- What You Are Actually Preparing For
- Exam Format and Booking Mechanics
- Skills to Have Before You Start
- Domain-by-Domain Study Walkthrough
- Building an Isolated Lab for Practice
- Sequencing the Domains Across Your Weeks
- Handling Multiple-Choice Questions on Offensive PowerShell
- After You Pass: Validity and Renewal
- Frequently Asked Questions
- The Mile2 outline lists 100 multiple-choice questions, roughly two hours, and a 70% minimum passing grade.
- Eight preparation domains run from PowerShell basics through Active Directory attacks to defending against PowerShell attacks.
- Mile2 suggests C)PEH and C)PTE or equivalent knowledge, but neither certification is mandatory.
- Mile2 sources conflict on open-book and proctoring rules, so confirm instructions in your own Mile2.com account.
What You Are Actually Preparing For
Certified Powershell Hacker is a Mile2 credential, styled "Certified PowerShell Hacker" in Mile2's course materials. It focuses on how attackers use PowerShell inside Windows and Active Directory environments, and on how defenders detect and limit that activity. If you are new to the acronym, our explainers on what C)PSH certification is and what C)PSH stands for cover the naming basics. This guide assumes you have decided to sit the exam and want a practical plan.
The first thing to understand is that the exam is knowledge-based. The published outline describes multiple-choice questions, not a hands-on practical. That shapes how you should study: you need to recognize concepts, cmdlets, attack stages, and defensive controls quickly and accurately, but you are not being asked to compromise a live network under a timer.
Exam Format and Booking Mechanics
According to the current Mile2 Certified PowerShell Hacker course outline, the exam has these characteristics:
| Item | What the Mile2 outline states |
|---|---|
| Question count | 100 multiple-choice questions |
| Time allowed | Approximately two hours |
| Minimum passing grade | 70% |
| Delivery | Online, through Mile2's learning management system and your Mile2.com account |
| Attempts | Mile2's FAQ states exam purchases include two attempts |
A 70% minimum on 100 questions means you need 70 correct answers, and our page on the C)PSH passing score goes deeper on what that margin means in practice. Mile2's FAQ also says standard exams are available online on demand without a live-proctor appointment, and that a course purchase is not required to buy the exam. If you are budgeting, the C)PSH certification cost breakdown explains what is and is not verified. Mile2 lists a C)PSH Exam Combo that includes exam access, a preparation guide, and quiz/simulator preparation, but a current bundle price and a separate exam-only fee should be confirmed directly on Mile2's listing rather than taken from older promotions.
For scheduling questions, see our notes on C)PSH exam dates and scheduling. Because delivery is on demand, your real deadline is the one you set for yourself.
Skills to Have Before You Start
Mile2's suggested preparation includes C)PEH and C)PTE or equivalent knowledge, along with penetration-testing fundamentals, Active Directory, scripting, and programming. These are recommendations, not mandatory prior certifications. Our C)PSH requirements guide separates what is required from what is merely advisable.
In practical terms, ask yourself three questions before you begin:
- Can you read a multi-line PowerShell script and explain what each pipeline stage does?
- Can you describe how a Windows domain authenticates a user and what a domain controller is responsible for?
- Can you explain the general phases of a penetration test, from scoping to reporting?
If any answer is shaky, spend your first study sessions there. The later domains build directly on these foundations, and candidates who skip them often find the Kerberos and privilege escalation material harder than it needs to be. For a realistic sense of difficulty, read how hard the C)PSH exam is.
Domain-by-Domain Study Walkthrough
The eight domains below mirror the preparation curriculum headings in the Detailed Outline of Mile2's course outline PDF. They are unweighted preparation topics, not a verified weighted exam blueprint, so do not assume any domain is worth more questions than another. For a longer treatment, see the complete guide to all eight content areas.
Domain 1: Introduction to PowerShell
This is your language foundation. Everything offensive and defensive later depends on fluency here.
- Cmdlet naming, the object-based pipeline, and how output is filtered and formatted
- Variables, functions, modules, and execution policy concepts
- Remoting concepts and how PowerShell interacts with .NET and WMI/CIM
- How to read unfamiliar scripts and predict their effect
Domain 2: Introduction to Active Directory and Kerberos
Most of the credential's attack paths run through Active Directory, so this domain deserves real time.
- Domains, forests, trusts, organizational units, groups, and service accounts
- The Kerberos flow: tickets, the ticket-granting service, and what each ticket proves
- Why Kerberos design choices create abusable weaknesses
- How AD objects and permissions are represented and queried
Domain 3: Pen Testing Methodology Revisited
Use the detailed heading from the outline as your guide. Expect questions that place PowerShell activity inside a structured engagement.
- Phases of an authorized engagement and where PowerShell tooling fits in each
- Rules of engagement, scoping, and documentation habits
- Mapping findings to attacker objectives rather than isolated tricks
Domain 4: Information Gathering and Enumeration
Know what can be learned about a Windows environment and which native capabilities reveal it.
- Enumerating users, groups, computers, shares, and trust relationships
- Identifying high-value accounts and privileged group membership
- Distinguishing noisy enumeration from quieter methods, and why defenders care
Domain 5: Privilege Escalation
Focus on the categories of weakness rather than memorizing individual tools.
- Misconfigured services, permissions, and unquoted or writable paths
- Credential exposure in scripts, files, and memory, at a conceptual level
- Kerberos-related account abuse and why weak service account passwords matter
Domain 6: Lateral Movements and Abusing Trust
This domain connects Domains 2 and 5: once an attacker holds a credential, how do they use it elsewhere?
