C)PTC logo
Focused certification exam prep
Start practice

C)PTC Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • C)PTC here means Mile2's Certified Penetration Testing Consultant, not any other credential sharing the acronym.
  • The knowledge exam is 100 multiple-choice questions, two hours, 70% required.
  • The hands-on part requires exploiting four of five lab systems, identifying flags and submitting a complete written report.
  • The 12 domain lines are unweighted curriculum headings from Mile2's detailed outline, not an official blueprint.

Identity Check: Which C)PTC This Sheet Covers

This cheat sheet covers Certified Penetration Testing Consultant (C)PTC), a credential issued by Mile2. Several unrelated credentials and competitions abbreviate to similar letters, including a transplant-coordinator certification and the Collegiate Penetration Testing Competition. None of their facts apply here. If a fee, date, or pass mark you find online does not trace back to Mile2's own materials for this certification, discard it.

Everything below draws on Mile2's currently linked, undated course outline. Issuer sources were checked on October 2, 2026. If you are still deciding whether this is the right credential, start with our explainers on what C)PTC certification is and what C)PTC stands for, then return to this page for the quick-reference facts.

The Two-Part Assessment at a Glance

The most common mistake on this credential is treating it as a single multiple-choice test. Mile2's outline describes a two-part certification assessment, and each part tests something different.

PartWhat It InvolvesVerified Detail
Part 1: Hands-on penetration testExploit lab systems, identify flags, write a complete reportSuccessful exploitation of four of five lab systems required
Part 2a: Flag-selection questionsOnline, delivered through Mile2's Assessment and Certification System (MACS)Separate from the knowledge exam
Part 2b: Knowledge examinationOnline through MACS100 multiple-choice questions, two hours, 70% to pass
Practical time limit: A time limit for the hands-on practical was not verified in the issuer sources. Do not trust third-party timers or forum claims about how long you get. Confirm the practical's schedule and rules directly in your Mile2 assessment instructions.

For a deeper look at difficulty across both parts, see How Hard Is the C)PTC Exam?

Written Exam Facts

When people say "the exam" in connection with C)PTC, the issuer's Exam line refers only to the written knowledge component. Memorize these numbers:

  • Questions: 100 multiple-choice
  • Time allowed: two hours
  • Passing requirement: 70%
  • Delivery: online, through MACS

That 70% applies to the knowledge examination, not to the practical lab work or the report, which are judged on their own requirements. For a closer look at how scoring works, read the C)PTC passing score breakdown.

Proctoring and open-book caution: Mile2's general Policies and Procedures (dated May 26, 2026) describes open-book examinations but uses broad proctoring language, while the current FAQ describes most standard exams as on-demand without a live proctor. These two descriptions differ. Follow the instructions assigned to your exact C)PTC assessment rather than assuming every component is unproctored.

The 12 Curriculum Headings in One Pass

The twelve lines below reproduce the Detailed Outline on pages 3-4 of Mile2's Certified Penetration Testing Consultant PDF. They are unweighted preparation headings. They are not an official 12-domain exam count, a weighted blueprint, or a guarantee of exhaustive exam coverage. For a longer treatment of each one, see the complete guide to all 12 content areas.

#HeadingOne-Line Memory Hook
1Pentesting Team FoundationRoles, project metrics, authorized-lab discipline
2NMAP AutomationScan, read, and interpret reports at scale
3Exploitation ProcessesFrom finding to controlled compromise
4Fuzzing with SpikeMalformed input to expose crashes
5Privilege EscalationLow-privilege foothold to higher access
6Stack Based Windows Buffer OverflowWindows stack memory fundamentals
7Web Application Security and ExploitationReferences OWASP Top 10-2017
8Linux Stack SmashingThe Linux counterpart to Domain 6
9Linux Address Space Layout RandomizationASLR on Linux
10Windows Exploit ProtectionDefensive mitigations on Windows
11Getting Around SEH and ASLR (Windows)Bypass thinking for protected Windows targets
12Penetration Testing Report WritingRemediation-focused deliverables

Exploit Development Concepts to Memorize

The back half of the outline is where candidates with only scanning experience struggle. Keep these concept pairs straight.

Stack Overflow Fundamentals (Domains 6 and 8)

Know why overflowing a stack buffer can redirect execution, and how the Windows and Linux variants differ in practice.

  • Distinguish Windows stack-based overflow concepts from Linux stack smashing concepts
  • Understand how a fuzzing crash becomes an analyzable memory-corruption finding
  • Keep all exploitation practice inside authorized lab environments

Mitigations and Their Bypass Concepts (Domains 9, 10 and 11)

Pair each protection with what it is meant to stop.

  • ASLR: randomizes address layout, covered on Linux in Domain 9
  • DEP: marks memory non-executable so injected data cannot simply run
  • SEH: Windows structured exception handling, a classic target in overflow work
  • SafeSEH and SEHOP: protections that validate or protect the exception-handler chain
  • Domain 11 asks you to reason about getting around SEH and ASLR together on Windows

Fuzzing with Spike (Domain 4)

Understand fuzzing as a discovery technique: send structured but malformed input to a service and watch for abnormal behavior that signals a memory-handling flaw. Be able to describe the workflow conceptually, from identifying an input surface to confirming a crash worth investigating.

