- What You Are Actually Preparing For
- Format, Delivery and the Proctoring Question
- Recommended Experience Versus Required Training
- The Ten Curriculum Domains and How to Study Them
- Scenario Drills Worth Building
- A Domain-Ordered Study Sequence
- Standard C)PTE Versus the Accredited Exam
- Fees, Access Periods and Credential Validity
- Where the Credential Fits in the Job Market
- Frequently Asked Questions
- The Standard C)PTE exam is 100 multiple-choice questions in roughly two hours, with a 70% minimum passing grade.
- No prerequisite course is required to sit the exam, though C)PEH-level knowledge and networking experience are strongly suggested.
- The Standard Exam Combo describes online, on-demand delivery without a proctor; C)PTE-A rules are different.
- Mile2's ten curriculum headings are unweighted, so distribute study time by your own weak spots.
What You Are Actually Preparing For
The Certified Penetration Testing Engineer, written C)PTE, is a Mile2 credential aimed at people who perform authorized offensive security work. Before you open a single study resource, confirm which exam you are targeting, because the acronym is shared with unrelated credentials and the Canadian Physiotherapy Examination uses a similar abbreviation in a completely different profession. Everything in this guide concerns the Mile2 Standard C)PTE, using the 2026 preparation curriculum. It does not cover the separate C)PTE-A accredited examination, and it should not be mixed with material from any other certification that happens to share the letters.
If you are still orienting yourself, the explainer pages on what C)PTE certification is and what C)PTE stands for cover the basics. This article assumes you have decided to pursue it and want a practical path to a first-attempt pass.
Format, Delivery and the Proctoring Question
According to Mile2's current course outline, the Standard exam consists of 100 multiple-choice questions, runs approximately two hours, and requires a minimum passing grade of 70%. That is a knowledge examination. It is not a hands-on practical, even though the course itself includes labs. Those labs are preparation; they are not a separately verified practical certification exam. For a deeper look at scoring, see our breakdown of the C)PTE passing score.
The Standard Exam Combo explicitly describes online, on-demand delivery through your Mile2 account without a proctor. It includes an exam-preparation guide, a practice quiz and two attempts. That is the product description you should plan around.
There is a wrinkle worth knowing. Mile2's general Policies and Procedures document, dated May 26, 2026, describes open-book testing but uses broader proctoring language than the Standard product page does. Those two sources do not perfectly align, and this guide does not pretend otherwise. The safe approach: follow the instructions shown inside your own exam purchase and account, read the policy document before test day, and contact Mile2 if anything on the exam screen contradicts what you expected. Do not import rules from the accredited exam, which has its own live proctoring and a different passing requirement.
Recommended Experience Versus Required Training
This distinction trips up many candidates. Mile2 does not require a prerequisite course to sit the certification exam. Anyone may attempt it. However, Mile2 suggests preparation that includes:
- C)PEH knowledge or equivalent ethical hacking foundations
- Around 12 months of networking experience
- Sound TCP/IP knowledge
- Basic Linux familiarity
- Microsoft security experience
Treat that list as a diagnostic, not a gate. If you cannot explain how a three-way handshake works, read a packet capture, or navigate a Linux shell comfortably, the exam's exploitation and post-exploitation topics will feel like memorization rather than understanding. The Microsoft security recommendation is especially relevant in 2026 because the curriculum devotes an entire domain to cloud and Active Directory exploitation. More detail on eligibility lives in our C)PTE requirements guide.
The Ten Curriculum Domains and How to Study Them
The ten domain headings below reproduce Mile2's current Detailed Outline for the Certified Penetration Testing Engineer course (pages 4-5 of the outline PDF linked from the course outline page). They are unweighted preparation headings. Mile2 does not publish a weighted exam blueprint for them, and they should not be read as a guarantee of exhaustive exam coverage or an official ten-domain question count. Do not substitute older 13-module lists you may find on other sites. For a companion walkthrough, see the C)PTE exam domains guide.
Domain 1: Penetration Testing Methodologies
The foundation. Expect questions on how an engagement is structured from authorization through delivery.
- Scope documents, rules of engagement and legal authorization boundaries
- Phases of a test and how findings feed the next phase
- Deciding when an action falls outside agreed scope
Domain 2: Advanced Recon & Attack Surface Mapping
Reconnaissance is more than running a scanner. Know the reasoning behind each technique.
