C)PEH logo
Focused certification exam prep
Start practice

What Is C)PEH Certification?

TL;DR
  • C)PEH is Mile2's Certified Professional Ethical Hacker credential, distinct from GAQM CPEH-001 and EC-Council CEH.
  • The written exam is 100 multiple-choice questions in roughly two hours, with a 70% minimum passing grade.
  • The linked outline has 11 unweighted headings, Module 00 plus Modules 01-10; no official domain percentages were verified.
  • The Exam Combo is listed at $500 sale ($795 list) with two attempts; confirm the live checkout price.

What C)PEH Actually Is

C)PEH stands for Certified Professional Ethical Hacker. It is a Mile2 credential: Mile2 governs and administers it, and the official designation is written with the closing parenthesis, C)PEH. The certification is aimed at people who need to understand how attackers think and operate so they can test systems with permission, document what they find, and help organizations fix weaknesses.

If you are searching for a quick definition, the short version is this: a C)PEH holder has passed a 100-question multiple-choice assessment covering the ethical hacking lifecycle, from reconnaissance and vulnerability analysis through exploitation, social engineering, wireless testing, and professional reporting. For more phrasing variants of the same question, our pages on what C)PEH is, what C)PEH stands for, and C)PEH meaning cover the vocabulary from different angles.

Why the distinction matters: Mile2 sells both training and the exam. The two are separable. Mile2 expressly permits testing without purchasing its course, so you can come in through self-study, a third-party class, or on-the-job experience.

What It Is Not: Clearing Up the Acronym

Several credentials in the security market have similar-sounding names, and search results blend them together. This article is only about the Mile2 C)PEH. Specifically, it is not:

  • GAQM CPEH-001, a different certification from a different certifying body.
  • EC-Council CEH, the Certified Ethical Hacker credential, which has its own exam, fees, and blueprint.
  • Mile2 C)PTE (Certified Penetration Testing Engineer) or C)PTE-A, which sit in a separate, more penetration-testing-focused part of the Mile2 catalog.

That matters for practical reasons. Exam fees, passing scores, renewal rules, and curriculum all differ by issuer. A forum post about "CPEH" may be describing a completely different product. Treat any number you read elsewhere with suspicion until you confirm which credential it belongs to.

The 11 Curriculum Headings

The seven-page Mile2 outline currently linked from its C)PEH course outline page lists Module 00 (Course Introduction) and ten substantive modules. We treat these as preparation-curriculum headings. They are not 11 official exam domains, they carry no published weights, and they are not an exhaustive exam blueprint. Because no percentage allocation was verified, nobody can honestly tell you which area is "most heavily tested." Plan for breadth.

#HeadingWhat it covers in practice
1Course IntroductionOrientation, lab setup, and course scope
2Introduction to Ethical HackingAttacker mindset, authorization, rules of engagement
3Cybersecurity FoundationNetworking, protocols, and security concepts underpinning later work
4Reconnaissance & EnumerationGathering target information and mapping services
5CryptographyEncryption, hashing, and how they fail
6Vulnerability Scanning & AnalysisFinding, validating, and prioritizing weaknesses
7Web and Application AttacksWeb, application, and API weakness classes
8Exploitation and Post-ExploitationGaining access and what happens afterward
9Social EngineeringHuman-targeted attack techniques and defenses
10Wireless PentestingAssessing wireless networks
11Reporting & EthicsDocumentation, communication, and professional conduct

One note for anyone comparing sources: older reseller and academy listings sometimes show a 16-module version of this course. This article does not borrow from those lists; it follows the currently linked outline. If your study material has 16 modules, check that it matches the outline above before you rely on it. For a deeper walk through each area, see our guide to all 11 C)PEH content areas.

Exam Format and Delivery

The credential PDF describes a single written exam:

  • Questions: 100 multiple-choice items.
  • Time: approximately two hours.
  • Passing grade: 70% minimum.
  • Delivery: online through Mile2's learning-management system.

Mile2 does not publish how many of the 100 items are scored versus unscored, so do not assume every question counts. We have also found no verified separate hands-on performance exam in the C)PEH specification. The five-day course, 40 course CEUs, and 16 substantive labs with setup describe the training, not the exam. Labs build skill; the credential itself is awarded for the written test. Our page on the C)PEH passing score goes deeper on what 70% implies in practice.

Proctoring and open-book: confirm before you book. Mile2's own sources do not line up neatly. Its FAQ says most standard exams can start on demand without a live-proctor appointment, naming C)ISSO-A and C)PTE-A as exceptions. Its broader Policies and Procedures document (May 26, 2026) describes an open-book exam with live camera and screen proctoring scheduled at least 48 hours ahead. How that applies to the standard C)PEH product is not reconciled. Do not assume either an unproctored session or a live proctor, and do not assume unrestricted reference materials. Get written confirmation at booking.

