C)PSH logo
Focused certification exam prep
Start practice

C)PSH Pass Rate 2026: What the Data Shows

TL;DR
  • Mile2 does not publish a verified C)PSH pass rate; any specific percentage you see online should be treated as unsupported.
  • The exam is 100 multiple-choice questions in roughly two hours, with a minimum passing grade of 70%.
  • Exam purchases include two attempts, so a first-try miss is not necessarily the end of your certification effort.
  • Strong Active Directory, Kerberos, and PowerShell scripting knowledge is the best practical predictor of success.

Why a Verified C)PSH Pass Rate Does Not Exist

Search for the Certified Powershell Hacker pass rate and you will find confident-sounding numbers on forums, aggregator sites, and thin "exam stats" pages. None of them trace back to a Mile2 publication. As of the October 3, 2026 source review behind this article, Mile2's course outline, FAQ, and policy documents contain a passing score, a question count, and a time limit, but no cohort-level pass or fail statistics for the C)PSH exam.

That matters because a pass rate is only meaningful when you know who is counted: first-time takers only, or all attempts? Candidates who bought the course, or exam-only purchasers? People who finished the four-day training, or those who sat the exam cold? Without that denominator, a headline percentage tells you almost nothing about your own odds. This article therefore does something more useful than quoting a number. It shows you what the verified data does say, how to interpret it, and which preparation levers realistically move your chance of passing.

A rule of thumb for evaluating any "pass rate" claim: If the source cannot name the certifying body, the time period, and the population measured, discard it. For C)PSH specifically, no such source has been verified, so qualitative preparation matters more than a statistic you cannot check.

For the broader picture of difficulty, see How Hard Is the C)PSH Exam? Complete Difficulty Guide 2026, and for a quick exam facts refresher, the C)PSH Cheat Sheet 2026.

What Mile2 Actually Publishes About the Exam

The hard facts Mile2 does provide are enough to build a realistic picture of the challenge. The table below summarizes them and flags what remains unverified.

ItemWhat the sources supportStatus
Awarding bodyMile2 (Certified Powershell Hacker)Verified
Question count100 multiple-choice questionsVerified in course outline
Time allowedApproximately two hoursVerified; FAQ also gives a two-hour limit for standard exams
Minimum passing grade70%Verified in course outline
DeliveryOnline through the learning management system and your Mile2.com accountVerified
Attempts includedTwo with an exam purchasePer Mile2 FAQ
Certification validityThree yearsVerified
Published pass rateNone foundNot available
Exam-only fee / current bundle priceNot verified in the retrieved listingCheck Mile2 directly

Notice what is absent: any official domain weighting. The eight curriculum headings (covered below) are preparation topics, not a verified weighted blueprint. That means you cannot reliably say "Domain 5 is worth a fixed share of the score," and you should be skeptical of any site that does. If cost is on your mind, our C)PSH Certification Cost 2026 breakdown explains what is and is not confirmed about pricing.

Reading the 70% Threshold Correctly

A 70% minimum on a 100-question exam means you need roughly 70 correct answers. With approximately two hours available, you have about 72 seconds per question on average. That is generous for recall questions and tight for scenario items that require you to mentally trace a PowerShell command, a Kerberos exchange, or a privilege escalation chain.

Because the format is multiple choice, the exam rewards two distinct skills:

  • Recognition of technique and tooling concepts: knowing what a given attack class does and which defensive control addresses it.
  • Reading precision: distinguishing a command that enumerates from one that modifies, or a cmdlet that reads from one that writes.

The 70% bar is neither forgiving nor extreme. Candidates who have genuinely worked in a lab environment tend to find the recognition questions straightforward; candidates who only read slides tend to stumble on the "which of these would actually work" variety. For the exact scoring details, see C)PSH Passing Score 2026: Exactly What You Need to Pass.

Key Takeaway

Aim to be consistently scoring well above 70% on practice material before booking. A margin of safety absorbs the questions you will inevitably find ambiguous. You can test your readiness with the practice resources at our main practice test site.

Where Candidates Lose Points: Domain-by-Domain Risk

Since no official pass-rate data exists, the most defensible way to estimate your own risk is to look at the eight curriculum areas and ask where a typical candidate's knowledge is thinnest. The assessments below are qualitative judgments grounded in how the topics are structured, not statistics. For the full topic list, see C)PSH Exam Domains 2026: Complete Guide to All 8 Content Areas.

