C)PSH logo
Focused certification exam prep
Start practice

C)PSH Exam Domains 2026: Complete Guide to All 8 Content Areas

TL;DR
  • Certified Powershell Hacker from Mile2 lists eight preparation topics, unweighted, in its detailed course outline.
  • The outline specifies 100 multiple-choice questions, roughly two hours, and a 70% minimum passing grade.
  • Domains 5 through 7 (escalation, lateral movement, persistence) are the offensive core; Domain 8 flips to defense.
  • Active Directory and Kerberos knowledge from Domain 2 underpins nearly every later domain.

How to Read the Eight Domains

Many certification guides present a tidy pie chart of weighted exam domains. This one cannot, and it is worth understanding why before you build a study plan. The eight headings below come from the Detailed Outline in Mile2's Certified PowerShell Hacker course outline PDF (pages 3-4). They are preparation curriculum headings, not a verified weighted exam blueprint. Mile2 does not publish percentage weights per domain in the retrieved materials, and the outline does not establish that every exam question maps neatly to exactly one of these eight buckets.

That distinction matters for how you study. Because no weights are published, you should not skip a domain on the theory that it is "only 5% of the exam." Treat all eight as fair game and allocate extra time according to your personal gaps instead. If you want the broader context for how this credential is defined, see What Is C)PSH Certification? and What Does C)PSH Stand For?.

A note on naming: Certified Powershell Hacker is styled "Certified PowerShell Hacker" in Mile2's course materials, and "CPSH" works as a punctuation-free search alias. The overview section of the outline uses a different title for Module 3, but the detailed heading, Pen Testing Methodology Revisited, is the one used throughout this guide.

Exam Format and Booking Mechanics

Before diving into content, here is what the published sources say about the exam itself.

ItemWhat the sources state
Awarding bodyMile2
Question count100 multiple-choice questions
TimeApproximately two hours (the general FAQ also gives a two-hour limit for standard exams)
Minimum passing grade70%
DeliveryOnline, through Mile2's learning management system and your Mile2.com account
AttemptsExam purchases include two attempts, per the FAQ
SchedulingStandard exams are described as available on demand without a live-proctor appointment
Course requirementPurchasing or completing a Mile2 course is not required to purchase the exam

Two points deserve extra caution. First, the four-day course, the 32 course CEUs, and the seven training labs describe preparation, not exam length, a practical assessment, or a renewal-hour requirement. Do not expect a hands-on lab component inside the exam based on those numbers. Second, the sources conflict on proctoring and open-book rules: the FAQ describes on-demand delivery without a live-proctor appointment, while the May 26, 2026 Policies and Procedures document describes randomized, open-book online examinations with webcam and screen-sharing proctoring in its general procedures, and other sections say only some exams require proctors. Mile2's separately named C)ISSO-A and C)PTE-A proctoring exceptions are different credentials. The safe approach is to follow the instructions shown in your own C)PSH account and booking flow rather than assuming either rule applies universally. For scheduling specifics, see C)PSH Exam Dates 2026, and for how the passing line works, C)PSH Passing Score 2026.

On cost, the C)PSH Exam Combo is listed as including exam access, a preparation guide, and quiz/simulator preparation. A current bundle price and a separate exam-only fee were not verified in the retrieved listing, so older promotional figures should not be treated as current. Check the live product page and read C)PSH Certification Cost 2026 for the pricing breakdown.

Domains 1-2: PowerShell, Active Directory and Kerberos

Domain 1: Introduction to PowerShell

Introduction to PowerShell

This is the language foundation. Everything offensive and defensive later in the curriculum assumes you can read and reason about PowerShell fluently, not just run copied commands.

  • The object pipeline: how cmdlets pass .NET objects rather than plain text, and why that changes how you filter and extract data
  • Cmdlet discovery and help: Get-Command, Get-Help, Get-Member as your orientation tools
  • Variables, operators, conditionals, loops, functions, and error handling at the scripting level
  • Modules, execution policy, and how scripts are loaded and run
  • Remoting concepts and how PowerShell interacts with Windows internals and .NET

Expect questions that test whether you can predict what a snippet does or identify the right cmdlet for a task. Candidates who have only used PowerShell for light administration often underestimate how much scripting literacy the later domains demand.

