C)PTE logo
Focused certification exam prep
Start practice

C)PTE Study Guide 2026: How to Pass on Your First Attempt

TL;DR
  • The Standard C)PTE exam is 100 multiple-choice questions in roughly two hours, with a 70% minimum passing grade.
  • No prerequisite course is required to sit the exam, though C)PEH-level knowledge and networking experience are strongly suggested.
  • The Standard Exam Combo describes online, on-demand delivery without a proctor; C)PTE-A rules are different.
  • Mile2's ten curriculum headings are unweighted, so distribute study time by your own weak spots.

What You Are Actually Preparing For

The Certified Penetration Testing Engineer, written C)PTE, is a Mile2 credential aimed at people who perform authorized offensive security work. Before you open a single study resource, confirm which exam you are targeting, because the acronym is shared with unrelated credentials and the Canadian Physiotherapy Examination uses a similar abbreviation in a completely different profession. Everything in this guide concerns the Mile2 Standard C)PTE, using the 2026 preparation curriculum. It does not cover the separate C)PTE-A accredited examination, and it should not be mixed with material from any other certification that happens to share the letters.

If you are still orienting yourself, the explainer pages on what C)PTE certification is and what C)PTE stands for cover the basics. This article assumes you have decided to pursue it and want a practical path to a first-attempt pass.

Why identity matters for your prep: Practice questions, forum posts and third-party "dumps" frequently blur different credentials together. If a resource cites a fee, passing score or proctoring rule that does not match Mile2's Standard C)PTE, treat it as unreliable until you verify it on mile2.com.

Format, Delivery and the Proctoring Question

According to Mile2's current course outline, the Standard exam consists of 100 multiple-choice questions, runs approximately two hours, and requires a minimum passing grade of 70%. That is a knowledge examination. It is not a hands-on practical, even though the course itself includes labs. Those labs are preparation; they are not a separately verified practical certification exam. For a deeper look at scoring, see our breakdown of the C)PTE passing score.

The Standard Exam Combo explicitly describes online, on-demand delivery through your Mile2 account without a proctor. It includes an exam-preparation guide, a practice quiz and two attempts. That is the product description you should plan around.

There is a wrinkle worth knowing. Mile2's general Policies and Procedures document, dated May 26, 2026, describes open-book testing but uses broader proctoring language than the Standard product page does. Those two sources do not perfectly align, and this guide does not pretend otherwise. The safe approach: follow the instructions shown inside your own exam purchase and account, read the policy document before test day, and contact Mile2 if anything on the exam screen contradicts what you expected. Do not import rules from the accredited exam, which has its own live proctoring and a different passing requirement.

Practical consequence: An unproctored, on-demand format removes scheduling pressure but also removes the structure of a fixed testing window. If you want to understand how scheduling works, our C)PTE exam dates guide explains what to expect, and you should still confirm the details in your Mile2 account.

Recommended Experience Versus Required Training

This distinction trips up many candidates. Mile2 does not require a prerequisite course to sit the certification exam. Anyone may attempt it. However, Mile2 suggests preparation that includes:

  • C)PEH knowledge or equivalent ethical hacking foundations
  • Around 12 months of networking experience
  • Sound TCP/IP knowledge
  • Basic Linux familiarity
  • Microsoft security experience

Treat that list as a diagnostic, not a gate. If you cannot explain how a three-way handshake works, read a packet capture, or navigate a Linux shell comfortably, the exam's exploitation and post-exploitation topics will feel like memorization rather than understanding. The Microsoft security recommendation is especially relevant in 2026 because the curriculum devotes an entire domain to cloud and Active Directory exploitation. More detail on eligibility lives in our C)PTE requirements guide.

The Ten Curriculum Domains and How to Study Them

The ten domain headings below reproduce Mile2's current Detailed Outline for the Certified Penetration Testing Engineer course (pages 4-5 of the outline PDF linked from the course outline page). They are unweighted preparation headings. Mile2 does not publish a weighted exam blueprint for them, and they should not be read as a guarantee of exhaustive exam coverage or an official ten-domain question count. Do not substitute older 13-module lists you may find on other sites. For a companion walkthrough, see the C)PTE exam domains guide.

Domain 1: Penetration Testing Methodologies

The foundation. Expect questions on how an engagement is structured from authorization through delivery.

  • Scope documents, rules of engagement and legal authorization boundaries
  • Phases of a test and how findings feed the next phase
  • Deciding when an action falls outside agreed scope

Domain 2: Advanced Recon & Attack Surface Mapping

Reconnaissance is more than running a scanner. Know the reasoning behind each technique.

