How Long to Study for CEH (Certified Ethical Hacker)
A complete week-by-week study plan for the CEH (Certified Ethical Hacker) (Hard difficulty, ~60% pass rate).
10
Weeks
12
Hrs/Week
122
Total Hours
~60%
Pass Rate
8-10 hours this week
- Download CEH Exam Blueprint v5.0 from cert.eccouncil.org and write the nine domains with their question counts on one page
- Install Kali Linux in VirtualBox or VMware and snapshot a clean state
- Add Metasploitable 2, DVWA and a Windows Server evaluation VM on a host-only network
- Decide your eligibility route now: official training, or the USD 100 application which averages 5 to 10 working days to process
- Take a 50-question diagnostic from the EC-Council CEH Exam Prep product (USD 149) or another bank and record per-domain accuracy
8-10 hours this week
- Memorize the five phases of hacking and the seven stages of the Lockheed Martin cyber kill chain
- Map the kill chain against MITRE ATT&CK tactics on attack.mitre.org
- Learn the scope of PCI DSS, HIPAA, SOX, GDPR and ISO/IEC 27001 well enough to match each to a one-line scenario
- Write flashcards for black hat, white hat, gray hat, suicide hacker, hacktivist and state-sponsored classifications
- Work 25 practice questions on domain 1 and review every wrong answer against the blueprint sub-topics
10-12 hours this week
- Run theHarvester, Recon-ng and Maltego CE against a domain you own and record what each returns
- Practice Shodan and Censys filters for banner grabbing without touching the target
- Work through Whois, DNS zone transfer with dig axfr, and reverse DNS lookups
- Learn Google dorking operators: site, filetype, inurl, intitle, cache, link
- Complete the TryHackMe Passive Reconnaissance and Google Dorking rooms
12-14 hours this week
- Drill Nmap flags until recall is automatic: -sS, -sT, -sU, -sn, -sV, -O, -A, -T0 to -T5, -f, -D, --scanflags
- Learn TCP flag combinations behind NULL, FIN and Xmas scans and the RST behaviour that identifies open ports
- Enumerate SMB with enum4linux, SNMP with snmpwalk and default community strings, LDAP with ldapsearch
- Memorize default ports for SSH 22, Telnet 23, SMTP 25, DNS 53, HTTP 80, POP3 110, NetBIOS 137 to 139, IMAP 143, SNMP 161, LDAP 389, HTTPS 443, SMB 445, RDP 3389, MySQL 3306, MSSQL 1433
- Complete the TryHackMe Nmap and Network Services rooms and repeat missed sections
12-14 hours this week
- Run OpenVAS or Nessus Essentials against Metasploitable 2 and read the full report, not just the critical findings
- Learn CVSS base metrics and how CVE, CWE and NVD relate to each other
- Crack sample hashes with John the Ripper and hashcat, including LM, NTLM, MD5 and SHA-512 crypt
- Practice Windows and Linux privilege escalation checks with WinPEAS and LinPEAS
- Study log clearing, alternate data streams, steganography and rootkit types, then answer 30 domain 3 questions
12-14 hours this week
- Classify Trojans, viruses, worms, fileless malware and APT stages, with one named example for each
- Capture ARP poisoning traffic in Wireshark on your lab network and identify the gratuitous ARP frames
- Learn DHCP starvation, MAC flooding, DNS poisoning and the switch countermeasures: port security, DHCP snooping, dynamic ARP inspection
- Study DoS categories: volumetric, protocol and application layer, plus SYN flood, Smurf, Slowloris and amplification
- Read the Snort rule syntax and be able to identify what a given rule detects
12-14 hours this week
- Study application-level hijacking: session fixation, session sidejacking, cross-site request forgery, predictable token generation
- Learn IDS evasion techniques: fragmentation, insertion, obfuscation, encryption, session splicing, and where snort and honeypots fit
- Compare low-interaction and high-interaction honeypots and know the detection giveaways
- Work through social engineering categories: phishing, spear phishing, whaling, vishing, smishing, pretexting, tailgating, dumpster diving, quid pro quo
- Answer 40 mixed domain 4 questions, which is the single heaviest domain at 30 of 125 marks
12-14 hours this week
- Complete the PortSwigger Web Security Academy paths for SQL injection, authentication and access control, which are free
- Run sqlmap against DVWA and read what each stage of the automation is actually doing
- Practice Burp Suite Community: intercept, repeater, intruder and decoder
- Study union-based, error-based, boolean blind, time-based blind and out-of-band SQL injection and be able to name each from a description
- Review the OWASP Top 10 2021 categories and map them to the blueprint web app sub-topics including web API, webhook and web shell attacks
12-14 hours this week
- Compare WEP, WPA, WPA2 and WPA3 by cipher, key length and known attack, and learn the Aircrack-ng suite tool by tool
- Study Android rooting, iOS jailbreaking, OWASP Mobile Top 10 and mobile device management controls
- Learn IoT protocols such as MQTT, CoAP, Zigbee and BLE, and OT protocols such as Modbus, DNP3 and Profinet
- Cover cloud shared responsibility, container escapes, serverless risks and metadata service abuse
- Memorize algorithm properties: AES block and key sizes, DES 56-bit key, RSA key exchange, ECC efficiency, MD5 128-bit and SHA-256 output lengths
14-16 hours this week
- Sit two full 125-question, 240-minute timed papers in one week under exam conditions
- Rebuild your per-domain accuracy table and spend all remaining revision on the two lowest domains
- Rehearse the pacing plan: 31 questions by minute 60, 63 by minute 120, 94 by minute 180
- Re-read the blueprint sub-domain bullets one final time and confirm every bullet triggers a recall
- Book the exam, confirm your voucher expiry date, and verify your ID matches the registration name exactly
Duration: 15 weeks
Hours/week: 8 hours
Daily: ~2 hours on weeknights
Weekends: 3-4 hours Saturday + Sunday
Study during lunch breaks and commute time. Use weekends for deeper study sessions and practice tests.
Duration: 20 weeks
Hours/week: 6 hours
Saturday: 4-5 hours of focused study
Sunday: 3-4 hours of practice tests
Longer timeline but sustainable. Review flashcards on weeknights for 15-20 minutes to maintain retention.
How long does it take to study for the CEH (Certified Ethical Hacker)?
Plan for 10 weeks of dedicated study at 12 hours per week (122 total hours). If studying while working full-time, extend to 15 weeks.
Can I pass the CEH (Certified Ethical Hacker) in 2 weeks?
It's unlikely for most candidates. The CEH (Certified Ethical Hacker) is rated "Hard" difficulty and typically requires 10 weeks of preparation. Rushing increases your risk of failing and paying the exam fee again.
How many hours a day should I study for CEH (Certified Ethical Hacker)?
Aim for 2-3 hours per day on weekdays. Quality matters more than quantity, use active recall and practice tests rather than passive reading.
Is CEH (Certified Ethical Hacker) hard to pass?
The CEH (Certified Ethical Hacker) is rated "Hard" difficulty with a pass rate of ~60%. Solid preparation over several months is recommended.
Ready to start your CEH (Certified Ethical Hacker) journey?
Get the complete exam guide with tips, resources, and practice questions.
View CEH (Certified Ethical Hacker) Guide