- The Short Answer: What C)PSH Actually Is
- Who Issues It and How the Exam Is Delivered
- Question Style, Length, and Passing Grade
- The Eight Curriculum Areas, One by One
- Who the Credential Fits (and Who Hires for These Skills)
- What to Know Before You Start
- Registration, Fees, and Attempts
- Three-Year Validity and the Renewal Picture
- Sequencing Your Preparation Around the Curriculum
- Frequently Asked Questions
- C)PSH means Certified Powershell Hacker, awarded by Mile2 and focused on offensive and defensive use of PowerShell in Windows and Active Directory environments.
- The course outline specifies 100 multiple-choice questions, roughly two hours, and a minimum passing grade of 70%.
- Mile2 publishes eight preparation topics, from PowerShell basics to defending against PowerShell attacks; they are not a weighted exam blueprint.
- Certification is valid for three years, and renewal sources conflict, so confirm your exact path in your Mile2 account.
The Short Answer: What C)PSH Actually Is
C)PSH stands for Certified Powershell Hacker. Mile2's own course materials style it "Certified PowerShell Hacker," and you will see both spellings. If you are searching without punctuation, "CPSH" is the common alias, and it points to the same credential. For quick definitions of the acronym itself, see our short explainers on what C)PSH stands for and the C)PSH meaning.
The certification validates that a candidate understands how PowerShell is used as an attack platform inside Windows environments, particularly Active Directory domains, and how defenders detect and limit that activity. It sits in the offensive-security family of credentials, but its scope is narrower than a general penetration testing certification. Everything revolves around one tool and the ecosystem around it: scripting, Kerberos authentication, enumeration, privilege escalation, lateral movement, persistence, and defensive countermeasures.
Who Issues It and How the Exam Is Delivered
Mile2 awards the credential. The exam is delivered online through Mile2's learning management system and your Mile2.com account, so there is no testing-center trip to plan around. Mile2's general FAQ states that its standard exams are available online on demand without a live-proctor appointment, and that exam purchases include two attempts. The C)ISSO-A and C)PTE-A exams are named as proctoring exceptions in that FAQ, and C)PSH is not one of them.
There is one wrinkle worth knowing about. Mile2's Policies and Procedures document (dated May 26, 2026) describes randomized, open-book online examinations and webcam/screen-sharing proctoring in its general certification procedures, while other sections say only some exams require proctors. Those published statements do not line up neatly. The safe approach is to follow the instructions shown in your own C)PSH account and booking flow rather than assuming a blanket open-book or proctoring rule. Read every on-screen instruction before you launch the exam, and do not rely on forum hearsay about what is or isn't allowed.
For scheduling and timing questions, our guide to C)PSH exam dates and scheduling covers how on-demand access changes the usual "testing window" thinking.
Question Style, Length, and Passing Grade
According to the current Certified PowerShell Hacker course outline on Mile2's site, the exam consists of 100 multiple-choice questions, takes approximately two hours, and requires a minimum passing grade of 70%. The outline is an undated five-page PDF, and Mile2's general FAQ separately gives a two-hour limit for standard exams, which is consistent with it.
| Item | What Mile2 Publishes |
|---|---|
| Credential name | Certified Powershell Hacker (C)PSH) |
| Question count | 100 |
| Question type | Multiple choice |
| Time | Approximately two hours |
| Passing grade | 70% minimum |
| Delivery | Online via Mile2 LMS and Mile2.com account |
| Attempts included | Two with an exam purchase |
| Validity | Three years |
Mile2 does not publish a weighted breakdown showing what percentage of questions comes from each topic, so be skeptical of any site that claims precise domain weights. For a deeper look at what 70% means in practice, see our C)PSH passing score breakdown. If you are weighing your odds, our difficulty guide discusses what makes the exam demanding, and the pass rate article explains why no verified figure is available to cite.
The Eight Curriculum Areas, One by One
The Detailed Outline in Mile2's PDF lists eight headings. They are preparation topics from the course, not a verified weighted exam blueprint, and they do not prove exhaustive exam coverage. Treat them as the best published map of what to learn. For a longer treatment of each, read our complete guide to the C)PSH content areas.
