CEH (Certified Ethical Hacker)
EC-Council
Complete guide to passing the CEH (Certified Ethical Hacker) exam on your first attempt.
$950-$1199
~60%
3 years
Global
EC-Council
$80k-$130k
Are you ready for CEH (Certified Ethical Hacker)?
Loading quiz...
Complete Overview
The Certified Ethical Hacker (CEH) is a four-hour, 125-question multiple-choice exam from EC-Council, exam code 312-50, that tests offensive security knowledge across nine published domains ranging from footprinting and enumeration to cloud hacking and cryptography. It is taken by SOC analysts, network administrators, vulnerability analysts, junior penetration testers and defense contractors who need a credential approved under US Department of Defense Directive 8140; candidates who skip official training pay a non-refundable USD 100 eligibility application fee plus the cost of an exam voucher, and EC-Council states on its certification site that it does not prescribe a fixed voucher price because consumer price-fixing laws prevent it from setting minimums across its partner network.
There are exactly two routes to sit the exam. Route one is attending official EC-Council training through iClass, an Authorized Training Center, or an EC-Council Academia Partner, in which case the USD 100 application fee is folded into the training price and the training center can release the exam directly. Route two is the eligibility application, open to anyone with at least two years of documented information security work experience or a legacy CEH v1 to v7 certification. EC-Council says application processing averages five to ten working days once verifiers respond, and an approved application stays valid for three months.
The exam runs on the ECC Exam Centre portal or at Pearson VUE test centers, and every EC-Council exam can also be proctored remotely. There is no single passing percentage. EC-Council builds multiple forms of the 312-50 from different question banks, rates the difficulty of each item, and sets a cut score per form, so the published range on cert.eccouncil.org is 60 percent to 85 percent depending on which form you receive. The CEH product page describes typical cut scores as 65 percent to 85 percent. Your cut score and your achieved score both appear on the exam transcript, which is available immediately after you finish.
EC-Council does not publish a CEH pass rate. It describes the exam as difficult for candidates with limited background and moderately challenging for seasoned IT and security professionals, and it publishes cut score methodology instead of outcome statistics.
The current blueprint is CEH Exam Blueprint v5.0, which took effect in April 2024 and maps the 125 questions across nine domains. Network and Perimeter Hacking is the largest at 30 questions, followed by Reconnaissance Techniques at 21 and System Hacking Phases and Attack Techniques at 19.
A separate six-hour practical exam presents 20 real-world challenges inside the iLabs Cyber Range and uses the same 60 percent to 85 percent cut score band. It costs USD 550 from the EC-Council store, with a retake priced at USD 500. Passing both the knowledge exam and the practical exam earns the CEH Master designation.
CEH sits under the EC-Council Continuing Education scheme. Holders must log 120 ECE credits per certification within a three-year window and pay an annual continuing education fee of USD 80 for members holding at least one certification under the ECE policy.
Why Get CEH (Certified Ethical Hacker) Certified?
CEH is approved under US Department of Defense Directive 8140 as meeting baseline requirements for 4 of the 5 Cybersecurity Service Provider roles: CSSP Analyst, CSSP Infrastructure Support, CSSP Incident Responder and CSSP Auditor.
The blueprint covers 125 scored questions across 9 domains, so one credential validates reconnaissance, system hacking, network attacks, web application attacks, wireless, mobile and IoT, cloud and cryptography in a single sitting.
EC-Council holds ISO/IEC 17024 accreditation from ANAB for CEH, which is why cut scores are set per exam form by psychometricians rather than fixed at a round number.
EC-Council reports it has trained more than 400,000 cybersecurity professionals and operates in over 170 countries, so the credential is recognized by hiring managers outside the United States.
The US Bureau of Labor Statistics projects information security analyst employment to grow 29 percent between 2024 and 2034, adding 52,100 jobs to a 2024 base of 182,800.
CEH is approved for US Department of Veterans Affairs reimbursement under Post-9/11 GI Bill funds and for the US Army Ignited credentialing assistance program.
Adding the six-hour, 20-challenge CEH Practical for USD 550 upgrades the credential to CEH Master, which gives a hands-on artifact to point at in interviews alongside the multiple-choice pass.
Exam Format & Structure
Duration
4 hours (240 minutes)
Questions
125 multiple-choice questions
Passing Score
No fixed percentage. EC-Council sets a cut score per exam form; cert.eccouncil.org publishes a range of 60 percent to 85 percent, and the CEH product page describes typical cut scores of 65 percent to 85 percent. Your cut score and achieved score both print on the transcript.
Question Types
- Single-best-answer multiple choice
- Scenario questions that name a tool and ask for its output or purpose
- Methodology-ordering questions that ask which phase comes next
- Countermeasure questions that ask for the correct defensive control
- Command and flag recognition, for example Nmap scan types and Metasploit module paths
Delivery Method
Exam code 312-50, delivered through the ECC Exam Centre portal or at Pearson VUE test centers. EC-Council states all of its exams can also be proctored remotely. A voucher upgrade between ECC Exam, Pearson VUE and remote proctoring costs USD 100 in the EC-Council store.
