- How to Read the Mile2 C)PTC Outline
- How the Assessment Is Structured
- Domains 1-3: Team, Scanning and Exploitation Process
- Domains 4-6: Fuzzing, Privilege Escalation and Windows Overflows
- Domain 7: Web Application Security and Exploitation
- Domains 8-9: Linux Stack Smashing and ASLR
- Domains 10-11: Windows Exploit Protection, SEH and ASLR
- Domain 12: Penetration Testing Report Writing
- The Page 1 vs Detailed Outline Conflict
- Sequencing the Domains in Your Preparation
- Frequently Asked Questions
- The 12 domains are headings from Mile2's detailed outline (pages 3-4 of the PDF), not a weighted exam blueprint.
- Certification has a hands-on part (four of five lab systems plus a report) and online MACS assessments.
- The written knowledge exam is 100 multiple-choice questions, two hours, 70% required.
- Module 7 references OWASP Top 10-2017, so the outline is undated and should not be treated as freshly updated for 2026.
How to Read the Mile2 C)PTC Outline
The Certified Penetration Testing Consultant credential, abbreviated C)PTC, is issued by Mile2. Before you plan study time around its content areas, it helps to understand exactly what the "12 domains" are. They are the twelve module headings in the Detailed Outline on pages 3-4 of Mile2's C)PTC course outline PDF, which is linked from the issuer's course outline page. They are unweighted preparation curriculum headings. Mile2 has not published a percentage-by-domain exam blueprint in the sources reviewed for this guide, and the headings should not be read as a guarantee that every possible exam question maps neatly to one of them.
That distinction matters for how you study. Because no weights are published, you cannot responsibly skip a domain on the theory that it is "only worth a few points." Treat all twelve as in scope, then spend extra time where your own background is thinnest. If you are brand new to the credential, the explainer on what C)PTC certification is covers the basics before you dive into the module list below.
How the Assessment Is Structured
Mile2 describes the C)PTC certification assessment as two parts, and the domains feed both.
- Hands-on penetration test: candidates must successfully exploit four of five lab systems, identify flags and deliver a complete written report. A time limit for this practical component was not verified, so be wary of any third-party site quoting a precise practical timer.
- Online assessments through MACS: Mile2's Assessment and Certification System hosts flag-selection questions plus a knowledge examination of 100 multiple-choice questions. The knowledge exam allows two hours and requires 70%.
The "exam" figures you will see quoted (100 questions, two hours, 70%) refer only to that written knowledge component. They do not describe the practical work, the report, or the flag-selection questions. For the scoring side specifically, see our breakdown of the C)PTC passing score, and for eligibility details see C)PTC requirements.
Mile2 also states that purchasing or completing its training is not mandatory. Suggested preparation is C)PEH and C)PTE or equivalent knowledge, two years of networking experience, sound TCP/IP knowledge and computer-hardware knowledge. The five-day course and its 40 CEUs are training measures, not examination timing.
Domains 1-3: Team, Scanning and Exploitation Process
The first three modules establish how a professional engagement is organized and how a tester moves from discovery to compromise. They are less glamorous than the memory-corruption modules later on, but they shape how you think about every lab system.
Domain 1: Pentesting Team Foundation
This module frames penetration testing as a managed project rather than a solo hobby. Expect concepts around authorized-lab scope, project metrics and team roles.
- Why written authorization and defined scope come before any scanning
- How roles within a testing team divide responsibility
- Which project metrics show progress and quality to a client
Domain 2: NMAP Automation
Scanning is the first evidence-gathering step, and this module is about doing it repeatably and reading the results correctly.
- Scripting and automating scans so results are reproducible
- Interpreting NMAP report output: open ports, service versions and host states
- Turning raw scan data into a prioritized target list for the lab systems
Domain 3: Exploitation Processes
This module covers the disciplined path from a discovered weakness to a working compromise, and what to record along the way.
