C)PTE logo
Focused certification exam prep
Start practice

C)PTE Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • The Standard C)PTE exam is 100 multiple-choice questions in about two hours, with a 70% minimum passing grade.
  • The Standard exam is delivered online and on demand through your Mile2 account, without a proctor.
  • No prerequisite course is required to sit the exam; C)PEH-level knowledge and networking experience are only recommended.
  • Certification lasts three years; renewal is by 60 CEUs plus the renewal purchase and ethics compliance, or by passing the current exam.

Which C)PTE This Cheat Sheet Covers

This page covers the Mile2 Certified Penetration Testing Engineer (C)PTE), specifically the traditional Standard exam aligned to the current 2026 preparation curriculum. It is not the separate C)PTE-A accredited examination, and it has nothing to do with the Canadian Physiotherapy Examination, which sometimes surfaces in searches for the same letters. If you are still orienting yourself, the explainers on what C)PTE certification is and what C)PTE stands for give the background; this article assumes you are already committed and want the facts on one page.

Everything below is drawn from Mile2's published course outline, product listings, policies and renewal pages as checked in October 2026. Where the issuer's own pages conflict or leave something unconfirmed, this cheat sheet says so rather than guessing.

Exam Facts at a Glance

ItemStandard C)PTE
IssuerMile2
Format100 multiple-choice questions
TimeApproximately two hours
Minimum passing grade70%
DeliveryOnline, on demand, through your Mile2 account; described as unproctored for the Standard Exam Combo
Exam Combo contentsExam-preparation guide, practice quiz, two attempts
Prerequisite courseNone required to sit the exam
ValidityThree years

Two details deserve emphasis. First, this is a knowledge examination. The course labs are preparation, not a separately verified practical certification exam, so you should not expect to be graded on a live-fire engagement. Second, the exam fee for the Standard exam could not be independently confirmed from the retrievable issuer listings, so this page does not quote one. Check the Standard option on Mile2's Exam Combo page directly, and see the C)PTE certification cost breakdown for how the cost components fit together.

Read the product page, not just the pass mark: The Standard Exam Combo explicitly describes online, on-demand delivery without a proctor. Mile2's broader Policies and Procedures document (dated May 26, 2026) describes open-book testing but uses wider proctoring language. That conflict is real. Follow the instructions shown for the Standard exam in your own account, and confirm them before test day.

For a deeper look at scoring, see the C)PTE passing score guide, and for scheduling questions the exam dates and scheduling article.

The Ten Preparation Domains in One Pass

The ten domain lines below reproduce the headings in Mile2's current C)PTE Detailed Outline. They are unweighted preparation curriculum headings, not an official weighted blueprint and not a guarantee of exhaustive exam coverage. Treat them as a map of what to know, and do not assume equal question counts per domain. The full walkthrough lives in the C)PTE exam domains guide; this is the compressed version.

Domain 1: Penetration Testing Methodologies

The framing layer for everything else.

  • Authorized scope, rules of engagement and written permission before any testing
  • Phases of an engagement and how findings map to the work performed
  • Why out-of-scope discoveries get reported, not exploited

Domain 2: Advanced Recon & Attack Surface Mapping

Know what each reconnaissance technique reveals and what it risks.

  • DNS enumeration and OSINT collection
  • Service discovery and fingerprinting
  • Passive versus active reconnaissance and the footprint each leaves

Domain 3: Exploitation Techniques (Local & Remote)

Distinguish local privilege escalation from remote initial access.

  • Matching a vulnerability class to an exploitation approach
  • Local escalation paths on Windows and Linux hosts
  • Remote exploitation prerequisites and reliability considerations

Domain 4: Post-Exploitation & Lateral Movement

What happens after the foothold.

  • Credential harvesting and pivoting between hosts
  • Persistence concepts and, just as important, cleanup
  • Keeping actions inside the agreed scope while moving laterally

Domain 5: Cloud & Active Directory Exploitation

Identity is the modern perimeter.

  • Entra ID, Microsoft 365 and hybrid identity attack paths
  • Active Directory trust, delegation and privilege concepts
  • How on-premises compromise extends into cloud tenants and back

Domain 6: Evasion & Payload Crafting

Concepts in a controlled-lab context.