How scoring works
Score scale
Percentage of weighted points earned across 125 questions, compared against a cut score that is set separately for each exam form. The published cut score band is 60 percent to 85 percent.
Score needed to pass
Varies by exam form, from 60 percent to 85 percent. EC-Council does not disclose which form you will receive before you sit.
When results arrive
Pass or fail status is shown within a few minutes of submitting the exam. A printed report gives the overall result plus per-subject-area performance feedback, and the exam transcript showing both your cut score and your achieved score is available immediately. EC-Council does not disclose which individual questions were answered incorrectly.
How the scale is built
Each question carries a difficulty rating assigned during beta testing with a sample group under a committee of subject matter experts. Individual ratings aggregate into a cumulative cut score for that form, which is why forms differ. Scoring is compensatory: the total score decides pass or fail, and you can score poorly in one domain and still pass. There is no negative marking, so a wrong answer costs the same as a blank.
Pacing and time budget
125 questions in 240 minutes gives you 1 minute 55 seconds per question.
60
31 questions
120
63 questions
180
94 questions
215
125 questions, leaving 25 minutes for flagged items
| At this point | You should have answered |
|---|---|
| 60 | 31 questions |
| 120 | 63 questions |
| 180 | 94 questions |
| 215 | 125 questions, leaving 25 minutes for flagged items |
- Two-pass the paper. First pass answers everything you know in under 45 seconds and flags the rest; second pass works the flags with the time you banked.
- Never leave a question blank. There is no negative marking, so an unanswered item and a wrong item score identically while a guess between two options is worth about half a mark.
- Recall questions on ports, algorithms and tool flags should take under 30 seconds each. If one is taking longer, the answer is not coming back and the time is better spent elsewhere.
- Scenario questions in the 30-question network and perimeter domain and the 18-question web application domain are the ones worth re-reading, because the stem usually contains a single word that eliminates two options.
- Do not recheck answers you were confident about. On a form with an 85 percent cut score, finishing all 125 questions matters more than perfecting the first 40.
Where the marks are
Network and perimeter hacking
24% (30 of 125 questions)
Five six-question sub-domains at once: sniffing, social engineering, DoS, session hijacking and IDS or firewall evasion. Questions name a technique and ask for its countermeasure or its detection signature.
Reconnaissance techniques
17% (21 of 125 questions)
Footprinting, scanning and enumeration at seven questions each. The exam shows tool output or a command and asks what it reveals, so Nmap flags and enumeration protocols pay directly.
System hacking phases and attack techniques
15% (19 of 125 questions)
Vulnerability analysis, the gain-escalate-maintain-clear sequence, and malware taxonomy. Sequence questions and malware classification questions dominate this block.
Web application hacking
14% (18 of 125 questions)
Web server attacks, web app attacks and SQL injection at six each. Expect to name the SQL injection variant from a description and to pick the correct input validation countermeasure.
Mobile platform, IoT and OT hacking
10% (12 of 125 questions)
Six mobile questions and six IoT and OT questions. OT protocol weaknesses and mobile device management controls are asked as straightforward recall, and both are commonly skipped in revision.
Information security and ethical hacking overview
6% (7 of 125 questions)
Definitions, the cyber kill chain, hacker classifications and which law or standard applies to a described dataset. Pure recall and the fastest questions on the paper.
Wireless network hacking
5% (6 of 125 questions)
Which encryption standard is broken by which attack, and which Aircrack-ng tool performs which step. Six marks available from one evening of memorisation.
Cryptography
5% (6 of 125 questions)
Algorithm and hash properties, PKI trust chains and named cryptanalysis attacks. No calculation is required, which makes these among the cheapest marks in the exam.
