- What C)PSH Training Actually Covers
- Training Versus the Exam: Keeping Them Separate
- The Eight Curriculum Areas, Topic by Topic
- Building a Safe, Authorized Lab
- Background Knowledge That Makes Training Easier
- Training Routes Compared
- Sequencing the Curriculum Across Your Prep
- Exam Format and Booking Mechanics
- After Training: Renewal and Career Context
- Frequently Asked Questions
- The Mile2 outline lists eight curriculum headings, from Introduction to PowerShell through Defending Against PowerShell Attacks.
- The exam is 100 multiple-choice questions in roughly two hours, with a 70% minimum passing grade.
- Buying or completing Mile2's course is not required to purchase the exam.
- The four-day course, 32 CEUs, and seven labs describe training, not exam length or a practical test.
What C)PSH Training Actually Covers
Certified Powershell Hacker is a Mile2 credential built around the offensive and defensive use of PowerShell in Windows and Active Directory environments. Mile2's course materials style the name "Certified PowerShell Hacker," and many candidates search for it simply as CPSH. If you are still orienting yourself, our explainers on what C)PSH is and the C)PSH certification lay out the basics before you commit to a training plan.
"Training" for this credential means two overlapping things: the structured curriculum Mile2 publishes in its course outline, and whatever independent preparation you do to turn that curriculum into working skill. This article walks through both, with an emphasis on what each of the eight curriculum headings expects you to understand.
Training Versus the Exam: Keeping Them Separate
The most common source of confusion is mixing up course logistics with exam logistics. Mile2 describes its course as a four-day program carrying 32 course CEUs and seven training labs. Those figures describe preparation. They do not describe how long the exam lasts, they do not indicate a separate practical assessment, and they should not be read as a renewal-hour requirement.
The exam itself, according to the current course outline, is 100 multiple-choice questions with an approximate two-hour limit and a minimum passing grade of 70%. It is delivered online through Mile2's learning management system and your Mile2.com account. Crucially, purchasing or completing a Mile2 course is not required to purchase the exam, so self-directed candidates are not locked out. For a deeper look at the score threshold, see our guide to the C)PSH passing score.
The Eight Curriculum Areas, Topic by Topic
Below is each heading from the Detailed Outline, with the kind of knowledge a multiple-choice exam on this material tends to reward. For a longer treatment of each area, read the complete guide to the eight C)PSH content areas.
Domain 1: Introduction to PowerShell
The foundation. You need fluency in how PowerShell actually works, not just a handful of memorized one-liners.
- The object pipeline and how cmdlets pass structured objects rather than text
- Execution policy: what it is, and why it is a guardrail rather than a security boundary
- Modules, profiles, remoting basics, and the difference between Windows PowerShell and newer editions
- Reading and writing scripts, including variables, loops, functions, and error handling
Domain 2: Introduction to Active Directory and Kerberos
Most of the later material assumes you understand the directory you are operating against.
- Domains, forests, trusts, organizational units, groups, and service accounts
- How Kerberos authentication flows, including tickets and the roles of the key distribution components
- Why authentication design choices create the weaknesses that later domains exploit
Domain 3: Pen Testing Methodology Revisited
Note the exact heading: the course overview uses a different Module 3 title, but the Detailed Outline's "Pen Testing Methodology Revisited" is the controlling label.
- Penetration-testing phases and how PowerShell fits into each
- Scoping, rules of engagement, and authorization
- Reporting expectations and how to translate technical findings into remediation advice
Domain 4: Information Gathering and Enumeration
Enumeration questions often ask what information a given technique yields and what that reveals about attack paths.
- Enumerating users, groups, computers, shares, and domain relationships
- Using native PowerShell and AD-aware tooling to map an environment
- Recognizing which enumeration activity is noisy and which is quiet from a defender's view
Domain 5: Privilege Escalation
Conceptual understanding of how low-privilege footholds become higher-privilege access.
- Common local misconfiguration categories on Windows systems
- Credential exposure and token-related concepts
- How enumeration findings from Domain 4 feed escalation decisions
Domain 6: Lateral Movements and Abusing Trust
Where Kerberos knowledge from Domain 2 pays off.
- Moving between systems using legitimate administrative channels such as remoting
- Authentication material reuse and trust relationships between accounts, systems, and domains
- Why over-broad trust and delegation settings are recurring findings
Domain 7: Persistence and Bypassing Defenses
How an attacker retains access and evades controls, studied so defenders can detect it.
- Persistence mechanism categories on Windows and in Active Directory
- Defensive features PowerShell attacks try to sidestep, and why bypass attempts are often detectable
- The relationship between logging coverage and what an attacker can hide
Domain 8: Defending Against PowerShell Attacks
The defender's mirror image of everything above, and easy to under-study.
- Script block logging, module logging, and transcription as detection sources
- Constrained language mode and application control concepts
- Hardening Active Directory to reduce the impact of the earlier techniques
Building a Safe, Authorized Lab
Offensive PowerShell skills must be practiced only where you have explicit permission. That means an isolated lab you own, not a work network, a school network, or anyone else's infrastructure. A modest setup is enough: a hypervisor, a Windows Server promoted to a domain controller, and one or two Windows client machines joined to that domain, all on a host-only or otherwise isolated virtual network with no route to production systems.
Mile2's own course includes seven training labs, which gives you a sense of the intended scale of hands-on practice. If you build your own lab, aim to cover each curriculum area at least once from both the offensive and the defensive side, since Domain 8 explicitly expects you to know how the earlier activity looks to defenders.