  • How payloads are structured and delivered
  • Why detection controls catch or miss particular techniques
  • Authorization limits on using evasion against production defenses

Domain 7: Web, API & Mobile Attacks

Authorization failures are a recurring theme.

  • Broken access control and object-level authorization in web apps and APIs
  • Session and token handling weaknesses
  • Mobile app testing concepts and where trust boundaries sit

Domain 8: Threat Simulation & Attack Chains

Thinking in sequences, not single bugs.

  • Mapping a multi-step intrusion to MITRE ATT&CK tactics
  • Choosing realistic adversary behavior for the engagement goal
  • Why chaining low-severity issues can produce high business impact

Domain 9: Purple Team Collaboration

Offense and defense working the same problem.

  • Detection validation: did the blue team see the technique, and how fast?
  • Turning test results into detection and control improvements
  • Communication norms between testers and defenders

Domain 10: Reporting & Business Risk Analysis

The deliverable is the product.

  • Separating the technical report from the executive summary
  • Rating findings by business risk, not just technical severity
  • Remediation guidance a real engineering team can act on

Scenario Patterns to Recognize

Questions on a certification exam like this tend to reward judgment, not trivia. Practice reading short situations and asking what the correct next professional action is. A few patterns worth drilling:

The scope trap

A tester discovers a neighboring subnet that was not listed in the rules of engagement. The right answer almost never involves testing it "just to see." Stop, document, and ask the client for written scope clarification. Domain 1 logic sits underneath questions from every other domain.

The hybrid identity chain

A foothold on an on-premises server leads to a synced account that holds privileged roles in a Microsoft 365 tenant. The exam-relevant skill is recognizing how hybrid identity creates a path between environments, and which report finding captures the root cause (the trust relationship and role assignment), not just the final symptom.

The authorization-versus-authentication confusion

An API returns another user's record when an identifier is changed in the request. Candidates sometimes label this an authentication problem. It is an authorization failure: the caller is legitimately logged in but is not restricted to their own objects.

The purple-team debrief

A technique succeeded but generated no alert. The productive outcome is a documented detection gap with a recommended telemetry or rule improvement, not a claim that the defenders failed. Frame findings as collaborative control validation.

The reporting audience question

You are asked what belongs in the executive summary versus the technical appendix. Executives need business impact, risk ranking and decisions required; engineers need reproduction steps, evidence and fixes.

Cleanup is testable: Post-exploitation questions often hide a cleanup angle. Removing implants, restoring modified configurations and documenting every change made is part of a professional engagement, not an optional courtesy.

Standard vs. Accredited Testing

Mile2 offers both a Standard C)PTE exam and a separate accredited C)PTE-A examination. They are different products with different rules. Mixing them up is the most common source of bad advice online.

TopicStandard C)PTEC)PTE-A (accredited)
ProctoringDescribed as unproctored, online and on demandLive proctoring applies
Passing requirement70% minimum62% (do not apply to Standard)
Scope of this pageCoveredNot covered; see Mile2's accredited-exam page

If a forum post quotes a 62% pass mark or live proctoring for "the C)PTE," check which version it means before you adjust your preparation. The pass rate discussion explains why you should also be cautious about any pass-rate number that lacks a published source.

Course Access vs. Credential Validity

Several different clocks run in parallel, and candidates routinely confuse them:

  • Exam timing: about two hours for the 100 questions. The five-day live course and its 40 course CEUs are not exam timing.
  • Course and lab access: the optional Ultimate Combo includes one-year course access, videos, a digital workbook, a lab guide, two weeks of Cyber Range access and two exam attempts. Those access windows govern how long you can study, not how long your credential lasts.
  • Exam Combo attempts: two attempts come with the Exam Combo.
  • Certification validity: three years from certification, governed by the renewal rules below.

Key Takeaway

When your Cyber Range time or course access expires, your certification does not. When your certification cycle ends, extra lab access will not extend it. Track the two separately.

