Certified Ethical Hacker Exam Guide: What to Study, How to Plan, and When to Schedule
The Certified Ethical Hacker (CEH) exam validates knowledge of information-security threats, attack vectors, detection, prevention, procedures, and ethical-hacking methodologies. It is designed for cybersecurity candidates who want a structured foundation in offensive security, as well as practitioners who need to demonstrate that foundation to employers or government-oriented organizations. This guide helps you decide whether your current experience is sufficient, whether to prepare for the knowledge exam alone or both assessments, and how to turn the CEH v13 modules and blueprint into a workable study plan.
What does the CEH exam validate?
CEH tests whether you can recognize how attacks work and select appropriate defensive or ethical-hacking responses. The official knowledge-exam description includes information-security threats and attack vectors, attack detection, attack prevention, procedures, and methodologies. The certification is therefore broader than memorizing tool names: preparation should connect an attack, its target, its indicators, its likely outcome, and its countermeasure.
EC-Council describes CEH Version 13 as covering 20 learning modules and more than 550 attack techniques. The course outline moves from ethical-hacking fundamentals and reconnaissance through scanning, enumeration, vulnerability analysis, system hacking, malware, sniffing, social engineering, denial of service, session hijacking, evasion, web servers, web applications, wireless, mobile, IoT and OT, cloud computing, and cryptography.
The training also incorporates AI-driven ethical-hacking topics, including ChatGPT-powered AI tools for ethical hackers. Treat those topics as part of the current version’s learning scope rather than as a reason to ignore core networking, operating-system, web, and cryptography concepts. AI can accelerate analysis, but it does not replace authorization, evidence handling, or sound technical judgment.
Who should take CEH, and who should wait?
CEH is a reasonable fit for an IT or cybersecurity professional who needs a broad ethical-hacking foundation and can already work comfortably with basic networks, operating systems, and security terminology. EC-Council recommends a minimum of 2 years of IT security experience before attempting CEH. That recommendation is practical guidance, not a claim that every candidate has the same background or learning path.
Candidates with security operations, network administration, systems administration, vulnerability management, incident response, or junior penetration-testing experience can use CEH to organize knowledge across several domains. It can also support roles where employers or government programs recognize the credential; EC-Council states that CEH meets U.S. DoD 8140 requirements and is accepted for college credit by many institutions.
A beginner should not interpret the certification’s broad module list as permission to skip fundamentals. If you cannot explain TCP/IP behavior, authentication, common operating-system controls, DNS, HTTP, access control, or basic scripting, begin with those foundations. You may still choose CEH, but allow additional preparation time and use labs to build understanding rather than relying on vocabulary review.
Check the current eligibility process before buying an exam attempt. EC-Council’s self-study option states that an eligibility application is required. Training routes and eligibility treatment can vary, so confirm the current requirement in the official candidate materials for your location and route.
What are the CEH exam formats and delivery details?
The CEH knowledge exam is listed as 125 multiple-choice questions with a four-hour duration and online delivery through the ECC exam portal. EC-Council lists a passing-score range of 60% to 85%, so candidates should not plan around a single assumed cutoff. Verify the current authorization, delivery instructions, and score policy before scheduling.
The practical exam is described by EC-Council as a six-hour assessment containing 20 real-world challenges. It uses a live corporate network of virtual machines and applications, with candidates expected to uncover vulnerabilities by applying ethical-hacking skills. This is a different preparation problem from the knowledge exam: you must locate, interpret, and document findings while working through a scenario.
EC-Council presents the practical exam as optional but states that taking both the knowledge and practical exams can earn the CEH Master certification in CEH Version 13. Decide early whether that outcome matters to your career plan. If you need only the knowledge credential for a stated job requirement, concentrate first on the knowledge blueprint; if you want the Master pathway, build practical work into the same study cycle.
EC-Council’s online-training page lists both CEH exams as ANAB ISO/IEC 17024 and U.S. DoD 8140 accredited. Accreditation or recognition does not remove the need to confirm an employer’s exact requirement, especially where a role specifies a particular certification level or current version.
How should you interpret the passing-score information?
Do not treat 60% to 85% as a target score or assume that one fixed percentage applies to every attempt. The official exam-details material presents the knowledge-exam passing score as a range. Your preparation goal should be consistent mastery across the blueprint, not optimization around a guessed threshold.
How is the knowledge blueprint weighted?