Background Knowledge That Makes Training Easier
Mile2 suggests, but does not mandate, that candidates arrive with C)PEH and C)PTE or equivalent knowledge, plus penetration-testing fundamentals, Active Directory familiarity, and scripting and programming experience. These are recommendations, not mandatory prior certifications. Our C)PSH requirements guide explains the distinction between suggested background and formal eligibility.
If you are missing pieces, prioritize in this order: first, comfort reading and writing scripts, because Domains 1 and 4 through 7 all assume it; second, a working mental model of Active Directory, because Domains 2, 5, and 6 depend on it; third, general penetration-testing vocabulary, which makes Domain 3 nearly a review. Candidates weighing whether the effort is justified can consult the difficulty guide.
Training Routes Compared
You have more than one route to readiness. The right one depends on your background, budget, and learning style.
| Route | What It Includes | Best For |
|---|---|---|
| Mile2 instructor-led or official course | Four-day course, 32 course CEUs, seven training labs | Candidates who want structure and guided labs |
| C)PSH Exam Combo | Exam access, a preparation guide, and quiz/simulator preparation | Self-directed candidates who want the exam plus supporting materials |
| Independent study with a home lab | Your own domain-controller lab and self-selected resources | Experienced administrators and testers comfortable building their own environment |
Pricing for the combo and any exam-only fee was not verified in the listing we reviewed, and earlier promotional amounts should not be treated as current, so check Mile2's product page directly before budgeting. Our C)PSH certification cost breakdown tracks what is and is not confirmed.
Sequencing the Curriculum Across Your Prep
Generic scheduling advice is less useful than ordering the material by dependency. The curriculum builds on itself, so the sequence below respects those dependencies. Adjust the pacing to your own calendar; for a fuller plan, see the C)PSH study guide.
PowerShell and Active Directory Foundations
- Domain 1: pipeline, scripting, remoting basics
- Domain 2: AD structure and Kerberos flow, drawn by hand from memory
Methodology, Enumeration, and Escalation
- Domain 3: methodology and authorization concepts
- Domain 4: enumeration in your lab
- Domain 5: escalation categories, tied back to enumeration output
Movement, Persistence, and Defense
- Domain 6 and Domain 7: trust abuse, persistence, defensive bypass concepts
- Domain 8: map every earlier technique to a detection or hardening control
Question Practice and Gap Review
- Timed sets of multiple-choice questions mirroring the 100-question format
- Return to whichever domain produced the most misses
The reasoning: Domain 8 is placed last on purpose, because defensive controls only make sense once you know what they are defending against. Candidates who skip it tend to lose points on questions that ask which logging source would reveal a given activity.
Exam Format and Booking Mechanics
The exam is delivered online through the Mile2 learning management system and your Mile2.com account. Mile2's FAQ states that standard exams are available online on demand without a live-proctor appointment, and that exam purchases include two attempts. The separately named C)ISSO-A and C)PTE-A proctoring exceptions in that FAQ are not this credential.
There is one published inconsistency worth flagging. Mile2's Policies and Procedures document describes randomized, open-book online examinations with webcam and screen-sharing proctoring in its general certification procedures, while other sections say only some exams require proctors. Because these instructions conflict, do not assume a universal open-book or proctoring rule for C)PSH. Follow the exam-specific instructions shown in your own account and booking flow, and confirm them before test day. Scheduling questions are covered in our exam dates guide.
Key Takeaway
Do your training against the format you will face: 100 multiple-choice questions in about two hours means roughly a minute per question. Practice at that pace in the main practice test site so timing is never the surprise.
If you want a quick visual recap of format facts before sitting the exam, the C)PSH cheat sheet condenses the essentials, and the pass rate article explains why no verified figure should be quoted as fact.
After Training: Renewal and Career Context
Certification is valid for three years. Mile2's dedicated Certification Renewal Program and Paths to Renewal pages describe a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase, and an ethics acknowledgment, or an alternative route involving the latest existing certification exam or an eligible qualifying exam. The FAQ lists a USD 200 U.S.-region renewal fee.
On the career side, the credential speaks to roles that touch Windows and Active Directory security: penetration testers, red-team members, security analysts, and administrators who defend domain environments. Because Domain 8 is explicitly defensive, blue-team professionals have as much reason to study it as offensive specialists. For realistic expectations, our C)PSH jobs article, the salary guide, and the ROI analysis discuss the market without inventing figures.
Frequently Asked Questions
No. Purchasing or completing a Mile2 course is not required to purchase the exam. The course is one preparation route, and self-directed candidates can prepare independently or use the exam combo.
The current course outline specifies 100 multiple-choice questions, approximately two hours, and a minimum passing grade of 70%. Mile2's FAQ also gives a two-hour limit for standard exams.
No. The four-day length, 32 course CEUs, and seven training labs describe the preparation course. They do not describe exam duration, a separate practical assessment, or a verified renewal-hour requirement.
Mile2's published materials conflict on this. Its FAQ says standard exams are on demand without a live-proctor appointment, while its general policy document describes open-book and webcam proctoring language. Follow the instructions in your own C)PSH account and booking flow.
It includes exam access, a preparation guide, and quiz/simulator preparation. A current bundle price was not verified, so confirm it on Mile2's product page. For naming questions, see what C)PSH stands for.