- C)PEH is Mile2's Certified Professional Ethical Hacker credential, distinct from GAQM CPEH-001 and EC-Council CEH.
- The written exam is 100 multiple-choice questions in roughly two hours, with a 70% minimum passing grade.
- The linked outline has 11 unweighted headings, Module 00 plus Modules 01-10; no official domain percentages were verified.
- The Exam Combo is listed at $500 sale ($795 list) with two attempts; confirm the live checkout price.
What C)PEH Actually Is
C)PEH stands for Certified Professional Ethical Hacker. It is a Mile2 credential: Mile2 governs and administers it, and the official designation is written with the closing parenthesis, C)PEH. The certification is aimed at people who need to understand how attackers think and operate so they can test systems with permission, document what they find, and help organizations fix weaknesses.
If you are searching for a quick definition, the short version is this: a C)PEH holder has passed a 100-question multiple-choice assessment covering the ethical hacking lifecycle, from reconnaissance and vulnerability analysis through exploitation, social engineering, wireless testing, and professional reporting. For more phrasing variants of the same question, our pages on what C)PEH is, what C)PEH stands for, and C)PEH meaning cover the vocabulary from different angles.
What It Is Not: Clearing Up the Acronym
Several credentials in the security market have similar-sounding names, and search results blend them together. This article is only about the Mile2 C)PEH. Specifically, it is not:
- GAQM CPEH-001, a different certification from a different certifying body.
- EC-Council CEH, the Certified Ethical Hacker credential, which has its own exam, fees, and blueprint.
- Mile2 C)PTE (Certified Penetration Testing Engineer) or C)PTE-A, which sit in a separate, more penetration-testing-focused part of the Mile2 catalog.
That matters for practical reasons. Exam fees, passing scores, renewal rules, and curriculum all differ by issuer. A forum post about "CPEH" may be describing a completely different product. Treat any number you read elsewhere with suspicion until you confirm which credential it belongs to.
The 11 Curriculum Headings
The seven-page Mile2 outline currently linked from its C)PEH course outline page lists Module 00 (Course Introduction) and ten substantive modules. We treat these as preparation-curriculum headings. They are not 11 official exam domains, they carry no published weights, and they are not an exhaustive exam blueprint. Because no percentage allocation was verified, nobody can honestly tell you which area is "most heavily tested." Plan for breadth.
| # | Heading | What it covers in practice |
|---|---|---|
| 1 | Course Introduction | Orientation, lab setup, and course scope |
| 2 | Introduction to Ethical Hacking | Attacker mindset, authorization, rules of engagement |
| 3 | Cybersecurity Foundation | Networking, protocols, and security concepts underpinning later work |
| 4 | Reconnaissance & Enumeration | Gathering target information and mapping services |
| 5 | Cryptography | Encryption, hashing, and how they fail |
| 6 | Vulnerability Scanning & Analysis | Finding, validating, and prioritizing weaknesses |
| 7 | Web and Application Attacks | Web, application, and API weakness classes |
| 8 | Exploitation and Post-Exploitation | Gaining access and what happens afterward |
| 9 | Social Engineering | Human-targeted attack techniques and defenses |
| 10 | Wireless Pentesting | Assessing wireless networks |
| 11 | Reporting & Ethics | Documentation, communication, and professional conduct |
One note for anyone comparing sources: older reseller and academy listings sometimes show a 16-module version of this course. This article does not borrow from those lists; it follows the currently linked outline. If your study material has 16 modules, check that it matches the outline above before you rely on it. For a deeper walk through each area, see our guide to all 11 C)PEH content areas.
Exam Format and Delivery
The credential PDF describes a single written exam:
- Questions: 100 multiple-choice items.
- Time: approximately two hours.
- Passing grade: 70% minimum.
- Delivery: online through Mile2's learning-management system.
Mile2 does not publish how many of the 100 items are scored versus unscored, so do not assume every question counts. We have also found no verified separate hands-on performance exam in the C)PEH specification. The five-day course, 40 course CEUs, and 16 substantive labs with setup describe the training, not the exam. Labs build skill; the credential itself is awarded for the written test. Our page on the C)PEH passing score goes deeper on what 70% implies in practice.
