C)PEH logo
Focused certification exam prep
Start practice

What Is C)PEH?

TL;DR
  • C)PEH is Mile2's Certified Professional Ethical Hacker credential, tested by a 100-question multiple-choice exam with a 70% minimum.
  • The curriculum has 11 unweighted headings, Module 00 plus Modules 01-10; no official domain percentages were verified.
  • Mile2 permits testing without buying its course, but suggested prep is C)SP or 12 months of IT or networking experience.
  • Proctoring and open-book rules differ between Mile2 sources, so confirm current delivery terms before booking.

What the C)PEH Credential Actually Is

C)PEH stands for Certified Professional Ethical Hacker, a certification governed and administered by Mile2. It targets people who need to understand how attackers think and operate, so they can find weaknesses in systems with permission and report them in a way an organization can act on. The designation is written with the closing parenthesis in the Mile2 style, and that punctuation is part of how Mile2 names its credentials.

The credential is built around a written, multiple-choice examination delivered online through Mile2's learning-management system. It sits alongside the company's broader security catalog rather than replacing it, and it is best understood as a foundation-to-intermediate offensive-security credential: wide coverage of the attack lifecycle, from reconnaissance through reporting, tested by questions rather than by a live hacking performance.

If you want the same ground covered with a different framing, our companion pieces What Is C)PEH Certification? and What Does C)PEH Stand For? approach the definition from other angles. This article focuses on how the credential is structured and what it demands of a candidate.

Not CEH, Not GAQM, Not C)PTE

Search results for "CPEH" are crowded, and the acronym is shared across the industry. Before you spend money, be certain which credential you are pursuing. The C)PEH covered on this site is the Mile2 Certified Professional Ethical Hacker. It is not any of the following:

  • EC-Council's CEH. A different issuer, a different exam, and a different set of policies.
  • GAQM's CPEH-001. A separate credential from a separate body that happens to share similar letters.
  • Mile2's C)PTE or C)PTE-A. These are the penetration-testing credentials in Mile2's own catalog, with their own scope and, in the case of C)PTE-A, different delivery rules.

The practical consequence is that details you read about one of these, such as fees, question counts, or exam windows, do not transfer to the others. When you read a forum thread or a reseller page, check which issuer it describes. Candidates weighing the two best-known names will find a fuller treatment in our difficulty guide, and the main practice test site is built specifically around Mile2's C)PEH.

Why the identity check matters: Cost, format, renewal, and policy facts differ by issuer. A study plan built on another credential's exam blueprint can leave you preparing for the wrong test. Confirm the issuer is Mile2 and the designation is C)PEH before you buy anything.

The Eleven Curriculum Headings

Mile2's current course outline lists a preparation curriculum organized into eleven headings: a Course Introduction (Module 00) followed by ten substantive modules (Modules 01-10). These are curriculum headings, not eleven officially weighted exam domains, and the outline is not an exhaustive exam blueprint. Mile2 does not publish percentage allocations in the material we verified, so no single heading can honestly be called the "most heavily tested." Treat all eleven as in scope and let your own weak spots decide where to spend extra time. Our complete domains guide walks through each area in more depth.

HeadingWhat it covers conceptually
Course IntroductionOrientation to the course, its goals, and how the material is organized
Introduction to Ethical HackingWhat ethical hacking is, its legal and professional boundaries, and the attack lifecycle
Cybersecurity FoundationCore networking, systems, and security principles that attacks build on
Reconnaissance & EnumerationGathering information about a target and mapping what is exposed
CryptographyHow encryption, hashing, and key handling protect data and where they fail
Vulnerability Scanning & AnalysisFinding weaknesses, interpreting results, and prioritizing what matters
Web and Application AttacksWeaknesses in web apps and APIs and how they are exploited
Exploitation and Post-ExploitationGaining access, then understanding what an attacker can do afterward
Social EngineeringManipulating people rather than machines to gain access
Wireless PentestingAssessing wireless networks and their protections
Reporting & EthicsDocumenting findings responsibly and operating within authorization
Legacy lists versus the current outline: Some older reseller and academy pages describe a 16-module version of this course. This article follows the currently linked Mile2 outline with its eleven headings. If a training provider hands you a different module list, ask which course version it matches before assuming it is interchangeable.

How the Written Exam Works

The examination is a set of 100 multiple-choice questions with a time allowance of approximately two hours, according to the credential outline. The minimum passing grade is 70%. It is taken online through Mile2's learning-management system, and Mile2's general Course and Exam Security page identifies LearnDash as the platform and describes a two-hour timed window that cannot be paused. Once you start, the clock runs.

Several things are worth knowing about what the exam is not. There is no verified separate hands-on performance examination in the C)PEH specification. The five-day course, its 40 course CEUs, and its 16 substantive labs describe training, not the examination. Labs help you learn the material, but your credential is awarded on the multiple-choice result. Mile2 also does not publish how many of the 100 questions are scored versus unscored, so do not rely on anyone who claims to know that split.

