C)PTC logo
Focused certification exam prep
Start practice

C)PTC Exam Domains 2026: Complete Guide to All 12 Content Areas

TL;DR
  • The 12 domains are headings from Mile2's detailed outline (pages 3-4 of the PDF), not a weighted exam blueprint.
  • Certification has a hands-on part (four of five lab systems plus a report) and online MACS assessments.
  • The written knowledge exam is 100 multiple-choice questions, two hours, 70% required.
  • Module 7 references OWASP Top 10-2017, so the outline is undated and should not be treated as freshly updated for 2026.

How to Read the Mile2 C)PTC Outline

The Certified Penetration Testing Consultant credential, abbreviated C)PTC, is issued by Mile2. Before you plan study time around its content areas, it helps to understand exactly what the "12 domains" are. They are the twelve module headings in the Detailed Outline on pages 3-4 of Mile2's C)PTC course outline PDF, which is linked from the issuer's course outline page. They are unweighted preparation curriculum headings. Mile2 has not published a percentage-by-domain exam blueprint in the sources reviewed for this guide, and the headings should not be read as a guarantee that every possible exam question maps neatly to one of them.

That distinction matters for how you study. Because no weights are published, you cannot responsibly skip a domain on the theory that it is "only worth a few points." Treat all twelve as in scope, then spend extra time where your own background is thinnest. If you are brand new to the credential, the explainer on what C)PTC certification is covers the basics before you dive into the module list below.

Undated outline, not a "2026 syllabus": The outline is undated, and its web application module explicitly references OWASP Top 10-2017. Although this guide is published for 2026 candidates, do not assume the content has been revised to match a newer OWASP list. Always check the current outline on the issuer's site before you finalize your plan.

How the Assessment Is Structured

Mile2 describes the C)PTC certification assessment as two parts, and the domains feed both.

  • Hands-on penetration test: candidates must successfully exploit four of five lab systems, identify flags and deliver a complete written report. A time limit for this practical component was not verified, so be wary of any third-party site quoting a precise practical timer.
  • Online assessments through MACS: Mile2's Assessment and Certification System hosts flag-selection questions plus a knowledge examination of 100 multiple-choice questions. The knowledge exam allows two hours and requires 70%.

The "exam" figures you will see quoted (100 questions, two hours, 70%) refer only to that written knowledge component. They do not describe the practical work, the report, or the flag-selection questions. For the scoring side specifically, see our breakdown of the C)PTC passing score, and for eligibility details see C)PTC requirements.

Mile2 also states that purchasing or completing its training is not mandatory. Suggested preparation is C)PEH and C)PTE or equivalent knowledge, two years of networking experience, sound TCP/IP knowledge and computer-hardware knowledge. The five-day course and its 40 CEUs are training measures, not examination timing.

Domains 1-3: Team, Scanning and Exploitation Process

The first three modules establish how a professional engagement is organized and how a tester moves from discovery to compromise. They are less glamorous than the memory-corruption modules later on, but they shape how you think about every lab system.

Domain 1: Pentesting Team Foundation

This module frames penetration testing as a managed project rather than a solo hobby. Expect concepts around authorized-lab scope, project metrics and team roles.

  • Why written authorization and defined scope come before any scanning
  • How roles within a testing team divide responsibility
  • Which project metrics show progress and quality to a client

Domain 2: NMAP Automation

Scanning is the first evidence-gathering step, and this module is about doing it repeatably and reading the results correctly.

  • Scripting and automating scans so results are reproducible
  • Interpreting NMAP report output: open ports, service versions and host states
  • Turning raw scan data into a prioritized target list for the lab systems

Domain 3: Exploitation Processes

This module covers the disciplined path from a discovered weakness to a working compromise, and what to record along the way.

  • Choosing and validating an exploitation approach against a service you have enumerated
  • Documenting each step so the final report is reproducible
  • Recognizing when an attempt has failed and what that tells you about the target

Because the practical component requires compromising four of five lab systems and identifying flags, the habits you build here (methodical enumeration, note-taking, evidence capture) pay off directly. If you want a candid read on overall difficulty before committing, see how hard the C)PTC exam is.