- DNS enumeration and OSINT collection
- Service discovery and fingerprinting
- Turning raw recon output into a prioritized attack surface
Domain 3: Exploitation Techniques (Local & Remote)
Understand the difference between a remote foothold and local privilege escalation, and why each succeeds.
- Remote service exploitation concepts
- Local privilege escalation paths on Windows and Linux
- Matching a vulnerability class to an appropriate technique
Domain 4: Post-Exploitation & Lateral Movement
What happens after access matters as much as getting it.
- Credential harvesting and pivoting concepts
- Moving between hosts while respecting scope
- Cleanup: restoring systems and removing artifacts you introduced
Domain 5: Cloud & Active Directory Exploitation
Given the Microsoft-security recommendation, give this domain real time.
- On-premises Active Directory attack paths
- Entra ID, Microsoft 365 and hybrid identity weaknesses
- How trust between cloud and on-premises identity creates pivot opportunities
Domain 6: Evasion & Payload Crafting
Approach this conceptually and in a controlled lab only.
- Payload types and delivery concepts
- Why defenses detect certain behaviors and how evasion alters them
- Authorization considerations when testing against live defenses
Domain 7: Web, API & Mobile Attacks
Authorization flaws are a recurring theme across all three surfaces.
- Broken access control in web applications and APIs
- Mobile client and backend trust assumptions
- Distinguishing authentication failures from authorization failures
Domain 8: Threat Simulation & Attack Chains
Individual techniques become scenarios here.
- Mapping steps to MITRE ATT&CK tactics and techniques
- Sequencing multiple weaknesses into one realistic chain
- Emulating adversary behavior rather than running isolated exploits
Domain 9: Purple Team Collaboration
Offense and defense working from the same data.
- Validating whether detections actually fire for a given technique
- Sharing indicators and tuning telemetry with defenders
- Measuring detection coverage after remediation
Domain 10: Reporting & Business Risk Analysis
A test that cannot be communicated has limited value.
- Writing technical findings with reproduction detail
- Translating impact into executive-level business risk
- Prioritizing remediation by likelihood and consequence
Scenario Drills Worth Building
Because the exam is multiple choice but scenario-flavored, the best preparation is working through realistic situations until the right answer becomes obvious. Build your own drills like these in a lab you own or are authorized to use:
Scope and authorization
You are handed a scope listing two subnets, but recon reveals a third-party hosted service tied to the target. Do you test it? The correct reasoning starts with the rules of engagement and written authorization, not technical curiosity. Practice stating, for any action, which document authorizes it.
Reconnaissance chain
Start from only a company domain. Use DNS records and open sources to enumerate subdomains, identify exposed services, and rank which deserves attention first. Write down why you ranked them that way. Exam questions often hinge on picking the most informative next step, not the flashiest one.
Hybrid identity pivot
Imagine you obtain a low-privilege cloud identity in a hybrid environment. Trace how that foothold might connect to on-premises directory objects, and what an administrator could do to break that chain. This single scenario touches Domains 4, 5, 8 and 9.
Web and API authorization
Take a simple API where users retrieve their own records by identifier. Practice recognizing when changing that identifier exposes another user's data, and how that differs from a missing login. The wording of exam answers often turns on this authentication-versus-authorization distinction.
Purple-team validation
Pick one ATT&CK technique, execute it in your lab, then check whether your logging and detection tooling noticed. If not, document the gap. Domain 9 questions reward candidates who think about detection as a measurable outcome.
Two audiences, one finding
Take a single vulnerability and write it up twice: once with technical reproduction steps, once as two sentences a non-technical executive would act on. Domain 10 expects you to know the difference.
Key Takeaway
For every technique you study, be able to answer three questions: what authorizes this action, what does it enable next, and how would a defender notice it. That framing connects nearly all ten domains.
A Domain-Ordered Study Sequence
Generic scheduling advice is easy to find, so this section ties the plan directly to the curriculum. The ordering below reflects dependency: later domains assume earlier ones. Adjust the length to your own background; a candidate already working in a security team may compress the early weeks, while someone newer to offensive work should extend them.