Domain 1: Introduction to PowerShell
This is the foundation. Candidates need real fluency in the language, not just recognition of cmdlet names.
- Cmdlet structure, the object pipeline, and how output is passed between commands
- Variables, functions, modules, and scripting constructs
- Execution policy concepts and what they do and do not enforce
- Remoting fundamentals and how PowerShell reaches other hosts
Domain 2: Introduction to Active Directory and Kerberos
Almost every later domain depends on understanding how Windows domains authenticate and authorize.
- Domain, forest, and trust structure; users, groups, and organizational units
- The Kerberos exchange: tickets, the key distribution center, and service tickets
- How delegation and service principal names create attack surface
- Why authentication artifacts matter to both attackers and defenders
Domain 3: Pen Testing Methodology Revisited
Mile2's overview page uses a different title for this module, but the detailed heading is "Pen Testing Methodology Revisited," and that is the name to remember. Expect a refresher on how an engagement is structured, framed around PowerShell-driven work.
- Phases of an authorized assessment and where PowerShell fits in each
- Rules of engagement, scope, and documentation habits
- Choosing native tooling versus external tooling in a Windows target
Domain 4: Information Gathering and Enumeration
This is where PowerShell's built-in access to directory and system data becomes a reconnaissance tool.
- Enumerating users, groups, computers, shares, and policies in a domain
- Finding relationships and permissions that reveal paths toward higher access
- Understanding which enumeration activity is noisy and which blends into normal administration
Domain 5: Privilege Escalation
Candidates should be able to recognize escalation opportunities and explain why they exist.
- Misconfigurations in services, permissions, and scheduled tasks
- Credential exposure and weak delegation settings
- The difference between local escalation and domain-level escalation
Domain 6: Lateral Movements and Abusing Trust
Once access exists, how does an attacker widen it? This area ties directly back to the Kerberos and trust concepts in Domain 2.
- Remote execution mechanisms and the authentication they rely on
- Abuse of trust relationships between systems and domains
- Credential reuse and ticket-based movement concepts
Domain 7: Persistence and Bypassing Defenses
This area covers how access is maintained and how protective controls get evaded, which is also the best way to understand what defenders must watch for.
- Persistence mechanisms available to a PowerShell-capable attacker
- Conceptual understanding of logging, scanning, and constrained-environment controls, and how they can be circumvented
- Why defense-evasion technique knowledge informs detection design
Domain 8: Defending Against PowerShell Attacks
The credential does not stop at offense. Defensive knowledge closes the loop.
- Logging and auditing options that expose script activity
- Hardening approaches that restrict what PowerShell can do
- Detection thinking: what malicious usage looks like in telemetry
Key Takeaway
The curriculum reads as a chain: language, then directory and authentication internals, then attack phases, then defense. If Domain 2 is weak, Domains 5 and 6 will feel like memorization instead of reasoning. Build the Kerberos understanding early.
Who the Credential Fits (and Who Hires for These Skills)
C)PSH suits people whose work touches Windows enterprise security from an offensive or defensive angle. Typical fits include penetration testers who regularly face Active Directory environments, red team members, security analysts and threat hunters who need to recognize malicious script behavior, and Windows administrators moving into security roles. Because Domain 8 focuses on defense, blue-team staff gain as much from the material as offensive practitioners do.
Employers who value these skills are those running large Windows estates: managed security service providers, consultancies that perform internal network assessments, enterprise security teams, and organizations with sizable Active Directory footprints. We do not cite salary numbers here because none are verified for this specific credential; our salary guide explains the qualitative factors that drive pay, and our C)PSH jobs overview looks at the kinds of roles where these skills come up. If you are asking whether the investment pays off for you personally, the ROI analysis walks through the trade-offs.
What to Know Before You Start
Mile2's suggested preparation includes C)PEH and C)PTE or equivalent knowledge, plus penetration-testing fundamentals, Active Directory, scripting, and programming. These are recommendations, not mandatory prior certifications. You do not need to hold C)PEH or C)PTE to purchase or sit the exam, and purchasing or completing a Mile2 course is likewise not required to buy the exam.
