C)PSH logo
Focused certification exam prep
Start practice

What Is A C)PSH?

TL;DR
  • A C)PSH is a Certified PowerShell Hacker, a credential awarded by Mile2.
  • The exam is 100 multiple-choice questions in about two hours with a 70% minimum passing grade.
  • Eight preparation domains run from PowerShell basics through Active Directory attacks to defending against PowerShell abuse.
  • Certification lasts three years, but published renewal rules conflict, so verify your own account's instructions.

The Short Answer: What a C)PSH Is

A C)PSH is a Certified PowerShell Hacker, a professional certification focused on how attackers abuse PowerShell inside Windows and Active Directory environments, and how defenders detect and contain that abuse. Mile2 styles the name "Certified PowerShell Hacker" in its course materials, and you will also see "Certified Powershell Hacker" in listings. Because the parenthesis in the acronym trips up many search engines, plenty of candidates simply search for CPSH, which is the punctuation-free alias for the same credential.

The credential sits in the offensive-security and Windows-security space. Where a general ethical hacking certification surveys many platforms and tools, the C)PSH narrows the lens: PowerShell as a scripting language, an administration framework, and an attack surface. If you want the broader terminology picture, our explainers on what C)PSH means and what C)PSH stands for cover the naming details, and What Is C)PSH Certification? approaches the same topic from the credential side.

Who Awards It and How the Exam Is Delivered

The certifying body is Mile2. The exam is delivered online through Mile2's learning management system and the candidate's Mile2.com account. That detail matters because your account is the control center for purchase, access, and attempts, so you should set it up and explore it before you plan any study schedule.

Mile2's FAQ states that standard exams are available online on demand without a live-proctor appointment, and that exam purchases include two attempts. Its named proctoring exceptions (C)ISSO-A and C)PTE-A) are separate credentials and do not apply here.

Proctoring and open-book rules: read your own booking page. Mile2's general Policies and Procedures document (dated May 26, 2026) describes randomized, open-book online examinations and webcam or screen-sharing proctoring in its general certification procedures, while other sections say only some exams require proctors. These published instructions conflict. Rather than assuming a universal rule, follow the instructions shown in your C)PSH-specific account and booking flow before exam day.

Exam Format: Questions, Time, and Passing Grade

The current Certified PowerShell Hacker course outline specifies the following exam parameters:

ElementWhat the Outline Specifies
Question count100 questions
Question styleMultiple choice
TimeApproximately two hours (the general FAQ gives a two-hour limit for standard exams)
Minimum passing grade70%
DeliveryOnline via Mile2 LMS / Mile2.com account
AttemptsTwo included with exam purchase, per the FAQ

A few practical consequences follow from these numbers. At 100 questions in roughly 120 minutes, you have a little over a minute per question, which is comfortable for recall questions but tight for scenario items that ask you to interpret a command or reason through an attack chain. The 70% minimum is a straightforward threshold, and our C)PSH passing score guide walks through what that means in practice. Because this is a multiple-choice exam, there is no separate practical lab assessment in the exam itself. The four-day course, 32 course CEUs, and seven training labs described by Mile2 describe preparation, not exam duration or a hands-on exam component.

If you are weighing difficulty, see How Hard Is the C)PSH Exam? for a candid look at where candidates typically feel pressure.

The Eight Preparation Domains Explained

The course outline's Detailed Outline lists eight headings. These are preparation curriculum topics, not a verified weighted exam blueprint, so treat them as the map of what to learn rather than a promise of exact question distribution. For a deeper walkthrough, see C)PSH Exam Domains: Complete Guide to All 8 Content Areas. Here is how each area fits into the larger picture.

Domain 1: Introduction to PowerShell

The foundation. You need to be fluent in the language before you can reason about its abuse.

  • Cmdlets, pipelines, objects, and the way PowerShell passes structured data
  • Scripting constructs, modules, and execution contexts
  • Why PowerShell is so attractive to both administrators and attackers

Domain 2: Introduction to Active Directory and Kerberos

Nearly everything later depends on understanding how Windows domains authenticate and authorize.