| Topic | Weight | Why it scores |
|---|---|---|
| Network and perimeter hacking | 24% (30 of 125 questions) | Five six-question sub-domains at once: sniffing, social engineering, DoS, session hijacking and IDS or firewall evasion. Questions name a technique and ask for its countermeasure or its detection signature. |
| Reconnaissance techniques | 17% (21 of 125 questions) | Footprinting, scanning and enumeration at seven questions each. The exam shows tool output or a command and asks what it reveals, so Nmap flags and enumeration protocols pay directly. |
| System hacking phases and attack techniques | 15% (19 of 125 questions) | Vulnerability analysis, the gain-escalate-maintain-clear sequence, and malware taxonomy. Sequence questions and malware classification questions dominate this block. |
| Web application hacking | 14% (18 of 125 questions) | Web server attacks, web app attacks and SQL injection at six each. Expect to name the SQL injection variant from a description and to pick the correct input validation countermeasure. |
| Mobile platform, IoT and OT hacking | 10% (12 of 125 questions) | Six mobile questions and six IoT and OT questions. OT protocol weaknesses and mobile device management controls are asked as straightforward recall, and both are commonly skipped in revision. |
| Information security and ethical hacking overview | 6% (7 of 125 questions) | Definitions, the cyber kill chain, hacker classifications and which law or standard applies to a described dataset. Pure recall and the fastest questions on the paper. |
| Wireless network hacking | 5% (6 of 125 questions) | Which encryption standard is broken by which attack, and which Aircrack-ng tool performs which step. Six marks available from one evening of memorisation. |
| Cryptography | 5% (6 of 125 questions) | Algorithm and hash properties, PKI trust chains and named cryptanalysis attacks. No calculation is required, which makes these among the cheapest marks in the exam. |
The numbers
4 hours, 125 multiple-choice questions, exam code 312-50
Exam length and question count
Source: EC-Council, CEH exam details, cert.eccouncil.org
60 percent to 85 percent, set per exam form
Cut score range
Source: EC-Council, CEH passing criteria, cert.eccouncil.org
Not published by EC-Council
Published pass rate
Source: EC-Council CEH programme pages, which publish cut score methodology but no outcome statistics
USD 100, non-refundable, application valid 3 months
Eligibility application fee
Source: EC-Council certification FAQ and EC-Council Store product listing
120 ECE credits within each 3-year certification cycle, plus a USD 80 annual continuing education fee for CEH. The fee is a single annual charge no matter how many EC-Council certifications you hold, except CCISO at USD 100 and CPENT or LPT at USD 250, which are billed separately
Recertification requirement
Source: EC-Council Continuing Education (ECE) Policy and Continuing Education Fees FAQ, cert.eccouncil.org
182,800 information security analyst jobs in 2024, projected 29 percent growth to 234,900 by 2034, median wage USD 124,910
Occupational demand for the target role
Source: US Bureau of Labor Statistics, Occupational Outlook Handbook, Information Security Analysts, May 2024 wage data
If you fail
Wait before retaking
No waiting period before the second attempt. A 14-day wait applies before the third, fourth and fifth attempts. After a fifth failed attempt, a 12-month wait applies before the sixth.
Attempt limit
Five attempts at a given exam within any 12-month period.
Retake fee
A new exam voucher is required for every attempt. EC-Council states it cannot prescribe pricing for its exams, so the only fixed figures are the ones listed in its own store: the CEH Retake Exam Voucher for remote proctoring is USD 500 against USD 950 for a first-sitting CEH Exam Voucher, and the CEH Practical retake is USD 500 against USD 550 for the first sitting. Retake vouchers are released only to candidates EC-Council has approved through its retake application form. Some official training packages include one free retake voucher, though proctoring fees still apply per attempt.
You do not repeat the eligibility application when retaking; the original approval carries. Refunds are not issued for failed attempts. EC-Council strongly recommends candidates who fail a third time attend official hands-on training covering the certification objectives, and reserves the right to revoke the certification status of anyone who attempts the exam outside this policy.
Exam Domains & Topics
The largest domain in Blueprint v5.0, carrying five sub-domains of six questions each: sniffing, social engineering, denial of service, session hijacking, and evading IDS, firewalls and honeypots.
Key Topics to Master:
- Sniffing techniques: MAC flooding, DHCP starvation, ARP poisoning, DNS poisoning
- Social engineering techniques, insider threats and impersonation on social networks
- DoS and DDoS attack techniques, botnets and protection tools
- Application-level and network-level session hijacking
- IDS, IPS, firewall and honeypot concepts and evasion
- Sniffing detection techniques and countermeasures
Three sub-domains of seven questions each: footprinting and reconnaissance, scanning networks, and enumeration. This is the domain where tool and flag recall pays the most.
Key Topics to Master:
- Footprinting through search engines, web services, social networks and Whois
- DNS, email, website and network footprinting plus countermeasures
- Host discovery, port and service discovery, OS fingerprinting and banner grabbing
- Scanning beyond IDS and firewall
- NetBIOS, SNMP, LDAP, NTP, NFS, SMTP and DNS enumeration
- Other enumeration: IPsec, VoIP, RPC, Unix and Linux, Telnet, FTP, TFTP, SMB, IPv6 and BGP
Vulnerability analysis carries 6 questions, system hacking 6, and malware threats 7. Expect the classic gain access, escalate, maintain, clear logs sequence plus malware taxonomy.
Key Topics to Master:
- Vulnerability assessment concepts, classification, tools and reports
- Password cracking, vulnerability exploitation and privilege escalation
- Maintaining access, executing applications, hiding files and establishing persistence
- Clearing logs and anti-forensics
- Trojan, virus, worm, fileless malware and APT concepts
- Malware analysis, countermeasures and anti-malware software
Three sub-domains of six questions each: hacking web servers, hacking web applications, and SQL injection. Blueprint v5.0 explicitly adds web APIs, webhooks and web shells.