- Choosing and validating an exploitation approach against a service you have enumerated
- Documenting each step so the final report is reproducible
- Recognizing when an attempt has failed and what that tells you about the target
Because the practical component requires compromising four of five lab systems and identifying flags, the habits you build here (methodical enumeration, note-taking, evidence capture) pay off directly. If you want a candid read on overall difficulty before committing, see how hard the C)PTC exam is.
Domains 4-6: Fuzzing, Privilege Escalation and Windows Overflows
Modules 4 through 6 shift from process to hands-on exploitation technique. They also introduce the memory-level thinking that the later Linux and Windows modules build on.
Domain 4: Fuzzing with Spike
Spike is a fuzzing framework, and this module teaches how to use structured, protocol-aware malformed input to find crashes.
- Defining a protocol's message structure so fuzz input is meaningful
- Observing a crash and judging whether it hints at an exploitable condition
- Connecting a fuzzing result to the buffer overflow work that follows
Domain 5: Privilege Escalation
Gaining a foothold is rarely the end of an engagement. This module reviews how a low-privileged session becomes a high-privileged one.
- Enumerating the local system for misconfigurations and weak permissions
- Understanding why an escalation path works, not just how to run it
- Recording escalation evidence for the report
Domain 6: Stack Based Windows Buffer Overflow
This is the first of the stack-focused modules. It builds the mental model of how a function call lays out the stack and how an overflow can redirect execution.
- Stack layout, saved return addresses and control of the instruction pointer
- Working from a fuzzer-induced crash toward controlled execution
- Why the Windows variant is the baseline for the protection-bypass modules later
Domain 7: Web Application Security and Exploitation
Module 7 moves up the stack to web applications. The outline explicitly references OWASP Top 10-2017, so the vulnerability categories you review should be anchored to that list as the outline presents it, even if you also read about newer OWASP editions for general awareness.
Domain 7: Web Application Security and Exploitation
Expect to understand both how web flaws are discovered and how they are exploited and remediated.
- Injection and authentication weaknesses as framed by the 2017 list
- Testing a web target methodically rather than firing payloads at random
- Writing remediation-focused findings that a development team can act on
Do not assume this module is "easy" because it is conceptually familiar. Web exploitation in a lab context still requires careful enumeration and clean evidence capture, which the report needs.
Domains 8-9: Linux Stack Smashing and ASLR
After the Windows baseline, the curriculum turns to Linux memory behavior.
Domain 8: Linux Stack Smashing
This module applies the stack-overflow concepts to Linux binaries, where calling conventions and tooling differ from the Windows examples.
- Stack structure on Linux and how an overflow alters control flow
- Differences in process memory layout compared with Windows
- Reading crash behavior to plan a reliable exploit
Domain 9: Linux Address Space Layout Randomization
ASLR randomizes memory locations to make exploitation less predictable. This module explains the protection and how its effects are handled in a lab setting.
- What ASLR randomizes and why that frustrates hard-coded addresses
- How the protection changes the exploitation approach
- What defenders should configure to keep it effective
These two modules reward comparison. As you study, keep a running note of what is the same and what differs between the Windows and Linux stack behavior; the contrast is a natural source of knowledge-exam questions.
Domains 10-11: Windows Exploit Protection, SEH and ASLR
The last technical stretch of the curriculum deals with Windows mitigations and how the outline addresses working around them in an authorized lab.
Domain 10: Windows Exploit Protection
This module catalogs the defensive features that make straightforward stack overflows harder on Windows.
- DEP (Data Execution Prevention) and the memory it marks non-executable
- SafeSEH and SEHOP as protections around structured exception handling
- ASLR as it applies to Windows processes
Domain 11: Getting Around SEH and ASLR (Windows)
Building on Domain 10, this module examines how structured exception handler mechanics and address randomization affect exploitation.
- How the SEH chain works and why it is attractive to an attacker
- Conceptual limits that SafeSEH, SEHOP and ASLR place on an exploit
- Why a defender who enables all of these layers raises the bar substantially
Treat Domains 10 and 11 as a pair: learn each protection first, then study how they interact. Memorizing the acronyms alone (DEP, SEH, SafeSEH, SEHOP, ASLR) will not be enough; you should be able to explain what each one stops and what it does not.
