- The Standard C)PTE exam is 100 multiple-choice questions in about two hours, with a 70% minimum passing grade.
- The Standard exam is delivered online and on demand through your Mile2 account, without a proctor.
- No prerequisite course is required to sit the exam; C)PEH-level knowledge and networking experience are only recommended.
- Certification lasts three years; renewal is by 60 CEUs plus the renewal purchase and ethics compliance, or by passing the current exam.
Which C)PTE This Cheat Sheet Covers
This page covers the Mile2 Certified Penetration Testing Engineer (C)PTE), specifically the traditional Standard exam aligned to the current 2026 preparation curriculum. It is not the separate C)PTE-A accredited examination, and it has nothing to do with the Canadian Physiotherapy Examination, which sometimes surfaces in searches for the same letters. If you are still orienting yourself, the explainers on what C)PTE certification is and what C)PTE stands for give the background; this article assumes you are already committed and want the facts on one page.
Everything below is drawn from Mile2's published course outline, product listings, policies and renewal pages as checked in October 2026. Where the issuer's own pages conflict or leave something unconfirmed, this cheat sheet says so rather than guessing.
Exam Facts at a Glance
| Item | Standard C)PTE |
|---|---|
| Issuer | Mile2 |
| Format | 100 multiple-choice questions |
| Time | Approximately two hours |
| Minimum passing grade | 70% |
| Delivery | Online, on demand, through your Mile2 account; described as unproctored for the Standard Exam Combo |
| Exam Combo contents | Exam-preparation guide, practice quiz, two attempts |
| Prerequisite course | None required to sit the exam |
| Validity | Three years |
Two details deserve emphasis. First, this is a knowledge examination. The course labs are preparation, not a separately verified practical certification exam, so you should not expect to be graded on a live-fire engagement. Second, the exam fee for the Standard exam could not be independently confirmed from the retrievable issuer listings, so this page does not quote one. Check the Standard option on Mile2's Exam Combo page directly, and see the C)PTE certification cost breakdown for how the cost components fit together.
For a deeper look at scoring, see the C)PTE passing score guide, and for scheduling questions the exam dates and scheduling article.
The Ten Preparation Domains in One Pass
The ten domain lines below reproduce the headings in Mile2's current C)PTE Detailed Outline. They are unweighted preparation curriculum headings, not an official weighted blueprint and not a guarantee of exhaustive exam coverage. Treat them as a map of what to know, and do not assume equal question counts per domain. The full walkthrough lives in the C)PTE exam domains guide; this is the compressed version.
Domain 1: Penetration Testing Methodologies
The framing layer for everything else.
- Authorized scope, rules of engagement and written permission before any testing
- Phases of an engagement and how findings map to the work performed
- Why out-of-scope discoveries get reported, not exploited
Domain 2: Advanced Recon & Attack Surface Mapping
Know what each reconnaissance technique reveals and what it risks.
- DNS enumeration and OSINT collection
- Service discovery and fingerprinting
- Passive versus active reconnaissance and the footprint each leaves
Domain 3: Exploitation Techniques (Local & Remote)
Distinguish local privilege escalation from remote initial access.
- Matching a vulnerability class to an exploitation approach
- Local escalation paths on Windows and Linux hosts
- Remote exploitation prerequisites and reliability considerations
Domain 4: Post-Exploitation & Lateral Movement
What happens after the foothold.
- Credential harvesting and pivoting between hosts
- Persistence concepts and, just as important, cleanup
- Keeping actions inside the agreed scope while moving laterally
Domain 5: Cloud & Active Directory Exploitation
Identity is the modern perimeter.
- Entra ID, Microsoft 365 and hybrid identity attack paths
- Active Directory trust, delegation and privilege concepts
- How on-premises compromise extends into cloud tenants and back
Domain 6: Evasion & Payload Crafting
Concepts in a controlled-lab context.
- How payloads are structured and delivered
- Why detection controls catch or miss particular techniques
- Authorization limits on using evasion against production defenses
Domain 7: Web, API & Mobile Attacks
Authorization failures are a recurring theme.
- Broken access control and object-level authorization in web apps and APIs
- Session and token handling weaknesses
- Mobile app testing concepts and where trust boundaries sit
Domain 8: Threat Simulation & Attack Chains
Thinking in sequences, not single bugs.
- Mapping a multi-step intrusion to MITRE ATT&CK tactics
- Choosing realistic adversary behavior for the engagement goal
- Why chaining low-severity issues can produce high business impact
Domain 9: Purple Team Collaboration
Offense and defense working the same problem.
- Detection validation: did the blue team see the technique, and how fast?
- Turning test results into detection and control improvements
- Communication norms between testers and defenders
Domain 10: Reporting & Business Risk Analysis
The deliverable is the product.
- Separating the technical report from the executive summary
- Rating findings by business risk, not just technical severity
- Remediation guidance a real engineering team can act on
Scenario Patterns to Recognize
Questions on a certification exam like this tend to reward judgment, not trivia. Practice reading short situations and asking what the correct next professional action is. A few patterns worth drilling:
The scope trap
A tester discovers a neighboring subnet that was not listed in the rules of engagement. The right answer almost never involves testing it "just to see." Stop, document, and ask the client for written scope clarification. Domain 1 logic sits underneath questions from every other domain.
The hybrid identity chain
A foothold on an on-premises server leads to a synced account that holds privileged roles in a Microsoft 365 tenant. The exam-relevant skill is recognizing how hybrid identity creates a path between environments, and which report finding captures the root cause (the trust relationship and role assignment), not just the final symptom.
The authorization-versus-authentication confusion
An API returns another user's record when an identifier is changed in the request. Candidates sometimes label this an authentication problem. It is an authorization failure: the caller is legitimately logged in but is not restricted to their own objects.
