- What the Certified PowerShell Hacker Credential Is
- Exam Format and Delivery
- The Eight Preparation Domains
- Suggested Background
- Registration, Attempts, and Fee Mechanics
- Where Mile2's Published Rules Disagree
- Validity and Renewal
- Who Benefits From This Credential
- Sequencing Your Preparation
- Frequently Asked Questions
- Mile2 awards the Certified PowerShell Hacker credential; the course outline lists 100 multiple-choice questions, about two hours, and a 70% minimum passing...
- The eight outline headings are preparation topics, not a verified weighted exam blueprint.
- Exam purchases include two attempts, and buying a Mile2 course is not required to buy the exam.
- Certification lasts three years; renewal sources differ, so confirm the current route in your Mile2 account.
What the Certified PowerShell Hacker Credential Is
The C)PSH credential, also searched as CPSH, is Mile2's Certified PowerShell Hacker certification. Mile2 styles the name "Certified PowerShell Hacker" in its course materials, and the credential centers on using PowerShell as an offensive and defensive tool in Windows and Active Directory environments. If you searched for this acronym and landed on information about a different certification, note that several unrelated credentials share similar letters. Everything on this page concerns the Mile2 credential only.
If you are still orienting yourself, our explainers What Is C)PSH? and What Does C)PSH Stand For? cover the naming basics, while this article focuses on the practical mechanics of the exam and how the curriculum is organized.
Exam Format and Delivery
According to the current Certified PowerShell Hacker course outline published by Mile2, the exam has these characteristics:
| Item | What the outline specifies |
|---|---|
| Question count | 100 |
| Question style | Multiple choice |
| Time allowed | Approximately two hours |
| Minimum passing grade | 70% |
| Delivery | Online, through Mile2's learning management system and your Mile2.com account |
| Format type | Multiple-choice exam; the outline does not describe a separate practical assessment |
Mile2's general FAQ also gives a two-hour limit for standard exams, which is consistent with the outline. Standard exams are described as available online on demand, without a live-proctor appointment. The course itself runs four days, carries 32 course CEUs, and includes seven training labs, but those figures describe the training, not the exam. They are not an exam duration or a separate hands-on test.
For a closer look at the scoring threshold, see C)PSH Passing Score 2026: Exactly What You Need to Pass. For difficulty expectations, read How Hard Is the C)PSH Exam?
The Eight Preparation Domains
The Detailed Outline on pages 3 and 4 of the course PDF lists eight headings. This article calls them Domains 1 through 8 for convenience. Important caveat: they are unweighted preparation topics. Mile2's published materials do not establish a weighted exam blueprint, an exhaustive coverage list, or an official count of exam domains. Treat the list as the best map of what to learn, not a guarantee of how questions are distributed.
One small wrinkle: the course overview uses a different title for Module 3, but the detailed heading, "Pen Testing Methodology Revisited," is the one used here. For a deeper walk-through, see C)PSH Exam Domains 2026: Complete Guide to All 8 Content Areas.
Domain 1: Introduction to PowerShell
The foundation. Without fluency here, every later domain becomes harder.
- Cmdlet structure, the object pipeline, and how PowerShell differs from text-based shells
- Variables, loops, functions, and scripting constructs
- Execution policy, remoting basics, and how scripts are loaded and run
Domain 2: Introduction to Active Directory and Kerberos
The environment where most PowerShell tradecraft is applied.
- Domains, forests, trusts, organizational units, groups, and service accounts
- How Kerberos authentication works: tickets, the key distribution center, and why ticket handling matters
- Why misconfigurations in delegation and service accounts create attack paths
Domain 3: Pen Testing Methodology Revisited
A refresher that frames the rest of the curriculum inside a structured engagement.
- Phases of a penetration test and where PowerShell fits in each
- Scoping, authorization, and rules of engagement
- Reporting findings in a way defenders can act on
Domain 4: Information Gathering and Enumeration
Using PowerShell to learn about a Windows environment.
- Enumerating users, groups, computers, shares, and domain structure
- Querying Active Directory through native interfaces
- Recognizing what enumeration activity looks like in logs
Domain 5: Privilege Escalation
Moving from limited access to greater control.
- Common local misconfigurations such as weak permissions and unquoted service paths
- Credential exposure and token concepts
- Conceptual understanding of why each escalation path exists and how it is remediated
Domain 6: Lateral Movements and Abusing Trust
How an attacker pivots once inside a network.
- PowerShell remoting and other remote execution mechanisms
- Abuse of trust relationships between systems and domains
- Reusing credentials and tickets across hosts
Domain 7: Persistence and Bypassing Defenses
Maintaining access and evading controls.
- Common persistence locations and mechanisms on Windows
- How defensive features such as script logging, antimalware scanning, and constrained language mode relate to evasion
- Why defenders should understand bypass concepts to build better detections
Domain 8: Defending Against PowerShell Attacks
The defensive capstone.
- Logging and monitoring approaches that expose malicious PowerShell use
- Hardening measures and language restrictions
- Detecting the techniques covered in Domains 4 through 7
Key Takeaway
Domain 8 is not an afterthought. Because every offensive technique in Domains 4 through 7 has a corresponding detection or mitigation, studying them in pairs, attack concept alongside its defense, is an efficient way to retain both.
Suggested Background
Mile2's materials suggest preparation that includes C)PEH and C)PTE or equivalent knowledge, along with penetration-testing fundamentals, Active Directory familiarity, scripting, and programming. These are recommendations, not mandatory prior certifications. You are not formally required to hold those other credentials to attempt this one, and buying or completing a Mile2 course is not required to purchase the exam.
