C)PSH logo
Focused certification exam prep
Start practice

What Is C)PSH Certification?

TL;DR
  • C)PSH here means Certified Powershell Hacker, awarded by Mile2 and focused on offensive and defensive PowerShell in Windows and Active Directory environments.
  • Mile2's course outline specifies 100 multiple-choice questions, about two hours, and a 70% minimum passing grade.
  • The outline lists eight preparation topics, from PowerShell basics through Kerberos, privilege escalation, persistence, and defending against PowerShell...
  • Certification is valid for three years; renewal sources differ, so confirm your route with Mile2 before relying on any single description.

What the Certified PowerShell Hacker Credential Actually Is

The Certified Powershell Hacker credential, styled "Certified PowerShell Hacker" in Mile2's course materials, is a vendor certification from Mile2 that validates your understanding of how PowerShell is used in modern Windows environments, both by attackers and by the defenders trying to stop them. If you have ever wondered what a C)PSH is, the short answer is this: it is a specialist, post-fundamentals certification aimed at people who already understand penetration testing concepts and want to work at the scripting and Active Directory layer.

PowerShell sits at an unusual intersection. It is a legitimate administrative tool installed on virtually every modern Windows system, which makes it enormously valuable to administrators and, for the same reasons, to adversaries. A candidate preparing for this credential needs to think in both directions: how a script can enumerate a domain, escalate privileges, and move laterally, and how a defender can detect, constrain, and log that same activity.

If you want a quick orientation on the terminology before going deeper, our short explainers on what C)PSH is and what C)PSH stands for cover the basics. This article goes further into format, curriculum, and practical decisions.

Clearing Up the Acronym: CPSH vs. Other Credentials

Several unrelated credentials in the industry share the same letters. For this site and this article, C)PSH refers only to Mile2's Certified Powershell Hacker. When you research exam details, fees, or career outcomes, make sure the source you are reading is actually about the Mile2 credential. Details belonging to a different certification with a similar acronym will mislead you on cost, format, and renewal.

Because the parenthesis in the name is awkward to type, many people search using the punctuation-free alias CPSH. The two refer to the same Mile2 credential here. For more on the naming question, see our pieces on the meaning of C)PSH and what C)PSH means.

Verify the source: Before trusting any fee, date, or pass-rate claim about this credential, confirm it comes from Mile2's own C)PSH pages or the current C)PSH course outline. If a number appears without a clear Mile2 source, treat it with caution.

Exam Format at a Glance

Mile2's current linked course outline for Certified PowerShell Hacker specifies the following exam parameters. The outline itself is undated, so check Mile2's course page for any revision before you schedule.

AttributeWhat Mile2's Outline Specifies
Question count100 questions
Question styleMultiple choice
Time allowedApproximately two hours
Minimum passing grade70%
DeliveryOnline, through Mile2's learning management system and your Mile2.com account
Attempts included with purchaseTwo (per Mile2's FAQ for exam purchases)

The 70% threshold means you need at least 70 of 100 questions correct if each question counts equally. For a deeper look at how scoring thresholds play out in practice, read our guide to the C)PSH passing score.

What about proctoring and open-book rules?

This is an area where Mile2's published material is not perfectly consistent. The FAQ states that standard exams are available online on demand without a live-proctor appointment. Meanwhile, Mile2's general Policies and Procedures document describes randomized, open-book online examinations and webcam or screen-sharing proctoring in its general certification procedures, while other sections say only some exams require proctors. Mile2 also names certain proctoring exceptions for other credentials, and those are not this one.

The practical takeaway: do not assume the exam is open-book, and do not assume it is unproctored. Follow the instructions shown in your own C)PSH account and booking flow, and prepare as though you must know the material cold. Our overview of scheduling and exam windows explains how to approach booking with this uncertainty in mind.

The Eight Preparation Topics in Detail

Mile2's Detailed Outline lists eight curriculum headings. These are preparation topics, not a verified weighted exam blueprint, so do not assume each carries equal weight or that the list is an exhaustive map of every question. They are, however, the best published guide to what to study. For a topic-by-topic walkthrough, see our complete guide to the C)PSH content areas.

Domain 1: Introduction to PowerShell

The foundation. You need real fluency with the language before any offensive or defensive concept makes sense.

  • Cmdlets, the pipeline, and object-based output
  • Variables, functions, modules, and scripting constructs
  • Execution policy and how scripts are loaded and run
  • Remoting concepts and how PowerShell communicates across systems

Domain 2: Introduction to Active Directory and Kerberos

Almost every later domain assumes you understand how a Windows domain is structured and how authentication flows through it.

