- The Short Answer: What Does Mile2 Actually Require?
- Which Credential This Article Covers
- Recommended Background: What Mile2 Suggests You Know
- Is the Mile2 Course Mandatory?
- Exam Format and Delivery Mechanics
- The Proctoring and Open-Book Ambiguity
- Technical Readiness Mapped to the Eight Curriculum Headings
- Buying the Exam: What Is and Is Not Verified
- Validity and Renewal: Reading the Conflicting Sources
- A Qualification Plan Sequenced by Curriculum Heading
- Who Tends to Pursue This Credential
- Frequently Asked Questions
- Mile2 lists C)PSH prerequisites as suggestions, not mandatory prior certifications; C)PEH and C)PTE or equivalent knowledge is recommended.
- You do not have to buy or complete a Mile2 course to purchase the exam.
- The outline specifies 100 multiple-choice questions, about two hours, and a 70% minimum passing grade.
- Exam purchases include two attempts, and standard exams are available online on demand.
The Short Answer: What Does Mile2 Actually Require?
If you are searching for C)PSH requirements, the reassuring news is that Mile2 does not publish a gate of mandatory prior certifications, years of experience, or a mandatory training purchase for this credential. What it does publish is a set of suggested preparation areas and a description of how the exam is delivered. The distinction between "recommended" and "required" matters, and a lot of confusion online comes from blurring the two.
In practical terms, qualifying for Certified Powershell Hacker comes down to three things: having enough hands-on knowledge to handle a 100-question multiple-choice exam, buying and scheduling the exam through your Mile2.com account, and scoring at least 70%. This article walks through each of those, keeps the verified facts separate from the unverified ones, and points out where Mile2's own published documents disagree so you are not caught off guard.
Which Credential This Article Covers
Mile2 awards Certified Powershell Hacker, which its course materials style as Certified PowerShell Hacker. Many candidates search for it using the punctuation-free alias "CPSH," which is the same credential. The exam is delivered online through Mile2's learning management system and the candidate's Mile2.com account.
The credential focuses on offensive and defensive use of PowerShell in Windows and Active Directory environments. If you want a broader introduction before diving into eligibility, our overview at What Is C)PSH? covers the fundamentals, and C)PSH Certification frames the credential at a high level.
Recommended Background: What Mile2 Suggests You Know
Mile2's published preparation guidance recommends the following background. Treat this as a readiness checklist, not an admissions test:
- C)PEH and C)PTE, or equivalent knowledge (Mile2's Certified Professional Ethical Hacker and Certified Penetration Testing Engineer tracks)
- Penetration-testing fundamentals
- Active Directory familiarity
- Scripting experience
- Programming background
Crucially, these are recommendations. Holding C)PEH or C)PTE is not a mandatory prior certification for sitting the C)PSH exam. The phrase "or equivalent knowledge" is doing real work: someone who has spent years doing authorized Windows internal assessments may be better prepared than someone who simply holds the named certificates.
| Item | Status per Mile2 materials |
|---|---|
| C)PEH or equivalent knowledge | Suggested preparation, not mandatory |
| C)PTE or equivalent knowledge | Suggested preparation, not mandatory |
| Penetration-testing fundamentals | Suggested preparation |
| Active Directory knowledge | Suggested preparation |
| Scripting and programming | Suggested preparation |
| Purchasing or completing a Mile2 course | Not required to purchase the exam |
Is the Mile2 Course Mandatory?
No. Per the verified facts, purchasing or completing a Mile2 course is not required to purchase the exam. That is a meaningful difference from certifications that lock the exam behind an official training purchase.
The associated course is described as four days, with 32 course CEUs and seven training labs. Those details describe preparation. They are not the exam duration, they do not represent a separate practical assessment, and they should not be read as a verified renewal-hour requirement. A common mistake is to see "32 CEUs" and assume it ties into renewal math. Keep those facts in the preparation bucket.
Exam Format and Delivery Mechanics
The current five-page Certified PowerShell Hacker course outline from Mile2 specifies the following exam parameters:
- Questions: 100 multiple-choice questions
- Time: approximately two hours
- Minimum passing grade: 70%
Mile2's general FAQ also gives a two-hour limit for standard exams, which is consistent with the outline. The FAQ states that standard exams are available online on demand, without a live-proctor appointment, and that exam purchases include two attempts.
Note that the outline is undated, so the verification date matters: these figures reflect a source review on October 3, 2026. If you are reading this later, check the outline linked from Mile2's C)PSH course-outline page before you commit to a plan. For a deeper look at scoring, read C)PSH Passing Score 2026, and for what the numbers imply about difficulty, see How Hard Is the C)PSH Exam?.
