- What You Are Actually Buying: The Credential in Plain Terms
- The Cost Side of the Equation
- Skills Return: What the Eight Domains Teach You
- Career Return: Who Values This Credential
- Exam Format and Risk Management
- The Renewal Burden Over Three Years
- Who Should Skip It, and Who Should Buy It
- Decision Matrix
- Sequencing Your Preparation by Domain
- Frequently Asked Questions
- C)PSH means Certified Powershell Hacker, awarded by Mile2 and delivered online through your Mile2.com account.
- The exam is 100 multiple-choice questions in roughly two hours, with a 70% minimum passing grade.
- Certification lasts three years, and renewal rules differ across Mile2 sources, so verify before budgeting.
- Value is highest for Windows and Active Directory-focused offensive and defensive security practitioners.
What You Are Actually Buying: The Credential in Plain Terms
Before calculating return on investment, you need to be precise about the asset. C)PSH stands for Certified Powershell Hacker (styled "Certified PowerShell Hacker" in Mile2's course materials). It is a Mile2 credential focused on using PowerShell offensively and defensively inside Windows and Active Directory environments. Searchers often type the punctuation-free alias CPSH, and if you want a fuller orientation, our explainers on what C)PSH certification is and what C)PSH stands for cover the basics.
The exam is delivered online through Mile2's learning management system and your Mile2.com account. Mile2's current course outline specifies 100 multiple-choice questions, approximately two hours, and a minimum passing grade of 70%. That is a knowledge-based assessment, not a hands-on lab practical. This distinction matters for ROI: the credential signals that you can reason about PowerShell tradecraft and defenses, and the tangible hands-on skill still has to come from your own lab practice.
The Cost Side of the Equation
An honest ROI analysis starts with costs, and here the picture needs a caveat: a current exam-only fee and a current bundle price were not verified in the retrieved Mile2 listing, and earlier promotional amounts should not be treated as today's fees. Rather than quote a number that may be stale, treat the following as the cost components you should price out directly on Mile2 before committing. Our C)PSH certification cost breakdown tracks the pricing structure in more detail.
Direct costs
- The exam itself. Mile2's FAQ states that standard exams are available online on demand without a live-proctor appointment and that exam purchases include two attempts. That built-in second attempt materially lowers your downside risk compared with credentials that charge a full fee per retake.
- The C)PSH Exam Combo. This listing includes exam access, a preparation guide, and quiz/simulator preparation. It is the lower-friction path if you want everything in one purchase and plan to self-study.
- Optional training. Mile2's instructor-led course is described as four days, with 32 course CEUs and seven training labs. Importantly, purchasing or completing a Mile2 course is not required to purchase the exam, so training is a choice rather than a gate.
- Renewal. The FAQ lists a USD 200 U.S.-region renewal fee. Treat this as a recurring cost every three years, subject to the renewal-path caveats discussed below.
Indirect costs
Your biggest hidden cost is time, plus any lab infrastructure you build yourself. Because the recommended background includes C)PEH and C)PTE or equivalent knowledge, penetration-testing fundamentals, Active Directory, scripting, and programming, a candidate missing those foundations is really budgeting for several months of prerequisite learning, not just exam prep. These are recommendations rather than mandatory prior certifications, so you are not forced to buy them, but skipping the knowledge they represent is how candidates fail. See C)PSH requirements and prerequisites for how to self-assess readiness.
Key Takeaway
The two-attempt exam purchase and the optional nature of training make C)PSH a comparatively low-risk spend. Your real exposure is the time needed to build Active Directory, Kerberos, and scripting fluency, not the exam fee.
Skills Return: What the Eight Domains Teach You
The strongest ROI argument for C)PSH is the skill content. Mile2's detailed course outline lists eight preparation curriculum headings. These are unweighted preparation topics rather than a verified weighted exam blueprint, so do not treat them as a guarantee of exhaustive exam coverage. Our complete guide to all eight content areas goes deeper, but here is how each maps to real-world value.
Domain 1: Introduction to PowerShell
The foundation. PowerShell is installed by default across modern Windows estates, which is exactly why attackers and defenders both care about it.
- Cmdlets, pipelines, objects, and scripting constructs
- Execution behavior and how administrators and adversaries use the same tooling
Domain 2: Introduction to Active Directory and Kerberos
The conceptual core of the whole credential. You cannot reason about lateral movement or privilege escalation without understanding how identity works in a Windows domain.