Other policy points worth knowing: the general exam-security page describes a two-hour timed window that cannot be paused; the policy document describes randomized items, the ability to return to skipped questions, and immediate results; and it covers identification, accommodations, and a 30-day wait before a third attempt. No C)PEH-specific adaptive-testing or calculator rule was verified.
Cost, Bundles, and Preparation Paths
Pricing is where candidates most often mix up products, so separate them clearly:
| Product | What it is | Price status |
|---|---|---|
| C)PEH Exam Combo | Exam, simulator/practice resource, preparation guide, and two attempts | Search index shows $500 sale / $795 list; live checkout not confirmed |
| C)PEH Electronic Book Kit | Preparation material, not an exam fee | Indexed at $400; live checkout not confirmed |
| Full training courses (Mile2 or authorized partners) | Instruction plus labs | Varies by provider; not the exam fee |
The Exam Combo is not the full training package. After you use both included attempts, Mile2's FAQ says two additional attempts require another retail purchase. No member/nonmember pricing tier is published. Training-provider prices (including authorized training partners) are not the issuer's examination fee. Product pages load dynamically, so verify the live amount at checkout. Our C)PEH certification cost breakdown tracks these components in more detail.
Suggested background, not a gate
Mile2 suggests any one of the following before attempting the course: its C)SP credential, 12 months of IT experience, or 12 months of networking experience. These are suggestions. No mandatory degree, reference, training-hour count, or experience gate was verified. See C)PEH requirements for the full eligibility picture.
Preparation resources
Beyond Mile2's own bundle, candidates commonly find preparation or training through providers such as OpenExamPrep, Hudson, Compendium CE, and Fast Lane. Treat these as discovery references, not endorsements or a current ranking. Be especially careful with third-party question banks: they are not authenticated real exam content, and a vendor's "success guarantee" is not a credential pass rate. Mile2 has not published a verified C)PEH pass rate; our pass rate analysis explains what can and cannot be said.
Topics You Need to Master
Because the exam is multiple choice and open to interpretation of exactly which items appear, the safest preparation is conceptual fluency across every heading. Here are the areas where candidates typically need depth.
Reconnaissance & Enumeration
You should be able to explain the difference between passive and active information gathering and why the line matters legally and operationally.
- What public sources reveal about an organization without touching its systems
- How port and service enumeration turns an IP range into a map of attack surface
- Why enumeration output (banners, shares, user lists) drives later decisions
Cryptography
Expect questions on the purpose of each primitive and the mistakes that undermine it, not on deriving algorithms by hand.
- Symmetric versus asymmetric encryption and where each is used
- Hashing for integrity versus encryption for confidentiality
- How weak keys, poor randomness, and outdated algorithms create exploitable gaps
Vulnerability Scanning & Analysis
A scanner produces a list; an ethical hacker produces judgment. Know how to separate real risk from noise.
- Why false positives occur and how validation resolves them
- How severity, exploitability, and asset value combine to set priority
- Why a "critical" finding on an isolated test box may rank below a "medium" on an internet-facing system
Web and Application Attacks
Be comfortable with common weakness categories and the vocabulary used to catalog them, including OWASP-style risk lists, CWE weakness identifiers, and API-specific issues.
- Injection, broken authentication, and access-control failures
- Why input handling and session management recur as root causes
- How API weaknesses differ from, and overlap with, classic web flaws
Exploitation and Post-Exploitation
The exam tests whether you understand the lifecycle, including what responsible testers do after gaining access.
- Distinguishing initial access from privilege escalation and lateral movement
- Maintaining scope and avoiding collateral damage during authorized lab work
- Why post-exploitation evidence supports the report rather than serving as an end in itself
Social Engineering & Wireless Pentesting
These two headings cover people and radio. Note that the outline's cover spells it "Wireless Pentesting" while the detailed section prints "Wireless Pen testing," so you may see either form.
- Pretexting, phishing, and the psychological levers they exploit
- Wireless encryption generations and the common ways they are weakened
Reporting & Ethics
This is easy to underestimate. A finding nobody can act on has little value, and the profession rests on authorization.
