C)PSH logo
Focused certification exam prep
Start practice

C)PSH Study Guide 2026: How to Pass on Your First Attempt

TL;DR
  • The Mile2 outline lists 100 multiple-choice questions, roughly two hours, and a 70% minimum passing grade.
  • Eight preparation domains run from PowerShell basics through Active Directory attacks to defending against PowerShell attacks.
  • Mile2 suggests C)PEH and C)PTE or equivalent knowledge, but neither certification is mandatory.
  • Mile2 sources conflict on open-book and proctoring rules, so confirm instructions in your own Mile2.com account.

What You Are Actually Preparing For

Certified Powershell Hacker is a Mile2 credential, styled "Certified PowerShell Hacker" in Mile2's course materials. It focuses on how attackers use PowerShell inside Windows and Active Directory environments, and on how defenders detect and limit that activity. If you are new to the acronym, our explainers on what C)PSH certification is and what C)PSH stands for cover the naming basics. This guide assumes you have decided to sit the exam and want a practical plan.

The first thing to understand is that the exam is knowledge-based. The published outline describes multiple-choice questions, not a hands-on practical. That shapes how you should study: you need to recognize concepts, cmdlets, attack stages, and defensive controls quickly and accurately, but you are not being asked to compromise a live network under a timer.

Exam Format and Booking Mechanics

According to the current Mile2 Certified PowerShell Hacker course outline, the exam has these characteristics:

ItemWhat the Mile2 outline states
Question count100 multiple-choice questions
Time allowedApproximately two hours
Minimum passing grade70%
DeliveryOnline, through Mile2's learning management system and your Mile2.com account
AttemptsMile2's FAQ states exam purchases include two attempts

A 70% minimum on 100 questions means you need 70 correct answers, and our page on the C)PSH passing score goes deeper on what that margin means in practice. Mile2's FAQ also says standard exams are available online on demand without a live-proctor appointment, and that a course purchase is not required to buy the exam. If you are budgeting, the C)PSH certification cost breakdown explains what is and is not verified. Mile2 lists a C)PSH Exam Combo that includes exam access, a preparation guide, and quiz/simulator preparation, but a current bundle price and a separate exam-only fee should be confirmed directly on Mile2's listing rather than taken from older promotions.

Check the proctoring rules yourself: Mile2's general Policies and Procedures document describes randomized, open-book online exams and webcam/screen-sharing proctoring, while other Mile2 sections say only some exams require proctors, and the FAQ says standard exams need no live-proctor appointment. These published statements conflict. Do not assume open-book rules or a proctoring requirement for C)PSH. Follow the instructions shown in your own account and booking flow, and prepare as though you will need to recall material from memory.

For scheduling questions, see our notes on C)PSH exam dates and scheduling. Because delivery is on demand, your real deadline is the one you set for yourself.

Skills to Have Before You Start

Mile2's suggested preparation includes C)PEH and C)PTE or equivalent knowledge, along with penetration-testing fundamentals, Active Directory, scripting, and programming. These are recommendations, not mandatory prior certifications. Our C)PSH requirements guide separates what is required from what is merely advisable.

In practical terms, ask yourself three questions before you begin:

  • Can you read a multi-line PowerShell script and explain what each pipeline stage does?
  • Can you describe how a Windows domain authenticates a user and what a domain controller is responsible for?
  • Can you explain the general phases of a penetration test, from scoping to reporting?

If any answer is shaky, spend your first study sessions there. The later domains build directly on these foundations, and candidates who skip them often find the Kerberos and privilege escalation material harder than it needs to be. For a realistic sense of difficulty, read how hard the C)PSH exam is.

Domain-by-Domain Study Walkthrough

The eight domains below mirror the preparation curriculum headings in the Detailed Outline of Mile2's course outline PDF. They are unweighted preparation topics, not a verified weighted exam blueprint, so do not assume any domain is worth more questions than another. For a longer treatment, see the complete guide to all eight content areas.

Domain 1: Introduction to PowerShell

This is your language foundation. Everything offensive and defensive later depends on fluency here.