Key Topics to Master:
- Web server attack methodology, countermeasures and patch management
- Bypassing client-side controls and attacking authentication and authorization schemes
- Attacking session management and application logic flaws
- Injection and input validation attacks
- Web API, webhooks and web shell attacks
- SQL injection types, methodology, tools and evasion techniques
Two sub-domains of six questions each: hacking mobile platforms, and IoT and OT hacking. OT and SCADA content grew in Blueprint v5.0 and is easy to skip by accident.
Key Topics to Master:
- Mobile platform attack vectors and Android OS hacking
- iOS hacking and mobile device management
- Mobile security guidelines and tools
- IoT concepts, attacks and hacking methodology
- OT concepts, attacks and hacking methodology
- IoT and OT attack countermeasures
One sub-domain covering definitions, frameworks and law. Small in weight but high in yield because the questions are recall, not analysis.
Key Topics to Master:
- Information security overview and the CIA triad
- Hacking methodologies and frameworks including the cyber kill chain and MITRE ATT&CK
- Hacking concepts and attacker classification
- Ethical hacking concepts, scope and limitations
- Information security controls and defense in depth
- Information security laws and standards such as PCI DSS, HIPAA, GDPR and ISO/IEC 27001
One sub-domain of six questions covering wireless encryption, threats, methodology, tools and Bluetooth. Small enough that many candidates skip it and then lose all six marks.
Key Topics to Master:
- Wireless concepts, standards and terminology
- Wireless encryption: WEP, WPA, WPA2, WPA3
- Wireless threats including evil twin, rogue AP and KRACK
- Wireless hacking methodology and tools such as Aircrack-ng
- Bluetooth hacking
- Wireless attack countermeasures and security tools
One sub-domain of six questions. Blueprint v5.0 lists container technology and serverless computing alongside classic cloud threats.
Key Topics to Master:
- Cloud computing concepts and service models
- Container technology and Kubernetes exposure
- Serverless computing risks
- Cloud computing threats and the shared responsibility model
- Cloud hacking techniques including bucket enumeration and metadata service abuse
- Cloud security controls
One sub-domain of six questions covering algorithms, PKI, disk and email encryption, and cryptanalysis. Pure recall, and the cheapest six marks on the paper to secure.
Key Topics to Master:
- Cryptography concepts, symmetric versus asymmetric
- Encryption algorithms: AES, DES, 3DES, RC4, RSA, ECC
- Hashing: MD5, SHA family, HMAC and collision concepts
- Public key infrastructure, certificate authorities and trust chains
- Email encryption with PGP and S/MIME, and disk encryption tools
- Cryptanalysis attacks and countermeasures
Recommended Study Plan
- 1Download CEH Exam Blueprint v5.0 from cert.eccouncil.org and write the nine domains with their question counts on one page
- 2Install Kali Linux in VirtualBox or VMware and snapshot a clean state
- 3Add Metasploitable 2, DVWA and a Windows Server evaluation VM on a host-only network
- 4Decide your eligibility route now: official training, or the USD 100 application which averages 5 to 10 working days to process
- 5Take a 50-question diagnostic from the EC-Council CEH Exam Prep product (USD 149) or another bank and record per-domain accuracy
- 1Memorize the five phases of hacking and the seven stages of the Lockheed Martin cyber kill chain
- 2Map the kill chain against MITRE ATT&CK tactics on attack.mitre.org
- 3Learn the scope of PCI DSS, HIPAA, SOX, GDPR and ISO/IEC 27001 well enough to match each to a one-line scenario
- 4Write flashcards for black hat, white hat, gray hat, suicide hacker, hacktivist and state-sponsored classifications
- 5Work 25 practice questions on domain 1 and review every wrong answer against the blueprint sub-topics
- 1Run theHarvester, Recon-ng and Maltego CE against a domain you own and record what each returns
- 2Practice Shodan and Censys filters for banner grabbing without touching the target
- 3Work through Whois, DNS zone transfer with dig axfr, and reverse DNS lookups
- 4Learn Google dorking operators: site, filetype, inurl, intitle, cache, link
- 5Complete the TryHackMe Passive Reconnaissance and Google Dorking rooms
- 1Drill Nmap flags until recall is automatic: -sS, -sT, -sU, -sn, -sV, -O, -A, -T0 to -T5, -f, -D, --scanflags
- 2Learn TCP flag combinations behind NULL, FIN and Xmas scans and the RST behaviour that identifies open ports
- 3Enumerate SMB with enum4linux, SNMP with snmpwalk and default community strings, LDAP with ldapsearch
- 4Memorize default ports for SSH 22, Telnet 23, SMTP 25, DNS 53, HTTP 80, POP3 110, NetBIOS 137 to 139, IMAP 143, SNMP 161, LDAP 389, HTTPS 443, SMB 445, RDP 3389, MySQL 3306, MSSQL 1433
- 5Complete the TryHackMe Nmap and Network Services rooms and repeat missed sections
- 1Run OpenVAS or Nessus Essentials against Metasploitable 2 and read the full report, not just the critical findings
- 2Learn CVSS base metrics and how CVE, CWE and NVD relate to each other
