- Identity and Exam Format at a Glance
- The Eight Preparation Domains on One Page
- Domains 1-2: PowerShell, Active Directory and Kerberos Essentials
- Domains 3-4: Methodology, Information Gathering and Enumeration
- Domains 5-6: Privilege Escalation and Lateral Movement
- Domains 7-8: Persistence, Bypassing Defenses and Defending
- Registration, Attempts and Proctoring Facts
- Validity and Renewal: What Is Settled and What Conflicts
- Where the Credential Fits Professionally
- A Domain-Ordered Review Schedule
- Frequently Asked Questions
- Certified Powershell Hacker is a Mile2 credential: 100 multiple-choice questions, about two hours, 70% minimum passing grade per the course outline.
- The eight Domain headings are preparation topics from the course outline, not a verified weighted exam blueprint.
- Exam purchases include two attempts, and buying a Mile2 course is not required to purchase the exam.
- Certification lasts three years, but renewal descriptions differ across Mile2 sources, so confirm your own account's path.
Identity and Exam Format at a Glance
This cheat sheet covers Certified Powershell Hacker, the Mile2 credential styled "Certified PowerShell Hacker" in the vendor's course materials. People also search for it under the punctuation-free alias CPSH. If you are still sorting out the name, our explainers on what C)PSH is and what C)PSH stands for cover the basics. This page assumes you already know what you are sitting for and want the facts compressed.
| Item | What the sources say |
|---|---|
| Certifying body | Mile2 |
| Delivery | Online, through Mile2's learning management system and your Mile2.com account |
| Question format | Multiple choice |
| Number of questions | 100 (per the course outline) |
| Time allowed | Approximately two hours; the general FAQ also gives a two-hour limit for standard exams |
| Minimum passing grade | 70% |
| Attempts included with purchase | Two |
| Certification validity | Three years |
The Eight Preparation Domains on One Page
The Detailed Outline on pages 3-4 of Mile2's course outline lists eight headings. They are unweighted preparation topics. They do not establish an official exam-domain count or exhaustive exam coverage, so treat them as a map of what to learn rather than a percentage-by-percentage blueprint. Our full C)PSH exam domains guide goes deeper on each one.
| # | Heading | Think of it as |
|---|---|---|
| 1 | Introduction to PowerShell | Language and tooling fluency |
| 2 | Introduction to Active Directory and Kerberos | The environment and its authentication model |
| 3 | Pen Testing Methodology Revisited | Process and structure |
| 4 | Information Gathering and Enumeration | Discovery |
| 5 | Privilege Escalation | Gaining higher access |
| 6 | Lateral Movements and Abusing Trust | Moving between systems |
| 7 | Persistence and Bypassing Defenses | Staying in and evading controls |
| 8 | Defending Against PowerShell Attacks | The blue-team mirror image |
Domains 1-2: PowerShell, Active Directory and Kerberos Essentials
Domain 1: Introduction to PowerShell
Everything later assumes you can read and write PowerShell without friction. Mile2 lists scripting and programming among the suggested preparation areas, and this domain is where that pays off.
- The cmdlet verb-noun pattern and how to discover commands and their parameters through built-in help
- The object pipeline: PowerShell passes objects, not text, so filtering and property selection behave differently from a traditional shell
- Variables, arrays, hash tables, loops and conditionals at a working level
- Functions, modules and execution policy as a concept, including why it is a safety feature rather than a security boundary
- Remoting concepts and how PowerShell reaches other machines
Domain 2: Introduction to Active Directory and Kerberos
This is the conceptual backbone of the credential. You cannot reason about enumeration, escalation or lateral movement without knowing how a domain is structured and how identities are verified.
- Domains, forests, trusts, organizational units, users, groups and computer accounts
- The role of domain controllers and the directory database
- Group Policy at a conceptual level and why it matters to both attackers and defenders
- Kerberos flow: the ticket-granting concept, service tickets, and what is verified at each step
- Why delegation and service accounts create interesting security questions
Expect multiple-choice items in these two areas to test whether you understand why something works, not only whether you can name it. Candidates who skim Kerberos tend to struggle later, because Domains 5 and 6 build directly on it. For a candid read on where people stumble, see how hard the C)PSH exam is.