The associated Mile2 course is described as four days with 32 course CEUs and seven training labs. Those details describe training, not the exam. They do not indicate an exam length, a separate practical assessment, or a renewal-hour requirement. Any hands-on practice you do should happen in an isolated lab you own or an environment where you have explicit authorization; never test techniques against systems you do not control.
If a structured training path appeals to you, our C)PSH training overview compares the formal course route with self-directed study.
Registration, Fees, and Attempts
Exam purchases include two attempts, and the exam is taken online from your Mile2.com account. Mile2 also lists a C)PSH Exam Combo that includes exam access, a preparation guide, and quiz/simulator preparation.
On cost, be careful. We did not verify a current bundle price or a separate exam-only fee in the retrieved listing, and earlier promotional amounts you may see quoted online should not be treated as current. Check the live Mile2 product page before budgeting. Our certification cost breakdown explains what to account for beyond the exam itself, such as optional training and renewal.
Three-Year Validity and the Renewal Picture
The certification is valid for three years. Renewal is where Mile2's published material is inconsistent, so it deserves careful reading rather than a tidy summary.
| Source | What It Describes |
|---|---|
| Dedicated Certification Renewal Program and Paths to Renewal pages | Two alternatives: a continuing-education route (60 documented CEUs over the term, a renewal purchase, and ethics acknowledgment) or an exam route using the latest existing certification exam or an eligible qualifying exam |
| C)PSH course outline | Mentions 20 CEUs annually plus passing the current exam |
| Policies and Procedures (May 2026) | CEUs plus a purchased recertification exam within seven days of expiry; full reexamination without CEUs after that period |
| General FAQ | Lists a USD 200 renewal fee for the U.S. region |
Sequencing Your Preparation Around the Curriculum
Rather than a generic study template, order your preparation by dependency. Each phase below leans on the one before it.
Language and Kerberos Foundations
- Work through Domain 1 until scripting feels natural
- Study Domain 2 and diagram the Kerberos flow from memory
Methodology and Enumeration
- Review Domain 3 to frame everything within an engagement
- Practice Domain 4 enumeration in an isolated lab you control
Escalation, Movement, and Persistence
- Cover Domains 5 and 6 together, since movement often follows escalation
- Add Domain 7, focusing on why each technique is detectable
Defense and Timed Review
- Close with Domain 8 so detection thinking colors your answers
- Run full-length timed sets of 100 questions in about two hours
Our full C)PSH study guide expands this into a detailed plan, and the one-page cheat sheet is useful for last-minute review. For timed multiple-choice repetition, our C)PSH practice tests mirror the 100-question, two-hour pacing described in Mile2's outline, so you can build stamina along with knowledge.
Key Takeaway
Because the exam is 100 questions in roughly two hours, you have about a minute per question. Practice reading scenario-style items quickly and eliminating wrong answers using domain reasoning, not recall alone.
Frequently Asked Questions
C)PSH stands for Certified Powershell Hacker, a credential awarded by Mile2. It is also written Certified PowerShell Hacker, and "CPSH" is the punctuation-free search alias. See what C)PSH certification is for more context.
Mile2's course outline specifies 100 multiple-choice questions, approximately two hours, and a minimum passing grade of 70%. The outline is undated, so confirm the details in your account when you book.
No. Purchasing or completing a Mile2 course is not required to purchase the exam. Mile2 does suggest C)PEH and C)PTE or equivalent knowledge, along with Active Directory, scripting, and programming experience, but these are recommendations rather than mandatory prerequisites.
Mile2's published material is inconsistent. The FAQ says standard exams run online on demand without a live-proctor appointment, while the general Policies and Procedures document describes open-book exams and webcam/screen-sharing proctoring for certain procedures. Follow the instructions shown in your own C)PSH account and booking flow.
It is valid for three years. Mile2's dedicated renewal pages describe either a CEU route (60 documented CEUs, a renewal purchase, and ethics acknowledgment) or an exam-based route. Other documents describe the process differently, so verify your specific path and fee with Mile2 before your expiry date.