Domains 4-6: Fuzzing, Privilege Escalation and Windows Overflows

Modules 4 through 6 shift from process to hands-on exploitation technique. They also introduce the memory-level thinking that the later Linux and Windows modules build on.

Domain 4: Fuzzing with Spike

Spike is a fuzzing framework, and this module teaches how to use structured, protocol-aware malformed input to find crashes.

  • Defining a protocol's message structure so fuzz input is meaningful
  • Observing a crash and judging whether it hints at an exploitable condition
  • Connecting a fuzzing result to the buffer overflow work that follows

Domain 5: Privilege Escalation

Gaining a foothold is rarely the end of an engagement. This module reviews how a low-privileged session becomes a high-privileged one.

  • Enumerating the local system for misconfigurations and weak permissions
  • Understanding why an escalation path works, not just how to run it
  • Recording escalation evidence for the report

Domain 6: Stack Based Windows Buffer Overflow

This is the first of the stack-focused modules. It builds the mental model of how a function call lays out the stack and how an overflow can redirect execution.

  • Stack layout, saved return addresses and control of the instruction pointer
  • Working from a fuzzer-induced crash toward controlled execution
  • Why the Windows variant is the baseline for the protection-bypass modules later
Why order matters: Spike (Domain 4) feeds directly into the Windows overflow (Domain 6), and both underpin the protection-bypass modules at the end of the curriculum. Candidates who rush past fuzzing often struggle when SEH and ASLR appear because they never internalized how a crash becomes control.

Domain 7: Web Application Security and Exploitation

Module 7 moves up the stack to web applications. The outline explicitly references OWASP Top 10-2017, so the vulnerability categories you review should be anchored to that list as the outline presents it, even if you also read about newer OWASP editions for general awareness.

Domain 7: Web Application Security and Exploitation

Expect to understand both how web flaws are discovered and how they are exploited and remediated.

  • Injection and authentication weaknesses as framed by the 2017 list
  • Testing a web target methodically rather than firing payloads at random
  • Writing remediation-focused findings that a development team can act on

Do not assume this module is "easy" because it is conceptually familiar. Web exploitation in a lab context still requires careful enumeration and clean evidence capture, which the report needs.

Domains 8-9: Linux Stack Smashing and ASLR

After the Windows baseline, the curriculum turns to Linux memory behavior.

Domain 8: Linux Stack Smashing

This module applies the stack-overflow concepts to Linux binaries, where calling conventions and tooling differ from the Windows examples.

  • Stack structure on Linux and how an overflow alters control flow
  • Differences in process memory layout compared with Windows
  • Reading crash behavior to plan a reliable exploit

Domain 9: Linux Address Space Layout Randomization

ASLR randomizes memory locations to make exploitation less predictable. This module explains the protection and how its effects are handled in a lab setting.

  • What ASLR randomizes and why that frustrates hard-coded addresses
  • How the protection changes the exploitation approach
  • What defenders should configure to keep it effective

These two modules reward comparison. As you study, keep a running note of what is the same and what differs between the Windows and Linux stack behavior; the contrast is a natural source of knowledge-exam questions.

Domains 10-11: Windows Exploit Protection, SEH and ASLR

The last technical stretch of the curriculum deals with Windows mitigations and how the outline addresses working around them in an authorized lab.

Domain 10: Windows Exploit Protection

This module catalogs the defensive features that make straightforward stack overflows harder on Windows.

  • DEP (Data Execution Prevention) and the memory it marks non-executable
  • SafeSEH and SEHOP as protections around structured exception handling
  • ASLR as it applies to Windows processes

Domain 11: Getting Around SEH and ASLR (Windows)

Building on Domain 10, this module examines how structured exception handler mechanics and address randomization affect exploitation.

  • How the SEH chain works and why it is attractive to an attacker
  • Conceptual limits that SafeSEH, SEHOP and ASLR place on an exploit
  • Why a defender who enables all of these layers raises the bar substantially

Treat Domains 10 and 11 as a pair: learn each protection first, then study how they interact. Memorizing the acronyms alone (DEP, SEH, SafeSEH, SEHOP, ASLR) will not be enough; you should be able to explain what each one stops and what it does not.

