- Why a Verified C)PSH Pass Rate Does Not Exist
- What Mile2 Actually Publishes About the Exam
- Reading the 70% Threshold Correctly
- Where Candidates Lose Points: Domain-by-Domain Risk
- Two Attempts, Online Delivery, and What That Changes
- The Open-Book and Proctoring Conflict
- Prerequisite Knowledge as a Pass-Rate Predictor
- A Domain-Sequenced Preparation Plan
- Renewal Rules and Why They Matter for Your Odds
- Frequently Asked Questions
- Mile2 does not publish a verified C)PSH pass rate; any specific percentage you see online should be treated as unsupported.
- The exam is 100 multiple-choice questions in roughly two hours, with a minimum passing grade of 70%.
- Exam purchases include two attempts, so a first-try miss is not necessarily the end of your certification effort.
- Strong Active Directory, Kerberos, and PowerShell scripting knowledge is the best practical predictor of success.
Why a Verified C)PSH Pass Rate Does Not Exist
Search for the Certified Powershell Hacker pass rate and you will find confident-sounding numbers on forums, aggregator sites, and thin "exam stats" pages. None of them trace back to a Mile2 publication. As of the October 3, 2026 source review behind this article, Mile2's course outline, FAQ, and policy documents contain a passing score, a question count, and a time limit, but no cohort-level pass or fail statistics for the C)PSH exam.
That matters because a pass rate is only meaningful when you know who is counted: first-time takers only, or all attempts? Candidates who bought the course, or exam-only purchasers? People who finished the four-day training, or those who sat the exam cold? Without that denominator, a headline percentage tells you almost nothing about your own odds. This article therefore does something more useful than quoting a number. It shows you what the verified data does say, how to interpret it, and which preparation levers realistically move your chance of passing.
For the broader picture of difficulty, see How Hard Is the C)PSH Exam? Complete Difficulty Guide 2026, and for a quick exam facts refresher, the C)PSH Cheat Sheet 2026.
What Mile2 Actually Publishes About the Exam
The hard facts Mile2 does provide are enough to build a realistic picture of the challenge. The table below summarizes them and flags what remains unverified.
| Item | What the sources support | Status |
|---|---|---|
| Awarding body | Mile2 (Certified Powershell Hacker) | Verified |
| Question count | 100 multiple-choice questions | Verified in course outline |
| Time allowed | Approximately two hours | Verified; FAQ also gives a two-hour limit for standard exams |
| Minimum passing grade | 70% | Verified in course outline |
| Delivery | Online through the learning management system and your Mile2.com account | Verified |
| Attempts included | Two with an exam purchase | Per Mile2 FAQ |
| Certification validity | Three years | Verified |
| Published pass rate | None found | Not available |
| Exam-only fee / current bundle price | Not verified in the retrieved listing | Check Mile2 directly |
Notice what is absent: any official domain weighting. The eight curriculum headings (covered below) are preparation topics, not a verified weighted blueprint. That means you cannot reliably say "Domain 5 is worth a fixed share of the score," and you should be skeptical of any site that does. If cost is on your mind, our C)PSH Certification Cost 2026 breakdown explains what is and is not confirmed about pricing.
Reading the 70% Threshold Correctly
A 70% minimum on a 100-question exam means you need roughly 70 correct answers. With approximately two hours available, you have about 72 seconds per question on average. That is generous for recall questions and tight for scenario items that require you to mentally trace a PowerShell command, a Kerberos exchange, or a privilege escalation chain.
Because the format is multiple choice, the exam rewards two distinct skills:
- Recognition of technique and tooling concepts: knowing what a given attack class does and which defensive control addresses it.
- Reading precision: distinguishing a command that enumerates from one that modifies, or a cmdlet that reads from one that writes.
The 70% bar is neither forgiving nor extreme. Candidates who have genuinely worked in a lab environment tend to find the recognition questions straightforward; candidates who only read slides tend to stumble on the "which of these would actually work" variety. For the exact scoring details, see C)PSH Passing Score 2026: Exactly What You Need to Pass.