For the arithmetic of the threshold, see our dedicated passing score page. A related warning: you will see confident pass-rate numbers circulating from training vendors and forum posts. Those are not published Mile2 figures. Our pass rate analysis explains why a vendor's success guarantee is a marketing statement and not a credential statistic.

Proctoring and Open-Book: What Is Unresolved

This is the area where Mile2's own documents do not line up cleanly, and an honest overview has to say so rather than pick a side.

  • Mile2's Frequently Asked Questions page says most standard exams can start on demand without a live-proctor appointment, and names C)ISSO-A and C)PTE-A as exceptions.
  • Mile2's broader Policies and Procedures document, dated May 26, 2026, describes LearnDash delivery, an open-book exam, live camera and screen proctoring scheduled at least 48 hours ahead, randomized items, the ability to return to skipped questions, and immediate results.
  • Within that policy, one section says some exams require a proctor while another describes proctored administration generally. How it applies to the standard C)PEH product is not reconciled with the FAQ.

Key Takeaway

Do not assume the C)PEH is either unproctored or live-proctored, and do not assume an unrestricted open-book resource policy. Before you commit, get written confirmation of the proctoring requirement and permitted materials at the moment you book. Even if open-book language applies, a two-hour window for 100 questions leaves little room to look up unfamiliar topics.

The general policy also covers identification requirements, accommodations, and a 30-day wait before a third attempt. No C)PEH-specific rule about adaptive testing or calculators was verified. For scheduling questions, see our exam dates guide.

Costs and What Each Purchase Includes

The most useful distinction in C)PEH pricing is between the exam product and the full training package. The Exam Combo is shown in Mile2's public search index at $500 on sale against a $795 original list price. The product-page body did not expose a price when we retrieved it, so confirm the live checkout amount before paying. The Combo includes an exam, a simulator or practice resource, a preparation guide, and two attempts. It is not the full course.

ItemWhat it isNote
C)PEH Exam ComboExam, practice resource, prep guide, two attempts$500 sale / $795 list in the search index; verify at checkout
C)PEH Electronic Book KitPreparation materialIndexed at $400; this is not the exam fee, and checkout price was not independently confirmed
Additional attemptsNeeded after both included attempts are usedRequires another retail purchase per Mile2's FAQ
Third-party trainingInstructor-led courses from authorized providersProvider prices are not the issuer's exam fee

No member versus nonmember pricing tier is published. Course access and the exam voucher in the Ultimate Combo are generally valid for one year, which is separate from the three-year life of the credential once earned, and Cyber Range access can have its own shorter term. For a fuller breakdown, see our pricing guide.

Suggested Preparation, Not Hard Prerequisites

Mile2 suggests any one of the following as preparation: its C)SP certification, 12 months of IT experience, or 12 months of networking experience. These are recommendations. We found no verified mandatory degree, reference, training-hour, or experience gate. Mile2 also expressly permits testing without purchasing its course, so self-study candidates are not shut out.

That said, the absence of a gate is not the same as the absence of difficulty. A candidate with no networking background will find reconnaissance, enumeration, and wireless topics demanding, because those headings assume you already understand how traffic moves. Our requirements guide covers eligibility in more detail.

Concepts You Need to Understand, Not Just Memorize

Because the exam is multiple-choice, it rewards candidates who can reason about scenarios, not those who have only memorized lists. A few areas are worth understanding at a conceptual level.

Reconnaissance & Enumeration

Reconnaissance is the discipline of learning about a target before touching it aggressively. Candidates should distinguish between gathering information passively from public sources and actively probing systems, and understand why the second carries more risk of detection and legal exposure.

  • Why enumeration follows discovery and what it adds, such as services, accounts, and shares
  • How the information gathered shapes every later decision in an engagement
  • The difference between an authorized assessment and unauthorized scanning

Cryptography

Expect to reason about what a cryptographic control actually guarantees. Encryption protects confidentiality, hashing supports integrity checks, and digital signatures support authenticity and non-repudiation. Many questions turn on knowing which property a mechanism provides and where a weak implementation or poor key handling undermines it.

Vulnerability Scanning & Analysis

A scanner produces findings, not conclusions. The skill being tested is prioritization: separating a theoretical weakness from one that is reachable, exploitable, and consequential in context.

  • Recognizing false positives and why results need validation
  • Weighing severity against exposure and business impact
  • Knowing that a long findings list is not the same as a useful assessment

Web and Application Attacks

This heading is where industry taxonomies matter. Be comfortable with the idea of common web weakness categories, such as those catalogued by OWASP, and with how weakness classifications like CWE describe the underlying flaw. Understand how API weaknesses differ from traditional page-based web flaws, since modern applications expose functionality through endpoints rather than only through forms.

Reporting & Ethics

The final heading is often underestimated. Ethical hacking is defined by authorization and scope: you test only what you have permission to test, you handle discovered data responsibly, and you communicate findings so that the client can fix them. A technically brilliant assessment that exceeds its scope, or that fails to explain risk clearly, is a failed engagement.

