Failed CEH (Certified Ethical Hacker)? Here's Your Recovery Plan
Failing an exam doesn't define you. The CEH (Certified Ethical Hacker) has a pass rate of ~60%, you're not alone. Here's exactly what to do next.
The CEH (Certified Ethical Hacker) has a pass rate of ~60%, which means many qualified candidates don't pass on their first attempt. This is a hard-difficulty exam that challenges even experienced professionals.
Most people who fail and try again with a better strategy pass on their second attempt. The key is understanding what went wrong and fixing it.
Wait Period
No waiting period before the second attempt. A 14-day wait applies before the third, fourth and fifth attempts. After a fifth failed attempt, a 12-month wait applies before the sixth.
Retake Cost
A new exam voucher is required for every attempt. EC-Council states it cannot prescribe pricing for its exams, so the only fixed figures are the ones listed in its own store: the CEH Retake Exam Voucher for remote proctoring is USD 500 against USD 950 for a first-sitting CEH Exam Voucher, and the CEH Practical retake is USD 500 against USD 550 for the first sitting. Retake vouchers are released only to candidates EC-Council has approved through its retake application form. Some official training packages include one free retake voucher, though proctoring fees still apply per attempt.
Max Attempts
Five attempts at a given exam within any 12-month period.
Pro tip: You do not repeat the eligibility application when retaking; the original approval carries. Refunds are not issued for failed attempts. EC-Council strongly recommends candidates who fail a third time attend official hands-on training covering the certification objectives, and reserves the right to revoke the certification status of anyone who attempts the exam outside this policy.
- Assuming the pass mark is 70 percentEC-Council does not use a fixed pass mark. Cut scores are set per exam form and cert.eccouncil.org publishes a 60 percent to 85 percent range. Plan for the 85 percent form, not the 60 percent one, because you do not get to choose which form you receive.
- Studying the 20 course modules instead of the nine blueprint domainsBlueprint v5.0 groups the modules into nine scored domains with fixed question counts. Sniffing, social engineering, DoS, session hijacking and IDS evasion together carry 30 of 125 questions under Network and Perimeter Hacking. Weight your revision by the blueprint, not by module count.
- Skipping cryptography, wireless and cloud because each is only 5 percentThose three domains carry 18 questions between them, more than the entire web application domain. All three are recall-heavy and cheap to secure. Losing all 18 can be the difference on a high cut score form.
- Applying for eligibility the week you want to testEC-Council says application processing averages 5 to 10 working days once verifiers respond, and the approval is valid for 3 months. Start the application before you finish studying, not after.
- Letting the exam voucher expireEC-Council vouchers are valid for one year from release. An extension costs USD 49 for 3 months or USD 99 for 1 year, and an already-expired voucher can still be extended for a year at USD 99 by writing to EC-Council.
- Learning tools without learning their outputCEH questions show you a fragment of Nmap output, an enum4linux dump or a Wireshark summary and ask what happened. Run each tool once in your own lab and read the output format, because recognising a half-open scan signature is a different skill from typing the command.
- Ignoring OT and SCADA content in the mobile and IoT domainBlueprint v5.0 splits that 12-question domain into 6 mobile questions and 6 IoT and OT questions, and OT is listed with its own concepts, attacks, methodology and countermeasures bullets. Modbus and DNP3 lack authentication by design, and that fact alone answers several question styles.
- Answering methodology questions out of orderMany items hinge on sequence: footprinting before scanning, scanning before enumeration, enumeration before vulnerability analysis, then gaining access, escalating privileges, maintaining access and clearing logs. If two answers both look technically correct, the sequence usually decides which is right.
- Choosing the most aggressive answerCEH is written from the perspective of an authorized tester working inside a signed scope. Where one option exceeds the stated authorization or skips written permission, it is wrong regardless of technical accuracy.
- Forgetting the certification does not stay valid on its ownCEH sits under the EC-Council Continuing Education scheme: 120 ECE credits per certification within a three-year window, plus an annual continuing education fee of USD 80 for members holding at least one ECE-covered certification. Credits are logged in the Aspen portal.
Analyze Your Score Report
Review your CEH (Certified Ethical Hacker) score report immediately. Identify which domains you scored lowest in, these are your priority areas. Write down specific topics you struggled with while the exam is fresh in your memory.
Take a Short Break (But Not Too Long)
Take 2-3 days off from studying to reset mentally. Failing is emotionally draining, and jumping back in immediately can lead to burnout. But don't wait too long, the material is still fresh.
Change Your Study Strategy
Whatever approach you used before didn't work. Switch it up: if you only read textbooks, add video courses. If you didn't do practice tests, make them your primary study method. Active recall beats passive review every time.
Focus on Weak Areas (80/20 Rule)
Spend 80% of your study time on the 2-3 domains where you scored lowest. You probably already know the topics you scored well on. For CEH (Certified Ethical Hacker), this targeted approach is far more effective than re-studying everything.
Take a Practice Test Before Rebooking
Don't rebook the exam until you're consistently scoring 85%+ on practice tests. This saves you money and builds real confidence. When you're scoring well, schedule the retake.
- Build a home lab with VMs
- Practice with Hack The Box, TryHackMe
- Study reconnaissance and enumeration tools
- Understand all attack phases
- Focus on practical hands-on skills
How long do I have to wait to retake the CEH (Certified Ethical Hacker)?
The retake waiting period for CEH (Certified Ethical Hacker) is No waiting period before the second attempt. A 14-day wait applies before the third, fourth and fifth attempts. After a fifth failed attempt, a 12-month wait applies before the sixth.. You do not repeat the eligibility application when retaking; the original approval carries. Refunds are not issued for failed attempts. EC-Council strongly recommends candidates who fail a third time attend official hands-on training covering the certification objectives, and reserves the right to revoke the certification status of anyone who attempts the exam outside this policy.
How much does it cost to retake the CEH (Certified Ethical Hacker)?
The retake cost is A new exam voucher is required for every attempt. EC-Council states it cannot prescribe pricing for its exams, so the only fixed figures are the ones listed in its own store: the CEH Retake Exam Voucher for remote proctoring is USD 500 against USD 950 for a first-sitting CEH Exam Voucher, and the CEH Practical retake is USD 500 against USD 550 for the first sitting. Retake vouchers are released only to candidates EC-Council has approved through its retake application form. Some official training packages include one free retake voucher, though proctoring fees still apply per attempt.. Maximum attempts: Five attempts at a given exam within any 12-month period..
What percentage of people fail the CEH (Certified Ethical Hacker)?
The CEH (Certified Ethical Hacker) has an average pass rate of ~60%, meaning roughly 40% of test-takers fail on their first attempt.
Is the CEH (Certified Ethical Hacker) harder the second time?
No, the CEH (Certified Ethical Hacker) difficulty is the same on retake. Many people pass on their second attempt because they know what to expect and can focus their study on weak areas.
Ready to pass CEH (Certified Ethical Hacker)?
Get the complete exam guide with study plan, resources, and expert tips.
View CEH (Certified Ethical Hacker) Guide