C)PTC logo
Focused certification exam prep
Start practice

C)PTC Certification

TL;DR
  • C)PTC is Mile2's Certified Penetration Testing Consultant credential, built around a hands-on lab plus online assessments.
  • The practical requires exploiting four of five lab systems, identifying flags and delivering a complete written report.
  • The knowledge exam is 100 multiple-choice questions, two hours, with a 70% requirement.
  • Mile2 training is optional; suggested background includes C)PTE or C)PEH-level knowledge and two years of networking experience.

What the C)PTC Credential Actually Is

The C)PTC is the Certified Penetration Testing Consultant credential issued by Mile2. It sits at the practitioner-to-lead end of Mile2's penetration testing track, and the word "Consultant" in the title is deliberate. The outline treats penetration testing as a deliverable-producing engagement, not a string of isolated hacks. Candidates are expected to work as part of a team, exploit systems, and then turn the technical work into a report a client can act on.

Because several credentials in the industry abbreviate to similar letters, it helps to be precise. This article covers only Mile2's Certified Penetration Testing Consultant. It is unrelated to transplant-coordinator certification and is a different thing from the Collegiate Penetration Testing Competition. If you are still orienting yourself on terminology, our explainers on what C)PTC certification is and what C)PTC stands for cover the naming question in more depth.

A note on sources: Everything here is drawn from Mile2's currently linked, undated course outline and related policy pages, checked October 2, 2026. Because the outline is undated, treat it as the current published scope, not as a freshly revised 2026 syllabus. Always confirm details on Mile2's own pages before you buy or schedule anything.

How the Two-Part Assessment Works

This is the part of the C)PTC that most distinguishes it from a pure multiple-choice certification. According to the issuer's outline, the assessment has two parts.

Part one: the hands-on penetration test

Candidates must complete a practical penetration test in which they successfully exploit four of five lab systems, identify flags, and produce a complete written report. Three separate skills are being tested at once: technical exploitation, evidence collection (the flags), and professional communication (the report). A candidate who is strong on the first and weak on the third is not going to clear this stage cleanly.

Part two: online assessments through MACS

The second part runs through Mile2's Assessment and Certification System, known as MACS. It comprises flag-selection questions and a 100-question multiple-choice knowledge examination. The knowledge exam allows two hours and requires 70% to pass.

Be careful with the numbers: The two-hour limit and the 70% requirement belong to the written knowledge exam only. They do not describe the practical work, the report, or the flag-selection assessment. A time limit for the practical was not verified in the sources, so any third-party timer you see quoted for the lab should be treated with skepticism. For the written component specifically, see our breakdown of the C)PTC passing score.

Proctoring and open-book language

Mile2's general Policies and Procedures document (dated May 26, 2026) describes open-book examinations but also uses broad proctoring language. The current FAQ, meanwhile, describes most standard exams as on-demand without a live proctor. Those two descriptions do not line up neatly, so the safest approach is to read the instructions attached to your exact C)PTC assessment when you register, instead of assuming that every component is unproctored or that every component is open-book.

The Twelve Curriculum Headings, Grouped by Skill

Mile2's detailed outline, on pages 3-4 of the Certified Penetration Testing Consultant PDF, lists twelve headings. These are unweighted preparation headings, not an official twelve-domain exam count, and Mile2 does not publish a weighted blueprint in the sources reviewed. That means you cannot assume equal or proportional question coverage, and you should not assume the list is exhaustive of everything that could appear. Here are the twelve, in the detailed outline's order:

  1. Pentesting Team Foundation
  2. NMAP Automation
  3. Exploitation Processes
  4. Fuzzing with Spike
  5. Privilege Escalation
  6. Stack Based Windows Buffer Overflow
  7. Web Application Security and Exploitation
  8. Linux Stack Smashing
  9. Linux Address Space Layout Randomization
  10. Windows Exploit Protection
  11. Getting Around SEH and ASLR (Windows)
  12. Penetration Testing Report Writing
A known source conflict: The summary on page 1 of the same PDF uses alternative labels. Notably, it calls Module 5 "Simple Buffer Overflow" instead of Privilege Escalation, and it labels Module 8 as "Linux Stack Smashing & Scanning." The detailed outline controls, and the two lists should not be blended. If you build a study plan from the page-1 summary, you may misjudge what Module 5 covers. For a fuller treatment of each heading, see our complete guide to the C)PTC exam domains.

A useful way to digest twelve headings is to group them by the kind of thinking they demand: process and communication (headings 1 and 12), reconnaissance and exploitation workflow (2, 3, 5), memory-corruption mechanics on two platforms (4, 6, 8, 9, 10, 11), and web exploitation (7). The sections below follow that grouping.