  • Cmdlet naming, the object-based pipeline, and how output is filtered and formatted
  • Variables, functions, modules, and execution policy concepts
  • Remoting concepts and how PowerShell interacts with .NET and WMI/CIM
  • How to read unfamiliar scripts and predict their effect

Domain 2: Introduction to Active Directory and Kerberos

Most of the credential's attack paths run through Active Directory, so this domain deserves real time.

  • Domains, forests, trusts, organizational units, groups, and service accounts
  • The Kerberos flow: tickets, the ticket-granting service, and what each ticket proves
  • Why Kerberos design choices create abusable weaknesses
  • How AD objects and permissions are represented and queried

Domain 3: Pen Testing Methodology Revisited

Use the detailed heading from the outline as your guide. Expect questions that place PowerShell activity inside a structured engagement.

  • Phases of an authorized engagement and where PowerShell tooling fits in each
  • Rules of engagement, scoping, and documentation habits
  • Mapping findings to attacker objectives rather than isolated tricks

Domain 4: Information Gathering and Enumeration

Know what can be learned about a Windows environment and which native capabilities reveal it.

  • Enumerating users, groups, computers, shares, and trust relationships
  • Identifying high-value accounts and privileged group membership
  • Distinguishing noisy enumeration from quieter methods, and why defenders care

Domain 5: Privilege Escalation

Focus on the categories of weakness rather than memorizing individual tools.

  • Misconfigured services, permissions, and unquoted or writable paths
  • Credential exposure in scripts, files, and memory, at a conceptual level
  • Kerberos-related account abuse and why weak service account passwords matter

Domain 6: Lateral Movements and Abusing Trust

This domain connects Domains 2 and 5: once an attacker holds a credential, how do they use it elsewhere?

  • Remote execution mechanisms and the artifacts they leave behind
  • Trust relationships between hosts, domains, and forests
  • Credential reuse and delegation concepts

Domain 7: Persistence and Bypassing Defenses

Understand why attackers want durable access and how they try to avoid detection, both for exam recognition and for defense.

  • Common persistence locations and mechanisms in Windows and AD
  • Concepts behind evading script scanning, logging, and application controls
  • How each evasion idea maps to a detection opportunity

Domain 8: Defending Against PowerShell Attacks

Do not treat this as an afterthought. Defensive controls give you a lens for reviewing every earlier domain.

  • PowerShell logging types and what each one captures
  • Constrained language concepts, application control, and least privilege
  • Hardening Active Directory to reduce the impact of the attacks in Domains 4 through 7
  • Monitoring approaches that surface suspicious script activity

Building an Isolated Lab for Practice

Mile2's course materials describe seven training labs, which signals that hands-on familiarity is part of the intended preparation even though the exam itself is multiple choice. Building your own environment helps concepts stick, but keep it strictly contained.

  • Run everything on isolated virtual machines with no route to production networks or the internet-facing parts of your home setup.
  • Stand up a small domain with a domain controller and one or two member machines so Kerberos and trust concepts become observable rather than abstract.
  • Use only systems you own or are explicitly authorized to test.
  • After exploring any attack concept, switch to the defender's view: find which log entry or configuration would have exposed it.
Why the lab matters for a multiple-choice exam: Questions often describe a scenario and ask what is happening, what comes next, or which control would stop it. Candidates who have seen the behavior in a lab recognize the pattern faster than those who only read about it.

Sequencing the Domains Across Your Weeks

Rather than spreading time evenly, order your study by dependency. PowerShell and Active Directory knowledge underpin everything else, so they come first. This is one possible six-week layout; compress or stretch it to match your background.

