C)PTE logo
Focused certification exam prep
Start practice

C)PTE Exam Domains 2026: Complete Guide to All 10 Content Areas

TL;DR
  • Mile2's 2026 C)PTE outline lists ten unweighted domain headings; they are preparation topics, not an official weighted blueprint.
  • The Standard exam is described as 100 multiple-choice questions, roughly two hours, with a 70% minimum passing grade.
  • No prerequisite course is required to sit the exam, though C)PEH-level knowledge and networking experience are strongly suggested.
  • The Standard exam is not the separate C)PTE-A accredited exam, so do not import its proctoring or 62% rules.

What the Ten Domains Actually Are

The Certified Penetration Testing Engineer (C)PTE) from Mile2 is organized around ten content areas drawn from the Detailed Outline on pages 4-5 of Mile2's current C)PTE course outline PDF. Mile2 identifies the course-and-exam update as 2026 on its launch pages. Before you build a study plan around those ten headings, understand what they are and what they are not.

They are unweighted preparation curriculum headings. Mile2 does not publish a percentage per domain in the material we reviewed, and the outline is not presented as an official ten-domain examination count or a guarantee of exhaustive exam coverage. Any resource that tells you "Domain 4 is 18% of the exam" is inventing a number. Treat all ten as fair game and weight your time by your own gaps rather than by a made-up blueprint.

This also means older material is a trap. Earlier C)PTE course versions used a longer module list, and the separate accredited C)PTE-A has its own blueprint. Neither maps onto the ten headings below. If you are new to the credential, start with what C)PTE certification is and then return here.

Not the Physiotherapy Exam: This guide covers the Mile2 Certified Penetration Testing Engineer only. The acronym is shared with other unrelated credentials, including the Canadian Physiotherapy Examination, so skip any source that does not name Mile2 and penetration testing.

Exam Format, Delivery and Policy Conflicts

The current course outline specifies 100 multiple-choice questions, approximately two hours, and a minimum passing grade of 70%. That is a knowledge examination. The labs in the course are preparation, not a separately verified practical certification exam, so do not expect to be handed a live network to compromise. For a deeper look at the score, see our breakdown of the C)PTE passing score.

The Standard Exam Combo explicitly describes online, on-demand delivery through your Mile2 account without a proctor. It includes an exam-preparation guide, a practice quiz and two attempts. We could not independently confirm the Standard exam price from retrievable issuer listings, so check the product page directly; our C)PTE certification cost guide explains how to separate the exam fee from optional training bundles.

A documented policy tension: Mile2's general Policies and Procedures document (dated May 26, 2026) describes open-book testing but uses broader proctoring language than the Standard product page's explicit unproctored statement. Follow the instructions shown on your own exam voucher and account, and confirm with Mile2 support if anything on screen disagrees with what you expected.

Domains 1-2: Methodology and Reconnaissance

Domain 1: Penetration Testing Methodologies

This domain frames everything else. Expect questions about how an engagement is scoped, authorized and structured before any packet is sent.

  • Authorization, scope documents and rules of engagement: what you may touch, when, and from where
  • Phases of an engagement and how findings flow from one phase into the next
  • Legal and ethical boundaries, including what to do when you discover something outside scope

Scenario to practice: Mid-test, you find credentials that also work on a system owned by a third party that is not in your scope letter. The correct answer is almost always to stop, document and escalate to the client contact, not to "just verify" access.

Domain 2: Advanced Recon & Attack Surface Mapping

Reconnaissance questions reward candidates who know what each technique reveals and how noisy it is.

  • DNS enumeration: zone data, record types, subdomain discovery and what misconfigurations expose
  • OSINT: employee, technology and infrastructure information gathered without touching the target
  • Service reconnaissance: port and service identification, banner interpretation and version inference

Scenario to practice: You are handed a company name and a scope of one domain. Decide which passive sources you would query first, which active scans fall inside scope, and how you would map the resulting attack surface into a prioritized target list.