Key Takeaway
Aim to be consistently scoring well above 70% on practice material before booking. A margin of safety absorbs the questions you will inevitably find ambiguous. You can test your readiness with the practice resources at our main practice test site.
Where Candidates Lose Points: Domain-by-Domain Risk
Since no official pass-rate data exists, the most defensible way to estimate your own risk is to look at the eight curriculum areas and ask where a typical candidate's knowledge is thinnest. The assessments below are qualitative judgments grounded in how the topics are structured, not statistics. For the full topic list, see C)PSH Exam Domains 2026: Complete Guide to All 8 Content Areas.
Domain 1: Introduction to PowerShell
Usually the comfortable domain for admins, and the risky one for pure penetration testers who rely on other tooling.
- The object pipeline and how output is passed between cmdlets
- Execution policy as a speed bump rather than a security boundary
- Remoting fundamentals and script structure
Domain 2: Introduction to Active Directory and Kerberos
The conceptual foundation for everything that follows, and a frequent weak spot. If you cannot explain the ticket exchange, later attack questions become guesswork.
- Domains, forests, trusts, and object relationships
- The Kerberos authentication flow and the role of tickets
- Why delegation and service accounts create exposure
Domain 3: Pen Testing Methodology Revisited
Methodology questions test whether you understand the sequence and purpose of phases, and how PowerShell fits into an authorized engagement.
- Scoping, rules of engagement, and authorization boundaries
- How PowerShell-centric tradecraft maps to engagement phases
Domain 4: Information Gathering and Enumeration
Expect questions about what a given enumeration approach reveals about an AD environment and what it leaves in logs.
- Directory, user, group, and computer enumeration concepts
- Identifying high-value targets and trust relationships
Domains 5 and 6: Privilege Escalation, and Lateral Movements and Abusing Trust
These are the conceptually densest areas. Candidates who memorize tool names without understanding the underlying weakness tend to lose points here.
- Misconfiguration-driven escalation paths
- Credential exposure and how trust is abused to move between systems
Domains 7 and 8: Persistence and Bypassing Defenses, and Defending Against PowerShell Attacks
Do not skip the defensive domain. It is the easiest place to pick up points because the answers follow from understanding the attacks you just studied.
- Detection and logging controls relevant to PowerShell activity
- Hardening approaches and how defenders reduce attack surface
All practice scenarios for these topics should stay conceptual or inside isolated, authorized training environments. Running offensive techniques against systems you do not own or have written permission to test is both unethical and illegal, and it is not required to pass.
Two Attempts, Online Delivery, and What That Changes
According to Mile2's FAQ, standard exams are available online on demand without a live-proctor appointment, and an exam purchase includes two attempts. Two features of this arrangement shape your strategy:
- On-demand access reduces scheduling pressure. You are not racing a fixed testing window, so you can book when your practice scores say you are ready. See C)PSH Exam Dates 2026 for how scheduling works in practice.
- Two attempts lower the cost of a miss, but not to zero. Treat the first attempt as a real attempt. Use any miss as diagnostic information, but do not plan on burning one for reconnaissance.
The FAQ's separately named proctoring exceptions, C)ISSO-A and C)PTE-A, are different credentials and do not describe C)PSH.
The Open-Book and Proctoring Conflict
This is one area where published sources genuinely disagree, and honest guidance means saying so. Mile2's FAQ describes standard exams as available online on demand without a live-proctor appointment. Yet the Policies and Procedures document (May 26, 2026) describes randomized, open-book online examinations and webcam/screen-sharing proctoring in its general certification procedures, while other sections state that only some exams require proctors.
The practical conclusion: do not assume the exam is open-book, and do not assume it is unproctored. Rely on the C)PSH-specific instructions shown in your Mile2.com account and booking flow, and read them fully before you begin. Even if an open-book rule were to apply, it would not rescue an unprepared candidate. With roughly 72 seconds per question, there is no time to research 100 items from scratch.
Prerequisite Knowledge as a Pass-Rate Predictor
Mile2 suggests preparation that includes C)PEH and C)PTE or equivalent knowledge, along with penetration-testing fundamentals, Active Directory, scripting, and programming. These are recommendations, not mandatory prior certifications. Still, they are the clearest signal about who is likely to find the exam manageable.