In practice, candidates who are weak on Active Directory and Kerberos tend to find Domains 4 through 6 the steepest climb, since those domains assume you already understand the environment being explored. For more on eligibility, see C)PSH Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Registration, Attempts, and Fee Mechanics
The exam is purchased and taken through your Mile2.com account and the learning management system. Several points from Mile2's published information are worth knowing:
- Two attempts are included. Mile2's FAQ states that exam purchases include two attempts.
- No course purchase required. You can buy the exam without enrolling in the training.
- The C)PSH Exam Combo. Mile2 lists a combo that includes exam access, a preparation guide, and quiz/simulator preparation.
- Pricing. A current bundle price and a separate exam-only fee were not confirmed in the product listing reviewed for this article. Older promotional amounts you may see elsewhere should not be assumed to be current. Check the live product page before budgeting.
Our dedicated breakdown, C)PSH Certification Cost 2026: Complete Pricing Breakdown, explains how to evaluate the pieces. For scheduling questions, see C)PSH Exam Dates 2026: Testing Windows, Deadlines & Scheduling.
Where Mile2's Published Rules Disagree
This matters practically: do not plan your preparation around the assumption that you can consult notes, and do not assume you will be unobserved. Confirm the technical requirements (browser, webcam, screen sharing) in your account before the day you intend to sit the exam.
Validity and Renewal
The certification is valid for three years. Renewal is where Mile2's sources diverge, so it is best handled carefully rather than reduced to one rule.
| Source | What it describes |
|---|---|
| Certification Renewal Program and Paths to Renewal pages | Two alternative routes: a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase, and ethics acknowledgment; or a route involving the latest existing certification exam or an eligible qualifying exam |
| Mile2 FAQ | Lists a USD 200 renewal fee for the U.S. region |
| Course outline | Says 20 CEUs annually plus passing the current exam |
| May 2026 Policies and Procedures | Describes CEUs plus a purchased recertification exam within seven days of expiry, and full reexamination without CEUs after that period |
These descriptions are not identical, and they should not be merged into a single unqualified requirement. The dedicated renewal pages present the CEU and exam routes as alternatives. Before your certification nears expiry, consult the current renewal pages and your account to see which path applies to you, and note any deadlines tied to your expiry date.
Who Benefits From This Credential
The credential is aimed at people who work with Windows environments from an offensive or defensive angle. Typical beneficiaries include:
- Penetration testers and red team members who need to demonstrate PowerShell-based tradecraft inside Active Directory environments
- Blue team analysts and detection engineers who must recognize and alert on malicious PowerShell activity
- Windows and systems administrators moving toward security roles
- Security consultants who assess enterprise Windows estates
Employers who run large Windows and Active Directory estates, and consultancies that deliver penetration testing, are the natural audience. Hiring outcomes depend heavily on your broader experience, so treat any certification as one signal among several. To explore the market side, see C)PSH Jobs, and for a value assessment, Is the C)PSH Certification Worth It? Complete ROI Analysis 2026. Compensation discussion lives in C)PSH Salary Guide 2026: Complete Earnings Analysis.
Sequencing Your Preparation
Because the domains build on each other, order matters more than volume. The plan below is a suggested sequence, not an official schedule. Adjust the pace to your own background and keep any hands-on practice inside isolated, authorized training environments such as a personal lab you own or a provided course lab.
Domain 1 and Domain 2
- Get comfortable writing and reading PowerShell, especially the object pipeline
- Build a mental model of Active Directory and trace a Kerberos authentication end to end
Domain 3 and Domain 4
- Review methodology so the techniques have context
- Practice enumeration concepts and note what each query reveals and what it would log
Domains 5 and 6
- Study escalation and lateral movement as paired attack and mitigation concepts
- Focus on why each path exists, since multiple-choice questions often test reasoning
Domains 7 and 8, then review
- Connect persistence and evasion concepts directly to the defensive controls in Domain 8
- Finish with timed practice at roughly one minute per question, matching the 100-question, two-hour format
For a fuller methodology, see the C)PSH Study Guide 2026: How to Pass on Your First Attempt, and keep the C)PSH Cheat Sheet 2026 handy for last-minute review. When you are ready to test yourself under realistic conditions, work through questions on the main practice test site, and revisit weak domains afterward.
Key Takeaway
With 100 questions in about two hours, pacing is part of the exam. Practice answering at a steady clip so that unfamiliar scenario wording does not eat the time you need for the questions you know well.
Frequently Asked Questions
Mile2 awards the Certified PowerShell Hacker credential. The exam is delivered online through Mile2's learning management system and the candidate's Mile2.com account.
The current course outline specifies 100 multiple-choice questions, approximately two hours, and a minimum passing grade of 70%.
No. Purchasing or completing a Mile2 course is not required to purchase the exam. Mile2 also suggests, but does not mandate, background such as C)PEH and C)PTE or equivalent knowledge.
Mile2's published statements conflict. The FAQ describes standard exams as on-demand without a live-proctor appointment, while the general policies document describes open-book online exams with webcam and screen-sharing proctoring. Follow the instructions in your own C)PSH booking and account page.
It is valid for three years. Mile2's renewal pages describe a CEU route (60 documented CEUs, a renewal purchase, and ethics acknowledgment) or an exam-based alternative, but other documents describe the process differently, so confirm the current path in your account. For related background, see What Is C)PSH Certification? and C)PSH Training.