Domains 3-4: Exploitation and Post-Exploitation

Domain 3: Exploitation Techniques (Local & Remote)

This is the core of the certification. The recommended background (C)PEH or equivalent knowledge, sound TCP/IP understanding and basic Linux skills) pays off most here.

  • Remote exploitation of exposed services versus local privilege escalation after a foothold
  • Selecting an exploit based on service version, configuration and operating system
  • Understanding why an exploit fails, such as patch level, architecture mismatch or host defenses

Domain 4: Post-Exploitation & Lateral Movement

Getting in is only the midpoint. This domain tests what a professional does next, and what they clean up afterward.

  • Situational awareness on a compromised host: users, network position, trust relationships
  • Credential harvesting and reuse, pivoting and moving between systems
  • Persistence concepts and, just as importantly, cleanup and restoration of the client environment

Scenario to practice: After compromising a workstation, you need to reach a segmented server. Reason through how you would identify a pivot path, what evidence you would preserve for the report, and how you would remove artifacts at the end of the engagement.

Domains 5-6: Cloud/AD and Evasion

Domain 5: Cloud & Active Directory Exploitation

Modern enterprises are hybrid, and the outline reflects that. Study on-premises Active Directory and the cloud identity layer that now sits on top of it.

  • Active Directory attack paths: enumeration, credential abuse and privilege escalation toward domain-level control
  • Entra ID and Microsoft 365 identity concepts, including tenant misconfiguration and over-permissioned accounts
  • Hybrid identity, where a weakness on-premises can become access in the cloud, and vice versa

Scenario to practice: A synchronized account has weak protection on-premises but holds a privileged role in the Microsoft 365 tenant. Trace how compromising the former yields the latter, and what control would break the chain.

Domain 6: Evasion & Payload Crafting

Approach this domain at the concept level. The aim is understanding why defenses catch or miss activity, within a controlled lab.

  • How payloads are built and delivered, and what makes one more detectable than another
  • Common defensive controls (signature detection, behavioral monitoring) and the general ideas behind bypassing them
  • Why testers must keep payload use inside authorized, controlled environments

Domains 7-8: Web/API/Mobile and Attack Chains

Domain 7: Web, API & Mobile Attacks

The unifying theme is authorization: who is allowed to see or change what, and where the application forgets to check.

  • Web application flaws such as injection, broken access control and session handling weaknesses
  • API issues, especially object-level and function-level authorization failures
  • Mobile application testing concepts, including insecure storage and weak communication with back-end services

Scenario to practice: An API returns another customer's record when you change an identifier in the request. Classify the flaw, explain the business impact, and describe the fix at the authorization layer rather than the input-filtering layer.

Domain 8: Threat Simulation & Attack Chains

Here individual techniques are strung together the way a real adversary would, commonly described using the MITRE ATT&CK framework.

  • Mapping techniques to ATT&CK tactics from initial access through objectives
  • Building a coherent chain: phishing foothold, credential access, lateral movement, data access
  • Emulating a defined threat actor's behavior rather than running tools at random

Domains 9-10: Purple Team and Reporting

Domain 9: Purple Team Collaboration

Purple teaming turns an attack into a measurable defensive improvement.

  • Running an agreed technique and checking whether the blue team's tooling detected, alerted or blocked it
  • Documenting detection gaps and tuning rules with the defenders
  • Repeating the test to confirm that a fix actually works

Domain 10: Reporting & Business Risk Analysis

Many technically strong candidates underprepare for this domain, yet reporting is where an engagement delivers its value.

  • Technical findings with reproduction steps, evidence and remediation guidance
  • Executive summaries that translate vulnerabilities into business risk and priorities
  • Risk ranking that reflects likelihood and impact, not just a scanner's severity label
Why Domain 10 matters for hiring: Employers of penetration testers care about the deliverable. Our look at C)PTE jobs covers the roles where report quality is part of the day-to-day work. We do not claim a measured salary premium for holders of this specific credential; general penetration-tester pay data should not be read as one. See the C)PTE salary guide for how to interpret the numbers responsibly.

