- What the C)PEH Credential Actually Is
- Not CEH, Not GAQM, Not C)PTE
- The Eleven Curriculum Headings
- How the Written Exam Works
- Proctoring and Open-Book: What Is Unresolved
- Costs and What Each Purchase Includes
- Suggested Preparation, Not Hard Prerequisites
- Concepts You Need to Understand, Not Just Memorize
- Who Hires, and How to Read the Salary Claim
- Validity and Renewal
- Sequencing Your Preparation
- Frequently Asked Questions
- C)PEH is Mile2's Certified Professional Ethical Hacker credential, tested by a 100-question multiple-choice exam with a 70% minimum.
- The curriculum has 11 unweighted headings, Module 00 plus Modules 01-10; no official domain percentages were verified.
- Mile2 permits testing without buying its course, but suggested prep is C)SP or 12 months of IT or networking experience.
- Proctoring and open-book rules differ between Mile2 sources, so confirm current delivery terms before booking.
What the C)PEH Credential Actually Is
C)PEH stands for Certified Professional Ethical Hacker, a certification governed and administered by Mile2. It targets people who need to understand how attackers think and operate, so they can find weaknesses in systems with permission and report them in a way an organization can act on. The designation is written with the closing parenthesis in the Mile2 style, and that punctuation is part of how Mile2 names its credentials.
The credential is built around a written, multiple-choice examination delivered online through Mile2's learning-management system. It sits alongside the company's broader security catalog rather than replacing it, and it is best understood as a foundation-to-intermediate offensive-security credential: wide coverage of the attack lifecycle, from reconnaissance through reporting, tested by questions rather than by a live hacking performance.
If you want the same ground covered with a different framing, our companion pieces What Is C)PEH Certification? and What Does C)PEH Stand For? approach the definition from other angles. This article focuses on how the credential is structured and what it demands of a candidate.
Not CEH, Not GAQM, Not C)PTE
Search results for "CPEH" are crowded, and the acronym is shared across the industry. Before you spend money, be certain which credential you are pursuing. The C)PEH covered on this site is the Mile2 Certified Professional Ethical Hacker. It is not any of the following:
- EC-Council's CEH. A different issuer, a different exam, and a different set of policies.
- GAQM's CPEH-001. A separate credential from a separate body that happens to share similar letters.
- Mile2's C)PTE or C)PTE-A. These are the penetration-testing credentials in Mile2's own catalog, with their own scope and, in the case of C)PTE-A, different delivery rules.
The practical consequence is that details you read about one of these, such as fees, question counts, or exam windows, do not transfer to the others. When you read a forum thread or a reseller page, check which issuer it describes. Candidates weighing the two best-known names will find a fuller treatment in our difficulty guide, and the main practice test site is built specifically around Mile2's C)PEH.
The Eleven Curriculum Headings
Mile2's current course outline lists a preparation curriculum organized into eleven headings: a Course Introduction (Module 00) followed by ten substantive modules (Modules 01-10). These are curriculum headings, not eleven officially weighted exam domains, and the outline is not an exhaustive exam blueprint. Mile2 does not publish percentage allocations in the material we verified, so no single heading can honestly be called the "most heavily tested." Treat all eleven as in scope and let your own weak spots decide where to spend extra time. Our complete domains guide walks through each area in more depth.
| Heading | What it covers conceptually |
|---|---|
| Course Introduction | Orientation to the course, its goals, and how the material is organized |
| Introduction to Ethical Hacking | What ethical hacking is, its legal and professional boundaries, and the attack lifecycle |
| Cybersecurity Foundation | Core networking, systems, and security principles that attacks build on |
| Reconnaissance & Enumeration | Gathering information about a target and mapping what is exposed |
| Cryptography | How encryption, hashing, and key handling protect data and where they fail |
| Vulnerability Scanning & Analysis | Finding weaknesses, interpreting results, and prioritizing what matters |
| Web and Application Attacks | Weaknesses in web apps and APIs and how they are exploited |
| Exploitation and Post-Exploitation | Gaining access, then understanding what an attacker can do afterward |
| Social Engineering | Manipulating people rather than machines to gain access |
| Wireless Pentesting | Assessing wireless networks and their protections |
| Reporting & Ethics | Documenting findings responsibly and operating within authorization |
How the Written Exam Works
The examination is a set of 100 multiple-choice questions with a time allowance of approximately two hours, according to the credential outline. The minimum passing grade is 70%. It is taken online through Mile2's learning-management system, and Mile2's general Course and Exam Security page identifies LearnDash as the platform and describes a two-hour timed window that cannot be paused. Once you start, the clock runs.
