- What the Ten Domains Actually Are
- Exam Format, Delivery and Policy Conflicts
- Domains 1-2: Methodology and Reconnaissance
- Domains 3-4: Exploitation and Post-Exploitation
- Domains 5-6: Cloud/AD and Evasion
- Domains 7-8: Web/API/Mobile and Attack Chains
- Domains 9-10: Purple Team and Reporting
- Sequencing the Domains in a Study Plan
- Standard vs. Accredited, and Course vs. Credential
- Validity and Renewal
- Frequently Asked Questions
- Mile2's 2026 C)PTE outline lists ten unweighted domain headings; they are preparation topics, not an official weighted blueprint.
- The Standard exam is described as 100 multiple-choice questions, roughly two hours, with a 70% minimum passing grade.
- No prerequisite course is required to sit the exam, though C)PEH-level knowledge and networking experience are strongly suggested.
- The Standard exam is not the separate C)PTE-A accredited exam, so do not import its proctoring or 62% rules.
What the Ten Domains Actually Are
The Certified Penetration Testing Engineer (C)PTE) from Mile2 is organized around ten content areas drawn from the Detailed Outline on pages 4-5 of Mile2's current C)PTE course outline PDF. Mile2 identifies the course-and-exam update as 2026 on its launch pages. Before you build a study plan around those ten headings, understand what they are and what they are not.
They are unweighted preparation curriculum headings. Mile2 does not publish a percentage per domain in the material we reviewed, and the outline is not presented as an official ten-domain examination count or a guarantee of exhaustive exam coverage. Any resource that tells you "Domain 4 is 18% of the exam" is inventing a number. Treat all ten as fair game and weight your time by your own gaps rather than by a made-up blueprint.
This also means older material is a trap. Earlier C)PTE course versions used a longer module list, and the separate accredited C)PTE-A has its own blueprint. Neither maps onto the ten headings below. If you are new to the credential, start with what C)PTE certification is and then return here.
Exam Format, Delivery and Policy Conflicts
The current course outline specifies 100 multiple-choice questions, approximately two hours, and a minimum passing grade of 70%. That is a knowledge examination. The labs in the course are preparation, not a separately verified practical certification exam, so do not expect to be handed a live network to compromise. For a deeper look at the score, see our breakdown of the C)PTE passing score.
The Standard Exam Combo explicitly describes online, on-demand delivery through your Mile2 account without a proctor. It includes an exam-preparation guide, a practice quiz and two attempts. We could not independently confirm the Standard exam price from retrievable issuer listings, so check the product page directly; our C)PTE certification cost guide explains how to separate the exam fee from optional training bundles.
Domains 1-2: Methodology and Reconnaissance
Domain 1: Penetration Testing Methodologies
This domain frames everything else. Expect questions about how an engagement is scoped, authorized and structured before any packet is sent.
- Authorization, scope documents and rules of engagement: what you may touch, when, and from where
- Phases of an engagement and how findings flow from one phase into the next
- Legal and ethical boundaries, including what to do when you discover something outside scope
Scenario to practice: Mid-test, you find credentials that also work on a system owned by a third party that is not in your scope letter. The correct answer is almost always to stop, document and escalate to the client contact, not to "just verify" access.
Domain 2: Advanced Recon & Attack Surface Mapping
Reconnaissance questions reward candidates who know what each technique reveals and how noisy it is.
- DNS enumeration: zone data, record types, subdomain discovery and what misconfigurations expose
- OSINT: employee, technology and infrastructure information gathered without touching the target
- Service reconnaissance: port and service identification, banner interpretation and version inference
Scenario to practice: You are handed a company name and a scope of one domain. Decide which passive sources you would query first, which active scans fall inside scope, and how you would map the resulting attack surface into a prioritized target list.
Domains 3-4: Exploitation and Post-Exploitation
Domain 3: Exploitation Techniques (Local & Remote)
This is the core of the certification. The recommended background (C)PEH or equivalent knowledge, sound TCP/IP understanding and basic Linux skills) pays off most here.
- Remote exploitation of exposed services versus local privilege escalation after a foothold
- Selecting an exploit based on service version, configuration and operating system
- Understanding why an exploit fails, such as patch level, architecture mismatch or host defenses
Domain 4: Post-Exploitation & Lateral Movement
Getting in is only the midpoint. This domain tests what a professional does next, and what they clean up afterward.
- Situational awareness on a compromised host: users, network position, trust relationships
- Credential harvesting and reuse, pivoting and moving between systems
- Persistence concepts and, just as importantly, cleanup and restoration of the client environment
Scenario to practice: After compromising a workstation, you need to reach a segmented server. Reason through how you would identify a pivot path, what evidence you would preserve for the report, and how you would remove artifacts at the end of the engagement.
Domains 5-6: Cloud/AD and Evasion
Domain 5: Cloud & Active Directory Exploitation
Modern enterprises are hybrid, and the outline reflects that. Study on-premises Active Directory and the cloud identity layer that now sits on top of it.
- Active Directory attack paths: enumeration, credential abuse and privilege escalation toward domain-level control
- Entra ID and Microsoft 365 identity concepts, including tenant misconfiguration and over-permissioned accounts
- Hybrid identity, where a weakness on-premises can become access in the cloud, and vice versa
Scenario to practice: A synchronized account has weak protection on-premises but holds a privileged role in the Microsoft 365 tenant. Trace how compromising the former yields the latter, and what control would break the chain.