Other policy points worth knowing: the general exam-security page describes a two-hour timed window that cannot be paused; the policy document describes randomized items, the ability to return to skipped questions, and immediate results; and it covers identification, accommodations, and a 30-day wait before a third attempt. No C)PEH-specific adaptive-testing or calculator rule was verified.

Cost, Bundles, and Preparation Paths

Pricing is where candidates most often mix up products, so separate them clearly:

ProductWhat it isPrice status
C)PEH Exam ComboExam, simulator/practice resource, preparation guide, and two attemptsSearch index shows $500 sale / $795 list; live checkout not confirmed
C)PEH Electronic Book KitPreparation material, not an exam feeIndexed at $400; live checkout not confirmed
Full training courses (Mile2 or authorized partners)Instruction plus labsVaries by provider; not the exam fee

The Exam Combo is not the full training package. After you use both included attempts, Mile2's FAQ says two additional attempts require another retail purchase. No member/nonmember pricing tier is published. Training-provider prices (including authorized training partners) are not the issuer's examination fee. Product pages load dynamically, so verify the live amount at checkout. Our C)PEH certification cost breakdown tracks these components in more detail.

Suggested background, not a gate

Mile2 suggests any one of the following before attempting the course: its C)SP credential, 12 months of IT experience, or 12 months of networking experience. These are suggestions. No mandatory degree, reference, training-hour count, or experience gate was verified. See C)PEH requirements for the full eligibility picture.

Preparation resources

Beyond Mile2's own bundle, candidates commonly find preparation or training through providers such as OpenExamPrep, Hudson, Compendium CE, and Fast Lane. Treat these as discovery references, not endorsements or a current ranking. Be especially careful with third-party question banks: they are not authenticated real exam content, and a vendor's "success guarantee" is not a credential pass rate. Mile2 has not published a verified C)PEH pass rate; our pass rate analysis explains what can and cannot be said.

Topics You Need to Master

Because the exam is multiple choice and open to interpretation of exactly which items appear, the safest preparation is conceptual fluency across every heading. Here are the areas where candidates typically need depth.

Reconnaissance & Enumeration

You should be able to explain the difference between passive and active information gathering and why the line matters legally and operationally.

  • What public sources reveal about an organization without touching its systems
  • How port and service enumeration turns an IP range into a map of attack surface
  • Why enumeration output (banners, shares, user lists) drives later decisions

Cryptography

Expect questions on the purpose of each primitive and the mistakes that undermine it, not on deriving algorithms by hand.

  • Symmetric versus asymmetric encryption and where each is used
  • Hashing for integrity versus encryption for confidentiality
  • How weak keys, poor randomness, and outdated algorithms create exploitable gaps

Vulnerability Scanning & Analysis

A scanner produces a list; an ethical hacker produces judgment. Know how to separate real risk from noise.

  • Why false positives occur and how validation resolves them
  • How severity, exploitability, and asset value combine to set priority
  • Why a "critical" finding on an isolated test box may rank below a "medium" on an internet-facing system

Web and Application Attacks

Be comfortable with common weakness categories and the vocabulary used to catalog them, including OWASP-style risk lists, CWE weakness identifiers, and API-specific issues.

  • Injection, broken authentication, and access-control failures
  • Why input handling and session management recur as root causes
  • How API weaknesses differ from, and overlap with, classic web flaws

Exploitation and Post-Exploitation

The exam tests whether you understand the lifecycle, including what responsible testers do after gaining access.

  • Distinguishing initial access from privilege escalation and lateral movement
  • Maintaining scope and avoiding collateral damage during authorized lab work
  • Why post-exploitation evidence supports the report rather than serving as an end in itself

Social Engineering & Wireless Pentesting

These two headings cover people and radio. Note that the outline's cover spells it "Wireless Pentesting" while the detailed section prints "Wireless Pen testing," so you may see either form.

  • Pretexting, phishing, and the psychological levers they exploit
  • Wireless encryption generations and the common ways they are weakened

Reporting & Ethics

This is easy to underestimate. A finding nobody can act on has little value, and the profession rests on authorization.

  • Written permission and clear scope before any testing
  • Writing findings so both executives and engineers can use them
  • Responsible handling of sensitive data encountered during an engagement

For a consolidated quick-review sheet once you have worked through these, our C)PEH cheat sheet compresses the must-know facts.

Who Hires and What the Salary Claims Mean

C)PEH is an entry-to-intermediate offensive-security credential, so it tends to be relevant for roles that need testing literacy: junior penetration testers, security analysts, vulnerability analysts, SOC staff moving toward offensive work, and IT or network administrators taking on security duties. Defense and government-adjacent employers, consultancies, and managed security providers are the typical environments for this skill set. See C)PEH jobs for the role landscape.