- 3Crack sample hashes with John the Ripper and hashcat, including LM, NTLM, MD5 and SHA-512 crypt
- 4Practice Windows and Linux privilege escalation checks with WinPEAS and LinPEAS
- 5Study log clearing, alternate data streams, steganography and rootkit types, then answer 30 domain 3 questions
- 1Classify Trojans, viruses, worms, fileless malware and APT stages, with one named example for each
- 2Capture ARP poisoning traffic in Wireshark on your lab network and identify the gratuitous ARP frames
- 3Learn DHCP starvation, MAC flooding, DNS poisoning and the switch countermeasures: port security, DHCP snooping, dynamic ARP inspection
- 4Study DoS categories: volumetric, protocol and application layer, plus SYN flood, Smurf, Slowloris and amplification
- 5Read the Snort rule syntax and be able to identify what a given rule detects
- 1Study application-level hijacking: session fixation, session sidejacking, cross-site request forgery, predictable token generation
- 2Learn IDS evasion techniques: fragmentation, insertion, obfuscation, encryption, session splicing, and where snort and honeypots fit
- 3Compare low-interaction and high-interaction honeypots and know the detection giveaways
- 4Work through social engineering categories: phishing, spear phishing, whaling, vishing, smishing, pretexting, tailgating, dumpster diving, quid pro quo
- 5Answer 40 mixed domain 4 questions, which is the single heaviest domain at 30 of 125 marks
- 1Complete the PortSwigger Web Security Academy paths for SQL injection, authentication and access control, which are free
- 2Run sqlmap against DVWA and read what each stage of the automation is actually doing
- 3Practice Burp Suite Community: intercept, repeater, intruder and decoder
- 4Study union-based, error-based, boolean blind, time-based blind and out-of-band SQL injection and be able to name each from a description
- 5Review the OWASP Top 10 2021 categories and map them to the blueprint web app sub-topics including web API, webhook and web shell attacks
- 1Compare WEP, WPA, WPA2 and WPA3 by cipher, key length and known attack, and learn the Aircrack-ng suite tool by tool
- 2Study Android rooting, iOS jailbreaking, OWASP Mobile Top 10 and mobile device management controls
- 3Learn IoT protocols such as MQTT, CoAP, Zigbee and BLE, and OT protocols such as Modbus, DNP3 and Profinet
- 4Cover cloud shared responsibility, container escapes, serverless risks and metadata service abuse
- 5Memorize algorithm properties: AES block and key sizes, DES 56-bit key, RSA key exchange, ECC efficiency, MD5 128-bit and SHA-256 output lengths
- 1Sit two full 125-question, 240-minute timed papers in one week under exam conditions
- 2Rebuild your per-domain accuracy table and spend all remaining revision on the two lowest domains
- 3Rehearse the pacing plan: 31 questions by minute 60, 63 by minute 120, 94 by minute 180
- 4Re-read the blueprint sub-domain bullets one final time and confirm every bullet triggers a recall
- 5Book the exam, confirm your voucher expiry date, and verify your ID matches the registration name exactly
Ready to pass CEH (Certified Ethical Hacker)?
Get 500+ practice questions, video walkthroughs, and a pass guarantee.
Best Study Resources
CEH Exam Blueprint v5.0 (EC-Council)
Official blueprint PDFThe authoritative document. Nine domains, sub-domain bullets, question counts per sub-domain and published weightings, effective April 2024. Downloadable from cert.eccouncil.org.
Free
EC-Council CEH Exam Prep
Official practice bankThe vendor practice product. EC-Council says official training students receive mock exam questions broken down by domain to assess readiness.
USD 149 from the EC-Council store
EC-Council iLabs / CyberQ Cyber Range
Hands-on labsThe lab environment used by official training, with 221 hands-on labs and coverage of over 4,000 tools according to EC-Council.
USD 199 for the CEH Labs product in the EC-Council store
CEH Certified Ethical Hacker All-in-One Exam Guide by Matt Walker (McGraw Hill)
BookThe most widely used third-party CEH text, organized by exam domain with end-of-chapter questions.
Typically USD 45 to 60 new
PortSwigger Web Security Academy
Free interactive labsBuilt by the makers of Burp Suite. The SQL injection, authentication, access control and API paths cover the 18-question web application domain better than any CEH-branded material.
Free
TryHackMe
Guided hands-on platformStructured rooms on Nmap, network services, passive reconnaissance and Metasploit that give the muscle memory the multiple-choice questions assume you have.
Free tier plus a paid subscription
Hack The Box
Practice labsUnstructured target machines. Useful after the guided rooms, and directly relevant if you plan to add the six-hour CEH Practical.
Free tier plus paid tiers
OWASP Top 10 (2021)
Free referenceThe reference list behind most web application questions. Read the full category pages, not the summary list.
Free
MITRE ATT&CK
Free framework referenceBlueprint v5.0 lists hacking methodologies and frameworks as a domain 1 sub-topic. ATT&CK tactic and technique names appear in scenario wording.