- Written permission and clear scope before any testing
- Writing findings so both executives and engineers can use them
- Responsible handling of sensitive data encountered during an engagement
For a consolidated quick-review sheet once you have worked through these, our C)PEH cheat sheet compresses the must-know facts.
Who Hires and What the Salary Claims Mean
C)PEH is an entry-to-intermediate offensive-security credential, so it tends to be relevant for roles that need testing literacy: junior penetration testers, security analysts, vulnerability analysts, SOC staff moving toward offensive work, and IT or network administrators taking on security duties. Defense and government-adjacent employers, consultancies, and managed security providers are the typical environments for this skill set. See C)PEH jobs for the role landscape.
If you are weighing it against the better-known EC-Council CEH, remember they are separate credentials from separate bodies with separate exams. Compare their exam format, cost, renewal terms, and employer recognition in your target market rather than assuming they are interchangeable. Likewise, C)PTE is a different Mile2 product with a different focus.
Validity and Renewal
The C)PEH credential is valid for three years. There is no annual membership requirement. Current central renewal guidance describes:
- 60 documented qualifying CEUs across the three-year cycle, commonly expressed as 20 per year
- Purchase of the applicable renewal product
- Seven Code of Ethics questions and agreement to current policies
The FAQ lists a U.S. standard CEU-route renewal price of $200, with eligible developing-region pricing potentially as low as $100, subject to checkout or issuer confirmation. Mile2's Renewal Paths page also publishes an exam-based alternative, including passing the latest relevant exam, which may cost more.
Also note a timing distinction: Ultimate Combo course access and any included exam voucher are generally good for one year, which is separate from the three-year credential validity. Cyber Range access can carry its own shorter term.
A Sensible Study Order
Since there are no official weights, schedule by dependency rather than by guessed importance. Foundations feed everything else, and reporting and ethics frame how every technical topic is applied. One workable sequence, assuming a six-week window:
Orientation, ethics, and foundations
- Introduction to Ethical Hacking and Cybersecurity Foundation, because later modules assume this vocabulary
- Set up a lab environment you are authorized to attack
Seeing the target
- Reconnaissance & Enumeration, then Vulnerability Scanning & Analysis, since scan output depends on enumeration
Cryptography
- Dedicate a full week; it is conceptual and benefits from slow reading rather than cramming
Attack techniques
- Web and Application Attacks, then Exploitation and Post-Exploitation
People, radio, and professionalism
- Social Engineering, Wireless Pentesting, and Reporting & Ethics
Consolidation
- Timed practice runs at 100 questions in about two hours, then review every miss against the relevant heading
For a fuller plan, see the C)PEH study guide, and for a realistic sense of effort, how hard the C)PEH exam is. You can also try timed questions on our main practice test site; the format mirrors the 100-question multiple-choice structure, though no third-party bank is real exam content. Confirm your window using our exam dates and scheduling page.
Frequently Asked Questions
C)PEH stands for Certified Professional Ethical Hacker, a credential governed and administered by Mile2. It is not the same as GAQM CPEH-001, EC-Council CEH, or Mile2's C)PTE. See what C)PEH certification is for related definitions.
The credential PDF describes 100 multiple-choice questions in approximately two hours, with a 70% minimum passing grade, delivered online through Mile2's learning-management system. Mile2 does not publish the split between scored and unscored items.
No. Mile2 expressly permits testing without purchasing its course. The Exam Combo (exam, simulator, preparation guide, two attempts) is listed at $500 sale / $795 list in search results, but confirm the live checkout price before buying.
Mile2's sources are not fully reconciled. The FAQ suggests most standard exams start on demand without a live proctor, while the policy document describes open-book delivery with live camera and screen proctoring scheduled 48 hours ahead. Confirm the rules for your specific booking before test day.
It is valid for three years. Central guidance describes 60 documented CEUs, a renewal purchase, and seven Code of Ethics questions, with an exam-based alternative also published. Because some Mile2 documents conflict, verify your route and deadline with the issuer before expiry.