  • Domain structure, users, groups, and trust relationships
  • How Kerberos tickets are requested, issued, and presented
  • Why authentication design choices create attack opportunities

Domain 3: Pen Testing Methodology Revisited

A methodology refresher framed around PowerShell-driven assessments. Note that Mile2's overview uses a different title for this module; the detailed heading "Pen Testing Methodology Revisited" is the one this article follows.

  • Phases of an engagement and where PowerShell fits in each
  • Staying within scope and authorization

Domain 4: Information Gathering and Enumeration

Mapping the environment from a foothold.

  • Enumerating domain objects, users, groups, and computers with native tooling
  • Understanding what information an ordinary domain account can see

Domain 5: Privilege Escalation

Moving from limited access toward higher privilege on Windows hosts and within the domain.

  • Recognizing misconfigurations that enable escalation
  • Connecting host-level weaknesses to domain-level consequences

Domain 6: Lateral Movements and Abusing Trust

Spreading across systems by exploiting how Windows environments trust one another.

  • Remote execution and credential reuse concepts
  • How trust relationships widen an attacker's reach

Domain 7: Persistence and Bypassing Defenses

How attackers maintain access and evade controls, studied so that defenders can recognize it.

  • Common persistence mechanisms in Windows environments
  • Why logging, language restrictions, and scanning interfaces matter

Domain 8: Defending Against PowerShell Attacks

The defensive counterweight: detection, hardening, and monitoring.

  • Logging and visibility for PowerShell activity
  • Hardening choices that reduce attacker options

Notice the arc: language fundamentals, then identity infrastructure, then methodology, then the attack chain from enumeration through escalation, movement, and persistence, and finally defense. Candidates who already know how to attack but have never thought about detection often find Domain 8 an easy place to drop points.

Suggested Background Versus Hard Requirements

Mile2 suggests that candidates arrive with C)PEH and C)PTE or equivalent knowledge, plus familiarity with penetration-testing fundamentals, Active Directory, scripting, and programming. These are recommendations, not mandatory prior certifications. Purchasing or completing a Mile2 course is also not required to purchase the exam.

What "equivalent knowledge" realistically means: you should already be comfortable reading and writing basic scripts, understand how a Windows domain is structured, and know the stages of a penetration test. If any of those feel shaky, shore them up before you tackle the PowerShell-specific material. Our C)PSH requirements guide separates the formal rules from the practical expectations.

Registration Mechanics and Fee Caveats

Mile2 offers a C)PSH Exam Combo that includes exam access, a preparation guide, and quiz or simulator preparation. In the listing retrieved for this review, a current bundle price and a separate exam-only fee were not verified, and earlier promotional amounts should not be treated as current fees. Always confirm pricing directly on the Mile2 product page at the moment you buy. For a structured look at what goes into total spend, including retakes, renewal, and optional training, see the C)PSH certification cost breakdown.

Scheduling is simpler than with proctored test-center exams, because standard Mile2 exams are available on demand online. If you want to understand the timing side, our C)PSH exam dates and scheduling guide covers how to plan around access windows and your own readiness.

Three-Year Validity and the Renewal Puzzle

Certification is valid for three years. Renewal is where Mile2's own published materials diverge, so it is worth being precise about what each source says:

  • The dedicated Certification Renewal Program and Paths to Renewal pages describe a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase, and an ethics acknowledgment, or an alternative route involving the latest existing certification exam or an eligible qualifying exam. These pages present CEUs and exams as alternatives.
  • The Mile2 FAQ lists a USD 200 U.S.-region renewal fee.
  • The course outline says 20 CEUs annually plus passing the current exam.
  • The May 2026 Policies and Procedures uses CEUs plus a purchased recertification exam within seven days of expiry, and full reexamination without CEUs after that period.