Several things are worth knowing about what the exam is not. There is no verified separate hands-on performance examination in the C)PEH specification. The five-day course, its 40 course CEUs, and its 16 substantive labs describe training, not the examination. Labs help you learn the material, but your credential is awarded on the multiple-choice result. Mile2 also does not publish how many of the 100 questions are scored versus unscored, so do not rely on anyone who claims to know that split.
For the arithmetic of the threshold, see our dedicated passing score page. A related warning: you will see confident pass-rate numbers circulating from training vendors and forum posts. Those are not published Mile2 figures. Our pass rate analysis explains why a vendor's success guarantee is a marketing statement and not a credential statistic.
Proctoring and Open-Book: What Is Unresolved
This is the area where Mile2's own documents do not line up cleanly, and an honest overview has to say so rather than pick a side.
- Mile2's Frequently Asked Questions page says most standard exams can start on demand without a live-proctor appointment, and names C)ISSO-A and C)PTE-A as exceptions.
- Mile2's broader Policies and Procedures document, dated May 26, 2026, describes LearnDash delivery, an open-book exam, live camera and screen proctoring scheduled at least 48 hours ahead, randomized items, the ability to return to skipped questions, and immediate results.
- Within that policy, one section says some exams require a proctor while another describes proctored administration generally. How it applies to the standard C)PEH product is not reconciled with the FAQ.
Key Takeaway
Do not assume the C)PEH is either unproctored or live-proctored, and do not assume an unrestricted open-book resource policy. Before you commit, get written confirmation of the proctoring requirement and permitted materials at the moment you book. Even if open-book language applies, a two-hour window for 100 questions leaves little room to look up unfamiliar topics.
The general policy also covers identification requirements, accommodations, and a 30-day wait before a third attempt. No C)PEH-specific rule about adaptive testing or calculators was verified. For scheduling questions, see our exam dates guide.
Costs and What Each Purchase Includes
The most useful distinction in C)PEH pricing is between the exam product and the full training package. The Exam Combo is shown in Mile2's public search index at $500 on sale against a $795 original list price. The product-page body did not expose a price when we retrieved it, so confirm the live checkout amount before paying. The Combo includes an exam, a simulator or practice resource, a preparation guide, and two attempts. It is not the full course.
| Item | What it is | Note |
|---|---|---|
| C)PEH Exam Combo | Exam, practice resource, prep guide, two attempts | $500 sale / $795 list in the search index; verify at checkout |
| C)PEH Electronic Book Kit | Preparation material | Indexed at $400; this is not the exam fee, and checkout price was not independently confirmed |
| Additional attempts | Needed after both included attempts are used | Requires another retail purchase per Mile2's FAQ |
| Third-party training | Instructor-led courses from authorized providers | Provider prices are not the issuer's exam fee |
No member versus nonmember pricing tier is published. Course access and the exam voucher in the Ultimate Combo are generally valid for one year, which is separate from the three-year life of the credential once earned, and Cyber Range access can have its own shorter term. For a fuller breakdown, see our pricing guide.
Suggested Preparation, Not Hard Prerequisites
Mile2 suggests any one of the following as preparation: its C)SP certification, 12 months of IT experience, or 12 months of networking experience. These are recommendations. We found no verified mandatory degree, reference, training-hour, or experience gate. Mile2 also expressly permits testing without purchasing its course, so self-study candidates are not shut out.
That said, the absence of a gate is not the same as the absence of difficulty. A candidate with no networking background will find reconnaissance, enumeration, and wireless topics demanding, because those headings assume you already understand how traffic moves. Our requirements guide covers eligibility in more detail.
Concepts You Need to Understand, Not Just Memorize
Because the exam is multiple-choice, it rewards candidates who can reason about scenarios, not those who have only memorized lists. A few areas are worth understanding at a conceptual level.
Reconnaissance & Enumeration
Reconnaissance is the discipline of learning about a target before touching it aggressively. Candidates should distinguish between gathering information passively from public sources and actively probing systems, and understand why the second carries more risk of detection and legal exposure.
- Why enumeration follows discovery and what it adds, such as services, accounts, and shares
- How the information gathered shapes every later decision in an engagement
- The difference between an authorized assessment and unauthorized scanning
Cryptography
Expect to reason about what a cryptographic control actually guarantees. Encryption protects confidentiality, hashing supports integrity checks, and digital signatures support authenticity and non-repudiation. Many questions turn on knowing which property a mechanism provides and where a weak implementation or poor key handling undermines it.
Vulnerability Scanning & Analysis
A scanner produces findings, not conclusions. The skill being tested is prioritization: separating a theoretical weakness from one that is reachable, exploitable, and consequential in context.