  • Domains, forests, trusts, organizational units, and group policy
  • Users, groups, service accounts, and delegation
  • The Kerberos ticket exchange and why its design creates both security and attack surface

Domain 3: Pen Testing Methodology Revisited

Mile2's overview uses a different title for this module, but the detailed heading is "Pen Testing Methodology Revisited." It frames the engagement workflow through a PowerShell lens.

  • How standard penetration-testing phases map onto PowerShell-driven work
  • Scoping, authorization, and staying within rules of engagement
  • Where scripting fits at each phase of an assessment

Domain 4: Information Gathering and Enumeration

Understanding what an environment reveals about itself to an authenticated or unauthenticated user.

  • Enumerating domain objects, accounts, groups, and computers
  • Identifying relationships and trust paths worth investigating
  • Recognizing which native tooling produces telltale logs

Domain 5: Privilege Escalation

How a low-privileged foothold becomes something more powerful, and which misconfigurations make that possible.

  • Common local and domain-level escalation weaknesses
  • Credential exposure and misconfigured permissions
  • How escalation techniques appear from a defender's perspective

Domain 6: Lateral Movements and Abusing Trust

Moving between systems and exploiting the trust relationships that administrators create for convenience.

  • Remote execution mechanisms and their authentication requirements
  • Trust relationships between accounts, systems, and domains
  • Why legitimate administrative pathways are hard to distinguish from abuse

Domain 7: Persistence and Bypassing Defenses

How access is maintained over time and how defensive controls can be evaded, studied so that you can recognize and counter it.

  • Persistence mechanisms and where they hide
  • Defensive controls and their known limitations
  • Conceptual awareness of evasion, kept within authorized, isolated training environments

Domain 8: Defending Against PowerShell Attacks

The payoff domain for blue teams and a differentiator for the credential overall.

  • Logging, monitoring, and detection strategies for script-based activity
  • Hardening and constraining PowerShell in production environments
  • Translating what you learned offensively into concrete defensive controls

Key Takeaway

Do not treat Domain 8 as an afterthought. A credential built around PowerShell attacks inevitably asks whether you can also defend against them, and defensive knowledge often anchors the most practical scenario questions.

Who Should Pursue It and Who Hires for These Skills

The skills behind this credential map to several job families. Penetration testers and red team members use PowerShell to automate enumeration and assess Active Directory weaknesses. Security analysts and incident responders need to recognize malicious script activity in logs. Windows and Active Directory administrators benefit from understanding how their own environments get attacked. Defensive engineers building detection and hardening programs find Domain 8 directly applicable.

Employers that run Windows-heavy infrastructure, security consultancies, managed security providers, and internal security teams all value people who understand PowerShell tradecraft. Whether the certification itself moves your compensation is a separate question, and we address it candidly in our salary analysis and the broader worth-it breakdown. We do not quote specific earnings here because reliable credential-specific figures are scarce. You can also browse our overview of C)PSH jobs to see how the skills translate into roles.

Suggested Background Knowledge

Mile2's materials suggest preparation that includes the C)PEH and C)PTE certifications or equivalent knowledge, along with penetration-testing fundamentals, Active Directory, scripting, and programming. These are recommendations, not mandatory prior certifications. You are not formally required to hold any earlier Mile2 credential to buy the exam, and purchasing or completing a Mile2 course is likewise not required. Our requirements guide walks through eligibility in more detail.

Self-assessment test: If you cannot write a short PowerShell function, explain what a Kerberos ticket-granting ticket does, and describe what a domain trust is, spend time on Domains 1 and 2 before touching anything else. Gaps in those foundations make every later domain harder.

Mile2's training offering

Mile2 pairs the credential with a four-day course that carries 32 course CEUs and includes seven training labs. Those figures describe the training, not the exam. They do not indicate how long the exam lasts, they do not represent a separate practical assessment, and they should not be read as a verified renewal-hour requirement. If you want a self-directed route instead, see our notes on C)PSH training options.

Buying the Exam: Mechanics and Open Questions

Mile2 offers a C)PSH Exam Combo that includes exam access, a preparation guide, and quiz or simulator preparation. A separate exam-only fee and a current bundle price were not verified in the listing we reviewed, and earlier promotional amounts should not be treated as today's fees. Always confirm the live price on Mile2's product page at checkout. Our cost breakdown explains how to think about total spend without relying on stale numbers.

