- Identity Check: Which C)PTC This Sheet Covers
- The Two-Part Assessment at a Glance
- Written Exam Facts
- The 12 Curriculum Headings in One Pass
- Exploit Development Concepts to Memorize
- Recon, Team Workflow and Reporting Reminders
- Source Conflicts and Caveats to Remember
- Prerequisites, Fees and Renewal
- Which Heading to Schedule When
- Frequently Asked Questions
- C)PTC here means Mile2's Certified Penetration Testing Consultant, not any other credential sharing the acronym.
- The knowledge exam is 100 multiple-choice questions, two hours, 70% required.
- The hands-on part requires exploiting four of five lab systems, identifying flags and submitting a complete written report.
- The 12 domain lines are unweighted curriculum headings from Mile2's detailed outline, not an official blueprint.
Identity Check: Which C)PTC This Sheet Covers
This cheat sheet covers Certified Penetration Testing Consultant (C)PTC), a credential issued by Mile2. Several unrelated credentials and competitions abbreviate to similar letters, including a transplant-coordinator certification and the Collegiate Penetration Testing Competition. None of their facts apply here. If a fee, date, or pass mark you find online does not trace back to Mile2's own materials for this certification, discard it.
Everything below draws on Mile2's currently linked, undated course outline. Issuer sources were checked on October 2, 2026. If you are still deciding whether this is the right credential, start with our explainers on what C)PTC certification is and what C)PTC stands for, then return to this page for the quick-reference facts.
The Two-Part Assessment at a Glance
The most common mistake on this credential is treating it as a single multiple-choice test. Mile2's outline describes a two-part certification assessment, and each part tests something different.
| Part | What It Involves | Verified Detail |
|---|---|---|
| Part 1: Hands-on penetration test | Exploit lab systems, identify flags, write a complete report | Successful exploitation of four of five lab systems required |
| Part 2a: Flag-selection questions | Online, delivered through Mile2's Assessment and Certification System (MACS) | Separate from the knowledge exam |
| Part 2b: Knowledge examination | Online through MACS | 100 multiple-choice questions, two hours, 70% to pass |
For a deeper look at difficulty across both parts, see How Hard Is the C)PTC Exam?
Written Exam Facts
When people say "the exam" in connection with C)PTC, the issuer's Exam line refers only to the written knowledge component. Memorize these numbers:
- Questions: 100 multiple-choice
- Time allowed: two hours
- Passing requirement: 70%
- Delivery: online, through MACS
That 70% applies to the knowledge examination, not to the practical lab work or the report, which are judged on their own requirements. For a closer look at how scoring works, read the C)PTC passing score breakdown.
The 12 Curriculum Headings in One Pass
The twelve lines below reproduce the Detailed Outline on pages 3-4 of Mile2's Certified Penetration Testing Consultant PDF. They are unweighted preparation headings. They are not an official 12-domain exam count, a weighted blueprint, or a guarantee of exhaustive exam coverage. For a longer treatment of each one, see the complete guide to all 12 content areas.
| # | Heading | One-Line Memory Hook |
|---|---|---|
| 1 | Pentesting Team Foundation | Roles, project metrics, authorized-lab discipline |
| 2 | NMAP Automation | Scan, read, and interpret reports at scale |
| 3 | Exploitation Processes | From finding to controlled compromise |
| 4 | Fuzzing with Spike | Malformed input to expose crashes |
| 5 | Privilege Escalation | Low-privilege foothold to higher access |
| 6 | Stack Based Windows Buffer Overflow | Windows stack memory fundamentals |
| 7 | Web Application Security and Exploitation | References OWASP Top 10-2017 |
| 8 | Linux Stack Smashing | The Linux counterpart to Domain 6 |
| 9 | Linux Address Space Layout Randomization | ASLR on Linux |
| 10 | Windows Exploit Protection | Defensive mitigations on Windows |
| 11 | Getting Around SEH and ASLR (Windows) | Bypass thinking for protected Windows targets |
| 12 | Penetration Testing Report Writing | Remediation-focused deliverables |
Exploit Development Concepts to Memorize
The back half of the outline is where candidates with only scanning experience struggle. Keep these concept pairs straight.
Stack Overflow Fundamentals (Domains 6 and 8)
Know why overflowing a stack buffer can redirect execution, and how the Windows and Linux variants differ in practice.
- Distinguish Windows stack-based overflow concepts from Linux stack smashing concepts
- Understand how a fuzzing crash becomes an analyzable memory-corruption finding
- Keep all exploitation practice inside authorized lab environments
Mitigations and Their Bypass Concepts (Domains 9, 10 and 11)
Pair each protection with what it is meant to stop.
- ASLR: randomizes address layout, covered on Linux in Domain 9
- DEP: marks memory non-executable so injected data cannot simply run
- SEH: Windows structured exception handling, a classic target in overflow work
- SafeSEH and SEHOP: protections that validate or protect the exception-handler chain
- Domain 11 asks you to reason about getting around SEH and ASLR together on Windows
Fuzzing with Spike (Domain 4)
Understand fuzzing as a discovery technique: send structured but malformed input to a service and watch for abnormal behavior that signals a memory-handling flaw. Be able to describe the workflow conceptually, from identifying an input surface to confirming a crash worth investigating.
