- What the C)PTC Credential Actually Is
- How the Two-Part Assessment Works
- The Twelve Curriculum Headings, Grouped by Skill
- Team Foundations and Report Writing
- NMAP Automation, Exploitation and Privilege Escalation
- Fuzzing and Memory Corruption Topics
- Web Application Security Under the 2017 Lens
- Sequencing Your Preparation
- Prerequisites, Fees and the Combo Package
- Validity and Renewal
- Where It Sits Among Related Credentials
- Frequently Asked Questions
- C)PTC is Mile2's Certified Penetration Testing Consultant credential, built around a hands-on lab plus online assessments.
- The practical requires exploiting four of five lab systems, identifying flags and delivering a complete written report.
- The knowledge exam is 100 multiple-choice questions, two hours, with a 70% requirement.
- Mile2 training is optional; suggested background includes C)PTE or C)PEH-level knowledge and two years of networking experience.
What the C)PTC Credential Actually Is
The C)PTC is the Certified Penetration Testing Consultant credential issued by Mile2. It sits at the practitioner-to-lead end of Mile2's penetration testing track, and the word "Consultant" in the title is deliberate. The outline treats penetration testing as a deliverable-producing engagement, not a string of isolated hacks. Candidates are expected to work as part of a team, exploit systems, and then turn the technical work into a report a client can act on.
Because several credentials in the industry abbreviate to similar letters, it helps to be precise. This article covers only Mile2's Certified Penetration Testing Consultant. It is unrelated to transplant-coordinator certification and is a different thing from the Collegiate Penetration Testing Competition. If you are still orienting yourself on terminology, our explainers on what C)PTC certification is and what C)PTC stands for cover the naming question in more depth.
How the Two-Part Assessment Works
This is the part of the C)PTC that most distinguishes it from a pure multiple-choice certification. According to the issuer's outline, the assessment has two parts.
Part one: the hands-on penetration test
Candidates must complete a practical penetration test in which they successfully exploit four of five lab systems, identify flags, and produce a complete written report. Three separate skills are being tested at once: technical exploitation, evidence collection (the flags), and professional communication (the report). A candidate who is strong on the first and weak on the third is not going to clear this stage cleanly.
Part two: online assessments through MACS
The second part runs through Mile2's Assessment and Certification System, known as MACS. It comprises flag-selection questions and a 100-question multiple-choice knowledge examination. The knowledge exam allows two hours and requires 70% to pass.
Proctoring and open-book language
Mile2's general Policies and Procedures document (dated May 26, 2026) describes open-book examinations but also uses broad proctoring language. The current FAQ, meanwhile, describes most standard exams as on-demand without a live proctor. Those two descriptions do not line up neatly, so the safest approach is to read the instructions attached to your exact C)PTC assessment when you register, instead of assuming that every component is unproctored or that every component is open-book.
The Twelve Curriculum Headings, Grouped by Skill
Mile2's detailed outline, on pages 3-4 of the Certified Penetration Testing Consultant PDF, lists twelve headings. These are unweighted preparation headings, not an official twelve-domain exam count, and Mile2 does not publish a weighted blueprint in the sources reviewed. That means you cannot assume equal or proportional question coverage, and you should not assume the list is exhaustive of everything that could appear. Here are the twelve, in the detailed outline's order:
- Pentesting Team Foundation
- NMAP Automation
- Exploitation Processes
- Fuzzing with Spike
- Privilege Escalation
- Stack Based Windows Buffer Overflow
- Web Application Security and Exploitation
- Linux Stack Smashing
- Linux Address Space Layout Randomization
- Windows Exploit Protection
- Getting Around SEH and ASLR (Windows)
- Penetration Testing Report Writing
A useful way to digest twelve headings is to group them by the kind of thinking they demand: process and communication (headings 1 and 12), reconnaissance and exploitation workflow (2, 3, 5), memory-corruption mechanics on two platforms (4, 6, 8, 9, 10, 11), and web exploitation (7). The sections below follow that grouping.
Team Foundations and Report Writing
These two headings bookend the outline, and they are the ones candidates most often underinvest in because they feel less technical. That is a mistake for a credential with "Consultant" in its name and a graded written report in its practical.