Free
Damn Vulnerable Web Application and Metasploitable 2
Free target VMsThe two standard deliberately vulnerable targets for practising SQL injection, command injection, file upload attacks and service exploitation on your own network.
Free
Common Mistakes to Avoid
Assuming the pass mark is 70 percent
EC-Council does not use a fixed pass mark. Cut scores are set per exam form and cert.eccouncil.org publishes a 60 percent to 85 percent range. Plan for the 85 percent form, not the 60 percent one, because you do not get to choose which form you receive.
Studying the 20 course modules instead of the nine blueprint domains
Blueprint v5.0 groups the modules into nine scored domains with fixed question counts. Sniffing, social engineering, DoS, session hijacking and IDS evasion together carry 30 of 125 questions under Network and Perimeter Hacking. Weight your revision by the blueprint, not by module count.
Skipping cryptography, wireless and cloud because each is only 5 percent
Those three domains carry 18 questions between them, more than the entire web application domain. All three are recall-heavy and cheap to secure. Losing all 18 can be the difference on a high cut score form.
Applying for eligibility the week you want to test
EC-Council says application processing averages 5 to 10 working days once verifiers respond, and the approval is valid for 3 months. Start the application before you finish studying, not after.
Letting the exam voucher expire
EC-Council vouchers are valid for one year from release. An extension costs USD 49 for 3 months or USD 99 for 1 year, and an already-expired voucher can still be extended for a year at USD 99 by writing to EC-Council.
Learning tools without learning their output
CEH questions show you a fragment of Nmap output, an enum4linux dump or a Wireshark summary and ask what happened. Run each tool once in your own lab and read the output format, because recognising a half-open scan signature is a different skill from typing the command.
Ignoring OT and SCADA content in the mobile and IoT domain
Blueprint v5.0 splits that 12-question domain into 6 mobile questions and 6 IoT and OT questions, and OT is listed with its own concepts, attacks, methodology and countermeasures bullets. Modbus and DNP3 lack authentication by design, and that fact alone answers several question styles.
Answering methodology questions out of order
Many items hinge on sequence: footprinting before scanning, scanning before enumeration, enumeration before vulnerability analysis, then gaining access, escalating privileges, maintaining access and clearing logs. If two answers both look technically correct, the sequence usually decides which is right.
Choosing the most aggressive answer
CEH is written from the perspective of an authorized tester working inside a signed scope. Where one option exceeds the stated authorization or skips written permission, it is wrong regardless of technical accuracy.
Forgetting the certification does not stay valid on its own
CEH sits under the EC-Council Continuing Education scheme: 120 ECE credits per certification within a three-year window, plus an annual continuing education fee of USD 80 for members holding at least one ECE-covered certification. Credits are logged in the Aspen portal.
Exam Day Tips
- 1
Confirm which delivery channel your voucher is tied to before exam day. ECC Exam Centre, Pearson VUE and remote proctoring are separate channels, and switching between them costs USD 100 per upgrade in the EC-Council store.
- 2
For a Pearson VUE seat, bring a valid, unexpired government-issued photo ID whose name matches your EC-Council registration exactly, including middle names and suffixes.
- 3
For a remotely proctored sitting, test your webcam, microphone and bandwidth on the same machine and network you will use, and clear the desk and walls before the proctor starts the room scan.
- 4
You must accept the EC-Council Non-Disclosure Agreement before the exam unlocks. Read it in advance so the clock does not start while you are reading legal text.
- 5
Budget 1 minute 55 seconds per question. That is the arithmetic of 240 minutes divided by 125 questions, and it is tight enough that two long re-reads cost you a whole question.
- 6
There is no negative marking, so answer every one of the 125 questions. A blank is worth exactly zero and a guess between two remaining options is worth roughly half a mark.
- 7
Flag and move on after 90 seconds on any single item. The heavy domains reward finishing the paper more than they reward perfecting one question.
- 8
Watch for authorization wording in scenario stems: internal versus external, with a signed scope or without, production versus staging. That wording usually eliminates two of the four options.
- 9
Your cut score and achieved score both appear on the transcript, which EC-Council makes available immediately after you complete the exam, so you will know your result before you leave the seat.
- 10
If you need a special accommodation, email EC-Council's Special Accommodation Request Form to [email protected] before you book, scanned so it carries the certifying authority's signature, and list every exam and version you need the accommodation for.
- 11
Do not photograph, transcribe or discuss questions afterwards. You accept EC-Council's Non-Disclosure Agreement before the exam unlocks, and EC-Council reserves the right to revoke the certification status of anyone who does not comply with its examination policies.
Career Paths & Salary Ranges
Information security analyst
The entry point most CEH holders occupy: monitoring alerts, triaging incidents and running vulnerability scans. BLS counted 182,800 jobs in this occupation in 2024.