  • DNS enumeration and OSINT collection
  • Service discovery and fingerprinting
  • Turning raw recon output into a prioritized attack surface

Domain 3: Exploitation Techniques (Local & Remote)

Understand the difference between a remote foothold and local privilege escalation, and why each succeeds.

  • Remote service exploitation concepts
  • Local privilege escalation paths on Windows and Linux
  • Matching a vulnerability class to an appropriate technique

Domain 4: Post-Exploitation & Lateral Movement

What happens after access matters as much as getting it.

  • Credential harvesting and pivoting concepts
  • Moving between hosts while respecting scope
  • Cleanup: restoring systems and removing artifacts you introduced

Domain 5: Cloud & Active Directory Exploitation

Given the Microsoft-security recommendation, give this domain real time.

  • On-premises Active Directory attack paths
  • Entra ID, Microsoft 365 and hybrid identity weaknesses
  • How trust between cloud and on-premises identity creates pivot opportunities

Domain 6: Evasion & Payload Crafting

Approach this conceptually and in a controlled lab only.

  • Payload types and delivery concepts
  • Why defenses detect certain behaviors and how evasion alters them
  • Authorization considerations when testing against live defenses

Domain 7: Web, API & Mobile Attacks

Authorization flaws are a recurring theme across all three surfaces.

  • Broken access control in web applications and APIs
  • Mobile client and backend trust assumptions
  • Distinguishing authentication failures from authorization failures

Domain 8: Threat Simulation & Attack Chains

Individual techniques become scenarios here.

  • Mapping steps to MITRE ATT&CK tactics and techniques
  • Sequencing multiple weaknesses into one realistic chain
  • Emulating adversary behavior rather than running isolated exploits

Domain 9: Purple Team Collaboration

Offense and defense working from the same data.

  • Validating whether detections actually fire for a given technique
  • Sharing indicators and tuning telemetry with defenders
  • Measuring detection coverage after remediation

Domain 10: Reporting & Business Risk Analysis

A test that cannot be communicated has limited value.

  • Writing technical findings with reproduction detail
  • Translating impact into executive-level business risk
  • Prioritizing remediation by likelihood and consequence

Scenario Drills Worth Building

Because the exam is multiple choice but scenario-flavored, the best preparation is working through realistic situations until the right answer becomes obvious. Build your own drills like these in a lab you own or are authorized to use:

Scope and authorization

You are handed a scope listing two subnets, but recon reveals a third-party hosted service tied to the target. Do you test it? The correct reasoning starts with the rules of engagement and written authorization, not technical curiosity. Practice stating, for any action, which document authorizes it.

Reconnaissance chain

Start from only a company domain. Use DNS records and open sources to enumerate subdomains, identify exposed services, and rank which deserves attention first. Write down why you ranked them that way. Exam questions often hinge on picking the most informative next step, not the flashiest one.

Hybrid identity pivot

Imagine you obtain a low-privilege cloud identity in a hybrid environment. Trace how that foothold might connect to on-premises directory objects, and what an administrator could do to break that chain. This single scenario touches Domains 4, 5, 8 and 9.

Web and API authorization

Take a simple API where users retrieve their own records by identifier. Practice recognizing when changing that identifier exposes another user's data, and how that differs from a missing login. The wording of exam answers often turns on this authentication-versus-authorization distinction.

Purple-team validation

Pick one ATT&CK technique, execute it in your lab, then check whether your logging and detection tooling noticed. If not, document the gap. Domain 9 questions reward candidates who think about detection as a measurable outcome.

Two audiences, one finding

Take a single vulnerability and write it up twice: once with technical reproduction steps, once as two sentences a non-technical executive would act on. Domain 10 expects you to know the difference.

Key Takeaway

For every technique you study, be able to answer three questions: what authorizes this action, what does it enable next, and how would a defender notice it. That framing connects nearly all ten domains.

A Domain-Ordered Study Sequence

Generic scheduling advice is easy to find, so this section ties the plan directly to the curriculum. The ordering below reflects dependency: later domains assume earlier ones. Adjust the length to your own background; a candidate already working in a security team may compress the early weeks, while someone newer to offensive work should extend them.