Pentesting Team Foundation
Expect this area to frame how an authorized engagement is organized before any tool is run. Build your own mental model around:
- Authorized-lab concepts: scope, rules of engagement and written permission as the boundary between testing and an offense
- Project metrics: how an engagement's progress and coverage can be tracked and communicated
- Team roles: who leads, who executes, who documents, and how findings are handed between them
Penetration Testing Report Writing
The report is a graded artifact in the practical, not an afterthought. Practice writing findings so that a non-technical reader can understand impact and a technical reader can reproduce the issue.
- Pair every finding with evidence such as command output, screenshots and the flag you captured
- Write remediation-focused recommendations, not only descriptions of what you broke
- Separate executive-level summary from technical detail
One practical habit: keep running notes during every lab session, with timestamps, targets and commands. Candidates who reconstruct their steps from memory at the end tend to produce thin reports, and thin reports undermine otherwise successful exploitation.
NMAP Automation, Exploitation and Privilege Escalation
This cluster covers the working loop of a penetration test: discover, exploit, elevate. The practical's "four of five systems" requirement means you need a repeatable workflow and not heroic one-off successes.
NMAP Automation
The emphasis is on automating scans and, just as importantly, interpreting what comes back. Practice reading NMAP output and deciding what it implies for next steps.
- Translate open ports and service banners into a prioritized target list
- Distinguish filtered, closed and open states and understand what each suggests
- Script repeatable scan runs so results are consistent and documentable
Exploitation Processes
Review exploitation as a disciplined process: confirm the vulnerability, select an approach, execute in the authorized lab, and capture evidence. Understand why an exploit works, not just which tool launches it, because the knowledge exam can probe concepts that tool familiarity alone will not cover.
Privilege Escalation
Detailed-outline Module 5 is Privilege Escalation, which is exactly the area where the page-1 summary's alternative "Simple Buffer Overflow" label can mislead. Study the moving from low-privilege access to higher control on both Windows and Linux hosts, including misconfigurations, weak permissions and local weaknesses.
Fuzzing and Memory Corruption Topics
Six of the twelve headings live here, which makes this the densest part of the outline. It is also where candidates without prior exploit-development exposure feel the steepest climb. For a sense of that climb, read how hard the C)PTC exam is.
Fuzzing with Spike
Spike is a fuzzing framework used to send malformed or unexpected input to a service to provoke crashes that may point to exploitable flaws. Concepts to own: how a protocol is described to the fuzzer, how crashes are observed, and how a crash is narrowed toward a controllable condition.
Stack Based Windows Buffer Overflow and Linux Stack Smashing
These two headings mirror each other across platforms. Know how the stack is laid out, how an overflow can overwrite control data such as a return address, and how an attacker-controlled value can redirect execution. Be ready to compare how the same conceptual bug looks on Windows versus Linux.
Mitigations: ASLR, DEP, SEH, SafeSEH and SEHOP
The outline then moves to defenses and the techniques that interact with them. The relevant headings are Linux Address Space Layout Randomization, Windows Exploit Protection, and Getting Around SEH and ASLR (Windows). Build a comparison for yourself:
| Concept | What to be able to explain |
|---|---|
| ASLR | Randomization of memory layout and why it frustrates fixed-address assumptions, on both Linux and Windows |
| DEP | Marking memory non-executable and how that changes where payloads can run |
| SEH | Windows structured exception handling and why its structures are a point of interest to an exploit author |
| SafeSEH | A protection that validates exception handlers and what it does and does not cover |
| SEHOP | Exception-chain validation intended to detect tampered handler chains |
Key Takeaway
Do not memorize these protections as a glossary. For each one, be able to state what it blocks, what it leaves exposed, and what a defender would change in configuration or code to close the gap. That remediation framing carries straight into the reporting heading.
Web Application Security Under the 2017 Lens
The Web Application Security and Exploitation heading explicitly references the OWASP Top 10-2017 in the issuer's outline. That detail matters for two reasons. First, it tells you the outline's web material is anchored to that edition's categories, so study those categories as presented there. Second, it reinforces that the undated outline should not be described as a newly updated 2026 syllabus.
Practical advice: learn each category in terms of how a flaw is found, how it is exploited in an authorized lab, and how it is fixed. Supplement with current web security knowledge for real-world work, but remember that exam-relevant framing comes from the outline's reference, not from whichever list is newest.