Recon, Team Workflow and Reporting Reminders

Team Foundation and NMAP (Domains 1 and 2)

Domain 1 treats a penetration test as a managed project, so expect concepts around team roles, project metrics and keeping testing within authorized scope. Domain 2 centers on automating NMAP and, importantly, interpreting its output. Practice reading scan reports and deciding what each open port, service banner and version string means for next steps, rather than only running scans.

Exploitation, Escalation and Web (Domains 3, 5 and 7)

Domain 3 frames exploitation as a process, and Domain 5 covers privilege escalation as the follow-on step after initial access. Domain 7 covers web application security and exploitation, and the outline explicitly references OWASP Top 10-2017. That reference matters: it signals the web material is tied to that older list, so do not assume the course has been rebuilt around a newer one.

Report Writing (Domain 12)

Because the practical requires a complete written report, Domain 12 is not an afterthought. A strong report is remediation-focused: it explains what was found, why it matters, and how the client fixes it, not just how you got in. Practice writing findings that a technical owner could act on without contacting you.

Key Takeaway

Treat the report as graded work, not paperwork. Four exploited systems and identified flags are only part of the hands-on requirement; the complete written report is the other part.

Source Conflicts and Caveats to Remember

Mile2's own documents do not perfectly agree, and a good cheat sheet records that instead of hiding it.

  • Module labels differ. The page 1 summary uses alternative labels, notably "Simple Buffer Overflow" for Module 5 where the detailed outline says "Privilege Escalation," and a different title for Module 8 than the detailed "Linux Stack Smashing" heading. The detailed sequence controls, and the two lists should not be blended.
  • The outline is undated. Do not treat it as a newly updated 2026 syllabus. The OWASP 2017 reference is a reminder of that.
  • Course measures are not exam timing. The five-day course and its 40 CEUs describe training, not how long you have to test.
  • The 12 headings are not weighted. Do not allocate study time by assumed percentages, because none are published for these headings.

Prerequisites, Fees and Renewal

Preparation Expectations

Purchasing or completing Mile2 training is not mandatory. Suggested preparation includes C)PEH and C)PTE or equivalent knowledge, two years of networking experience, sound TCP/IP knowledge and computer-hardware knowledge. See C)PTC requirements and eligibility for the full picture, and C)PTC training if you are weighing a course.

The Exam Combo and Fees

The Exam Combo includes an exam-preparation guide, practice questions or a simulator, and two exam attempts. The current initial package price could not be independently confirmed from the retrievable issuer listing, so no initial exam fee is stated here. Check Mile2's current Exam Combo page before budgeting, and see C)PTC certification cost for how to think through the pricing.

Renewal Cycle

ItemDetail
ValidityThree-year cycle
CEU route60 documented CEUs over the cycle, the applicable renewal purchase, and ethics/policy compliance
Alternative routePass the current full certification examination
U.S. regional CEU-route renewal feeUSD 200 (a renewal fee, not the initial exam fee)
Annual membershipNot required, per Mile2's FAQ
Do not confuse the two fees: The USD 200 figure applies to CEU-route renewal in the U.S. regional listing. It is not what you pay to sit the initial assessment.

Which Heading to Schedule When

If you have time to build a plan, sequence it by dependency rather than by the order you happen to enjoy. A reasonable arrangement, built around how these topics rely on each other:

Week 1

Foundations and Recon

  • Domain 1 team and project concepts
  • Domain 2 NMAP report interpretation
Week 2

Exploitation Flow

  • Domains 3 and 5 in sequence, so escalation follows initial access
  • Domain 7 with the OWASP Top 10-2017 reference in mind
Weeks 3-4

Memory Corruption and Mitigations

  • Domain 4 fuzzing, then Domains 6 and 8 stack concepts
  • Domains 9, 10 and 11, since bypass thinking only makes sense after you know what each mitigation does
Final week

Report and Review

  • Domain 12 report drafting from your own lab notes
  • Timed run-throughs on the practice test site for the knowledge exam format

Place the memory-corruption block in the middle rather than last, because it demands the most repetition. For a fuller method, see the C)PTC study guide.

Frequently Asked Questions

How many questions are on the C)PTC knowledge exam?

The knowledge examination has 100 multiple-choice questions, with two hours allowed and 70% required. That figure covers only the written component, not the hands-on practical or the flag-selection questions.

What does the hands-on part require?

Per Mile2's outline, you must successfully exploit four of five lab systems, identify flags and deliver a complete written report. A time limit for the practical was not verified, so confirm it in your assessment instructions.

Is Mile2 training required before I can certify?

No. Purchasing or completing Mile2 training is not mandatory. Mile2 suggests prior knowledge such as C)PEH and C)PTE or equivalent, plus two years of networking experience and solid TCP/IP understanding.

How does C)PTC compare with other penetration-testing credentials?

Comparisons depend on format and focus, and this sheet does not rank them. Our articles on whether C)PTC is worth it and earnings discuss value qualitatively, without unsupported salary premiums.

How do I keep the certification active?

Certification runs on a three-year cycle. Renew with 60 documented CEUs, the applicable renewal purchase and ethics/policy compliance, or pass the current full certification examination instead. For roles that value the credential, see C)PTC jobs.

Ready to pass your C)PTC exam?

Put this into practice with free C)PTC questions across every exam domain.