- Domain structure, objects, groups, and trust relationships
- Kerberos authentication flow and where it can be abused
Domain 3: Pen Testing Methodology Revisited
Frames PowerShell work within a structured engagement. Note that the course overview uses a different Module 3 title, but the detailed heading above is the one that governs.
- Where PowerShell fits in the phases of an authorized assessment
- Scoping, rules of engagement, and professional conduct
Domain 4: Information Gathering and Enumeration
Learning to map an environment using native tooling, which is valuable for both red teams and defenders validating exposure.
- Enumerating users, groups, computers, and domain structure
- Understanding what telemetry this activity generates
Domain 5: Privilege Escalation
Conceptual and scenario-driven knowledge of how low-privileged access becomes high-privileged access in Windows environments.
- Common misconfiguration classes and escalation paths
- How to recognize and remediate them
Domain 6: Lateral Movements and Abusing Trust
Moving between systems and exploiting trust relationships, which ties directly back to your Kerberos and Active Directory foundation.
- Remoting mechanisms and credential-based movement concepts
- Trust abuse and its defensive indicators
Domain 7: Persistence and Bypassing Defenses
How adversaries maintain access and evade controls, studied so defenders can anticipate and detect it.
- Persistence mechanism categories
- Defensive control evasion concepts and their countermeasures
Domain 8: Defending Against PowerShell Attacks
Arguably the highest-ROI domain for employers: logging, hardening, and detection practices that blunt PowerShell-based tradecraft.
- Logging and visibility improvements
- Hardening and constrained-use approaches
Notice the dual-use value. Domains 1 through 7 are offensive in framing but directly inform defenders, and Domain 8 closes the loop. That makes the skills portable across red team, blue team, and purple team roles. All practice should happen in isolated, authorized training environments that you own or have explicit permission to test.
Career Return: Who Values This Credential
Here is where you must resist inflated claims. No verified salary figure, pass rate, or hiring statistic for C)PSH is available in the sources behind this article, so any specific dollar uplift you see quoted should be treated skeptically unless it clearly cites this exact credential. What can be said qualitatively is where the skills are demanded.
- Penetration testers and red team operators working in Windows-heavy enterprises, where PowerShell and Active Directory knowledge is table stakes.
- Security analysts and threat hunters who need to recognize PowerShell abuse in logs and endpoint telemetry.
- Windows and Active Directory administrators moving toward security engineering, who benefit from understanding how attackers abuse the tools they manage daily.
- Government and contractor environments where Mile2 credentials may carry recognition, though you should check specific job postings rather than assume it.
For an up-to-date view of how employers describe these roles, browse C)PSH jobs and the C)PSH salary guide, and compare any figures against live postings in your market. The honest framing is that C)PSH is a specialist credential: it strengthens a profile that already includes Windows and security fundamentals, rather than opening doors by itself.
Exam Format and Risk Management
ROI also depends on the probability you actually earn the credential. The format facts are straightforward: 100 multiple-choice questions, about two hours, a 70% minimum, and two attempts included with the exam purchase. That works out to roughly a minute and twelve seconds per question, so pacing matters but is not punishing for well-prepared candidates. For the scoring details, see the C)PSH passing score guide, and for a realistic read on difficulty, how hard the C)PSH exam is. We do not cite a pass rate because no verified figure is available; the pass rate discussion explains what can and cannot be known.
The proctoring ambiguity
One area deserves careful handling. Mile2's FAQ says standard exams are available online on demand without a live-proctor appointment. However, the Mile2 Policies and Procedures document dated May 26, 2026 describes randomized, open-book online examinations and webcam/screen-sharing proctoring in its general certification procedures, while other sections say only some exams require proctors. These published instructions conflict. Mile2's named proctoring exceptions, C)ISSO-A and C)PTE-A, are not this credential.
The practical advice: do not assume the exam is open-book, and do not assume it is or is not proctored. Follow the specific instructions shown in your own C)PSH account and booking flow, and prepare as though you will need to rely on memory and reasoning. Preparing for the harder interpretation costs you nothing and protects you from a nasty surprise.
The Renewal Burden Over Three Years
The certification is valid for three years, so ROI should be calculated over a full cycle that includes renewal. This is also where Mile2's published guidance is inconsistent, so read carefully.
- The dedicated Certification Renewal Program and Paths to Renewal pages describe a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase, and an ethics acknowledgment, or an alternative route involving the latest existing certification exam or an eligible qualifying exam. These pages present the CEU and exam routes as alternatives.
- The course outline describes something different: 20 CEUs annually plus passing the current exam.