Use the blueprint to allocate study time, but keep each percentage attached to its domain. The CEH Exam Blueprint v5.0 assigns Reconnaissance Techniques 17% weight, System Hacking Phases and Attack Techniques 15% weight, Web Application Hacking 14% weight, and the Information Security and Ethical Hacking Overview domain seven questions and 6% weight.
These published facts identify several important areas, but they do not by themselves describe every domain in the exam. Download and read the current blueprint rather than reconstructing the exam from a partial list. The blueprint is the controlling study map for objectives, while the course modules provide broader instructional context.
A sensible allocation is to give the heaviest review blocks to reconnaissance, system hacking, and web application hacking, then use shorter recurring sessions for the remaining objectives. Do not turn the weights into a license to neglect smaller domains. A missed cluster in cryptography, wireless, cloud, legal issues, or defensive controls can expose a knowledge gap even if your preferred technical topic is strong.
What should you know in the highest-weight areas?
For Reconnaissance Techniques, practice distinguishing passive information gathering from active discovery, selecting an appropriate source or technique, and identifying what a finding enables in the next phase. Your notes should connect reconnaissance output to scan selection, target profiling, and risk rather than treating it as an isolated list of commands.
For System Hacking Phases and Attack Techniques, organize material around the sequence of obtaining access, escalating or maintaining control, and covering tracks, while keeping the legal and defensive context visible. Review authentication weaknesses, malware-related concepts, steganography, countermeasures, and the difference between an attack technique and evidence that the technique succeeded.
For Web Application Hacking, learn the purpose and defensive consequence of common web attacks. The official module includes a web-application hacking methodology, attacks, auditing, and countermeasures. Study SQL injection, cross-site scripting, cross-site request forgery, LDAP injection, authentication bypass, information disclosure, and remote-code-execution concepts as related classes of weakness, not as interchangeable labels.
Which CEH modules deserve hands-on practice?
Prioritize activities that force you to make a decision and observe a result. EC-Council lists more than 221 hands-on labs, says more than half of CEH v13 training time is devoted to labs, and lists more than 4,000 hacking and security tools in the training materials. The useful lesson is not to memorize thousands of tools; it is to become comfortable choosing a tool, interpreting output, and explaining a countermeasure.
Start with a controlled network and a small number of targets. Practice reconnaissance, scanning, enumeration, vulnerability identification, web testing, traffic observation, and basic reporting. Record the target condition, action taken, evidence observed, security implication, and remediation. This format builds a reusable knowledge base and discourages unsafe experimentation against systems you do not own or have explicit permission to test.
The CEH framework identifies five ethical-hacking phases: reconnaissance, scanning, gaining access, maintaining access, and covering tracks. Use those phases as a lab checklist, but study them within an authorized engagement. Covering tracks is an exam and methodology concept; it is not permission to erase logs, alter evidence, or interfere with production monitoring.
The training environment described by EC-Council includes pre-configured targets, vulnerable websites, vulnerable unpatched operating systems, fully networked environments, and a cloud-based cyber range. If you use another lab provider, seek comparable isolation and deliberately vulnerable systems. Never substitute a public website, workplace system, or third-party infrastructure for an authorized target.
How should you use a lab notebook?
A useful lab record has five fields: objective, setup, action, evidence, and defense. For example, after a web test, write what weakness class you investigated, what response or behavior indicated the issue, what an attacker could gain, and which validation or remediation would reduce the risk. The notebook becomes both a revision aid and a practical troubleshooting record.
What study sequence works best for CEH?
Study in a dependency order rather than following whichever topic looks most interesting. Build foundations first, then move through the engagement lifecycle, then concentrate on application and platform-specific attacks, and finally consolidate defenses, law, cryptography, and mixed scenarios. This sequence makes later modules easier because you understand where a technique fits and what evidence it produces.
Phase one: establish the operating base. Review information-security principles, ethical-hacking rules, laws and standard procedures, networking layers and devices, common protocols, operating-system concepts, authentication, access control, and basic cryptography. Make a glossary only for terms you can explain in a scenario. A definition without a use case is a weak revision note.
Phase two: work through reconnaissance, scanning, enumeration, and vulnerability analysis. For every technique, answer four questions: What does it discover? What prerequisite does it require? What result would confirm the finding? What control or countermeasure reduces exposure? This approach turns passive reading into a decision process.
Phase three: study system hacking, malware, sniffing, social engineering, denial of service, session hijacking, and evasion. Compare similar terms in tables, especially where the exam may test a distinction between attack type, tool behavior, protocol behavior, and defense. Review both the attacker’s objective and the defender’s observable signal.