Domain 6: Evasion & Payload Crafting
Approach this domain at the concept level. The aim is understanding why defenses catch or miss activity, within a controlled lab.
- How payloads are built and delivered, and what makes one more detectable than another
- Common defensive controls (signature detection, behavioral monitoring) and the general ideas behind bypassing them
- Why testers must keep payload use inside authorized, controlled environments
Domains 7-8: Web/API/Mobile and Attack Chains
Domain 7: Web, API & Mobile Attacks
The unifying theme is authorization: who is allowed to see or change what, and where the application forgets to check.
- Web application flaws such as injection, broken access control and session handling weaknesses
- API issues, especially object-level and function-level authorization failures
- Mobile application testing concepts, including insecure storage and weak communication with back-end services
Scenario to practice: An API returns another customer's record when you change an identifier in the request. Classify the flaw, explain the business impact, and describe the fix at the authorization layer rather than the input-filtering layer.
Domain 8: Threat Simulation & Attack Chains
Here individual techniques are strung together the way a real adversary would, commonly described using the MITRE ATT&CK framework.
- Mapping techniques to ATT&CK tactics from initial access through objectives
- Building a coherent chain: phishing foothold, credential access, lateral movement, data access
- Emulating a defined threat actor's behavior rather than running tools at random
Domains 9-10: Purple Team and Reporting
Domain 9: Purple Team Collaboration
Purple teaming turns an attack into a measurable defensive improvement.
- Running an agreed technique and checking whether the blue team's tooling detected, alerted or blocked it
- Documenting detection gaps and tuning rules with the defenders
- Repeating the test to confirm that a fix actually works
Domain 10: Reporting & Business Risk Analysis
Many technically strong candidates underprepare for this domain, yet reporting is where an engagement delivers its value.
- Technical findings with reproduction steps, evidence and remediation guidance
- Executive summaries that translate vulnerabilities into business risk and priorities
- Risk ranking that reflects likelihood and impact, not just a scanner's severity label
Sequencing the Domains in a Study Plan
Because the outline is unweighted, order your study by dependency rather than by exam percentage. Reconnaissance and methodology make later exploitation questions easier to reason about, and the later chain and reporting domains reuse everything before them. The plan below is a sample; see the full C)PTE study guide for broader methods.
Foundations: Domains 1-2
- Scope, rules of engagement and legal boundaries
- DNS, OSINT and service reconnaissance in a lab
Getting In and Moving: Domains 3-4
- Local and remote exploitation reasoning
- Pivoting, credential reuse and cleanup
Identity and Evasion: Domains 5-6
- Active Directory and Entra ID/Microsoft 365 attack paths
- Payload concepts and defensive controls
Applications and Chains: Domains 7-8
- Web, API and mobile authorization flaws
- ATT&CK-mapped attack chains
Defense and Delivery: Domains 9-10, then review
- Purple-team detection validation and report writing
- Timed practice runs across all ten domains
If you are concerned about difficulty, read how hard the C)PTE exam is and the notes on pass rate; Mile2 does not publish a verified pass rate in the sources we reviewed, so be skeptical of any specific figure. When you are ready to test yourself on question style, use our C)PTE practice tests, and keep the C)PTE cheat sheet handy for last-minute review.
Standard vs. Accredited, and Course vs. Credential
Three distinctions trip up candidates more than any domain does.
| Topic | What applies to Standard C)PTE | Common mix-up |
|---|---|---|
| Exam variant | Standard exam: 100 questions, about two hours, 70% minimum | The separate C)PTE-A accredited exam has its own proctoring and a different passing requirement |
| Prerequisites | No prerequisite course required to sit the exam; C)PEH or equivalent, 12 months of networking, TCP/IP, basic Linux and Microsoft security experience are suggested | Treating "recommended" as "required" |
| Course access | The optional Ultimate Combo includes one-year course access, videos, a digital workbook, a lab guide, two weeks of Cyber Range access and two exam attempts | Confusing course, lab or voucher access periods with how long the certification is valid |
Likewise, the five-day live course and its 40 course CEUs describe training, not exam timing. For eligibility details, read our C)PTE requirements guide, and check C)PTE exam dates for how on-demand scheduling works.
Validity and Renewal
The certification has a three-year validity cycle. You can renew through 60 documented CEUs, the applicable renewal purchase and compliance with ethics and policy requirements, or by passing the current full certification examination. Mile2's FAQ quotes USD 200 for the U.S. regional CEU-route renewal fee and states that annual membership is not required. Confirm the current amount for your region on Mile2's renewal pages before you budget, and keep this separate from your course or lab access window. To judge whether the whole path is worthwhile, see whether the C)PTE is worth it.
Frequently Asked Questions
Not in the sources we reviewed. The ten headings come from Mile2's detailed course outline and are unweighted preparation topics, not an official weighted blueprint, so study all of them.
The Standard exam is described as 100 multiple-choice questions over roughly two hours. Course labs help you prepare but are not a separately verified practical certification exam.
No. Mile2 does not require a prerequisite course to sit the exam, although C)PEH or equivalent knowledge, networking experience, TCP/IP, Linux and Microsoft security familiarity are suggested.
C)PTE-A is a separate accredited examination with its own blueprint, live proctoring and passing requirement. Those rules do not apply to the Standard C)PTE, which uses the 70% minimum and unproctored delivery described on its product page.
It runs on a three-year cycle. Renew with 60 documented CEUs plus the applicable renewal purchase and policy compliance, or pass the current full certification exam.