Week 1

Foundations: Domains 1 and 2

  • Methodology, scope and rules of engagement
  • Recon and attack surface mapping exercises in a lab
  • Close any TCP/IP or Linux gaps now
Week 2

Access: Domains 3 and 4

  • Local and remote exploitation concepts
  • Post-exploitation, lateral movement and cleanup
Week 3

Identity and evasion: Domains 5 and 6

  • Active Directory, Entra ID and hybrid paths (spend extra time here)
  • Payload and evasion concepts in a controlled lab
Week 4

Applications and chains: Domains 7 and 8

  • Web, API and mobile authorization flaws
  • Mapping full attack chains to ATT&CK
Week 5

Defense and communication: Domains 9 and 10, then review

  • Purple-team detection validation
  • Technical and executive reporting practice
  • Full-length practice under timed conditions, then targeted weak-spot review

When you reach the review stage, use timed practice to build the pacing you need: 100 questions in about two hours leaves little room to dwell. You can drill that rhythm with the C)PTE practice tests, and our C)PTE cheat sheet helps with last-day recall of the facts above. To calibrate your effort, read how hard the C)PTE exam is. For context on outcomes, our pass rate article explains what is and is not known; no verified pass-rate figure should be assumed.

Standard C)PTE Versus the Accredited Exam

Mile2 offers a separate accredited version, C)PTE-A, and its rules differ from the Standard exam. Keeping them apart prevents expensive misunderstandings.

AspectStandard C)PTEC)PTE-A (accredited)
DeliveryOnline, on-demand via Mile2 account, described as unproctoredLive proctoring
Passing requirement70% minimum (per current course outline)Different; a distinct requirement applies
Scope of this guideCoveredNot covered
Where to verifyExam Combo page, course outlineMile2's accredited-exam page

If your employer or a contract specifically requires the accredited version, confirm that before buying anything. Do not assume the Standard exam satisfies an accreditation requirement.

Fees, Access Periods and Credential Validity

Three different clocks tend to get confused, so separate them clearly.

  • Exam purchase: The Standard Exam Combo includes a preparation guide, a practice quiz and two attempts. Current Standard exam and optional training-bundle prices could not be independently confirmed from Mile2's retrievable product listings, so check the live product page rather than trusting any quoted number, including old promotional prices you may see elsewhere. Our certification cost guide explains the components.
  • Course and lab access: The optional Ultimate Combo includes one-year course access, videos, a digital workbook, a lab guide, two weeks of Cyber Range access and two exam attempts. Those are access periods for learning resources. They are not the validity period of the certification. The five-day live course and its 40 course CEUs likewise describe training, not exam timing.
  • Credential validity: Once earned, the certification has a three-year validity cycle. Renewal is through 60 documented CEUs plus the applicable renewal purchase and ethics/policy compliance, or by passing the current full certification examination. Mile2's FAQ quotes USD 200 for the U.S. regional CEU-route renewal fee and states that annual membership is not required.
Plan your renewal early: Because renewal can be satisfied through documented CEUs, start logging relevant learning, conference attendance and security work from the day you pass. Waiting until year three to reconstruct documentation is the most common avoidable headache.

Where the Credential Fits in the Job Market

C)PTE is most relevant to roles that involve authorized offensive testing: penetration tester, red team operator, vulnerability assessor and security consultant, as well as defensive roles that benefit from understanding attacker tradecraft. Our C)PTE jobs page explores typical titles in more depth. Consulting firms and security service providers are the most natural fit, but internal security teams sometimes value it too, particularly when paired with demonstrated lab or engagement experience.

On compensation, be cautious. General penetration-tester salary data exists, but it should not be read as a measured premium for C)PTE holders specifically, and no such premium is established here. For a measured discussion, see the salary guide, and for a return-on-investment view, the article asking whether the certification is worth it. Many candidates also compare it against CEH, CompTIA PenTest+ and OSCP; each differs in format and emphasis, so decide based on whether you want a knowledge exam, a hands-on practical, or recognition with a particular employer.

Frequently Asked Questions

How many questions are on the Standard C)PTE exam?

Mile2's current course outline specifies 100 multiple-choice questions over approximately two hours, with a minimum passing grade of 70%.

Do I have to take the Mile2 course before sitting the exam?

No prerequisite course is required to sit the certification exam. Mile2 does suggest C)PEH or equivalent knowledge, about 12 months of networking experience, TCP/IP knowledge, basic Linux skills and Microsoft security experience.

Is the Standard C)PTE exam proctored?

The Standard Exam Combo describes online, on-demand delivery through your Mile2 account without a proctor. Mile2's general policy document uses broader proctoring language, so follow the instructions in your own exam account and verify with Mile2 if unsure. C)PTE-A's live proctoring is a separate rule set.

Are the ten domains weighted on the exam?

Mile2 presents them as unweighted preparation curriculum headings, not an official weighted blueprint. Because weights are not published, study all ten and prioritize by your own weaker areas.

How long does the certification last, and how do I renew?

It has a three-year validity cycle. Renewal is through 60 documented CEUs with the applicable renewal purchase and ethics/policy compliance, or by passing the current full certification examination. Course access periods are unrelated to this validity cycle.

Ready to pass your C)PTE exam?

Put this into practice with free C)PTE questions across every exam domain.