Phase four: focus on web servers, web applications, wireless, mobile, IoT and OT, cloud computing, and cryptography. These topics have different technologies and failure modes, so avoid a single generic checklist. For example, web testing emphasizes requests, input handling, sessions, and application logic; wireless testing requires attention to standards, encryption, access points, and radio-specific exposure.
Phase five: run mixed review. Combine a reconnaissance question with a scanning decision, a vulnerability with a remediation, or an attack with its evidence and legal constraint. Mixed practice reveals whether you understand relationships between modules rather than merely recognizing isolated flashcards.
What should a practical six-week roadmap look like?
A six-week plan is a planning model, not an official CEH schedule. Adjust it for your background, available lab access, and whether you are preparing for the practical assessment. Each week should include blueprint reading, module study, hands-on work, retrieval practice, and an error review. Schedule only after your weak areas are visible and your exam authorization is confirmed.
Week one: read the current blueprint and candidate handbook, check eligibility, and assess your baseline. Review the overview material, security principles, ethical-hacking phases, networking, and operating-system fundamentals. Create a topic matrix with three columns: confident, uncertain, and not yet studied. Do not spend the entire week making notes; complete a small authorized lab to establish how you learn from evidence.
Week two: complete reconnaissance, scanning, enumeration, and vulnerability-analysis study. Practice selecting information sources and scanning approaches, then interpret results. At the end of the week, explain a complete path from an initial target profile to a defensible vulnerability hypothesis. Review every incorrect practice question by objective, not only by answer choice.
Week three: study system hacking, malware, sniffing, social engineering, denial of service, and session hijacking. Use diagrams for attack flows and countermeasure mappings. In labs, focus on safe observation and validation. For each topic, write a short response to the question, “What would a defender see, and what should the defender do next?”
Week four: study IDS, firewalls, honeypots, web servers, and web applications. Give additional attention to the blueprint’s Web Application Hacking 14% weight. Practice reading HTTP behavior, identifying classes of input or authentication weakness, and pairing a finding with a remediation or verification step. Keep all testing inside an explicitly authorized environment.
Week five: cover wireless, mobile, IoT and OT, cloud computing, and cryptography. Revisit the blueprint’s larger areas, including Reconnaissance Techniques 17% weight and System Hacking Phases and Attack Techniques 15% weight, but also test every smaller topic in your matrix. Complete timed mixed-question sessions and maintain an error log containing the objective, mistaken assumption, correct reasoning, and follow-up lab.
Week six: simulate the knowledge-exam conditions using the official format as your planning reference: 125 multiple-choice questions and four hours. The purpose is pacing and diagnosis, not predicting a real score. Review concepts you missed, not just the answer key. If taking the practical exam, add scenario blocks in which you enumerate a target, investigate a finding, capture evidence, and write a concise conclusion.
If your baseline shows major gaps, extend the plan instead of compressing the final review. A calendar deadline is not evidence of readiness. The better scheduling decision is to move the exam when your error log shows recurring understanding rather than unfamiliarity with one chapter.
How should you prepare differently for the practical exam?
The practical exam rewards a repeatable investigation process. You must work through real-world challenges in a live virtual environment, so prepare to identify the target, gather evidence, test a hypothesis, and explain the result. Tool familiarity matters, but disciplined enumeration and documentation matter more than launching commands without a clear question.
Use a four-part loop in practice. First, define the objective and scope. Second, enumerate methodically and save relevant output. Third, validate the suspected weakness without causing unnecessary impact. Fourth, record the evidence and the defensive implication. If a path fails, document what the result means and choose the next justified test instead of randomly changing tools.
Practice switching between breadth and depth. Early in a scenario, inspect the environment broadly so you do not miss an exposed service or application path. Once evidence points to a likely weakness, narrow the test and preserve proof. This is more reliable than spending the entire attempt on the first interesting service.
EC-Council describes its practical environment as a four-phase engagement that uses flags to assess critical thinking and applied knowledge. If your preparation includes a comparable capture-the-flag or cyber-range exercise, focus on reasoning and evidence. Do not assume that success in an unrelated challenge predicts the exact practical experience or content of the CEH assessment.
Prepare a compact personal checklist: scope, target identification, ports and services, application paths, credentials or access assumptions, evidence capture, remediation notes, and final review. The checklist should support your thinking, not replace it.
Which mistakes make CEH preparation inefficient?
