C)PSH logo
Focused certification exam prep
Start practice

C)PSH Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • Certified Powershell Hacker is a Mile2 credential: 100 multiple-choice questions, about two hours, 70% minimum passing grade per the course outline.
  • The eight Domain headings are preparation topics from the course outline, not a verified weighted exam blueprint.
  • Exam purchases include two attempts, and buying a Mile2 course is not required to purchase the exam.
  • Certification lasts three years, but renewal descriptions differ across Mile2 sources, so confirm your own account's path.

Identity and Exam Format at a Glance

This cheat sheet covers Certified Powershell Hacker, the Mile2 credential styled "Certified PowerShell Hacker" in the vendor's course materials. People also search for it under the punctuation-free alias CPSH. If you are still sorting out the name, our explainers on what C)PSH is and what C)PSH stands for cover the basics. This page assumes you already know what you are sitting for and want the facts compressed.

ItemWhat the sources say
Certifying bodyMile2
DeliveryOnline, through Mile2's learning management system and your Mile2.com account
Question formatMultiple choice
Number of questions100 (per the course outline)
Time allowedApproximately two hours; the general FAQ also gives a two-hour limit for standard exams
Minimum passing grade70%
Attempts included with purchaseTwo
Certification validityThree years
Source note: The five-page course outline PDF is undated, and the figures above come from it and from Mile2's FAQ. Always confirm the live details inside your Mile2.com account before you book, because vendor pages change. For a deeper look at what 70% means in practice, see our C)PSH passing score guide.

The Eight Preparation Domains on One Page

The Detailed Outline on pages 3-4 of Mile2's course outline lists eight headings. They are unweighted preparation topics. They do not establish an official exam-domain count or exhaustive exam coverage, so treat them as a map of what to learn rather than a percentage-by-percentage blueprint. Our full C)PSH exam domains guide goes deeper on each one.

#HeadingThink of it as
1Introduction to PowerShellLanguage and tooling fluency
2Introduction to Active Directory and KerberosThe environment and its authentication model
3Pen Testing Methodology RevisitedProcess and structure
4Information Gathering and EnumerationDiscovery
5Privilege EscalationGaining higher access
6Lateral Movements and Abusing TrustMoving between systems
7Persistence and Bypassing DefensesStaying in and evading controls
8Defending Against PowerShell AttacksThe blue-team mirror image
Naming quirk: The course overview uses a different title for Module 3 than the detailed outline. The detailed heading, Pen Testing Methodology Revisited, is the one used throughout this cheat sheet. If you see a different module title in a summary page, they refer to the same slot in the sequence.

Domains 1-2: PowerShell, Active Directory and Kerberos Essentials

Domain 1: Introduction to PowerShell

Everything later assumes you can read and write PowerShell without friction. Mile2 lists scripting and programming among the suggested preparation areas, and this domain is where that pays off.

  • The cmdlet verb-noun pattern and how to discover commands and their parameters through built-in help
  • The object pipeline: PowerShell passes objects, not text, so filtering and property selection behave differently from a traditional shell
  • Variables, arrays, hash tables, loops and conditionals at a working level
  • Functions, modules and execution policy as a concept, including why it is a safety feature rather than a security boundary
  • Remoting concepts and how PowerShell reaches other machines

Domain 2: Introduction to Active Directory and Kerberos

This is the conceptual backbone of the credential. You cannot reason about enumeration, escalation or lateral movement without knowing how a domain is structured and how identities are verified.

  • Domains, forests, trusts, organizational units, users, groups and computer accounts
  • The role of domain controllers and the directory database
  • Group Policy at a conceptual level and why it matters to both attackers and defenders
  • Kerberos flow: the ticket-granting concept, service tickets, and what is verified at each step
  • Why delegation and service accounts create interesting security questions

Expect multiple-choice items in these two areas to test whether you understand why something works, not only whether you can name it. Candidates who skim Kerberos tend to struggle later, because Domains 5 and 6 build directly on it. For a candid read on where people stumble, see how hard the C)PSH exam is.

Domains 3-4: Methodology, Information Gathering and Enumeration

Domain 3: Pen Testing Methodology Revisited

Think of this as the framework that keeps the technical work organized. Mile2 suggests penetration-testing fundamentals as background, and this domain revisits them in a PowerShell and Active Directory context.