Domain 1: Introduction to PowerShell

Usually the comfortable domain for admins, and the risky one for pure penetration testers who rely on other tooling.

  • The object pipeline and how output is passed between cmdlets
  • Execution policy as a speed bump rather than a security boundary
  • Remoting fundamentals and script structure

Domain 2: Introduction to Active Directory and Kerberos

The conceptual foundation for everything that follows, and a frequent weak spot. If you cannot explain the ticket exchange, later attack questions become guesswork.

  • Domains, forests, trusts, and object relationships
  • The Kerberos authentication flow and the role of tickets
  • Why delegation and service accounts create exposure

Domain 3: Pen Testing Methodology Revisited

Methodology questions test whether you understand the sequence and purpose of phases, and how PowerShell fits into an authorized engagement.

  • Scoping, rules of engagement, and authorization boundaries
  • How PowerShell-centric tradecraft maps to engagement phases

Domain 4: Information Gathering and Enumeration

Expect questions about what a given enumeration approach reveals about an AD environment and what it leaves in logs.

  • Directory, user, group, and computer enumeration concepts
  • Identifying high-value targets and trust relationships

Domains 5 and 6: Privilege Escalation, and Lateral Movements and Abusing Trust

These are the conceptually densest areas. Candidates who memorize tool names without understanding the underlying weakness tend to lose points here.

  • Misconfiguration-driven escalation paths
  • Credential exposure and how trust is abused to move between systems

Domains 7 and 8: Persistence and Bypassing Defenses, and Defending Against PowerShell Attacks

Do not skip the defensive domain. It is the easiest place to pick up points because the answers follow from understanding the attacks you just studied.

  • Detection and logging controls relevant to PowerShell activity
  • Hardening approaches and how defenders reduce attack surface

All practice scenarios for these topics should stay conceptual or inside isolated, authorized training environments. Running offensive techniques against systems you do not own or have written permission to test is both unethical and illegal, and it is not required to pass.

Two Attempts, Online Delivery, and What That Changes

According to Mile2's FAQ, standard exams are available online on demand without a live-proctor appointment, and an exam purchase includes two attempts. Two features of this arrangement shape your strategy:

  1. On-demand access reduces scheduling pressure. You are not racing a fixed testing window, so you can book when your practice scores say you are ready. See C)PSH Exam Dates 2026 for how scheduling works in practice.
  2. Two attempts lower the cost of a miss, but not to zero. Treat the first attempt as a real attempt. Use any miss as diagnostic information, but do not plan on burning one for reconnaissance.

The FAQ's separately named proctoring exceptions, C)ISSO-A and C)PTE-A, are different credentials and do not describe C)PSH.

Purchase flexibility: Per Mile2's information, buying or completing a Mile2 course is not required to purchase the exam. The C)PSH Exam Combo bundles exam access, a preparation guide, and quiz/simulator preparation, but a verified current bundle price and a separate exam-only fee were not available in the retrieved listing. Confirm pricing on Mile2.com before budgeting.

The Open-Book and Proctoring Conflict

This is one area where published sources genuinely disagree, and honest guidance means saying so. Mile2's FAQ describes standard exams as available online on demand without a live-proctor appointment. Yet the Policies and Procedures document (May 26, 2026) describes randomized, open-book online examinations and webcam/screen-sharing proctoring in its general certification procedures, while other sections state that only some exams require proctors.

The practical conclusion: do not assume the exam is open-book, and do not assume it is unproctored. Rely on the C)PSH-specific instructions shown in your Mile2.com account and booking flow, and read them fully before you begin. Even if an open-book rule were to apply, it would not rescue an unprepared candidate. With roughly 72 seconds per question, there is no time to research 100 items from scratch.

Prerequisite Knowledge as a Pass-Rate Predictor

Mile2 suggests preparation that includes C)PEH and C)PTE or equivalent knowledge, along with penetration-testing fundamentals, Active Directory, scripting, and programming. These are recommendations, not mandatory prior certifications. Still, they are the clearest signal about who is likely to find the exam manageable.

  • Strong fit: a security practitioner or sysadmin who already writes PowerShell scripts, understands AD object structure, and has run authorized assessments in a lab.
  • Higher risk: a candidate who can name attack tools but has never read a PowerShell script line by line or traced a Kerberos ticket request.
  • Middle path: someone strong in one half (scripting or AD) who needs to deliberately build the other before booking.