Team Foundations and Report Writing

These two headings bookend the outline, and they are the ones candidates most often underinvest in because they feel less technical. That is a mistake for a credential with "Consultant" in its name and a graded written report in its practical.

Pentesting Team Foundation

Expect this area to frame how an authorized engagement is organized before any tool is run. Build your own mental model around:

  • Authorized-lab concepts: scope, rules of engagement and written permission as the boundary between testing and an offense
  • Project metrics: how an engagement's progress and coverage can be tracked and communicated
  • Team roles: who leads, who executes, who documents, and how findings are handed between them

Penetration Testing Report Writing

The report is a graded artifact in the practical, not an afterthought. Practice writing findings so that a non-technical reader can understand impact and a technical reader can reproduce the issue.

  • Pair every finding with evidence such as command output, screenshots and the flag you captured
  • Write remediation-focused recommendations, not only descriptions of what you broke
  • Separate executive-level summary from technical detail

One practical habit: keep running notes during every lab session, with timestamps, targets and commands. Candidates who reconstruct their steps from memory at the end tend to produce thin reports, and thin reports undermine otherwise successful exploitation.

NMAP Automation, Exploitation and Privilege Escalation

This cluster covers the working loop of a penetration test: discover, exploit, elevate. The practical's "four of five systems" requirement means you need a repeatable workflow and not heroic one-off successes.

NMAP Automation

The emphasis is on automating scans and, just as importantly, interpreting what comes back. Practice reading NMAP output and deciding what it implies for next steps.

  • Translate open ports and service banners into a prioritized target list
  • Distinguish filtered, closed and open states and understand what each suggests
  • Script repeatable scan runs so results are consistent and documentable

Exploitation Processes

Review exploitation as a disciplined process: confirm the vulnerability, select an approach, execute in the authorized lab, and capture evidence. Understand why an exploit works, not just which tool launches it, because the knowledge exam can probe concepts that tool familiarity alone will not cover.

Privilege Escalation

Detailed-outline Module 5 is Privilege Escalation, which is exactly the area where the page-1 summary's alternative "Simple Buffer Overflow" label can mislead. Study the moving from low-privilege access to higher control on both Windows and Linux hosts, including misconfigurations, weak permissions and local weaknesses.

Fuzzing and Memory Corruption Topics

Six of the twelve headings live here, which makes this the densest part of the outline. It is also where candidates without prior exploit-development exposure feel the steepest climb. For a sense of that climb, read how hard the C)PTC exam is.

Fuzzing with Spike

Spike is a fuzzing framework used to send malformed or unexpected input to a service to provoke crashes that may point to exploitable flaws. Concepts to own: how a protocol is described to the fuzzer, how crashes are observed, and how a crash is narrowed toward a controllable condition.

Stack Based Windows Buffer Overflow and Linux Stack Smashing

These two headings mirror each other across platforms. Know how the stack is laid out, how an overflow can overwrite control data such as a return address, and how an attacker-controlled value can redirect execution. Be ready to compare how the same conceptual bug looks on Windows versus Linux.

Mitigations: ASLR, DEP, SEH, SafeSEH and SEHOP

The outline then moves to defenses and the techniques that interact with them. The relevant headings are Linux Address Space Layout Randomization, Windows Exploit Protection, and Getting Around SEH and ASLR (Windows). Build a comparison for yourself:

ConceptWhat to be able to explain
ASLRRandomization of memory layout and why it frustrates fixed-address assumptions, on both Linux and Windows
DEPMarking memory non-executable and how that changes where payloads can run
SEHWindows structured exception handling and why its structures are a point of interest to an exploit author
SafeSEHA protection that validates exception handlers and what it does and does not cover
SEHOPException-chain validation intended to detect tampered handler chains

Key Takeaway

Do not memorize these protections as a glossary. For each one, be able to state what it blocks, what it leaves exposed, and what a defender would change in configuration or code to close the gap. That remediation framing carries straight into the reporting heading.

Web Application Security Under the 2017 Lens

The Web Application Security and Exploitation heading explicitly references the OWASP Top 10-2017 in the issuer's outline. That detail matters for two reasons. First, it tells you the outline's web material is anchored to that edition's categories, so study those categories as presented there. Second, it reinforces that the undated outline should not be described as a newly updated 2026 syllabus.

Practical advice: learn each category in terms of how a flaw is found, how it is exploited in an authorized lab, and how it is fixed. Supplement with current web security knowledge for real-world work, but remember that exam-relevant framing comes from the outline's reference, not from whichever list is newest.

Sequencing Your Preparation

Generic study advice matters less here than ordering, because the memory-corruption headings build on one another. A sensible sequence respects those dependencies. For broader planning resources, our C)PTC study guide and one-page cheat sheet are good companions.