  • Phases of an engagement: scoping, reconnaissance, exploitation, post-exploitation, reporting
  • Rules of engagement and written authorization as non-negotiable preconditions
  • Where PowerShell-based tradecraft fits within each phase
  • Documenting findings so they can be reproduced and remediated

Domain 4: Information Gathering and Enumeration

Enumeration in a Windows domain means learning who and what exists, and how they relate.

  • Enumerating users, groups, computers, shares and organizational structure
  • Identifying privileged groups and accounts of interest
  • Mapping trust relationships between domains
  • Understanding which enumeration activities are noisy and which blend into normal directory traffic
  • Recognizing what a built-in cmdlet can reveal compared with a purpose-built tool

Key Takeaway

Questions in these domains often reward process thinking. When two answers both sound technically plausible, the one that respects scope, authorization and documentation is usually the better fit for a methodology-flavored item.

Domains 5-6: Privilege Escalation and Lateral Movement

Domain 5: Privilege Escalation

Know the categories of weakness, not just a catalog of named techniques.

  • Local escalation themes: misconfigured services, weak permissions on files and registry entries, stored credentials
  • Domain-level escalation themes: over-privileged accounts, delegation misconfigurations, weak password policies
  • How token and credential handling on Windows affects what an attacker can reuse
  • The defensive counterpart for each weakness class, since you will meet it again in Domain 8

Domain 6: Lateral Movements and Abusing Trust

This is where Kerberos knowledge from Domain 2 becomes practical.

  • Remote execution and remoting channels used to pivot between hosts
  • Credential reuse and ticket-based movement as concepts
  • Abusing trust relationships between domains and between accounts and services
  • Why a compromise of one host so often becomes a compromise of many
Keep it ethical and isolated: Practice these topics only in isolated, authorized training environments, such as your own lab or the labs Mile2 provides alongside its course. For exam purposes, conceptual understanding of how and why each technique works, and how it is detected, is what multiple-choice items measure.

Domains 7-8: Persistence, Bypassing Defenses and Defending

Domain 7: Persistence and Bypassing Defenses

This domain pairs two ideas: keeping access over time and getting past the controls meant to stop it.

  • Common persistence locations and mechanisms on Windows systems at a conceptual level
  • Why defenders hunt in startup locations, scheduled mechanisms and directory objects
  • Defensive controls that PowerShell activity must contend with, and the general idea behind evading them
  • Logging and visibility gaps that make some activity harder to see

Domain 8: Defending Against PowerShell Attacks

The outline closes by flipping perspective, and you should expect it to matter. A professional credential in this space is as much about detection and hardening as about offense.

  • PowerShell logging concepts and what each kind of logging captures
  • Constrained execution approaches and application control as mitigations
  • Credential hygiene, least privilege and tiered administration in Active Directory
  • Monitoring for the behaviors described in Domains 4 through 7

A useful study habit: for every offensive technique you learn in Domains 4-7, write one line describing how you would detect it and one line describing how you would prevent it. That single habit prepares you for Domain 8 almost automatically.

Registration, Attempts and Proctoring Facts

  • Course not required for the exam purchase. Buying or completing a Mile2 course is not a prerequisite to purchasing the exam. Read our C)PSH requirements guide for the full eligibility picture.
  • Suggested, not mandatory, background. Mile2 recommends C)PEH and C)PTE or equivalent knowledge, plus penetration-testing fundamentals, Active Directory, scripting and programming. These are recommendations, not required prior certifications.
  • Two attempts. Mile2's FAQ states that exam purchases include two attempts.
  • On-demand delivery. The FAQ says standard exams are available online on demand without a live-proctor appointment. The proctoring exceptions it names, C)ISSO-A and C)PTE-A, are different credentials and do not apply here.
  • The C)PSH Exam Combo. The listing describes exam access, a preparation guide, and quiz/simulator preparation.
  • Pricing. A current bundle price and a separate exam-only fee were not verified in the retrieved listing, and earlier promotional amounts should not be treated as current. Check your account and see our C)PSH certification cost breakdown for how to think about total spend.
A genuine conflict in Mile2's published material: The Policies and Procedures document (dated May 26, 2026) describes randomized, open-book online examinations and webcam/screen-sharing proctoring in its general certification procedures, while other sections say only some exams require proctors. Mile2's FAQ describes standard exams as on demand without a live-proctor appointment. These statements do not line up neatly, so do not assume the exam is open-book or unproctored. Follow the instructions shown in your own account and booking flow, and read them before exam day. Scheduling logistics are covered in our C)PSH exam dates guide.