Domain 12: Penetration Testing Report Writing

The final module is also one of the most consequential for the hands-on part of certification, because the practical requires not just compromising systems and finding flags but delivering a complete written report.

Domain 12: Penetration Testing Report Writing

This module treats the report as the product the client actually receives.

  • Structuring findings so an executive and an engineer can both use them
  • Pairing every finding with evidence and a remediation recommendation
  • Keeping the narrative reproducible, tying back to your Domain 3 documentation habits

Key Takeaway

Write your lab notes as if they were report drafts from day one. Candidates who capture commands, outputs and reasoning while they work spend far less time reconstructing events when the report is due.

The Page 1 vs Detailed Outline Conflict

There is a quirk worth knowing about. The summary on page 1 of Mile2's PDF uses alternative module labels that do not match the detailed outline on pages 3-4. The clearest examples are Module 5, where the summary reads Simple Buffer Overflow while the detailed outline reads Privilege Escalation, and Module 8, where the summary uses Linux Stack Smashing & Scanning while the detailed outline uses a different heading.

ModulePage 1 summary labelDetailed outline label (used in this guide)
Module 5Simple Buffer OverflowPrivilege Escalation
Module 8Linux Stack Smashing & ScanningLinux Stack Smashing

This guide follows the detailed sequence, and the two lists should not be blended into one. Practically, that means you should study both buffer-overflow concepts and privilege escalation regardless of which label a given resource uses, since a mislabeled module is the last thing you want to be surprised by. Verify the current PDF on the issuer's site before building a final study map.

Sequencing the Domains in Your Preparation

One short planning model, tied to the curriculum rather than generic advice: group the domains by dependency, not by number alone. The full method is covered in our C)PTC study guide.

Block 1

Process and scanning (Domains 1-3)

  • Practice authorized-lab scoping and role definition
  • Run and interpret NMAP output until reading it is automatic
  • Start a note template you will reuse for the report
Block 2

Technique foundations (Domains 4-6)

  • Fuzz with Spike before attempting the Windows overflow
  • Study privilege escalation as its own skill
Block 3

Web and Linux memory (Domains 7-9)

  • Review web flaws against the OWASP Top 10-2017 framing
  • Compare Linux stack behavior against your Windows notes
Block 4

Protections and reporting (Domains 10-12)

  • Learn DEP, SafeSEH, SEHOP and ASLR individually, then together
  • Draft a full remediation-focused report from your lab notes

When you are ready to check recall under timed conditions, use the C)PTC practice test site to rehearse multiple-choice questions in the style of the written component, and keep the C)PTC cheat sheet handy for last-minute review. For a view of what passing candidates tend to experience, see the discussion in C)PTC pass rate; note that Mile2 does not publish a verified pass rate in the sources reviewed here, so treat any precise number with caution.

Frequently Asked Questions

Are the 12 domains weighted on the exam?

No weighting has been published in the sources reviewed. The 12 domains are headings from Mile2's detailed outline, which are preparation curriculum headings rather than an official weighted blueprint or a guarantee of exhaustive exam coverage.

How many questions are on the written C)PTC exam?

The knowledge examination is 100 multiple-choice questions with two hours allowed and 70% required. That applies only to the written component, not the hands-on practical, the report or the flag-selection questions.

What does the hands-on portion require?

Mile2's outline describes successful exploitation of four of five lab systems, identification of flags and a complete written report. A practical-assessment time limit was not verified, so check the issuer's current instructions directly.

Do I have to take Mile2 training first?

No. Mile2 states that purchasing or completing its training is not mandatory. Suggested preparation includes C)PEH and C)PTE or equivalent knowledge, two years of networking experience, sound TCP/IP knowledge and computer-hardware knowledge. See C)PTC certification cost for pricing context.

How long does the certification last?

It has a three-year validity cycle. Renewal can be done by documenting 60 CEUs over the cycle with the applicable renewal purchase and ethics/policy compliance, or by passing the current full certification examination. Mile2's FAQ lists USD 200 as the U.S. regional CEU-route renewal fee, which is not the initial examination fee.

Ready to pass your C)PTC exam?

Put this into practice with free C)PTC questions across every exam domain.