Domains 3-4: Methodology, Information Gathering and Enumeration
Domain 3: Pen Testing Methodology Revisited
Think of this as the framework that keeps the technical work organized. Mile2 suggests penetration-testing fundamentals as background, and this domain revisits them in a PowerShell and Active Directory context.
- Phases of an engagement: scoping, reconnaissance, exploitation, post-exploitation, reporting
- Rules of engagement and written authorization as non-negotiable preconditions
- Where PowerShell-based tradecraft fits within each phase
- Documenting findings so they can be reproduced and remediated
Domain 4: Information Gathering and Enumeration
Enumeration in a Windows domain means learning who and what exists, and how they relate.
- Enumerating users, groups, computers, shares and organizational structure
- Identifying privileged groups and accounts of interest
- Mapping trust relationships between domains
- Understanding which enumeration activities are noisy and which blend into normal directory traffic
- Recognizing what a built-in cmdlet can reveal compared with a purpose-built tool
Key Takeaway
Questions in these domains often reward process thinking. When two answers both sound technically plausible, the one that respects scope, authorization and documentation is usually the better fit for a methodology-flavored item.
Domains 5-6: Privilege Escalation and Lateral Movement
Domain 5: Privilege Escalation
Know the categories of weakness, not just a catalog of named techniques.
- Local escalation themes: misconfigured services, weak permissions on files and registry entries, stored credentials
- Domain-level escalation themes: over-privileged accounts, delegation misconfigurations, weak password policies
- How token and credential handling on Windows affects what an attacker can reuse
- The defensive counterpart for each weakness class, since you will meet it again in Domain 8
Domain 6: Lateral Movements and Abusing Trust
This is where Kerberos knowledge from Domain 2 becomes practical.
- Remote execution and remoting channels used to pivot between hosts
- Credential reuse and ticket-based movement as concepts
- Abusing trust relationships between domains and between accounts and services
- Why a compromise of one host so often becomes a compromise of many
Domains 7-8: Persistence, Bypassing Defenses and Defending
Domain 7: Persistence and Bypassing Defenses
This domain pairs two ideas: keeping access over time and getting past the controls meant to stop it.
- Common persistence locations and mechanisms on Windows systems at a conceptual level
- Why defenders hunt in startup locations, scheduled mechanisms and directory objects
- Defensive controls that PowerShell activity must contend with, and the general idea behind evading them
- Logging and visibility gaps that make some activity harder to see
Domain 8: Defending Against PowerShell Attacks
The outline closes by flipping perspective, and you should expect it to matter. A professional credential in this space is as much about detection and hardening as about offense.
- PowerShell logging concepts and what each kind of logging captures
- Constrained execution approaches and application control as mitigations
- Credential hygiene, least privilege and tiered administration in Active Directory
- Monitoring for the behaviors described in Domains 4 through 7
A useful study habit: for every offensive technique you learn in Domains 4-7, write one line describing how you would detect it and one line describing how you would prevent it. That single habit prepares you for Domain 8 almost automatically.
Registration, Attempts and Proctoring Facts
- Course not required for the exam purchase. Buying or completing a Mile2 course is not a prerequisite to purchasing the exam. Read our C)PSH requirements guide for the full eligibility picture.
- Suggested, not mandatory, background. Mile2 recommends C)PEH and C)PTE or equivalent knowledge, plus penetration-testing fundamentals, Active Directory, scripting and programming. These are recommendations, not required prior certifications.
- Two attempts. Mile2's FAQ states that exam purchases include two attempts.
- On-demand delivery. The FAQ says standard exams are available online on demand without a live-proctor appointment. The proctoring exceptions it names, C)ISSO-A and C)PTE-A, are different credentials and do not apply here.