USD 69,660 at the 10th percentile to USD 124,910 median (BLS OEWS, May 2024, SOC 15-1212)
Penetration tester
Offensive testing under a signed scope. BLS folds penetration testing into the information security analyst code, and testers cluster in the upper half of that distribution because the role needs demonstrated exploitation skill.
USD 124,910 median to USD 186,420 at the 90th percentile (BLS OEWS, May 2024, SOC 15-1212)
Network security engineer
Designing and hardening segmentation, firewalls, VPNs and IDS deployments. The CEH network and perimeter domain maps directly onto the evasion techniques this role has to block.
USD 130,390 median (BLS OEWS, May 2024, computer network architects, SOC 15-1241)
Security operations and systems administration
Patch management, hardening, log collection and account controls. A common starting point for candidates who take CEH to move from IT operations into security.
USD 96,800 median (BLS OEWS, May 2024, network and computer systems administrators, SOC 15-1244)
Security consultant
Client-facing assessment and advisory work. Consulting firms are one of the five largest employing industries for this occupation, holding 6 percent of the jobs.
USD 120,050 median for information security analysts in management, scientific and technical consulting services (BLS OEWS, May 2024)
Information security manager
Owning the security programme, budget and staff. CEH is usually a stepping stone here rather than the qualifying credential, and the DoD 8140 approval matters for government-facing roles.
USD 171,200 median (BLS OEWS, May 2024, computer and information systems managers, SOC 11-3021)
Prerequisites & Requirements
- Route one: attend official EC-Council training through iClass, an Authorized Training Center or an EC-Council Academia Partner. The USD 100 application fee is included in the training price and no separate eligibility application is needed.
- Route two: a minimum of two years of documented work experience in the information security domain, submitted with the eligibility application and a non-refundable USD 100 fee.
- Route three: holding a legacy Certified Ethical Hacker certification from version 1 to version 7, which waives the application fee.
- There is no degree requirement and no mandatory prior certification.
- Minors cannot sit an EC-Council exam without written consent from a parent or legal guardian plus a supporting letter from a nationally accredited institution of learning.
- Practical readiness that EC-Council assumes rather than requires: TCP/IP and subnetting, Windows and Linux command line, basic HTTP and HTML, and comfort running a virtual machine lab.
- An approved eligibility application is valid for 3 months, and an exam voucher is valid for 1 year from release.
Frequently Asked Questions
What score do I need to pass the CEH exam?
There is no single passing score. EC-Council builds multiple forms of the 312-50 from different question banks, rates each question for difficulty, and sets a cumulative cut score per form. Its certification site publishes a range of 60 percent to 85 percent, and the CEH product page describes typical cut scores as 65 percent to 85 percent. Your cut score and your achieved score both appear on the transcript you receive immediately after the exam.
What is the CEH pass rate?
EC-Council does not publish a pass rate for the CEH. Any percentage you see quoted online is not sourced to EC-Council. What the vendor does publish is its methodology: psychometricians set cut scores per exam form and regularly evaluate question performance and average pass and fail results across the programme.
How much does CEH cost?
EC-Council does not publish a fixed exam voucher price and states on its certification site that consumer price-fixing laws prevent it from prescribing minimum pricing, since vouchers are usually bundled with training by partners. The prices EC-Council does publish in its own store are the eligibility application fee at USD 100, CEH Exam Prep at USD 149, CEH Labs at USD 199, the CEH Practical exam at USD 550 and a CEH Practical retake at USD 500. Voucher channel upgrades cost USD 100 each.
What happens if I fail the CEH exam?
You can retake it immediately. EC-Council imposes no waiting period between the first attempt and the second. From the second attempt onward, a 14-day waiting period applies before each subsequent attempt. You will need to request another exam voucher by email, but you do not repeat the eligibility application process. Refunds are not given for a failed attempt.
How many times can I take the CEH exam?
Five times in any 12-month period. After a fifth failed attempt, a 12-month waiting period applies before a sixth attempt. EC-Council also states it strongly recommends candidates who fail a third time attend official hands-on training covering the certification objectives, and it reserves the right to revoke certification obtained in breach of the retake policy.
Do I need official EC-Council training?
No. Official courseware is recommended but not mandatory, and EC-Council states plainly that it does not guarantee a pass. Without training you must apply for exam eligibility with at least two years of information security work experience and pay the USD 100 non-refundable application fee. Self-study materials can be bought from the EC-Council store, but self-published YouTube courses are not accepted as a valid study method on an eligibility application.
How long does the eligibility application take?
EC-Council says processing averages 5 to 10 working days once the verifiers listed on your application respond to its requests for information. The delay is usually your referees, not EC-Council. An approved application stays valid for 3 months, so time the application to your intended test window.
How long is my exam voucher valid?
One year from the date of voucher release. You can extend an unexpired voucher for USD 49 for three months or USD 99 for one year. An expired voucher can still be extended for one year at USD 99. Extensions are requested by email from EC-Council with your voucher details.
Can I take the CEH exam online?