The purple-team debrief
A technique succeeded but generated no alert. The productive outcome is a documented detection gap with a recommended telemetry or rule improvement, not a claim that the defenders failed. Frame findings as collaborative control validation.
The reporting audience question
You are asked what belongs in the executive summary versus the technical appendix. Executives need business impact, risk ranking and decisions required; engineers need reproduction steps, evidence and fixes.
Standard vs. Accredited Testing
Mile2 offers both a Standard C)PTE exam and a separate accredited C)PTE-A examination. They are different products with different rules. Mixing them up is the most common source of bad advice online.
| Topic | Standard C)PTE | C)PTE-A (accredited) |
|---|---|---|
| Proctoring | Described as unproctored, online and on demand | Live proctoring applies |
| Passing requirement | 70% minimum | 62% (do not apply to Standard) |
| Scope of this page | Covered | Not covered; see Mile2's accredited-exam page |
If a forum post quotes a 62% pass mark or live proctoring for "the C)PTE," check which version it means before you adjust your preparation. The pass rate discussion explains why you should also be cautious about any pass-rate number that lacks a published source.
Course Access vs. Credential Validity
Several different clocks run in parallel, and candidates routinely confuse them:
- Exam timing: about two hours for the 100 questions. The five-day live course and its 40 course CEUs are not exam timing.
- Course and lab access: the optional Ultimate Combo includes one-year course access, videos, a digital workbook, a lab guide, two weeks of Cyber Range access and two exam attempts. Those access windows govern how long you can study, not how long your credential lasts.
- Exam Combo attempts: two attempts come with the Exam Combo.
- Certification validity: three years from certification, governed by the renewal rules below.
Key Takeaway
When your Cyber Range time or course access expires, your certification does not. When your certification cycle ends, extra lab access will not extend it. Track the two separately.
Renewal Mechanics
The certification runs on a three-year validity cycle. You have two renewal routes:
- CEU route: document 60 CEUs, complete the applicable renewal purchase and stay compliant with Mile2's ethics and policy requirements. Mile2's FAQ quotes USD 200 for the U.S. regional CEU-route renewal fee and states that annual membership is not required.
- Re-examination: pass the current full certification examination.
Do not confuse that renewal fee with the price of the Standard exam; they are different line items. Because the Standard exam price was not confirmable from the retrievable listings, avoid back-solving it from renewal figures. Renewal planning also feeds into long-term value questions covered in the is C)PTE worth it analysis.
Domain-Ordered Review Plan
If you are building a short review on top of a longer study effort, order the material so each domain supports the next. This is the only generic planning section in this article, and it is tied directly to the C)PTE domain sequence. For a fuller approach, use the C)PTE study guide.
Methodology and Reconnaissance (Domains 1-2)
- Lock in scope, rules of engagement and authorization logic first, since it frames later questions
- Review DNS, OSINT and service discovery, and what each leaves behind
Exploitation and Post-Exploitation (Domains 3-4)
- Separate local from remote exploitation
- Practice lateral movement reasoning and cleanup steps
Identity, Evasion and Applications (Domains 5-7)
- Spend extra time on Entra ID, Microsoft 365 and hybrid identity paths
- Review payload concepts and web, API and mobile authorization flaws
Chains, Purple Team and Reporting (Domains 8-10)
- Walk through ATT&CK-mapped attack chains end to end
- Rehearse detection-validation outcomes and the technical-versus-executive report split
- Finish with timed question sets in the practice test
How C)PTE Sits Next to Other Credentials
Candidates often weigh C)PTE against better-known names. Keep the comparison grounded in format and scope instead of reputation claims:
- Versus OSCP: the Standard C)PTE exam is a multiple-choice knowledge test, while hands-on practical certifications test you in a live environment. They measure different things.
- Versus CEH and PenTest+: all three sit in the broader security-certification space, but they come from different issuers with different outlines and exam rules. Compare the current published outlines directly rather than relying on summaries.
- Versus C)PTE-A: same issuer, different examination rules, as covered above.
On pay, be careful. General penetration-tester salary data exists, but it is not a measured C)PTE-holder premium, and this article does not claim one. The salary guide and the C)PTE jobs overview discuss how the credential is typically positioned in job listings, and the difficulty guide helps you judge your readiness against the format.
On eligibility, recall that no prerequisite course is required to sit the exam. Mile2's suggested preparation is C)PEH or equivalent knowledge, 12 months of networking experience, sound TCP/IP knowledge, basic Linux knowledge and Microsoft security experience. These are recommendations, not gates. See C)PTE requirements for the full picture, and C)PTE training options if you want structured preparation.
FAQ
The current course outline specifies 100 multiple-choice questions with an approximately two-hour time allowance and a minimum passing grade of 70%.
The Standard Exam Combo explicitly describes online, on-demand delivery through your Mile2 account without a proctor. Mile2's general Policies and Procedures uses broader proctoring language, so confirm the instructions shown for your own exam before test day. Do not assume the live proctoring that applies to C)PTE-A.
No. No prerequisite course is required to sit the certification exam. Mile2 suggests C)PEH or equivalent knowledge, 12 months of networking experience, TCP/IP knowledge, basic Linux knowledge and Microsoft security experience, but these are recommendations.
Certification has a three-year validity cycle. You can renew with 60 documented CEUs, the applicable renewal purchase and ethics/policy compliance, or by passing the current full certification examination. Mile2's FAQ quotes USD 200 for the U.S. regional CEU-route renewal fee.
No. The ten domain lines reproduce the headings in Mile2's current Detailed Outline. They are unweighted preparation curriculum headings, so do not infer question counts per domain or assume exhaustive coverage of every subtopic.