- The Short Answer: What a C)PSH Is
- Who Awards It and How the Exam Is Delivered
- Exam Format: Questions, Time, and Passing Grade
- The Eight Preparation Domains Explained
- Suggested Background Versus Hard Requirements
- Registration Mechanics and Fee Caveats
- Three-Year Validity and the Renewal Puzzle
- Who Benefits From the Credential
- Sequencing Your Preparation Around the Domains
- Frequently Asked Questions
- A C)PSH is a Certified PowerShell Hacker, a credential awarded by Mile2.
- The exam is 100 multiple-choice questions in about two hours with a 70% minimum passing grade.
- Eight preparation domains run from PowerShell basics through Active Directory attacks to defending against PowerShell abuse.
- Certification lasts three years, but published renewal rules conflict, so verify your own account's instructions.
The Short Answer: What a C)PSH Is
A C)PSH is a Certified PowerShell Hacker, a professional certification focused on how attackers abuse PowerShell inside Windows and Active Directory environments, and how defenders detect and contain that abuse. Mile2 styles the name "Certified PowerShell Hacker" in its course materials, and you will also see "Certified Powershell Hacker" in listings. Because the parenthesis in the acronym trips up many search engines, plenty of candidates simply search for CPSH, which is the punctuation-free alias for the same credential.
The credential sits in the offensive-security and Windows-security space. Where a general ethical hacking certification surveys many platforms and tools, the C)PSH narrows the lens: PowerShell as a scripting language, an administration framework, and an attack surface. If you want the broader terminology picture, our explainers on what C)PSH means and what C)PSH stands for cover the naming details, and What Is C)PSH Certification? approaches the same topic from the credential side.
Who Awards It and How the Exam Is Delivered
The certifying body is Mile2. The exam is delivered online through Mile2's learning management system and the candidate's Mile2.com account. That detail matters because your account is the control center for purchase, access, and attempts, so you should set it up and explore it before you plan any study schedule.
Mile2's FAQ states that standard exams are available online on demand without a live-proctor appointment, and that exam purchases include two attempts. Its named proctoring exceptions (C)ISSO-A and C)PTE-A) are separate credentials and do not apply here.
Exam Format: Questions, Time, and Passing Grade
The current Certified PowerShell Hacker course outline specifies the following exam parameters:
| Element | What the Outline Specifies |
|---|---|
| Question count | 100 questions |
| Question style | Multiple choice |
| Time | Approximately two hours (the general FAQ gives a two-hour limit for standard exams) |
| Minimum passing grade | 70% |
| Delivery | Online via Mile2 LMS / Mile2.com account |
| Attempts | Two included with exam purchase, per the FAQ |
A few practical consequences follow from these numbers. At 100 questions in roughly 120 minutes, you have a little over a minute per question, which is comfortable for recall questions but tight for scenario items that ask you to interpret a command or reason through an attack chain. The 70% minimum is a straightforward threshold, and our C)PSH passing score guide walks through what that means in practice. Because this is a multiple-choice exam, there is no separate practical lab assessment in the exam itself. The four-day course, 32 course CEUs, and seven training labs described by Mile2 describe preparation, not exam duration or a hands-on exam component.
If you are weighing difficulty, see How Hard Is the C)PSH Exam? for a candid look at where candidates typically feel pressure.
The Eight Preparation Domains Explained
The course outline's Detailed Outline lists eight headings. These are preparation curriculum topics, not a verified weighted exam blueprint, so treat them as the map of what to learn rather than a promise of exact question distribution. For a deeper walkthrough, see C)PSH Exam Domains: Complete Guide to All 8 Content Areas. Here is how each area fits into the larger picture.
Domain 1: Introduction to PowerShell
The foundation. You need to be fluent in the language before you can reason about its abuse.
- Cmdlets, pipelines, objects, and the way PowerShell passes structured data
- Scripting constructs, modules, and execution contexts
- Why PowerShell is so attractive to both administrators and attackers
Domain 2: Introduction to Active Directory and Kerberos
Nearly everything later depends on understanding how Windows domains authenticate and authorize.
- Domain structure, users, groups, and trust relationships
- How Kerberos tickets are requested, issued, and presented
- Why authentication design choices create attack opportunities
Domain 3: Pen Testing Methodology Revisited
A methodology refresher framed around PowerShell-driven assessments. Note that Mile2's overview uses a different title for this module; the detailed heading "Pen Testing Methodology Revisited" is the one this article follows.
- Phases of an engagement and where PowerShell fits in each
- Staying within scope and authorization
Domain 4: Information Gathering and Enumeration
Mapping the environment from a foothold.
- Enumerating domain objects, users, groups, and computers with native tooling
- Understanding what information an ordinary domain account can see
Domain 5: Privilege Escalation
Moving from limited access toward higher privilege on Windows hosts and within the domain.
- Recognizing misconfigurations that enable escalation
- Connecting host-level weaknesses to domain-level consequences
Domain 6: Lateral Movements and Abusing Trust
Spreading across systems by exploiting how Windows environments trust one another.
- Remote execution and credential reuse concepts
- How trust relationships widen an attacker's reach
Domain 7: Persistence and Bypassing Defenses
How attackers maintain access and evade controls, studied so that defenders can recognize it.
- Common persistence mechanisms in Windows environments
- Why logging, language restrictions, and scanning interfaces matter
Domain 8: Defending Against PowerShell Attacks
The defensive counterweight: detection, hardening, and monitoring.
