An unhandled error has occurred. Reload X
View official blueprint on Cert Atlas

Certified Ethical Hacker (CEH) Practice Test

140 questions available

EC-Council Certified Ethical Hacker exam covering ethical hacking methodology, attack vectors, and cybersecurity defense strategies. Administered by EC-Council as a linear format exam. Key domains include Denial-of-Service, Evading IDS, Firewalls, and Honeypots, Session Hijacking and Sniffing. The exam consists of 125 questions over 240 minutes.

Certification exam
125 Exam questions
4 hours Time Limit
Career Opportunities & Salary
Entry $62,540 - $94,540
Mid-Career $92,540 - $137,540
Senior $127,540 - $187,540
growing market
Why This Certification Opens Doors

In today's threat landscape, defending an organization requires understanding the offensive perspective. The CEH provides this critical lens. Its practical value lies in equipping professionals with the same tools and techniques used by attackers, enabling them to proactively discover weaknesses, conduct authorized penetration tests, and build more resilient defenses. This directly translates to reducing organizational risk, preventing costly data breaches, and ensuring compliance with security standards. It moves security from a reactive, theoretical model to a proactive, hands-on discipline.

Exam Blueprint

Each domain is weighted to match the real certification exam, so a full practice simulation predicts your result.

01Denial-of-ServiceUnderstand different Denial of Service (DoS) and Distributed DoS (DDoS) attack techniques and countermeasures.
24%
02Evading IDS, Firewalls, and HoneypotsUnderstand firewall, intrusion detection system (IDS), and honeypot evasion techniques and countermeasures.
24%
03Session HijackingUnderstand session hijacking techniques and countermeasures.
24%
04SniffingPerform packet-sniffing techniques and countermeasures.
24%
05Social EngineeringUnderstand social engineering concepts and countermeasures.
24%
06EnumerationPerform enumeration techniques using various tools and countermeasures.
17%
07Footprinting and ReconnaissancePerform footprinting and reconnaissance using various tools and techniques.
17%
08Scanning NetworksPerform network scanning techniques and countermeasures.
17%
09Malware ThreatsUnderstand different types of malware, malware analysis procedures, and countermeasures.
15%
10System HackingPerform system hacking methodologies to discover system and network vulnerabilities.
15%
11Vulnerability AnalysisIdentify security loopholes in a target organization’s network, communication infrastructure, and end systems.
15%
12Hacking Web ApplicationsPerform web application attacks and countermeasures.
14%
13Hacking Web ServersPerform web server attacks and countermeasures.
14%
14SQL InjectionUnderstand SQL injection attack techniques, evasion techniques, and countermeasures.
14%
15Hacking Mobile PlatformsUnderstand mobile platform attack vectors, security guidelines, and tools.
10%
16IoT and OT HackingUnderstand IoT and OT hacking methodologies, tools, and countermeasures.
10%
17Introduction to Ethical HackingUnderstand the fundamentals of ethical hacking, information security controls, and relevant laws and procedures.
6%
18Cloud ComputingUnderstand cloud computing threats, attacks, methodologies, and security tools.
5%
19CryptographyUnderstand encryption algorithms, cryptography tools, and cryptanalysis techniques.
5%
20Hacking Wireless NetworksUnderstand wireless network hacking methodologies, tools, and countermeasures.
5%
Exam Details 312-50 | $550 USD | 4 hours
Exam Code 312-50
Vendor EC-Council
Exam Cost $550 USD
Passing Score 70
Time Limit 4 hours
Exam questions 125
Question Types Multiple Choice
Retake Policy No official waiting period specified between retakes. Full exam fee required for each retake.
Exam Format Linear
Online Proctoring Available
Available In
English
Retake Policy 0-day waiting period between attempts
Study Resources
EC-Council Official CoursewareOfficialOnline Course
EC-CouncilFree
Instructor-led and iLearn self-paced options
View
Frequently Asked Questions

Is the CEH mostly theory, or does it test practical skills?

The CEH has evolved to strongly emphasize practical skills. While earlier versions were more theory-focused, the current exam (CEH Practical) is a fully hands-on, performance-based assessment where you must demonstrate exploits and techniques in a live lab environment. The ANSI-accredited CEH (312-50) multiple-choice exam also heavily utilizes scenario-based questions that test applied knowledge.

I have no direct security experience. Can I pass the CEH?

It is possible but highly challenging. EC-Council officially requires either two years of relevant security experience or completion of their official training to be eligible for the exam. A strong background in networking (e.g., CompTIA Network+ level), operating systems, and basic IT administration is an absolute prerequisite. Without this foundation, the breadth of topics will be overwhelming.

How much hands-on lab practice is necessary?

Extensive lab practice is non-negotiable for success. You should plan to spend a significant portion of your study time in a virtual lab environment (using tools like VirtualBox or VMware) practicing reconnaissance, scanning, vulnerability exploitation, and tool usage. Theoretical knowledge of an exploit is insufficient; you must be able to execute the steps and understand the output.

How does the CEH compare to the CompTIA PenTest+ or OSCP?

The CEH offers broad coverage of the attack landscape and is widely recognized for HR and DoD 8570 compliance. PenTest+ is also broad but is often seen as a step below CEH in depth. The OSCP (Offensive Security Certified Professional) is a more advanced, intensely practical exam focused deeply on penetration testing methodology and exploit development, with a grueling 24-hour hands-on exam. CEH is a strong entry-to-mid-level credential that provides a wide foundation.

What is the best way to start preparing after meeting the prerequisites?

Begin by thoroughly studying the official CEH curriculum and blueprint. Build a stable home lab for practice. Use official study guides and video training as your core, and supplement with reputable practice exams to identify knowledge gaps. Focus on understanding attack phases sequentially: Reconnaissance, Scanning, Gaining Access, Maintaining Access, and Covering Tracks. Join online communities or study groups to discuss scenarios and tools.

Reviews & Ratings
No reviews yet

Be the first to review this exam and help other learners!


Share Your Experience