- Strong fit: a security practitioner or sysadmin who already writes PowerShell scripts, understands AD object structure, and has run authorized assessments in a lab.
- Higher risk: a candidate who can name attack tools but has never read a PowerShell script line by line or traced a Kerberos ticket request.
- Middle path: someone strong in one half (scripting or AD) who needs to deliberately build the other before booking.
For a detailed look at eligibility versus recommended background, read C)PSH Requirements 2026: Eligibility, Prerequisites & How to Qualify. If you are wondering whether the investment pays off, see Is the C)PSH Certification Worth It? Complete ROI Analysis 2026 and the C)PSH Salary Guide 2026.
Key Takeaway
If you can already explain the Kerberos exchange aloud, read an unfamiliar PowerShell function and predict its output, and describe how a defender would detect it, you are in the profile most likely to clear 70%. If any of those three feel shaky, spend your time there first.
A Domain-Sequenced Preparation Plan
Rather than a generic schedule, sequence your study so each domain builds on the last. The Mile2 course itself runs four days with seven training labs, but those figures describe training, not exam length. A self-paced plan can stretch the same content over several weeks. For a fuller walkthrough, see the C)PSH Study Guide 2026: How to Pass on Your First Attempt.
Foundations: Domains 1 and 2
- Write small PowerShell scripts that exercise the pipeline and remoting concepts
- Diagram the Kerberos flow from memory until you can do it without notes
Method and discovery: Domains 3 and 4
- Map each engagement phase to the PowerShell activity it involves
- Practice reading enumeration output in an isolated, authorized lab
Attack paths: Domains 5 and 6
- For each escalation or trust-abuse concept, write down the underlying misconfiguration
- Focus on why it works, not just what it is called
Evasion, defense, and rehearsal: Domains 7 and 8
- Pair every attack concept with its detection and hardening counterpart
- Take timed practice sets of 100 questions in about two hours
Schedule Domains 1 and 2 first because a weak foundation there quietly drags down your performance everywhere else. Place Domain 8 last, but do not shortchange it: it consolidates everything you learned and is often where well-prepared candidates pick up their margin above 70%.
Renewal Rules and Why They Matter for Your Odds
Certification is valid for three years, and renewal is relevant to the pass-rate conversation for one reason: the sources describing it do not fully agree, and some routes involve passing an exam again. Mile2's dedicated Certification Renewal Program pages describe a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase, and an ethics acknowledgment, or an alternative route involving the latest existing certification exam or an eligible qualifying exam. The FAQ lists a USD 200 U.S.-region renewal fee.
The course outline and the May 2026 policy document describe the process differently. The outline mentions 20 CEUs annually plus passing the current exam, while the policy describes CEUs plus a purchased recertification exam within seven days of expiry, and full reexamination without CEUs after that period. These descriptions should not be merged into one unqualified rule. If renewal is part of your long-term plan, confirm the current route on Mile2's renewal pages at the time you are due.
For the cost side of this, revisit C)PSH Certification Cost 2026. For the career angle on why people pursue and maintain the credential, see C)PSH Jobs and C)PSH Training.
Frequently Asked Questions
Mile2 has not published a verified pass rate for the Certified Powershell Hacker exam, so any specific percentage you see elsewhere is unsupported. What is verified: 100 multiple-choice questions, approximately two hours, and a 70% minimum passing grade.
According to Mile2's FAQ, exam purchases include two attempts. Confirm the details in your own account at the time of purchase, since terms can change.
No. Purchasing or completing a Mile2 course is not required to purchase the exam. The four-day course, 32 course CEUs, and seven training labs describe preparation, not an exam requirement.
Mile2's published materials conflict on this. The FAQ describes on-demand online exams without a live-proctor appointment, while the policy document describes open-book and webcam or screen-sharing proctoring in general procedures. Follow the instructions in your C)PSH account and booking flow.
Build real fluency in PowerShell scripting, Active Directory, and Kerberos before attacking the advanced domains, then practice timed 100-question sets. Review the study guide and try the practice questions at our practice test site.