Domain 2: Introduction to Active Directory and Kerberos

Active Directory and Kerberos

The outline's suggested background includes Active Directory, scripting, and programming, and this domain is where that recommendation pays off. Domains 4 through 7 lean heavily on it.

  • AD structure: forests, domains, trusts, organizational units, groups, and the objects within them
  • Authentication fundamentals: how Kerberos tickets are requested and used, and the roles of the key players in the exchange
  • Why Kerberos design choices create abuse opportunities that attackers study
  • Group Policy at a conceptual level and how it shapes the environment

Key Takeaway

If you can explain a Kerberos authentication flow from memory, many questions in Domains 5, 6, and 7 become easier because you understand what is being abused, not just the name of the technique.

Domains 3-4: Methodology, Gathering and Enumeration

Domain 3: Pen Testing Methodology Revisited

This domain recasts the standard penetration-testing lifecycle through a PowerShell lens. The word "revisited" signals that the curriculum assumes you have seen a methodology before, consistent with the suggested prior knowledge of C)PEH and C)PTE or equivalent. Those are recommendations, not mandatory certifications; see C)PSH Requirements 2026 for how to think about eligibility.

  • Phases of an engagement and where PowerShell tooling fits in each
  • Scoping, rules of engagement, and authorization, which are foundational to legitimate testing
  • Why living off the land (using native tooling) changes both attacker tradecraft and detection strategy

Domain 4: Information Gathering and Enumeration

Information Gathering and Enumeration

Here the curriculum moves from theory to the first practical offensive phase: learning what exists in an environment before attempting anything else.

  • Enumerating domain objects: users, groups, computers, and their relationships
  • Identifying interesting targets such as privileged accounts and service accounts
  • Network and host discovery performed through scripting
  • Reading and interpreting enumeration output to decide next steps

Questions here tend to reward understanding of why a given piece of information is valuable. Knowing that a particular group membership or account attribute opens a path forward is more important than memorizing syntax.

Domains 5-6: Privilege Escalation and Lateral Movement

Domain 5: Privilege Escalation

Privilege Escalation

This domain covers how a foothold with limited rights becomes something more powerful, on a single host and within a domain.

  • Local escalation concepts: misconfigurations in services, permissions, and scheduled tasks
  • Credential exposure and the ways credentials can be obtained or abused on Windows systems
  • Domain-level escalation paths that follow from the AD knowledge in Domain 2
  • Recognizing a misconfiguration from a described scenario

Domain 6: Lateral Movements and Abusing Trust

Lateral Movements and Abusing Trust

Once privileges are gained, an attacker moves. This domain focuses on how movement happens across hosts and across trust boundaries.

  • Remote execution and remoting mechanisms and how they are leveraged
  • Trust relationships between domains and forests, and why trust implies exposure
  • Authentication material reuse and the conceptual basis for ticket and credential abuse
  • Pivoting logic: choosing the next hop based on enumeration results
Keep practice safe and legal: Everything in these domains should be rehearsed only in isolated, authorized training environments such as the labs that accompany the course or a lab you build and own. Study the concepts and the defensive implications; never test techniques against systems you do not have explicit permission to assess.

Domains 7-8: Persistence, Bypassing Defenses and Defending

Domain 7: Persistence and Bypassing Defenses

Persistence and Bypassing Defenses

This domain pairs two ideas: keeping access over time, and avoiding or defeating the controls meant to stop it.

  • Persistence concepts: the kinds of places an attacker may leave a mechanism to regain access
  • How defensive controls such as logging, script inspection, and application restrictions are designed to catch PowerShell abuse
  • The conceptual categories of evasion that those controls must contend with
  • Why understanding evasion is the bridge to building better detection

Domain 8: Defending Against PowerShell Attacks

Defending Against PowerShell Attacks

The curriculum closes by turning the whole course around. After seven domains of attacker perspective, you are expected to reason like a defender.

  • Logging and monitoring approaches that surface suspicious PowerShell activity
  • Constraining PowerShell: restricting capability and limiting who can do what
  • Hardening Active Directory to reduce the escalation and movement paths from earlier domains
  • Mapping each offensive technique you studied to a corresponding detection or mitigation

A useful way to study Domain 8 is as a mirror of Domains 5 through 7. For every attack path you learn, write down one control that would prevent it and one signal that would reveal it. That habit produces answers to scenario-style questions faster than rote memorization. For a condensed list of facts to revisit near exam day, see the C)PSH Cheat Sheet 2026.