  1. Create or sign in to your Mile2.com account.
  2. Review the current C)PSH course outline and exam listing for any updates.
  3. Choose between the exam combo and any exam-only option that is currently listed.
  4. Follow the booking and access instructions specific to C)PSH in your account.
  5. Remember that the purchase includes two attempts, so plan your first attempt as a genuine try rather than a throwaway.

Three-Year Validity and the Renewal Picture

Certification is valid for three years. Renewal is where Mile2's published sources diverge, and it is worth being precise about the disagreement rather than flattening it into one tidy rule.

SourceWhat It Describes
Dedicated renewal pagesTwo alternative routes: a continuing-education route requiring 60 documented CEUs over the term, a renewal purchase, and an ethics acknowledgment; or an exam route using the latest existing certification exam or an eligible qualifying exam
Course outlineDescribes 20 CEUs annually plus passing the current exam
Policies and Procedures (May 2026)Describes CEUs plus a purchased recertification exam within seven days of expiry, and full reexamination without CEUs after that period
FAQLists a USD 200 U.S.-region renewal fee

Because these descriptions differ, do not combine them into a single unqualified rule. The dedicated renewal pages present the CEU and exam routes as alternatives, which is the most direct reading, but confirm your exact obligations with Mile2 well before your expiry date. Keeping records of professional activity from the start protects you whichever route applies.

Sequencing Your Preparation Around the Curriculum

You do not need an elaborate system. What matters is ordering the eight topics so that each builds on the last. Because later domains assume earlier fluency, front-load the foundations. The sample plan below assumes you already have general penetration-testing familiarity; stretch it if you do not. For a fuller roadmap, see our C)PSH study guide, and when you want to gauge readiness, try the practice questions on the main practice test site.

Week 1

Language foundations

  • Domain 1: write small scripts daily in an isolated lab
  • Practice the pipeline, modules, and remoting concepts until they feel natural
Week 2

Identity infrastructure

  • Domain 2: draw the Kerberos exchange from memory
  • Map domain, forest, and trust structures
Week 3

Methodology and discovery

  • Domains 3 and 4: connect engagement phases to enumeration activity
  • Note which actions generate logs a defender would see
Week 4

Offense in sequence

  • Domains 5 and 6: escalation and lateral movement, studied conceptually or in authorized labs only
Week 5

Persistence and defense

  • Domains 7 and 8: pair every offensive technique with its detection and mitigation
  • Finish with timed practice sets under a two-hour limit

The reason Domain 8 gets the final slot is that defensive knowledge is easiest to retain once you understand what you are defending against. Revisit it twice. Also, since the exam is multiple choice, practice reading answer options carefully: in a technical field, two options often look plausible and only one fits the exact scenario. Our cheat sheet is useful for a final-days review, and our assessment of exam difficulty helps you calibrate how much time to budget.

Stay in bounds: Hands-on practice belongs in isolated, authorized training environments that you own or have explicit permission to use. Never test techniques against systems you do not control. Practicing the concepts safely is both ethical and entirely sufficient for the exam.

Frequently Asked Questions

What does C)PSH stand for?

On this site it stands for Certified Powershell Hacker, a Mile2 certification. Other credentials in the industry share the acronym, so confirm that any source you read is about the Mile2 certification. You can also search for it as CPSH. See our related explainer for more.

How many questions are on the exam and what score do I need?

Mile2's current course outline specifies 100 multiple-choice questions, roughly two hours, and a minimum passing grade of 70%. Because the outline is undated, check Mile2's course page for updates before you test.

Do I need to buy the course or hold earlier certifications?

No. Purchasing or completing a Mile2 course is not required to purchase the exam, and prior certifications are suggested rather than mandatory. Mile2 recommends C)PEH and C)PTE or equivalent knowledge, plus penetration-testing fundamentals, Active Directory, scripting, and programming.

Is the exam proctored or open-book?

Mile2's published material is inconsistent. The FAQ describes standard exams as available online on demand without a live-proctor appointment, while the general policies document describes open-book online exams and webcam or screen-sharing proctoring in certain procedures. Follow the instructions in your own C)PSH booking flow rather than assuming either rule.

How long does the certification last, and how do I renew?

It is valid for three years. Renewal sources differ: the dedicated pages describe a 60-CEU route and an alternative exam route, while other documents describe different CEU and exam combinations. Confirm your specific route with Mile2 before your expiry date.

Ready to pass your C)PSH exam?

Put this into practice with free C)PSH questions across every exam domain.