- The May 2026 policy describes yet another variant: CEUs plus a purchased recertification exam within seven days of expiry, and full reexamination without CEUs after that period.
- The FAQ lists a USD 200 U.S.-region renewal fee.
Key Takeaway
Do not combine these descriptions into a single renewal rule. Before you buy, check the dedicated renewal pages and your account for the path that applies to you, and budget both the fee and the time cost of documenting CEUs or sitting an exam again in year three.
The four-day course, 32 course CEUs, and seven training labs describe preparation. They should not be read as a verified renewal-hour requirement or as a separate practical assessment.
Who Should Skip It, and Who Should Buy It
Strong candidates for buying
- Windows-focused penetration testers who want a structured credential tied to Active Directory and PowerShell tradecraft.
- Defenders who need to articulate how PowerShell attacks work in order to build better detections, particularly using the logic of Domain 8.
- Candidates already holding C)PEH, C)PTE, or equivalent knowledge who want a natural next step in the Mile2 progression.
- Professionals whose employer reimburses certification costs or values Mile2 specifically.
Weaker candidates
- Beginners with no Windows, scripting, or networking foundation. You will spend most of your effort on prerequisites, and a broader entry-level credential may serve you better first.
- Anyone expecting a hands-on practical to prove skills. This exam is multiple-choice, so if you need a lab-based proof point, plan to supplement it with your own documented projects.
- People whose target employers explicitly require a different credential family, which you can verify by reading real job descriptions.
Decision Matrix
| Factor | What the Verified Facts Say | ROI Implication |
|---|---|---|
| Format | 100 multiple-choice questions, about two hours, 70% minimum | Knowledge-based, so supplement with lab proof |
| Attempts | Two attempts included with exam purchase | Lower financial risk on a first-try miss |
| Training requirement | Course not required to buy the exam | Self-study path keeps costs flexible |
| Validity | Three years | Plan for a renewal event within the cycle |
| Renewal fee | USD 200 U.S.-region per the FAQ | Recurring cost; confirm applicable path |
| Salary and pass-rate data | No verified figures available | Treat claims with caution; check live job postings |
| Proctoring | Sources conflict | Follow your account instructions, prepare conservatively |
Sequencing Your Preparation by Domain
If you decide the numbers work, sequence your study around dependencies between domains rather than reading the outline top to bottom. Active Directory and Kerberos concepts underpin several later domains, so they deserve early and repeated attention. For a fuller plan, use the C)PSH study guide, and keep the C)PSH cheat sheet handy for last-week review.
Foundations: Domains 1 and 2
- Get comfortable with PowerShell objects and the pipeline in an isolated lab
- Study Active Directory structure and the Kerberos authentication flow until you can explain it unprompted
Methodology and discovery: Domains 3 and 4
- Place PowerShell work inside an authorized engagement lifecycle
- Practice enumeration in your own lab and note what logs it produces
Offensive depth: Domains 5, 6, and 7
- Work through escalation, lateral movement, and persistence concepts as scenario questions
- Revisit Kerberos whenever trust abuse questions feel shaky
Defense and consolidation: Domain 8
- Map each earlier attack concept to a detection or hardening control
- Take timed practice sets of 100 questions in about two hours to rehearse pacing
Place Domain 8 last on purpose: it makes the most sense once you know what you are defending against, and it consolidates everything before test day. When you are ready to pressure-test your recall, the practice questions on the main practice test site are built to mirror the multiple-choice style of this exam.
Frequently Asked Questions
For practitioners who work in Windows and Active Directory environments, it is a reasonable specialist credential, because its eight domains map directly to real attack and defense work. It is less compelling as a first security certification or for someone seeking a hands-on practical assessment.
According to Mile2's current course outline, it is 100 multiple-choice questions in approximately two hours, with a minimum passing grade of 70%. It is delivered online through your Mile2.com account and the Mile2 learning management system.
No. Purchasing or completing a Mile2 course is not required to purchase the exam. The four-day course is a preparation option, not an eligibility gate, and the C)PSH Exam Combo offers a preparation guide and quiz/simulator prep alongside exam access.
Certification is valid for three years. Mile2's FAQ lists a USD 200 U.S.-region renewal fee, but renewal rules vary across Mile2 sources, so confirm the correct path for your situation on the dedicated renewal pages and in your account before you plan.
No verified salary figure for this credential is available, so any precise uplift you encounter should be treated skeptically. Compare live job postings in your market and read our ROI overview alongside the salary guide to form your own estimate.