Domain 12: Penetration Testing Report Writing
The final module is also one of the most consequential for the hands-on part of certification, because the practical requires not just compromising systems and finding flags but delivering a complete written report.
Domain 12: Penetration Testing Report Writing
This module treats the report as the product the client actually receives.
- Structuring findings so an executive and an engineer can both use them
- Pairing every finding with evidence and a remediation recommendation
- Keeping the narrative reproducible, tying back to your Domain 3 documentation habits
Key Takeaway
Write your lab notes as if they were report drafts from day one. Candidates who capture commands, outputs and reasoning while they work spend far less time reconstructing events when the report is due.
The Page 1 vs Detailed Outline Conflict
There is a quirk worth knowing about. The summary on page 1 of Mile2's PDF uses alternative module labels that do not match the detailed outline on pages 3-4. The clearest examples are Module 5, where the summary reads Simple Buffer Overflow while the detailed outline reads Privilege Escalation, and Module 8, where the summary uses Linux Stack Smashing & Scanning while the detailed outline uses a different heading.
| Module | Page 1 summary label | Detailed outline label (used in this guide) |
|---|---|---|
| Module 5 | Simple Buffer Overflow | Privilege Escalation |
| Module 8 | Linux Stack Smashing & Scanning | Linux Stack Smashing |
This guide follows the detailed sequence, and the two lists should not be blended into one. Practically, that means you should study both buffer-overflow concepts and privilege escalation regardless of which label a given resource uses, since a mislabeled module is the last thing you want to be surprised by. Verify the current PDF on the issuer's site before building a final study map.
Sequencing the Domains in Your Preparation
One short planning model, tied to the curriculum rather than generic advice: group the domains by dependency, not by number alone. The full method is covered in our C)PTC study guide.
Process and scanning (Domains 1-3)
- Practice authorized-lab scoping and role definition
- Run and interpret NMAP output until reading it is automatic
- Start a note template you will reuse for the report
Technique foundations (Domains 4-6)
- Fuzz with Spike before attempting the Windows overflow
- Study privilege escalation as its own skill
Web and Linux memory (Domains 7-9)
- Review web flaws against the OWASP Top 10-2017 framing
- Compare Linux stack behavior against your Windows notes
Protections and reporting (Domains 10-12)
- Learn DEP, SafeSEH, SEHOP and ASLR individually, then together
- Draft a full remediation-focused report from your lab notes
When you are ready to check recall under timed conditions, use the C)PTC practice test site to rehearse multiple-choice questions in the style of the written component, and keep the C)PTC cheat sheet handy for last-minute review. For a view of what passing candidates tend to experience, see the discussion in C)PTC pass rate; note that Mile2 does not publish a verified pass rate in the sources reviewed here, so treat any precise number with caution.
Frequently Asked Questions
No weighting has been published in the sources reviewed. The 12 domains are headings from Mile2's detailed outline, which are preparation curriculum headings rather than an official weighted blueprint or a guarantee of exhaustive exam coverage.
The knowledge examination is 100 multiple-choice questions with two hours allowed and 70% required. That applies only to the written component, not the hands-on practical, the report or the flag-selection questions.
Mile2's outline describes successful exploitation of four of five lab systems, identification of flags and a complete written report. A practical-assessment time limit was not verified, so check the issuer's current instructions directly.
No. Mile2 states that purchasing or completing its training is not mandatory. Suggested preparation includes C)PEH and C)PTE or equivalent knowledge, two years of networking experience, sound TCP/IP knowledge and computer-hardware knowledge. See C)PTC certification cost for pricing context.
It has a three-year validity cycle. Renewal can be done by documenting 60 CEUs over the cycle with the applicable renewal purchase and ethics/policy compliance, or by passing the current full certification examination. Mile2's FAQ lists USD 200 as the U.S. regional CEU-route renewal fee, which is not the initial examination fee.