Sequencing the Domains in a Study Plan

Because the outline is unweighted, order your study by dependency rather than by exam percentage. Reconnaissance and methodology make later exploitation questions easier to reason about, and the later chain and reporting domains reuse everything before them. The plan below is a sample; see the full C)PTE study guide for broader methods.

Week 1

Foundations: Domains 1-2

  • Scope, rules of engagement and legal boundaries
  • DNS, OSINT and service reconnaissance in a lab
Week 2

Getting In and Moving: Domains 3-4

  • Local and remote exploitation reasoning
  • Pivoting, credential reuse and cleanup
Week 3

Identity and Evasion: Domains 5-6

  • Active Directory and Entra ID/Microsoft 365 attack paths
  • Payload concepts and defensive controls
Week 4

Applications and Chains: Domains 7-8

  • Web, API and mobile authorization flaws
  • ATT&CK-mapped attack chains
Week 5

Defense and Delivery: Domains 9-10, then review

  • Purple-team detection validation and report writing
  • Timed practice runs across all ten domains

If you are concerned about difficulty, read how hard the C)PTE exam is and the notes on pass rate; Mile2 does not publish a verified pass rate in the sources we reviewed, so be skeptical of any specific figure. When you are ready to test yourself on question style, use our C)PTE practice tests, and keep the C)PTE cheat sheet handy for last-minute review.

Standard vs. Accredited, and Course vs. Credential

Three distinctions trip up candidates more than any domain does.

TopicWhat applies to Standard C)PTECommon mix-up
Exam variantStandard exam: 100 questions, about two hours, 70% minimumThe separate C)PTE-A accredited exam has its own proctoring and a different passing requirement
PrerequisitesNo prerequisite course required to sit the exam; C)PEH or equivalent, 12 months of networking, TCP/IP, basic Linux and Microsoft security experience are suggestedTreating "recommended" as "required"
Course accessThe optional Ultimate Combo includes one-year course access, videos, a digital workbook, a lab guide, two weeks of Cyber Range access and two exam attemptsConfusing course, lab or voucher access periods with how long the certification is valid

Likewise, the five-day live course and its 40 course CEUs describe training, not exam timing. For eligibility details, read our C)PTE requirements guide, and check C)PTE exam dates for how on-demand scheduling works.

Validity and Renewal

The certification has a three-year validity cycle. You can renew through 60 documented CEUs, the applicable renewal purchase and compliance with ethics and policy requirements, or by passing the current full certification examination. Mile2's FAQ quotes USD 200 for the U.S. regional CEU-route renewal fee and states that annual membership is not required. Confirm the current amount for your region on Mile2's renewal pages before you budget, and keep this separate from your course or lab access window. To judge whether the whole path is worthwhile, see whether the C)PTE is worth it.

Frequently Asked Questions

Are the ten domains weighted on the C)PTE exam?

Not in the sources we reviewed. The ten headings come from Mile2's detailed course outline and are unweighted preparation topics, not an official weighted blueprint, so study all of them.

Is the C)PTE a hands-on practical exam?

The Standard exam is described as 100 multiple-choice questions over roughly two hours. Course labs help you prepare but are not a separately verified practical certification exam.

Do I need to take the course before sitting the exam?

No. Mile2 does not require a prerequisite course to sit the exam, although C)PEH or equivalent knowledge, networking experience, TCP/IP, Linux and Microsoft security familiarity are suggested.

How is the Standard C)PTE different from C)PTE-A?

C)PTE-A is a separate accredited examination with its own blueprint, live proctoring and passing requirement. Those rules do not apply to the Standard C)PTE, which uses the 70% minimum and unproctored delivery described on its product page.

How long does the certification last?

It runs on a three-year cycle. Renew with 60 documented CEUs plus the applicable renewal purchase and policy compliance, or pass the current full certification exam.

Ready to pass your C)PTE exam?

Put this into practice with free C)PTE questions across every exam domain.