- Logging and visibility for PowerShell activity
- Hardening choices that reduce attacker options
Notice the arc: language fundamentals, then identity infrastructure, then methodology, then the attack chain from enumeration through escalation, movement, and persistence, and finally defense. Candidates who already know how to attack but have never thought about detection often find Domain 8 an easy place to drop points.
Suggested Background Versus Hard Requirements
Mile2 suggests that candidates arrive with C)PEH and C)PTE or equivalent knowledge, plus familiarity with penetration-testing fundamentals, Active Directory, scripting, and programming. These are recommendations, not mandatory prior certifications. Purchasing or completing a Mile2 course is also not required to purchase the exam.
Registration Mechanics and Fee Caveats
Mile2 offers a C)PSH Exam Combo that includes exam access, a preparation guide, and quiz or simulator preparation. In the listing retrieved for this review, a current bundle price and a separate exam-only fee were not verified, and earlier promotional amounts should not be treated as current fees. Always confirm pricing directly on the Mile2 product page at the moment you buy. For a structured look at what goes into total spend, including retakes, renewal, and optional training, see the C)PSH certification cost breakdown.
Scheduling is simpler than with proctored test-center exams, because standard Mile2 exams are available on demand online. If you want to understand the timing side, our C)PSH exam dates and scheduling guide covers how to plan around access windows and your own readiness.
Three-Year Validity and the Renewal Puzzle
Certification is valid for three years. Renewal is where Mile2's own published materials diverge, so it is worth being precise about what each source says:
- The dedicated Certification Renewal Program and Paths to Renewal pages describe a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase, and an ethics acknowledgment, or an alternative route involving the latest existing certification exam or an eligible qualifying exam. These pages present CEUs and exams as alternatives.
- The Mile2 FAQ lists a USD 200 U.S.-region renewal fee.
- The course outline says 20 CEUs annually plus passing the current exam.
- The May 2026 Policies and Procedures uses CEUs plus a purchased recertification exam within seven days of expiry, and full reexamination without CEUs after that period.
Key Takeaway
Do not collapse these descriptions into a single renewal rule. Mile2's sources differ, so before your three-year mark approaches, check the renewal pages and your account for the route that applies to you, and keep records of any continuing-education activity you might need to document.
Who Benefits From the Credential
The C)PSH speaks most directly to people whose work touches Windows environments from an adversarial or defensive angle:
- Penetration testers and red team operators who assess Active Directory environments and need PowerShell fluency to work efficiently.
- Blue team analysts and detection engineers who must recognize PowerShell-based tradecraft in logs and telemetry.
- Windows and security administrators responsible for hardening domains against the abuse patterns the certification teaches.
- Incident responders who encounter PowerShell in intrusion timelines and need to reason about what an attacker did.
Because the outline closes with defending against PowerShell attacks, the credential is not purely offensive. Employers that value it tend to look for people who can think like an attacker and then translate that knowledge into controls. For role-oriented detail, see C)PSH jobs, and for compensation context, the C)PSH salary guide. Whether the investment pays off for your situation is explored in Is the C)PSH Certification Worth It?
Sequencing Your Preparation Around the Domains
Rather than a generic study calendar, let the domain dependencies drive your order. Early domains are prerequisites for later ones, so reversing the order wastes effort. Here is one sensible sequence, scaled to a candidate who already has solid penetration-testing basics:
PowerShell and Kerberos foundations
- Domain 1: practice cmdlets, objects, and the pipeline until you can read unfamiliar scripts
- Domain 2: trace a Kerberos authentication flow end to end
Methodology and enumeration
- Domain 3: refresh engagement phases
- Domain 4: practice enumeration concepts in an isolated, authorized lab
The attack chain
- Domain 5: privilege escalation concepts
- Domain 6: lateral movement and trust abuse
Persistence, defense, and timed review
- Domain 7 and Domain 8 together, so detection knowledge reinforces what you learn about evasion
- Timed multiple-choice sets that mirror 100 questions in about two hours
Keep all hands-on practice inside isolated, authorized training environments, such as your own lab or Mile2's provided labs. The exam tests conceptual understanding through multiple-choice questions, so spend as much time explaining why a technique works and how it would be detected as you do on the mechanics. For a fuller plan, see the C)PSH study guide, and when you are ready to test recall, a one-page C)PSH cheat sheet helps with final review. You can also drill questions on our C)PSH practice test site to check whether your timing holds up across a full-length set.
Frequently Asked Questions
C)PSH stands for Certified PowerShell Hacker, a certification awarded by Mile2. Many candidates search for it as "CPSH" because the parenthesis is awkward to type.
The current course outline specifies 100 multiple-choice questions in approximately two hours, with a minimum passing grade of 70%.
No. Purchasing or completing a Mile2 course is not required to buy the exam, and C)PEH and C)PTE are suggested background, not mandatory prerequisites. Equivalent knowledge in penetration testing, Active Directory, scripting, and programming is what matters.
It is valid for three years. Mile2's renewal pages describe a CEU route (60 documented CEUs, a renewal purchase, and ethics acknowledgment) or an exam-based alternative, but other Mile2 documents describe the process differently. Check the renewal pages and your account for the rule that applies to you.
Mile2's published materials conflict on this point: the general policies mention open-book online exams and webcam or screen-sharing proctoring, while the FAQ says standard exams are on demand without a live-proctor appointment. Follow the instructions in your C)PSH account and booking flow rather than assuming either rule.