Read salary figures carefully: The undated Mile2 outline advertises $80,077 in annual salary potential. That is issuer marketing, with no dated credential-holder sample or published methodology. It is not a verified 2026 average for C)PEH holders, and it does not show that the certification caused any pay premium. Your actual compensation will depend on location, experience, employer, and role. Our salary guide and ROI analysis treat these limits openly.

If you are weighing it against the better-known EC-Council CEH, remember they are separate credentials from separate bodies with separate exams. Compare their exam format, cost, renewal terms, and employer recognition in your target market rather than assuming they are interchangeable. Likewise, C)PTE is a different Mile2 product with a different focus.

Validity and Renewal

The C)PEH credential is valid for three years. There is no annual membership requirement. Current central renewal guidance describes:

  • 60 documented qualifying CEUs across the three-year cycle, commonly expressed as 20 per year
  • Purchase of the applicable renewal product
  • Seven Code of Ethics questions and agreement to current policies

The FAQ lists a U.S. standard CEU-route renewal price of $200, with eligible developing-region pricing potentially as low as $100, subject to checkout or issuer confirmation. Mile2's Renewal Paths page also publishes an exam-based alternative, including passing the latest relevant exam, which may cost more.

Sources disagree, so verify: The C)PEH course PDF describes both a current-exam pass and annual CEUs as requirements, while central renewal pages present alternative paths. The May 2026 policy also mentions a recertification assessment and a seven-day window after expiry, and its sections are not consistent about whether a full exam replaces CEUs after that period. Do not equate an unspecified recertification assessment with either the full 100-question exam or the seven-question ethics acknowledgment. Confirm your route and deadline with Mile2 well before your expiry date.

Also note a timing distinction: Ultimate Combo course access and any included exam voucher are generally good for one year, which is separate from the three-year credential validity. Cyber Range access can carry its own shorter term.

A Sensible Study Order

Since there are no official weights, schedule by dependency rather than by guessed importance. Foundations feed everything else, and reporting and ethics frame how every technical topic is applied. One workable sequence, assuming a six-week window:

Week 1

Orientation, ethics, and foundations

  • Introduction to Ethical Hacking and Cybersecurity Foundation, because later modules assume this vocabulary
  • Set up a lab environment you are authorized to attack
Week 2

Seeing the target

  • Reconnaissance & Enumeration, then Vulnerability Scanning & Analysis, since scan output depends on enumeration
Week 3

Cryptography

  • Dedicate a full week; it is conceptual and benefits from slow reading rather than cramming
Week 4

Attack techniques

  • Web and Application Attacks, then Exploitation and Post-Exploitation
Week 5

People, radio, and professionalism

  • Social Engineering, Wireless Pentesting, and Reporting & Ethics
Week 6

Consolidation

  • Timed practice runs at 100 questions in about two hours, then review every miss against the relevant heading

For a fuller plan, see the C)PEH study guide, and for a realistic sense of effort, how hard the C)PEH exam is. You can also try timed questions on our main practice test site; the format mirrors the 100-question multiple-choice structure, though no third-party bank is real exam content. Confirm your window using our exam dates and scheduling page.

Frequently Asked Questions

What does C)PEH certification stand for?

C)PEH stands for Certified Professional Ethical Hacker, a credential governed and administered by Mile2. It is not the same as GAQM CPEH-001, EC-Council CEH, or Mile2's C)PTE. See what C)PEH certification is for related definitions.

How many questions are on the exam and what score do I need?

The credential PDF describes 100 multiple-choice questions in approximately two hours, with a 70% minimum passing grade, delivered online through Mile2's learning-management system. Mile2 does not publish the split between scored and unscored items.

Do I have to buy the training course to take the exam?

No. Mile2 expressly permits testing without purchasing its course. The Exam Combo (exam, simulator, preparation guide, two attempts) is listed at $500 sale / $795 list in search results, but confirm the live checkout price before buying.

Is the C)PEH exam open-book or proctored?

Mile2's sources are not fully reconciled. The FAQ suggests most standard exams start on demand without a live proctor, while the policy document describes open-book delivery with live camera and screen proctoring scheduled 48 hours ahead. Confirm the rules for your specific booking before test day.

How long is the certification valid, and how do I renew?

It is valid for three years. Central guidance describes 60 documented CEUs, a renewal purchase, and seven Code of Ethics questions, with an exam-based alternative also published. Because some Mile2 documents conflict, verify your route and deadline with the issuer before expiry.

Ready to pass your C)PEH exam?

Put this into practice with free C)PEH questions across every exam domain.