- Remote execution mechanisms and the artifacts they leave behind
- Trust relationships between hosts, domains, and forests
- Credential reuse and delegation concepts
Domain 7: Persistence and Bypassing Defenses
Understand why attackers want durable access and how they try to avoid detection, both for exam recognition and for defense.
- Common persistence locations and mechanisms in Windows and AD
- Concepts behind evading script scanning, logging, and application controls
- How each evasion idea maps to a detection opportunity
Domain 8: Defending Against PowerShell Attacks
Do not treat this as an afterthought. Defensive controls give you a lens for reviewing every earlier domain.
- PowerShell logging types and what each one captures
- Constrained language concepts, application control, and least privilege
- Hardening Active Directory to reduce the impact of the attacks in Domains 4 through 7
- Monitoring approaches that surface suspicious script activity
Building an Isolated Lab for Practice
Mile2's course materials describe seven training labs, which signals that hands-on familiarity is part of the intended preparation even though the exam itself is multiple choice. Building your own environment helps concepts stick, but keep it strictly contained.
- Run everything on isolated virtual machines with no route to production networks or the internet-facing parts of your home setup.
- Stand up a small domain with a domain controller and one or two member machines so Kerberos and trust concepts become observable rather than abstract.
- Use only systems you own or are explicitly authorized to test.
- After exploring any attack concept, switch to the defender's view: find which log entry or configuration would have exposed it.
Sequencing the Domains Across Your Weeks
Rather than spreading time evenly, order your study by dependency. PowerShell and Active Directory knowledge underpin everything else, so they come first. This is one possible six-week layout; compress or stretch it to match your background.
Domain 1: Introduction to PowerShell
- Write and read small scripts daily
- Practice pipeline filtering until it feels automatic
Domains 2 and 3: Active Directory, Kerberos, and methodology
- Draw the Kerberos ticket flow from memory
- Place each engagement phase alongside its PowerShell activities
Domain 4: Information Gathering and Enumeration
- Enumerate your lab domain and record what each query reveals
Domains 5 and 6: Privilege Escalation and Lateral Movements
- Group weaknesses by category
- Trace how one foothold becomes domain-wide access
Domains 7 and 8: Persistence, Bypassing Defenses, and Defense
- Pair every offensive technique with its detection or mitigation
Review and timed practice
- Sit full-length practice sets under two-hour conditions
- Revisit your weakest domain
For a compact reference to keep beside you during review, see the C)PSH cheat sheet, and use the C)PSH practice tests to measure how ready you are.
Handling Multiple-Choice Questions on Offensive PowerShell
With 100 questions in roughly two hours, you have a little over a minute per question on average. A few habits suit this subject matter well:
- Read the scenario for the stage of attack. Many questions become easy once you identify whether the described activity is enumeration, escalation, lateral movement, or persistence.
- Watch for cmdlet and parameter detail. Distractors frequently differ from the correct answer by a single parameter or a similar-sounding command.
- Think like both sides. If a question asks what a defender would see or do, recall the logging and hardening material from Domain 8 rather than the attacker mechanics.
- Flag and move on. Mark long script-reading questions, answer the quick ones first, and return with the remaining time.
Because Mile2 describes the exam as randomized, the order of topics you meet will not follow the curriculum order, so practice switching between domains instead of studying them only in blocks. Our C)PSH pass rate page explains why no official figure should be assumed, and the main practice test site offers mixed-domain sets for this kind of switching.
Key Takeaway
Treat Kerberos and Active Directory as the center of your preparation. Domains 4 through 7 all assume you understand how identities, tickets, and trusts work, and Domain 8 only makes sense once you know what is being defended.
After You Pass: Validity and Renewal
Certification is valid for three years. Renewal details vary across Mile2 sources, so read the dedicated pages before you plan. Mile2's Certification Renewal Program and Paths to Renewal pages describe two alternative routes: a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase, and an ethics acknowledgment, or a route involving the latest existing certification exam or an eligible qualifying exam. The FAQ lists a USD 200 U.S.-region renewal fee.
Other Mile2 documents describe renewal differently. The course outline mentions 20 CEUs annually plus passing the current exam, and the May 2026 policy document describes CEUs plus a purchased recertification exam within seven days of expiry, with full reexamination and no CEUs after that window. Do not merge these into one rule. Confirm the current requirement with Mile2 when your expiry approaches.
If you are weighing whether the credential suits your goals, see our analyses of whether the C)PSH is worth it, the C)PSH salary guide, and C)PSH jobs. The skills tend to be relevant to penetration testers, red teamers, and defenders who need to understand Windows-focused attack tradecraft.
Frequently Asked Questions
Mile2's current course outline specifies 100 multiple-choice questions, approximately two hours, and a minimum passing grade of 70%.
No. Purchasing or completing a Mile2 course is not required to purchase the exam. The four-day course and its labs are preparation options, not eligibility gates.
Mile2's published documents conflict. The general policies describe open-book, proctored online exams, while the FAQ says standard exams are on demand without a live-proctor appointment. Follow the instructions in your own Mile2.com account and booking flow.
They are suggested preparation, not mandatory prerequisites. Equivalent knowledge of penetration testing, Active Directory, scripting, and programming is what matters for readiness.
The certification is valid for three years. Mile2's renewal pages describe a CEU route (60 documented CEUs plus a renewal purchase and ethics acknowledgment) or an exam-based route as alternatives. Other Mile2 documents describe renewal differently, so confirm current terms with Mile2 before your expiry date.