Week 1

Domain 1: Introduction to PowerShell

  • Write and read small scripts daily
  • Practice pipeline filtering until it feels automatic
Week 2

Domains 2 and 3: Active Directory, Kerberos, and methodology

  • Draw the Kerberos ticket flow from memory
  • Place each engagement phase alongside its PowerShell activities
Week 3

Domain 4: Information Gathering and Enumeration

  • Enumerate your lab domain and record what each query reveals
Week 4

Domains 5 and 6: Privilege Escalation and Lateral Movements

  • Group weaknesses by category
  • Trace how one foothold becomes domain-wide access
Week 5

Domains 7 and 8: Persistence, Bypassing Defenses, and Defense

  • Pair every offensive technique with its detection or mitigation
Week 6

Review and timed practice

  • Sit full-length practice sets under two-hour conditions
  • Revisit your weakest domain

For a compact reference to keep beside you during review, see the C)PSH cheat sheet, and use the C)PSH practice tests to measure how ready you are.

Handling Multiple-Choice Questions on Offensive PowerShell

With 100 questions in roughly two hours, you have a little over a minute per question on average. A few habits suit this subject matter well:

  • Read the scenario for the stage of attack. Many questions become easy once you identify whether the described activity is enumeration, escalation, lateral movement, or persistence.
  • Watch for cmdlet and parameter detail. Distractors frequently differ from the correct answer by a single parameter or a similar-sounding command.
  • Think like both sides. If a question asks what a defender would see or do, recall the logging and hardening material from Domain 8 rather than the attacker mechanics.
  • Flag and move on. Mark long script-reading questions, answer the quick ones first, and return with the remaining time.

Because Mile2 describes the exam as randomized, the order of topics you meet will not follow the curriculum order, so practice switching between domains instead of studying them only in blocks. Our C)PSH pass rate page explains why no official figure should be assumed, and the main practice test site offers mixed-domain sets for this kind of switching.

Key Takeaway

Treat Kerberos and Active Directory as the center of your preparation. Domains 4 through 7 all assume you understand how identities, tickets, and trusts work, and Domain 8 only makes sense once you know what is being defended.

After You Pass: Validity and Renewal

Certification is valid for three years. Renewal details vary across Mile2 sources, so read the dedicated pages before you plan. Mile2's Certification Renewal Program and Paths to Renewal pages describe two alternative routes: a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase, and an ethics acknowledgment, or a route involving the latest existing certification exam or an eligible qualifying exam. The FAQ lists a USD 200 U.S.-region renewal fee.

Other Mile2 documents describe renewal differently. The course outline mentions 20 CEUs annually plus passing the current exam, and the May 2026 policy document describes CEUs plus a purchased recertification exam within seven days of expiry, with full reexamination and no CEUs after that window. Do not merge these into one rule. Confirm the current requirement with Mile2 when your expiry approaches.

If you are weighing whether the credential suits your goals, see our analyses of whether the C)PSH is worth it, the C)PSH salary guide, and C)PSH jobs. The skills tend to be relevant to penetration testers, red teamers, and defenders who need to understand Windows-focused attack tradecraft.

Frequently Asked Questions

How many questions are on the C)PSH exam and what score do I need?

Mile2's current course outline specifies 100 multiple-choice questions, approximately two hours, and a minimum passing grade of 70%.

Do I have to take a Mile2 course before buying the exam?

No. Purchasing or completing a Mile2 course is not required to purchase the exam. The four-day course and its labs are preparation options, not eligibility gates.

Is the C)PSH exam open-book or proctored?

Mile2's published documents conflict. The general policies describe open-book, proctored online exams, while the FAQ says standard exams are on demand without a live-proctor appointment. Follow the instructions in your own Mile2.com account and booking flow.

Do I need C)PEH and C)PTE first?

They are suggested preparation, not mandatory prerequisites. Equivalent knowledge of penetration testing, Active Directory, scripting, and programming is what matters for readiness.

How long is the certification valid and how do I renew?

The certification is valid for three years. Mile2's renewal pages describe a CEU route (60 documented CEUs plus a renewal purchase and ethics acknowledgment) or an exam-based route as alternatives. Other Mile2 documents describe renewal differently, so confirm current terms with Mile2 before your expiry date.

Ready to pass your C)PSH exam?

Put this into practice with free C)PSH questions across every exam domain.