- The C)PSH Exam Combo. The listing describes exam access, a preparation guide, and quiz/simulator preparation.
- Pricing. A current bundle price and a separate exam-only fee were not verified in the retrieved listing, and earlier promotional amounts should not be treated as current. Check your account and see our C)PSH certification cost breakdown for how to think about total spend.
Validity and Renewal: What Is Settled and What Conflicts
The settled part is simple: certification is valid for three years. Beyond that, Mile2's sources describe renewal in different ways, and you should not blend them into one rule.
| Source | What it describes |
|---|---|
| Dedicated Certification Renewal Program and Paths to Renewal pages | Two alternative routes: a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase and ethics acknowledgment; or a route involving the latest existing certification exam or an eligible qualifying exam |
| Course outline | States 20 CEUs annually plus passing the current exam |
| Policies and Procedures (May 2026) | CEUs plus a purchased recertification exam within seven days of expiry; full reexamination without CEUs after that period |
| FAQ | Lists a USD 200 renewal fee for the U.S. region |
Key Takeaway
The dedicated renewal pages present the CEU route and the exam route as alternatives, while the outline and policy document describe the process differently. Treat the dedicated renewal pages and your Mile2 account as the working reference, and confirm the current rule before your three years run out.
One more distinction worth remembering: the four-day course, 32 course CEUs and seven training labs describe the preparation course. They are not the exam length, not a separate practical assessment, and not a verified renewal-hour requirement.
Where the Credential Fits Professionally
The skill set sits at the intersection of offensive security and Windows enterprise administration. Roles where this knowledge is directly relevant include penetration testers, red team operators, security consultants who assess Active Directory environments, and blue team analysts or threat hunters who need to recognize PowerShell abuse. Because Domain 8 is explicitly defensive, the material also supports detection engineers and security engineers hardening Windows estates.
We deliberately do not quote salary figures here, since none are verified for this specific credential. For a qualitative discussion, read our C)PSH salary guide, the C)PSH jobs overview, and the C)PSH ROI analysis.
A Domain-Ordered Review Schedule
The only scheduling advice worth giving is about order, because the domains build on each other. Foundations first, then escalation and movement, then defense as a synthesis.
Domain 1 and Domain 2
- Drill the pipeline, objects and remoting until they feel automatic
- Diagram a Kerberos exchange from memory; this pays off in Week 3
Domain 3 and Domain 4
- Review engagement phases and authorization concepts
- Practice enumeration in an isolated lab you own or are licensed to use
Domain 5 and Domain 6
- Group weaknesses by category rather than memorizing names
- Connect each lateral movement concept back to Kerberos and trust
Domain 7, Domain 8 and timed review
- Pair every offensive technique with a detection and a prevention note
- Take timed sets of 100 questions in about two hours to match the exam pace
For a fuller plan, see the C)PSH study guide, and when you are ready for timed practice, use the C)PSH practice tests. Our C)PSH pass rate article explains why we do not quote a percentage here.
Frequently Asked Questions
Mile2's course outline specifies 100 multiple-choice questions, with approximately two hours allowed and a minimum passing grade of 70%.
No verified weighting exists. The eight headings come from the course outline's detailed section and are unweighted preparation topics, so they should not be read as an official exam blueprint.
No. Purchasing or completing a Mile2 course is not required to purchase the exam. Mile2 does suggest background such as C)PEH and C)PTE or equivalent knowledge, but these are recommendations rather than mandatory certifications.
Mile2's published materials conflict. The FAQ describes standard exams as on demand without a live-proctor appointment, while the Policies and Procedures document mentions open-book online exams and webcam/screen-sharing proctoring in general procedures. Follow the instructions in your own Mile2 account rather than assuming either.
It is valid for three years. The dedicated renewal pages describe a CEU route (60 documented CEUs, a renewal purchase and ethics acknowledgment) and an exam-based route as alternatives, though other Mile2 documents describe renewal differently. Confirm the current rule in your account before expiry.