Recon, Team Workflow and Reporting Reminders
Team Foundation and NMAP (Domains 1 and 2)
Domain 1 treats a penetration test as a managed project, so expect concepts around team roles, project metrics and keeping testing within authorized scope. Domain 2 centers on automating NMAP and, importantly, interpreting its output. Practice reading scan reports and deciding what each open port, service banner and version string means for next steps, rather than only running scans.
Exploitation, Escalation and Web (Domains 3, 5 and 7)
Domain 3 frames exploitation as a process, and Domain 5 covers privilege escalation as the follow-on step after initial access. Domain 7 covers web application security and exploitation, and the outline explicitly references OWASP Top 10-2017. That reference matters: it signals the web material is tied to that older list, so do not assume the course has been rebuilt around a newer one.
Report Writing (Domain 12)
Because the practical requires a complete written report, Domain 12 is not an afterthought. A strong report is remediation-focused: it explains what was found, why it matters, and how the client fixes it, not just how you got in. Practice writing findings that a technical owner could act on without contacting you.
Key Takeaway
Treat the report as graded work, not paperwork. Four exploited systems and identified flags are only part of the hands-on requirement; the complete written report is the other part.
Source Conflicts and Caveats to Remember
Mile2's own documents do not perfectly agree, and a good cheat sheet records that instead of hiding it.
- Module labels differ. The page 1 summary uses alternative labels, notably "Simple Buffer Overflow" for Module 5 where the detailed outline says "Privilege Escalation," and a different title for Module 8 than the detailed "Linux Stack Smashing" heading. The detailed sequence controls, and the two lists should not be blended.
- The outline is undated. Do not treat it as a newly updated 2026 syllabus. The OWASP 2017 reference is a reminder of that.
- Course measures are not exam timing. The five-day course and its 40 CEUs describe training, not how long you have to test.
- The 12 headings are not weighted. Do not allocate study time by assumed percentages, because none are published for these headings.
Prerequisites, Fees and Renewal
Preparation Expectations
Purchasing or completing Mile2 training is not mandatory. Suggested preparation includes C)PEH and C)PTE or equivalent knowledge, two years of networking experience, sound TCP/IP knowledge and computer-hardware knowledge. See C)PTC requirements and eligibility for the full picture, and C)PTC training if you are weighing a course.
The Exam Combo and Fees
The Exam Combo includes an exam-preparation guide, practice questions or a simulator, and two exam attempts. The current initial package price could not be independently confirmed from the retrievable issuer listing, so no initial exam fee is stated here. Check Mile2's current Exam Combo page before budgeting, and see C)PTC certification cost for how to think through the pricing.
Renewal Cycle
| Item | Detail |
|---|---|
| Validity | Three-year cycle |
| CEU route | 60 documented CEUs over the cycle, the applicable renewal purchase, and ethics/policy compliance |
| Alternative route | Pass the current full certification examination |
| U.S. regional CEU-route renewal fee | USD 200 (a renewal fee, not the initial exam fee) |
| Annual membership | Not required, per Mile2's FAQ |
Which Heading to Schedule When
If you have time to build a plan, sequence it by dependency rather than by the order you happen to enjoy. A reasonable arrangement, built around how these topics rely on each other:
Foundations and Recon
- Domain 1 team and project concepts
- Domain 2 NMAP report interpretation
Exploitation Flow
- Domains 3 and 5 in sequence, so escalation follows initial access
- Domain 7 with the OWASP Top 10-2017 reference in mind
Memory Corruption and Mitigations
- Domain 4 fuzzing, then Domains 6 and 8 stack concepts
- Domains 9, 10 and 11, since bypass thinking only makes sense after you know what each mitigation does
Report and Review
- Domain 12 report drafting from your own lab notes
- Timed run-throughs on the practice test site for the knowledge exam format
Place the memory-corruption block in the middle rather than last, because it demands the most repetition. For a fuller method, see the C)PTC study guide.
Frequently Asked Questions
The knowledge examination has 100 multiple-choice questions, with two hours allowed and 70% required. That figure covers only the written component, not the hands-on practical or the flag-selection questions.
Per Mile2's outline, you must successfully exploit four of five lab systems, identify flags and deliver a complete written report. A time limit for the practical was not verified, so confirm it in your assessment instructions.
No. Purchasing or completing Mile2 training is not mandatory. Mile2 suggests prior knowledge such as C)PEH and C)PTE or equivalent, plus two years of networking experience and solid TCP/IP understanding.
Comparisons depend on format and focus, and this sheet does not rank them. Our articles on whether C)PTC is worth it and earnings discuss value qualitatively, without unsupported salary premiums.
Certification runs on a three-year cycle. Renew with 60 documented CEUs, the applicable renewal purchase and ethics/policy compliance, or pass the current full certification examination instead. For roles that value the credential, see C)PTC jobs.