Week 1

Process and scanning

  • Team foundations, scope and roles
  • NMAP automation and output interpretation
Week 2

Exploitation and escalation

  • Exploitation processes in an authorized lab
  • Privilege escalation on Windows and Linux hosts
Weeks 3-4

Memory corruption foundations

  • Fuzzing with Spike
  • Windows stack overflow, then Linux stack smashing
Week 5

Mitigations and bypass concepts

  • Linux ASLR, Windows exploit protection
  • SEH, SafeSEH, SEHOP and getting around SEH and ASLR
Week 6

Web and reporting

  • Web application topics through the 2017 lens
  • Write a full practice report, then take timed multiple-choice sets

Why this order: scanning and exploitation give you the workflow the practical rewards, while the stack and mitigation topics are cumulative and benefit from being studied back to back. Reporting is scheduled last but should be practiced earlier too; treat Week 6 as the consolidation point, not the first time you write anything up.

To test your recall on the written side, use the question sets on our main practice test site. They are meant to build familiarity with question style and concepts, not to reproduce actual exam content.

Prerequisites, Fees and the Combo Package

Do you need the training?

No. Purchasing or completing Mile2 training is not mandatory. Mile2 does suggest a background: C)PEH and C)PTE or equivalent knowledge, two years of networking experience, sound TCP/IP knowledge and computer-hardware knowledge. Note that these are suggestions for preparation, so confirm current enrollment terms on Mile2's pages. Our C)PTC requirements guide goes deeper, and the C)PTC training overview covers the course side.

Course numbers are not exam numbers: The five-day course and its 40 CEUs are training measures. They describe the classroom offering, not the length of any examination. Do not confuse them with the two-hour knowledge exam.

The Exam Combo

Mile2's Exam Combo includes an exam-preparation guide, practice questions or a simulator, and two exam attempts. The current initial package price could not be independently confirmed from the retrievable issuer listing, so this article does not quote a figure; older promotional numbers you may find elsewhere should not be treated as current. Check Mile2's Exam Combo page directly, and see our certification cost breakdown for how to think about the total outlay.

Validity and Renewal

C)PTC operates on a three-year validity cycle. There are two documented ways to renew:

  • CEU route: 60 documented CEUs over the cycle, the applicable renewal purchase, and compliance with ethics and policy requirements.
  • Exam route: passing the current full certification examination.

Mile2's FAQ lists USD 200 as the U.S. regional fee for the CEU route. That is a renewal fee, not the initial examination fee, so do not read it as the cost of getting certified in the first place. The FAQ also states that annual membership is not required. Since fees and regional variations can change, verify against the Certification Renewal Program and Renewal Paths pages before planning.

Where It Sits Among Related Credentials

Candidates often ask how the C)PTC compares with adjacent certifications. Without importing facts about other credentials, a few structural observations hold true of the C)PTC itself.

ComparisonWhat to weigh
C)PTC vs C)PTEMile2 suggests C)PTE-level knowledge as preparation for C)PTC, which positions C)PTC as the further step along the same track.
C)PTC vs OSCPBoth involve hands-on work. Compare their formats, proctoring, time limits and fees directly on each issuer's current pages; this article does not assert details about the other credential.

For a more decision-oriented view, our analysis of whether the C)PTC is worth it walks through the trade-offs, and the salary guide and jobs overview discuss who hires for penetration testing skills. Salary outcomes vary widely by region, employer and experience, so no premium is claimed here.

Frequently Asked Questions

What format does the C)PTC assessment use?

Per Mile2's outline, it has two parts: a hands-on penetration test requiring successful exploitation of four of five lab systems, flag identification and a complete written report, plus online assessments through MACS that include flag-selection questions and a 100-question multiple-choice knowledge exam.

How long is the written exam and what score is needed?

The 100-question multiple-choice knowledge examination allows two hours and requires 70%. These figures apply only to the written component, not to the practical, the report or the flag-selection assessment.

Is Mile2 training required before I can certify?

No. Purchasing or completing Mile2 training is not mandatory. Suggested preparation includes C)PTE and C)PEH or equivalent knowledge, two years of networking experience, and sound TCP/IP and hardware knowledge.

How do I keep the certification current?

It has a three-year validity cycle. You can renew with 60 documented CEUs plus the applicable renewal purchase and ethics compliance, or by passing the current full certification exam. The FAQ lists USD 200 as the U.S. regional CEU-route renewal fee.

Are the twelve domains weighted on the exam?

The twelve headings come from Mile2's detailed outline and are unweighted preparation headings. They are not an official weighted blueprint or a guarantee of exhaustive coverage, so study all of them rather than guessing at emphasis.

Ready to pass your C)PTC exam?

Put this into practice with free C)PTC questions across every exam domain.