Foundations: Domains 1 and 2
- Methodology, scope and rules of engagement
- Recon and attack surface mapping exercises in a lab
- Close any TCP/IP or Linux gaps now
Access: Domains 3 and 4
- Local and remote exploitation concepts
- Post-exploitation, lateral movement and cleanup
Identity and evasion: Domains 5 and 6
- Active Directory, Entra ID and hybrid paths (spend extra time here)
- Payload and evasion concepts in a controlled lab
Applications and chains: Domains 7 and 8
- Web, API and mobile authorization flaws
- Mapping full attack chains to ATT&CK
Defense and communication: Domains 9 and 10, then review
- Purple-team detection validation
- Technical and executive reporting practice
- Full-length practice under timed conditions, then targeted weak-spot review
When you reach the review stage, use timed practice to build the pacing you need: 100 questions in about two hours leaves little room to dwell. You can drill that rhythm with the C)PTE practice tests, and our C)PTE cheat sheet helps with last-day recall of the facts above. To calibrate your effort, read how hard the C)PTE exam is. For context on outcomes, our pass rate article explains what is and is not known; no verified pass-rate figure should be assumed.
Standard C)PTE Versus the Accredited Exam
Mile2 offers a separate accredited version, C)PTE-A, and its rules differ from the Standard exam. Keeping them apart prevents expensive misunderstandings.
| Aspect | Standard C)PTE | C)PTE-A (accredited) |
|---|---|---|
| Delivery | Online, on-demand via Mile2 account, described as unproctored | Live proctoring |
| Passing requirement | 70% minimum (per current course outline) | Different; a distinct requirement applies |
| Scope of this guide | Covered | Not covered |
| Where to verify | Exam Combo page, course outline | Mile2's accredited-exam page |
If your employer or a contract specifically requires the accredited version, confirm that before buying anything. Do not assume the Standard exam satisfies an accreditation requirement.
Fees, Access Periods and Credential Validity
Three different clocks tend to get confused, so separate them clearly.
- Exam purchase: The Standard Exam Combo includes a preparation guide, a practice quiz and two attempts. Current Standard exam and optional training-bundle prices could not be independently confirmed from Mile2's retrievable product listings, so check the live product page rather than trusting any quoted number, including old promotional prices you may see elsewhere. Our certification cost guide explains the components.
- Course and lab access: The optional Ultimate Combo includes one-year course access, videos, a digital workbook, a lab guide, two weeks of Cyber Range access and two exam attempts. Those are access periods for learning resources. They are not the validity period of the certification. The five-day live course and its 40 course CEUs likewise describe training, not exam timing.
- Credential validity: Once earned, the certification has a three-year validity cycle. Renewal is through 60 documented CEUs plus the applicable renewal purchase and ethics/policy compliance, or by passing the current full certification examination. Mile2's FAQ quotes USD 200 for the U.S. regional CEU-route renewal fee and states that annual membership is not required.
Where the Credential Fits in the Job Market
C)PTE is most relevant to roles that involve authorized offensive testing: penetration tester, red team operator, vulnerability assessor and security consultant, as well as defensive roles that benefit from understanding attacker tradecraft. Our C)PTE jobs page explores typical titles in more depth. Consulting firms and security service providers are the most natural fit, but internal security teams sometimes value it too, particularly when paired with demonstrated lab or engagement experience.
On compensation, be cautious. General penetration-tester salary data exists, but it should not be read as a measured premium for C)PTE holders specifically, and no such premium is established here. For a measured discussion, see the salary guide, and for a return-on-investment view, the article asking whether the certification is worth it. Many candidates also compare it against CEH, CompTIA PenTest+ and OSCP; each differs in format and emphasis, so decide based on whether you want a knowledge exam, a hands-on practical, or recognition with a particular employer.
Frequently Asked Questions
Mile2's current course outline specifies 100 multiple-choice questions over approximately two hours, with a minimum passing grade of 70%.
No prerequisite course is required to sit the certification exam. Mile2 does suggest C)PEH or equivalent knowledge, about 12 months of networking experience, TCP/IP knowledge, basic Linux skills and Microsoft security experience.
The Standard Exam Combo describes online, on-demand delivery through your Mile2 account without a proctor. Mile2's general policy document uses broader proctoring language, so follow the instructions in your own exam account and verify with Mile2 if unsure. C)PTE-A's live proctoring is a separate rule set.
Mile2 presents them as unweighted preparation curriculum headings, not an official weighted blueprint. Because weights are not published, study all ten and prioritize by your own weaker areas.
It has a three-year validity cycle. Renewal is through 60 documented CEUs with the applicable renewal purchase and ethics/policy compliance, or by passing the current full certification examination. Course access periods are unrelated to this validity cycle.