Renewal Mechanics

The certification runs on a three-year validity cycle. You have two renewal routes:

  1. CEU route: document 60 CEUs, complete the applicable renewal purchase and stay compliant with Mile2's ethics and policy requirements. Mile2's FAQ quotes USD 200 for the U.S. regional CEU-route renewal fee and states that annual membership is not required.
  2. Re-examination: pass the current full certification examination.

Do not confuse that renewal fee with the price of the Standard exam; they are different line items. Because the Standard exam price was not confirmable from the retrievable listings, avoid back-solving it from renewal figures. Renewal planning also feeds into long-term value questions covered in the is C)PTE worth it analysis.

Domain-Ordered Review Plan

If you are building a short review on top of a longer study effort, order the material so each domain supports the next. This is the only generic planning section in this article, and it is tied directly to the C)PTE domain sequence. For a fuller approach, use the C)PTE study guide.

Week 1

Methodology and Reconnaissance (Domains 1-2)

  • Lock in scope, rules of engagement and authorization logic first, since it frames later questions
  • Review DNS, OSINT and service discovery, and what each leaves behind
Week 2

Exploitation and Post-Exploitation (Domains 3-4)

  • Separate local from remote exploitation
  • Practice lateral movement reasoning and cleanup steps
Week 3

Identity, Evasion and Applications (Domains 5-7)

  • Spend extra time on Entra ID, Microsoft 365 and hybrid identity paths
  • Review payload concepts and web, API and mobile authorization flaws
Week 4

Chains, Purple Team and Reporting (Domains 8-10)

  • Walk through ATT&CK-mapped attack chains end to end
  • Rehearse detection-validation outcomes and the technical-versus-executive report split
  • Finish with timed question sets in the practice test

How C)PTE Sits Next to Other Credentials

Candidates often weigh C)PTE against better-known names. Keep the comparison grounded in format and scope instead of reputation claims:

  • Versus OSCP: the Standard C)PTE exam is a multiple-choice knowledge test, while hands-on practical certifications test you in a live environment. They measure different things.
  • Versus CEH and PenTest+: all three sit in the broader security-certification space, but they come from different issuers with different outlines and exam rules. Compare the current published outlines directly rather than relying on summaries.
  • Versus C)PTE-A: same issuer, different examination rules, as covered above.

On pay, be careful. General penetration-tester salary data exists, but it is not a measured C)PTE-holder premium, and this article does not claim one. The salary guide and the C)PTE jobs overview discuss how the credential is typically positioned in job listings, and the difficulty guide helps you judge your readiness against the format.

On eligibility, recall that no prerequisite course is required to sit the exam. Mile2's suggested preparation is C)PEH or equivalent knowledge, 12 months of networking experience, sound TCP/IP knowledge, basic Linux knowledge and Microsoft security experience. These are recommendations, not gates. See C)PTE requirements for the full picture, and C)PTE training options if you want structured preparation.

FAQ

How many questions are on the Standard C)PTE exam?

The current course outline specifies 100 multiple-choice questions with an approximately two-hour time allowance and a minimum passing grade of 70%.

Is the Standard C)PTE exam proctored?

The Standard Exam Combo explicitly describes online, on-demand delivery through your Mile2 account without a proctor. Mile2's general Policies and Procedures uses broader proctoring language, so confirm the instructions shown for your own exam before test day. Do not assume the live proctoring that applies to C)PTE-A.

Do I have to take the course before the exam?

No. No prerequisite course is required to sit the certification exam. Mile2 suggests C)PEH or equivalent knowledge, 12 months of networking experience, TCP/IP knowledge, basic Linux knowledge and Microsoft security experience, but these are recommendations.

How long does the certification last, and how do I renew?

Certification has a three-year validity cycle. You can renew with 60 documented CEUs, the applicable renewal purchase and ethics/policy compliance, or by passing the current full certification examination. Mile2's FAQ quotes USD 200 for the U.S. regional CEU-route renewal fee.

Are the ten domains weighted like a formal exam blueprint?

No. The ten domain lines reproduce the headings in Mile2's current Detailed Outline. They are unweighted preparation curriculum headings, so do not infer question counts per domain or assume exhaustive coverage of every subtopic.

Ready to pass your C)PTE exam?

Put this into practice with free C)PTE questions across every exam domain.