Key Takeaway
Do the arithmetic before you start: 70% of 100 questions is 70 correct answers within roughly two hours. That averages out to a little over a minute per question, which is comfortable for recall questions and tight for scenario-heavy ones. Practice reading command output and syntax quickly.
The Proctoring and Open-Book Ambiguity
This is the part of the requirements picture where Mile2's own documents disagree, and honesty about that is more useful than a confident-sounding guess.
- The FAQ says standard exams are available online on demand without a live-proctor appointment. Its separately named proctoring exceptions (C)ISSO-A and C)PTE-A) are different credentials and do not apply here.
- The Mile2 Policies and Procedures document (May 26, 2026) describes randomized, open-book online examinations and webcam/screen-sharing proctoring in its general certification procedures, while other sections say only some exams require proctors.
These published instructions conflict. The responsible approach is to apply the C)PSH-specific account and booking instructions you see when you purchase and launch your exam, rather than assuming a universal open-book rule or a universal proctoring rule. Check your Mile2.com account for any hardware, webcam, browser, or screen-sharing requirements before exam day, and do not plan your preparation around the assumption that you can look things up.
Technical Readiness Mapped to the Eight Curriculum Headings
Mile2's detailed outline lists eight preparation headings. These are unweighted curriculum topics, not a verified weighted exam blueprint, and they do not establish exhaustive exam coverage or an official exam-domain count. They are still the best guide to what "qualified" looks like in practice. Our C)PSH Exam Domains 2026 guide goes deeper on each; here is how they translate into readiness.
Domain 1: Introduction to PowerShell
The foundation. You should be comfortable reading and reasoning about PowerShell syntax before attempting the offensive material.
- Cmdlet structure, the pipeline, and object handling
- Execution policy concepts and how they relate to script running
- Modules, remoting concepts, and scripting constructs
Domain 2: Introduction to Active Directory and Kerberos
Most of the later material assumes you understand how AD authenticates and authorizes.
- Domain, forest, and trust structure
- Kerberos ticket flow and why it matters to attackers and defenders
- Users, groups, and permissions as attack surface
Domain 3: Pen Testing Methodology Revisited
The detailed outline heading is "Pen Testing Methodology Revisited" (the overview uses a different Module 3 title, and the detailed heading controls). Expect methodology framed around PowerShell-centric assessments.
- Phases of an engagement and where PowerShell fits
- Authorization, scope, and rules of engagement
Domain 4: Information Gathering and Enumeration
Understanding what can be learned about a Windows environment using native tooling.
- Enumerating users, groups, hosts, and shares conceptually
- Recognizing what enumeration looks like from the defender's side
Domain 5: Privilege Escalation
Conceptual understanding of how misconfigurations lead to elevated access.
- Common Windows misconfiguration categories
- Why least privilege and patching reduce this risk
Domain 6: Lateral Movements and Abusing Trust
How access spreads once a foothold exists, and how trust relationships get misused.
- Remote execution concepts and credential exposure
- Trust relationships within and across domains
Domain 7: Persistence and Bypassing Defenses
How attackers maintain access and evade controls, studied so defenders can recognize it.
- Persistence mechanism categories at a conceptual level
- Defensive controls and the logic of how they get evaded
Domain 8: Defending Against PowerShell Attacks
The defensive counterpart: logging, constrained execution, and detection.
- PowerShell logging and visibility concepts
- Language-mode and execution-control ideas
- Detection and hardening strategy
Buying the Exam: What Is and Is Not Verified
The C)PSH Exam Combo is listed by Mile2 and includes exam access, a preparation guide, and quiz/simulator preparation. Purchases are handled through Mile2.com, and exam delivery runs through the learning management system tied to your account.
Here is what we can and cannot say about pricing. A current bundle price and a separate exam-only fee were not verified in the retrieved listing, and earlier promotional amounts are not treated as current fees. Rather than quoting a number that may be stale, check the product page directly. Our C)PSH Certification Cost 2026 article explains how to think about the total cost without relying on unverified figures.
| Purchase Detail | What Is Verified |
|---|---|
| Exam Combo contents | Exam access, preparation guide, quiz/simulator preparation |
| Attempts included | Two attempts with an exam purchase (per FAQ) |
| Delivery | Online, on demand, via Mile2 learning management system and account |
| Current bundle price | Not verified in the retrieved listing |
| Separate exam-only fee | Not verified in the retrieved listing |
Because exam purchases include two attempts and scheduling is on demand, there is no fixed test-window calendar to qualify for. If you are wondering about timing, read C)PSH Exam Dates 2026 for how the on-demand model affects planning.
