enumeration, since later attacks depend on it
Analysis and Application Layer
- Cryptography, then Vulnerability Scanning & Analysis
- Web and Application Attacks, the area with the most named taxonomies to learn
Attack Chain and Wrap-Up
- Exploitation and Post-Exploitation, Social Engineering, Wireless Pentesting
- Reporting & Ethics, then timed practice against the 100-question, two-hour format
When you reach the practice stage, use realistic practice questions to rehearse pacing, and keep in mind that third-party question banks are not authenticated real exam content. Likewise, treat vendor "success guarantees" as marketing rather than a credential pass rate; the sources reviewed publish no verified pass rate, which our pass rate article discusses.
Frequently Asked Questions
It is Mile2's Certified Professional Ethical Hacker certification. Candidates demonstrate knowledge of attack techniques and defensive context through a 100-question multiple-choice written exam. Its overall focus is covered further in What Is C)PEH Certification?
No. CEH is EC-Council's Certified Ethical Hacker. C)PEH is a separate Mile2 credential with its own outline, exam, and pricing. Do not use one's materials to prepare for the other.
No. Mile2 expressly permits testing without purchasing its course. The suggested preparation, one of C)SP, 12 months of IT experience, or 12 months of networking experience, is a recommendation rather than a verified mandatory gate.
No separate performance exam is verified in this specification. The labs are part of the training course; the credential exam itself is the written multiple-choice assessment.
Three years. Renewal paths and deadlines should be confirmed with Mile2 before expiry because the published sources describe them somewhat differently.
In short, the C)PEH is a focused, Mile2-issued written certification with a clearly defined format, a pricing structure that is easy to misread, and a few policy details worth verifying directly with the issuer. Start from the official outline, keep it distinct from similarly named credentials, and build your preparation around the eleven curriculum headings rather than around claims that the published sources cannot support.