- Recognizing false positives and why results need validation
- Weighing severity against exposure and business impact
- Knowing that a long findings list is not the same as a useful assessment
Web and Application Attacks
This heading is where industry taxonomies matter. Be comfortable with the idea of common web weakness categories, such as those catalogued by OWASP, and with how weakness classifications like CWE describe the underlying flaw. Understand how API weaknesses differ from traditional page-based web flaws, since modern applications expose functionality through endpoints rather than only through forms.
Reporting & Ethics
The final heading is often underestimated. Ethical hacking is defined by authorization and scope: you test only what you have permission to test, you handle discovered data responsibly, and you communicate findings so that the client can fix them. A technically brilliant assessment that exceeds its scope, or that fails to explain risk clearly, is a failed engagement.
The ten substantive modules also include exploitation and post-exploitation, social engineering, and wireless pentesting, all of which follow the same logic: understand the attacker's objective, the control that is meant to stop it, and the professional boundaries that separate assessment from abuse. Labs in the course are meant to be performed only in authorized environments. For a condensed review, our cheat sheet collects the must-know facts on one page.
Who Hires, and How to Read the Salary Claim
A credential like this is aimed at roles that sit near security testing and assessment: junior penetration testers, security analysts, vulnerability analysts, and IT staff moving toward security work. Organizations that employ these people include managed security providers, consultancies that perform assessments for clients, and internal security teams in larger enterprises. The credential signals that you understand the attack lifecycle and the ethics around it; it does not by itself substitute for demonstrated practical skill.
On earnings, be careful. Mile2's outline advertises an $80,077 annual salary potential, but it is undated and gives no sample or methodology. That figure is issuer marketing, not a verified 2026 average for C)PEH holders, and it does not establish that the credential caused any pay increase. Pay depends heavily on location, prior experience, and role. Our salary guide discusses how to evaluate such numbers, and the jobs overview looks at the roles themselves. If you are weighing whether to proceed, the ROI analysis frames that decision.
Validity and Renewal
The credential is valid for three years, and there is no annual membership requirement. Current central renewal guidance describes 60 documented qualifying CEUs across the three-year cycle, commonly expressed as 20 per year, along with purchase of the applicable renewal product, seven Code of Ethics questions, and agreement to current policies. The FAQ gives a U.S. standard CEU-route renewal price of $200, with eligible developing-region pricing potentially as low as $100, both subject to checkout confirmation. Mile2 also publishes exam-based renewal as an alternative, which may cost more.
Start documenting qualifying activities early, since CEU evidence is reviewed against Mile2's qualifying-CEU guidance.
Sequencing Your Preparation
Because no domain weights are published, sequence your study by dependency rather than by supposed exam emphasis. The foundation material supports everything else, and reporting and ethics are best studied last so the earlier technical content gives them context. Our full study guide and training overview expand on options.
Foundations and Orientation
- Work through the introduction, ethical hacking concepts, and cybersecurity foundations
- Shore up networking basics first if your background is thin, since later modules assume them
Discovery and Analysis
- Reconnaissance and enumeration, then vulnerability scanning and analysis
- Practice interpreting findings and prioritizing, not just recalling tool names
Attack Techniques and Cryptography
- Cryptography properties, web and application attacks, exploitation and post-exploitation
- Social engineering and wireless pentesting, using authorized lab environments only
Reporting, Ethics, and Timed Practice
- Reporting and ethics, then full-length timed practice to rehearse the two-hour window
- Revisit whichever headings scored weakest
Be cautious with third-party question banks. They can help you practice the style of reasoning, but they are not authenticated real exam content, and relying on them as a source of "actual questions" is a mistake. Use the C)PEH practice tests to measure readiness and identify weak headings, not to memorize answers.
Frequently Asked Questions
Mile2 governs and administers the Certified Professional Ethical Hacker credential. It is distinct from EC-Council's CEH, GAQM's CPEH-001, and Mile2's own C)PTE and C)PTE-A, so confirm the issuer before relying on any outside source.
The written exam has 100 multiple-choice questions, takes approximately two hours, and requires a minimum 70% to pass. Mile2 does not publish how many questions are scored versus unscored.
No separate hands-on performance exam was verified in the C)PEH specification. The course includes 16 substantive labs, but those are training activities, not part of the examination.
No. Mile2 expressly permits testing without purchasing its course. It suggests C)SP, 12 months of IT experience, or 12 months of networking experience as preparation, but these are recommendations and not verified mandatory gates.
Mile2's sources conflict. The FAQ says most standard exams start on demand without a live proctor, while the policy document describes open-book delivery and scheduled live proctoring. Confirm current rules at booking rather than assuming either.
Three years. Renewal guidance describes 60 documented CEUs over the cycle, a renewal purchase, and seven Code of Ethics questions, with an exam-based alternative also published. Confirm your applicable route and deadline before expiry.