Sequencing Your Preparation
Generic study advice matters less here than ordering, because the memory-corruption headings build on one another. A sensible sequence respects those dependencies. For broader planning resources, our C)PTC study guide and one-page cheat sheet are good companions.
Process and scanning
- Team foundations, scope and roles
- NMAP automation and output interpretation
Exploitation and escalation
- Exploitation processes in an authorized lab
- Privilege escalation on Windows and Linux hosts
Memory corruption foundations
- Fuzzing with Spike
- Windows stack overflow, then Linux stack smashing
Mitigations and bypass concepts
- Linux ASLR, Windows exploit protection
- SEH, SafeSEH, SEHOP and getting around SEH and ASLR
Web and reporting
- Web application topics through the 2017 lens
- Write a full practice report, then take timed multiple-choice sets
Why this order: scanning and exploitation give you the workflow the practical rewards, while the stack and mitigation topics are cumulative and benefit from being studied back to back. Reporting is scheduled last but should be practiced earlier too; treat Week 6 as the consolidation point, not the first time you write anything up.
To test your recall on the written side, use the question sets on our main practice test site. They are meant to build familiarity with question style and concepts, not to reproduce actual exam content.
Prerequisites, Fees and the Combo Package
Do you need the training?
No. Purchasing or completing Mile2 training is not mandatory. Mile2 does suggest a background: C)PEH and C)PTE or equivalent knowledge, two years of networking experience, sound TCP/IP knowledge and computer-hardware knowledge. Note that these are suggestions for preparation, so confirm current enrollment terms on Mile2's pages. Our C)PTC requirements guide goes deeper, and the C)PTC training overview covers the course side.
The Exam Combo
Mile2's Exam Combo includes an exam-preparation guide, practice questions or a simulator, and two exam attempts. The current initial package price could not be independently confirmed from the retrievable issuer listing, so this article does not quote a figure; older promotional numbers you may find elsewhere should not be treated as current. Check Mile2's Exam Combo page directly, and see our certification cost breakdown for how to think about the total outlay.
Validity and Renewal
C)PTC operates on a three-year validity cycle. There are two documented ways to renew:
- CEU route: 60 documented CEUs over the cycle, the applicable renewal purchase, and compliance with ethics and policy requirements.
- Exam route: passing the current full certification examination.
Mile2's FAQ lists USD 200 as the U.S. regional fee for the CEU route. That is a renewal fee, not the initial examination fee, so do not read it as the cost of getting certified in the first place. The FAQ also states that annual membership is not required. Since fees and regional variations can change, verify against the Certification Renewal Program and Renewal Paths pages before planning.
Where It Sits Among Related Credentials
Candidates often ask how the C)PTC compares with adjacent certifications. Without importing facts about other credentials, a few structural observations hold true of the C)PTC itself.
| Comparison | What to weigh |
|---|---|
| C)PTC vs C)PTE | Mile2 suggests C)PTE-level knowledge as preparation for C)PTC, which positions C)PTC as the further step along the same track. |
| C)PTC vs OSCP | Both involve hands-on work. Compare their formats, proctoring, time limits and fees directly on each issuer's current pages; this article does not assert details about the other credential. |
For a more decision-oriented view, our analysis of whether the C)PTC is worth it walks through the trade-offs, and the salary guide and jobs overview discuss who hires for penetration testing skills. Salary outcomes vary widely by region, employer and experience, so no premium is claimed here.
Frequently Asked Questions
Per Mile2's outline, it has two parts: a hands-on penetration test requiring successful exploitation of four of five lab systems, flag identification and a complete written report, plus online assessments through MACS that include flag-selection questions and a 100-question multiple-choice knowledge exam.
The 100-question multiple-choice knowledge examination allows two hours and requires 70%. These figures apply only to the written component, not to the practical, the report or the flag-selection assessment.
No. Purchasing or completing Mile2 training is not mandatory. Suggested preparation includes C)PTE and C)PEH or equivalent knowledge, two years of networking experience, and sound TCP/IP and hardware knowledge.
It has a three-year validity cycle. You can renew with 60 documented CEUs plus the applicable renewal purchase and ethics compliance, or by passing the current full certification exam. The FAQ lists USD 200 as the U.S. regional CEU-route renewal fee.
The twelve headings come from Mile2's detailed outline and are unweighted preparation headings. They are not an official weighted blueprint or a guarantee of exhaustive coverage, so study all of them rather than guessing at emphasis.