For a detailed look at eligibility versus recommended background, read C)PSH Requirements 2026: Eligibility, Prerequisites & How to Qualify. If you are wondering whether the investment pays off, see Is the C)PSH Certification Worth It? Complete ROI Analysis 2026 and the C)PSH Salary Guide 2026.

Key Takeaway

If you can already explain the Kerberos exchange aloud, read an unfamiliar PowerShell function and predict its output, and describe how a defender would detect it, you are in the profile most likely to clear 70%. If any of those three feel shaky, spend your time there first.

A Domain-Sequenced Preparation Plan

Rather than a generic schedule, sequence your study so each domain builds on the last. The Mile2 course itself runs four days with seven training labs, but those figures describe training, not exam length. A self-paced plan can stretch the same content over several weeks. For a fuller walkthrough, see the C)PSH Study Guide 2026: How to Pass on Your First Attempt.

Week 1

Foundations: Domains 1 and 2

  • Write small PowerShell scripts that exercise the pipeline and remoting concepts
  • Diagram the Kerberos flow from memory until you can do it without notes
Week 2

Method and discovery: Domains 3 and 4

  • Map each engagement phase to the PowerShell activity it involves
  • Practice reading enumeration output in an isolated, authorized lab
Week 3

Attack paths: Domains 5 and 6

  • For each escalation or trust-abuse concept, write down the underlying misconfiguration
  • Focus on why it works, not just what it is called
Week 4

Evasion, defense, and rehearsal: Domains 7 and 8

  • Pair every attack concept with its detection and hardening counterpart
  • Take timed practice sets of 100 questions in about two hours

Schedule Domains 1 and 2 first because a weak foundation there quietly drags down your performance everywhere else. Place Domain 8 last, but do not shortchange it: it consolidates everything you learned and is often where well-prepared candidates pick up their margin above 70%.

Renewal Rules and Why They Matter for Your Odds

Certification is valid for three years, and renewal is relevant to the pass-rate conversation for one reason: the sources describing it do not fully agree, and some routes involve passing an exam again. Mile2's dedicated Certification Renewal Program pages describe a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase, and an ethics acknowledgment, or an alternative route involving the latest existing certification exam or an eligible qualifying exam. The FAQ lists a USD 200 U.S.-region renewal fee.

The course outline and the May 2026 policy document describe the process differently. The outline mentions 20 CEUs annually plus passing the current exam, while the policy describes CEUs plus a purchased recertification exam within seven days of expiry, and full reexamination without CEUs after that period. These descriptions should not be merged into one unqualified rule. If renewal is part of your long-term plan, confirm the current route on Mile2's renewal pages at the time you are due.

For the cost side of this, revisit C)PSH Certification Cost 2026. For the career angle on why people pursue and maintain the credential, see C)PSH Jobs and C)PSH Training.

New to the credential? If you landed here still sorting out the basics, start with What Is C)PSH Certification? or What Does C)PSH Stand For?. This article concerns Mile2's Certified Powershell Hacker only, not any other credential that shares the acronym.

Frequently Asked Questions

What is the C)PSH pass rate?

Mile2 has not published a verified pass rate for the Certified Powershell Hacker exam, so any specific percentage you see elsewhere is unsupported. What is verified: 100 multiple-choice questions, approximately two hours, and a 70% minimum passing grade.

How many times can I attempt the C)PSH exam?

According to Mile2's FAQ, exam purchases include two attempts. Confirm the details in your own account at the time of purchase, since terms can change.

Do I need to take the Mile2 course before the exam?

No. Purchasing or completing a Mile2 course is not required to purchase the exam. The four-day course, 32 course CEUs, and seven training labs describe preparation, not an exam requirement.

Is the C)PSH exam open-book or proctored?

Mile2's published materials conflict on this. The FAQ describes on-demand online exams without a live-proctor appointment, while the policy document describes open-book and webcam or screen-sharing proctoring in general procedures. Follow the instructions in your C)PSH account and booking flow.

How do I improve my odds of passing on the first try?

Build real fluency in PowerShell scripting, Active Directory, and Kerberos before attacking the advanced domains, then practice timed 100-question sets. Review the study guide and try the practice questions at our practice test site.

Ready to pass your C)PSH exam?

Put this into practice with free C)PSH questions across every exam domain.