Validity and Renewal: What Is Settled and What Conflicts

The settled part is simple: certification is valid for three years. Beyond that, Mile2's sources describe renewal in different ways, and you should not blend them into one rule.

SourceWhat it describes
Dedicated Certification Renewal Program and Paths to Renewal pagesTwo alternative routes: a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase and ethics acknowledgment; or a route involving the latest existing certification exam or an eligible qualifying exam
Course outlineStates 20 CEUs annually plus passing the current exam
Policies and Procedures (May 2026)CEUs plus a purchased recertification exam within seven days of expiry; full reexamination without CEUs after that period
FAQLists a USD 200 renewal fee for the U.S. region

Key Takeaway

The dedicated renewal pages present the CEU route and the exam route as alternatives, while the outline and policy document describe the process differently. Treat the dedicated renewal pages and your Mile2 account as the working reference, and confirm the current rule before your three years run out.

One more distinction worth remembering: the four-day course, 32 course CEUs and seven training labs describe the preparation course. They are not the exam length, not a separate practical assessment, and not a verified renewal-hour requirement.

Where the Credential Fits Professionally

The skill set sits at the intersection of offensive security and Windows enterprise administration. Roles where this knowledge is directly relevant include penetration testers, red team operators, security consultants who assess Active Directory environments, and blue team analysts or threat hunters who need to recognize PowerShell abuse. Because Domain 8 is explicitly defensive, the material also supports detection engineers and security engineers hardening Windows estates.

We deliberately do not quote salary figures here, since none are verified for this specific credential. For a qualitative discussion, read our C)PSH salary guide, the C)PSH jobs overview, and the C)PSH ROI analysis.

A Domain-Ordered Review Schedule

The only scheduling advice worth giving is about order, because the domains build on each other. Foundations first, then escalation and movement, then defense as a synthesis.

Week 1

Domain 1 and Domain 2

  • Drill the pipeline, objects and remoting until they feel automatic
  • Diagram a Kerberos exchange from memory; this pays off in Week 3
Week 2

Domain 3 and Domain 4

  • Review engagement phases and authorization concepts
  • Practice enumeration in an isolated lab you own or are licensed to use
Week 3

Domain 5 and Domain 6

  • Group weaknesses by category rather than memorizing names
  • Connect each lateral movement concept back to Kerberos and trust
Week 4

Domain 7, Domain 8 and timed review

  • Pair every offensive technique with a detection and a prevention note
  • Take timed sets of 100 questions in about two hours to match the exam pace

For a fuller plan, see the C)PSH study guide, and when you are ready for timed practice, use the C)PSH practice tests. Our C)PSH pass rate article explains why we do not quote a percentage here.

Frequently Asked Questions

How many questions are on the Certified Powershell Hacker exam?

Mile2's course outline specifies 100 multiple-choice questions, with approximately two hours allowed and a minimum passing grade of 70%.

Are the eight domains weighted by percentage?

No verified weighting exists. The eight headings come from the course outline's detailed section and are unweighted preparation topics, so they should not be read as an official exam blueprint.

Do I have to take the Mile2 course before buying the exam?

No. Purchasing or completing a Mile2 course is not required to purchase the exam. Mile2 does suggest background such as C)PEH and C)PTE or equivalent knowledge, but these are recommendations rather than mandatory certifications.

Is the exam open-book or proctored?

Mile2's published materials conflict. The FAQ describes standard exams as on demand without a live-proctor appointment, while the Policies and Procedures document mentions open-book online exams and webcam/screen-sharing proctoring in general procedures. Follow the instructions in your own Mile2 account rather than assuming either.

How long does the certification last and how do I renew it?

It is valid for three years. The dedicated renewal pages describe a CEU route (60 documented CEUs, a renewal purchase and ethics acknowledgment) and an exam-based route as alternatives, though other Mile2 documents describe renewal differently. Confirm the current rule in your account before expiry.

Ready to pass your C)PSH exam?

Put this into practice with free C)PSH questions across every exam domain.