Validity and Renewal: Reading the Conflicting Sources
Qualifying is not only about the first pass. Certification is valid for three years, and staying certified involves renewal. This is another area where Mile2's published materials do not perfectly align, so it pays to read carefully rather than collapse everything into a single rule.
- Dedicated renewal pages (the Certification Renewal Program and Paths to Renewal): describe a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase, and ethics acknowledgment, or an alternative route involving the latest existing certification exam or an eligible qualifying exam. These are presented as alternatives.
- FAQ: lists a USD 200 U.S.-region renewal fee.
- Course outline: says 20 CEUs annually plus passing the current exam.
- May 2026 Policies and Procedures: uses CEUs plus a purchased recertification exam within seven days of expiry, and full reexamination without CEUs after that period.
For a look at whether the credential's long-term maintenance is worthwhile, see Is the C)PSH Certification Worth It?.
A Qualification Plan Sequenced by Curriculum Heading
This is the one planning section in the article, and it is tied to the eight C)PSH headings rather than generic advice. The sequencing logic is that later domains depend on earlier ones: you cannot reason about Kerberos abuse without understanding Kerberos, and you cannot reason about detection without understanding the technique.
PowerShell Fluency and AD Basics
- Domain 1: Introduction to PowerShell
- Domain 2: Introduction to Active Directory and Kerberos, starting with ticket flow
Methodology and Discovery
- Domain 3: Pen Testing Methodology Revisited
- Domain 4: Information Gathering and Enumeration
Escalation and Movement
- Domain 5: Privilege Escalation
- Domain 6: Lateral Movements and Abusing Trust
Persistence, Defense, and Timed Practice
- Domain 7: Persistence and Bypassing Defenses
- Domain 8: Defending Against PowerShell Attacks
- Full 100-question timed practice sets in about two hours
Adjust the length to your background. Someone fluent in AD may compress Weeks 1 and 2; someone new to scripting may stretch Week 1. Use the C)PSH practice tests to identify which of the eight headings is costing you points, and consult the C)PSH Cheat Sheet for a condensed review once your fundamentals are in place. Candidates curious about outcomes can also read C)PSH Pass Rate 2026, which explains what can and cannot be said about pass data.
Who Tends to Pursue This Credential
Because there is no hard prerequisite wall, the credential attracts a mix of roles. People who typically find the material relevant include:
- Penetration testers and red teamers who work in Windows and Active Directory environments
- Security analysts and blue-team members who need to understand PowerShell-based attacks in order to detect them
- Windows and systems administrators moving toward security roles
- Existing Mile2 certificate holders (for example C)PEH or C)PTE) extending into PowerShell-focused work
Domain 8, Defending Against PowerShell Attacks, is a reminder that the credential is not purely offensive. Employers evaluating candidates for defensive or hybrid roles can value that balance. For role-oriented context, see C)PSH Jobs, and for compensation discussion without invented figures, see the C)PSH Salary Guide 2026.
Key Takeaway
"Qualifying" for C)PSH is mostly about demonstrable competence, not paperwork. If you can explain Kerberos ticket flow, read PowerShell syntax fluently, and describe both an attack concept and its defensive counter for each curriculum heading, you are meeting the spirit of Mile2's recommendations.
Frequently Asked Questions
No. Mile2 suggests C)PEH and C)PTE or equivalent knowledge as preparation, but these are recommendations, not mandatory prior certifications. What matters is that you have the underlying penetration-testing, Active Directory, scripting, and programming knowledge.
No. Purchasing or completing a Mile2 course is not required to purchase the exam. The four-day course, 32 CEUs, and seven labs describe preparation, not an exam prerequisite.
The current course outline specifies 100 multiple-choice questions, approximately two hours, and a minimum passing grade of 70%. Exam purchases include two attempts, and standard exams are available online on demand.
Mile2's published documents conflict. The FAQ describes on-demand online exams without a live-proctor appointment, while the May 2026 policies describe randomized, open-book exams and webcam/screen-sharing proctoring in general procedures. Follow the instructions shown in your C)PSH account and booking flow rather than assuming either rule.
Certification is valid for three years. The dedicated renewal pages describe alternative routes: a continuing-education route requiring 60 documented CEUs, a renewal purchase, and ethics acknowledgment, or an exam-based route. Other Mile2 documents describe the mechanics differently, so confirm the current path in your Mile2 account before planning.
Ready to measure where you stand against the eight curriculum headings? Start with the C)PSH practice test site, and revisit the C)PSH Requirements overview whenever Mile2 updates its published guidance.