Yes. EC-Council states all of its exams can be proctored virtually, and the CEH knowledge exam is also delivered through the ECC Exam Centre portal and at Pearson VUE test centers. If your voucher was issued for a different channel, an upgrade between ECC Exam, Pearson VUE and remote proctoring costs USD 100 in the EC-Council store.
Are calculators or reference materials allowed?
No. The CEH is a closed-book, proctored multiple-choice exam and every candidate must accept a Non-Disclosure Agreement before the exam unlocks. No notes, no printed port lists and no external reference material. Nothing on the paper requires a calculator; the arithmetic is limited to concepts such as key lengths and subnetting.
When do I get my result?
Immediately. EC-Council states you receive notification of your pass or fail status within a few minutes of completing the exam, plus a report showing your result and per-subject-area performance feedback. Your cut score and achieved score appear on the exam transcript, which is available as soon as you finish. Digital certificates for successful candidates are issued after the result is confirmed.
Will EC-Council tell me which questions I got wrong?
No. EC-Council states this level of information is not provided, because the exam is designed to test whether you have the required skills rather than your ability to memorise specific questions. You receive a per-subject-area performance indicator on some exams, which is enough to identify weak domains for a retake but not enough to reconstruct the paper.
How do I keep my CEH valid?
CEH falls under the EC-Council Continuing Education scheme. You must earn 120 ECE credits per certification within a three-year window and log them in the Aspen portal. Credits come from IT security conferences, webinars, reading security books, writing research papers, instructing, and taking a newer version of the exam. On top of credits, any member certified or recertified since 1 January 2016 pays an annual continuing education fee of USD 80 if they hold at least one certification under the ECE policy, or USD 20 for certifications outside the policy.
What happens if I miss my ECE deadline?
Your membership is suspended rather than immediately revoked. EC-Council states that suspended members who meet the 120 ECE credit requirement within 12 months of the expiry of the three-year window are reinstated in good standing, provided the continuing education fee is paid. A reinstated member then has a reduced period for the next window: three years less the suspension period.
How do I request an accommodation for a disability?
Submit the EC-Council Special Accommodation Request Form at least 30 days before you register for the exam. Section 1 is completed by you and Section 2 by a legally approved healthcare professional confirming the need. EC-Council responds with a decision within 14 days and provides contact details for test centers equipped to accommodate the request. Candidates holding an ETC exam voucher code receive a free upgrade to remote proctoring.
What is the difference between CEH and CEH Practical?
CEH is a four-hour, 125-question multiple-choice knowledge exam. CEH Practical is a six-hour exam presenting 20 real-world challenges inside the iLabs Cyber Range using live virtual machines, networks and applications rather than simulated screens. It uses the same 60 percent to 85 percent cut score band, costs USD 550, and is proctored by the EC-Council certification department. Passing both earns the CEH Master designation.
CEH or OSCP?
They test different things. CEH is a proctored multiple-choice exam over nine breadth domains with a cut score set by exam form, and it is approved under DoD Directive 8140 for four of the five CSSP roles, which matters for US government and defense contracting. OSCP from OffSec is a 24-hour hands-on exploitation exam followed by a report. If your target role is a compliance-driven analyst or government position, CEH clears the requirement. If it is a commercial red team, the practical credential carries more weight. Adding CEH Practical narrows the gap.
How many hours should I study?
The study plan above spans 10 weeks at 8 to 16 hours per week, which is roughly 110 to 130 hours. The right number depends on your starting point: EC-Council states candidates should already have two years of IT security experience or complete official training, and describes the exam as difficult for those with limited background and moderately challenging for seasoned professionals. Official training is structured as a 5-day boot camp with six months of lab access.
Why do the published domain weights add up to 101 percent?
Rounding. Blueprint v5.0 lists rounded whole-number weightings of 6, 17, 15, 24, 14, 5, 10, 5 and 5, which total 101. The underlying question counts are exact and total 125: 7, 21, 19, 30, 18, 6, 12, 6 and 6. Study by question count rather than by the rounded percentage, because the question count is what actually appears on the paper.
Does the CEH count for US military benefits?
Yes. EC-Council states CEH is approved by the US Department of Veterans Affairs for reimbursement using Post-9/11 GI Bill funds and is eligible for reimbursement through the US Army Ignited programme. It is approved under DoD Directive 8140 for four of the five Cybersecurity Service Provider roles, and EC-Council says the certification meets the requirements of over 320 distinct military job roles across enlisted and officer ranks. Funding eligibility varies by branch.
Success Stories
“Matt Walker's book and TryHackMe were my main resources. Focus on understanding attack methodology, not just memorizing tools.”
James M.
Security Analyst
“Coming from a networking background, I spent 6 weeks studying. The scenario questions were the trickiest part.”
Sarah K.
Penetration Tester
“CEH opened doors for my first security role. Combined it with OSCP later for penetration testing positions.”
Raj P.
Security Consultant
Pass CEH (Certified Ethical Hacker), Guaranteed
94% pass rate on first attempt
One-time • Lifetime access