The ten substantive modules also include exploitation and post-exploitation, social engineering, and wireless pentesting, all of which follow the same logic: understand the attacker's objective, the control that is meant to stop it, and the professional boundaries that separate assessment from abuse. Labs in the course are meant to be performed only in authorized environments. For a condensed review, our cheat sheet collects the must-know facts on one page.

Who Hires, and How to Read the Salary Claim

A credential like this is aimed at roles that sit near security testing and assessment: junior penetration testers, security analysts, vulnerability analysts, and IT staff moving toward security work. Organizations that employ these people include managed security providers, consultancies that perform assessments for clients, and internal security teams in larger enterprises. The credential signals that you understand the attack lifecycle and the ethics around it; it does not by itself substitute for demonstrated practical skill.

On earnings, be careful. Mile2's outline advertises an $80,077 annual salary potential, but it is undated and gives no sample or methodology. That figure is issuer marketing, not a verified 2026 average for C)PEH holders, and it does not establish that the credential caused any pay increase. Pay depends heavily on location, prior experience, and role. Our salary guide discusses how to evaluate such numbers, and the jobs overview looks at the roles themselves. If you are weighing whether to proceed, the ROI analysis frames that decision.

Validity and Renewal

The credential is valid for three years, and there is no annual membership requirement. Current central renewal guidance describes 60 documented qualifying CEUs across the three-year cycle, commonly expressed as 20 per year, along with purchase of the applicable renewal product, seven Code of Ethics questions, and agreement to current policies. The FAQ gives a U.S. standard CEU-route renewal price of $200, with eligible developing-region pricing potentially as low as $100, both subject to checkout confirmation. Mile2 also publishes exam-based renewal as an alternative, which may cost more.

Renewal sources do not fully agree: The C)PEH course PDF describes both a current-exam pass and annual CEUs as requirements, while central renewal pages present them as alternative paths. The May 2026 policy mentions a recertification assessment and a seven-day window around expiry, with some sections requiring the full exam after that period and others using permissive wording. Do not equate the recertification assessment with either the 100-question exam or the seven-question ethics acknowledgment. Confirm your route and deadline well before expiry.

Start documenting qualifying activities early, since CEU evidence is reviewed against Mile2's qualifying-CEU guidance.

Sequencing Your Preparation

Because no domain weights are published, sequence your study by dependency rather than by supposed exam emphasis. The foundation material supports everything else, and reporting and ethics are best studied last so the earlier technical content gives them context. Our full study guide and training overview expand on options.

Weeks 1-2

Foundations and Orientation

  • Work through the introduction, ethical hacking concepts, and cybersecurity foundations
  • Shore up networking basics first if your background is thin, since later modules assume them
Weeks 3-4

Discovery and Analysis

  • Reconnaissance and enumeration, then vulnerability scanning and analysis
  • Practice interpreting findings and prioritizing, not just recalling tool names
Weeks 5-6

Attack Techniques and Cryptography

  • Cryptography properties, web and application attacks, exploitation and post-exploitation
  • Social engineering and wireless pentesting, using authorized lab environments only
Week 7

Reporting, Ethics, and Timed Practice

  • Reporting and ethics, then full-length timed practice to rehearse the two-hour window
  • Revisit whichever headings scored weakest

Be cautious with third-party question banks. They can help you practice the style of reasoning, but they are not authenticated real exam content, and relying on them as a source of "actual questions" is a mistake. Use the C)PEH practice tests to measure readiness and identify weak headings, not to memorize answers.

Frequently Asked Questions

Who issues the C)PEH certification?

Mile2 governs and administers the Certified Professional Ethical Hacker credential. It is distinct from EC-Council's CEH, GAQM's CPEH-001, and Mile2's own C)PTE and C)PTE-A, so confirm the issuer before relying on any outside source.

How many questions are on the exam and what score passes?

The written exam has 100 multiple-choice questions, takes approximately two hours, and requires a minimum 70% to pass. Mile2 does not publish how many questions are scored versus unscored.

Is there a hands-on practical exam?

No separate hands-on performance exam was verified in the C)PEH specification. The course includes 16 substantive labs, but those are training activities, not part of the examination.

Do I have to buy Mile2's course to take the exam?

No. Mile2 expressly permits testing without purchasing its course. It suggests C)SP, 12 months of IT experience, or 12 months of networking experience as preparation, but these are recommendations and not verified mandatory gates.

Is the C)PEH exam open-book or proctored?

Mile2's sources conflict. The FAQ says most standard exams start on demand without a live proctor, while the policy document describes open-book delivery and scheduled live proctoring. Confirm current rules at booking rather than assuming either.

How long is the credential valid?

Three years. Renewal guidance describes 60 documented CEUs over the cycle, a renewal purchase, and seven Code of Ethics questions, with an exam-based alternative also published. Confirm your applicable route and deadline before expiry.

Ready to pass your C)PEH exam?

Put this into practice with free C)PEH questions across every exam domain.