Sequencing Your Preparation by Domain

Because the domains build on each other, order matters more than hours. Here is one sequencing approach tied directly to the curriculum, adjustable to your starting point.

Week 1

PowerShell Fluency (Domain 1)

  • Drill the object pipeline, filtering, and scripting constructs
  • Read unfamiliar snippets and predict their output
Week 2

Active Directory and Kerberos (Domain 2)

  • Diagram forests, trusts, and the Kerberos exchange from memory
  • This is the highest-leverage week; do not rush it
Week 3

Methodology and Enumeration (Domains 3-4)

  • Review the engagement lifecycle and authorization concepts
  • Practice enumeration only inside an isolated lab you control
Week 4

Escalation and Movement (Domains 5-6)

  • Link each technique back to the AD or Kerberos mechanism it abuses
Week 5

Persistence, Evasion, and Defense (Domains 7-8)

  • Pair every offensive concept with a detection or mitigation
  • Finish with timed quiz and simulator sessions

For a broader plan, the C)PSH Study Guide 2026 covers preparation in more depth, and How Hard Is the C)PSH Exam? helps you judge how much time your background will require. For timed drilling in the style of the real exam, use the C)PSH practice tests.

Who Should Sit This Exam and Who Hires for It

The eight domains describe a profile that sits at the intersection of offensive security and Windows administration. The strongest fits are penetration testers, red team members, and security analysts who work in Windows and Active Directory environments. Defenders benefit too: Domain 8 and the attacker-perspective content equip blue-team staff, threat hunters, and incident responders to recognize PowerShell abuse.

Employers who value this kind of credential are typically organizations with large Windows estates and security teams that test or defend them, along with consultancies that perform AD-focused assessments. Specific salary data for this credential was not verified, so this guide makes no earnings claims; if compensation is your focus, read C)PSH Salary Guide 2026 for qualitative context, C)PSH Jobs for role types, and Is the C)PSH Certification Worth It? for a return-on-investment framing.

Validity and Renewal: Where the Sources Disagree

The certification is valid for three years. Renewal details, however, are described inconsistently across Mile2's published materials, and it would be inaccurate to compress them into a single rule.

  • Dedicated renewal pages: describe a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase, and ethics acknowledgment, or an alternative route involving the latest existing certification exam or an eligible qualifying exam. These are presented as alternatives.
  • Course outline: states 20 CEUs annually plus passing the current exam.
  • May 2026 policy: uses CEUs plus a purchased recertification exam within seven days of expiry, and full reexamination without CEUs after that period.
  • FAQ: lists a USD 200 U.S.-region renewal fee.
What to do about it: Treat the dedicated renewal pages as your starting reference, then confirm against your own Mile2 account before your expiry date approaches. Do not rely on a single blog summary, including this one, for the final rule.

Frequently Asked Questions

How many domains does the C)PSH exam have?

The detailed course outline lists eight preparation headings, but these are unweighted curriculum topics rather than a verified weighted exam blueprint. They do not establish an official exam-domain count, so study all eight.

How many questions are on the exam and what score do I need?

The course outline specifies 100 multiple-choice questions in approximately two hours, with a minimum passing grade of 70%. See the passing score guide for more.

Do I have to take the Mile2 course before buying the exam?

No. Purchasing or completing a Mile2 course is not required to purchase the exam. The suggested background, including C)PEH and C)PTE or equivalent knowledge, is a recommendation rather than a mandatory prerequisite.

Is the exam open-book or proctored?

Mile2's published materials conflict. The FAQ describes on-demand online delivery without a live-proctor appointment, while the general policies describe open-book, randomized exams with webcam proctoring for some exams. Follow the instructions in your own C)PSH account and booking flow.

Which domain should I start with?

Start with Domain 1 (PowerShell) and Domain 2 (Active Directory and Kerberos). Later domains on escalation, lateral movement, and persistence assume that foundation. For definitions and background, see What Is C)PSH? and our domains overview.

Ready to pass your C)PSH exam?

Put this into practice with free C)PSH questions across every exam domain.