Key Takeaway

Do not collapse these descriptions into a single renewal rule. Mile2's sources differ, so before your three-year mark approaches, check the renewal pages and your account for the route that applies to you, and keep records of any continuing-education activity you might need to document.

Who Benefits From the Credential

The C)PSH speaks most directly to people whose work touches Windows environments from an adversarial or defensive angle:

  • Penetration testers and red team operators who assess Active Directory environments and need PowerShell fluency to work efficiently.
  • Blue team analysts and detection engineers who must recognize PowerShell-based tradecraft in logs and telemetry.
  • Windows and security administrators responsible for hardening domains against the abuse patterns the certification teaches.
  • Incident responders who encounter PowerShell in intrusion timelines and need to reason about what an attacker did.

Because the outline closes with defending against PowerShell attacks, the credential is not purely offensive. Employers that value it tend to look for people who can think like an attacker and then translate that knowledge into controls. For role-oriented detail, see C)PSH jobs, and for compensation context, the C)PSH salary guide. Whether the investment pays off for your situation is explored in Is the C)PSH Certification Worth It?

Sequencing Your Preparation Around the Domains

Rather than a generic study calendar, let the domain dependencies drive your order. Early domains are prerequisites for later ones, so reversing the order wastes effort. Here is one sensible sequence, scaled to a candidate who already has solid penetration-testing basics:

Week 1

PowerShell and Kerberos foundations

  • Domain 1: practice cmdlets, objects, and the pipeline until you can read unfamiliar scripts
  • Domain 2: trace a Kerberos authentication flow end to end
Week 2

Methodology and enumeration

  • Domain 3: refresh engagement phases
  • Domain 4: practice enumeration concepts in an isolated, authorized lab
Week 3

The attack chain

  • Domain 5: privilege escalation concepts
  • Domain 6: lateral movement and trust abuse
Week 4

Persistence, defense, and timed review

  • Domain 7 and Domain 8 together, so detection knowledge reinforces what you learn about evasion
  • Timed multiple-choice sets that mirror 100 questions in about two hours

Keep all hands-on practice inside isolated, authorized training environments, such as your own lab or Mile2's provided labs. The exam tests conceptual understanding through multiple-choice questions, so spend as much time explaining why a technique works and how it would be detected as you do on the mechanics. For a fuller plan, see the C)PSH study guide, and when you are ready to test recall, a one-page C)PSH cheat sheet helps with final review. You can also drill questions on our C)PSH practice test site to check whether your timing holds up across a full-length set.

A note on pass-rate claims: no verified C)PSH pass rate is cited in this article, and you should be skeptical of any site that quotes a precise figure without a source. Our pass rate discussion explains what can and cannot be said responsibly.

Frequently Asked Questions

What does C)PSH stand for?

C)PSH stands for Certified PowerShell Hacker, a certification awarded by Mile2. Many candidates search for it as "CPSH" because the parenthesis is awkward to type.

How many questions are on the exam, and what score do I need?

The current course outline specifies 100 multiple-choice questions in approximately two hours, with a minimum passing grade of 70%.

Do I need to take a Mile2 course or hold other certifications first?

No. Purchasing or completing a Mile2 course is not required to buy the exam, and C)PEH and C)PTE are suggested background, not mandatory prerequisites. Equivalent knowledge in penetration testing, Active Directory, scripting, and programming is what matters.

How long is the certification valid, and how do I renew it?

It is valid for three years. Mile2's renewal pages describe a CEU route (60 documented CEUs, a renewal purchase, and ethics acknowledgment) or an exam-based alternative, but other Mile2 documents describe the process differently. Check the renewal pages and your account for the rule that applies to you.

Is the exam open-book or proctored?

Mile2's published materials conflict on this point: the general policies mention open-book online exams and webcam or screen-sharing proctoring, while the FAQ says standard exams are on demand without a live-proctor appointment. Follow the instructions in your C)PSH account and booking flow rather than assuming either rule.

Ready to pass your C)PSH exam?

Put this into practice with free C)PSH questions across every exam domain.