The most expensive preparation mistakes are usually planning mistakes: studying tools without objectives, ignoring the blueprint, postponing labs, and treating every practice question as a memory test. Correct those behaviors early. A candidate who can explain why an answer is correct and why the alternatives fail is building stronger exam judgment than a candidate who only tracks a percentage.
Do not memorize isolated port numbers, scan names, attack labels, or tool switches without understanding the protocol or weakness involved. Use comparison notes instead: what the technique targets, what it reveals, what prerequisite it needs, how it differs from a neighboring technique, and which defense addresses it.
Do not let the module count become a checklist race. Finishing a video or chapter is not the same as being able to apply the objective. After each study block, close the material and reconstruct the attack flow from memory. Then verify the reconstruction and use a lab to resolve any uncertainty.
Do not rely on unauthorized testing as practice. Ethical hacking requires permission and defined scope. Use EC-Council’s cyber range or another deliberately vulnerable environment, and keep tools and targets isolated. Exam preparation should improve judgment about boundaries, not normalize risky behavior.
Do not schedule because one mock set felt easy. Review the distribution of errors, especially repeated errors in high-weight domains and errors caused by confusing similar concepts. A readiness decision should consider breadth, reasoning, and practical execution if you intend to attempt both exams.
Do not use exam dumps or leaked questions. They cannot establish legitimate competence, may be inaccurate or outdated, and do not prepare you to investigate a live scenario. Use authorized courseware, the current blueprint, labs, and honest practice instead.
How should you choose training and budget for the exam?
Choose the least expensive preparation route that still gives you a current blueprint, credible explanations, and a controlled lab environment you will actually use. EC-Council lists on-demand, live-online, and other training options, while its self-study information says materials are available for purchase and an eligibility application is required for the exam. Compare what each package includes before treating a course price as the total cost.
The official North America page lists a single on-demand certification course starting at $1,699 and a single live-online certification course starting at $2,499. Those are listed course starting prices, not a universal CEH exam cost or a promise that the same pricing applies in every region. Confirm the current price, taxes, voucher terms, eligibility fees, and lab access directly with EC-Council before purchasing.
Funding may affect the route you choose. EC-Council says payment plans, discounts, and military or tuition assistance may be available. It also describes Army Credentialing Assistance and reimbursement options for certain military and veteran programs. Eligibility and coverage are program-specific, so verify the current rules with the relevant provider rather than assuming assistance will cover every component.
If you are self-studying, make a resource audit before applying: current blueprint, candidate handbook, module coverage, authorized labs, practice-question source, and a plan for resolving incorrect answers. If a provider cannot explain how its material maps to the current objectives, treat that as a reason to investigate further.
What should you verify before scheduling?
Before scheduling, confirm the exam version, eligibility route, delivery method, identification and technical requirements, cancellation or rescheduling rules, and whether you are booking the knowledge exam, the practical exam, or both. These administrative details can change, and the Candidate Handbook covers attempting the exam, retakes and extensions, special accommodations, certification policy, renewal, and continuing education.
Use the current CEH Candidate Handbook as the administrative checklist. The supplied handbook is dated July 1, 2025, but a dated document should still be checked against the latest official candidate information when you schedule. Pay particular attention to retake conditions and extensions if your preparation or eligibility timeline is uncertain.
The official knowledge-exam material identifies online delivery through the ECC exam portal. A retake product page separately describes remote proctoring by the RPS team and limits that product to candidates approved through EC-Council’s application process. Do not assume that the retake route, initial attempt, and practical assessment use identical procedures.
If you need accommodations, request them through the official process before booking. Do not wait until the appointment date to raise an administrative requirement. Keep confirmation emails, eligibility approval, voucher details, and scheduling information together in one record.
What should you do in the final seven days?
The final week should reduce uncertainty, not introduce a new library of tools. Re-read your error log, revisit the blueprint, complete short targeted labs, and rehearse the order in which you will approach unfamiliar questions or scenarios. Protect enough time for sleep and administrative checks; last-minute cramming is a poor substitute for a stable process.
Create one-page comparison sheets for commonly confused ideas: reconnaissance versus scanning, detection versus prevention, authentication versus authorization, passive versus active techniques, vulnerability evidence versus exploitation, and attack technique versus countermeasure. Use your own explanations. If you cannot state the distinction without looking it up, schedule a focused review.
For the knowledge exam, practice eliminating distractors by identifying the question’s objective and constraints. Ask whether it wants a phase, technique, indicator, tool category, vulnerability, or defense. For the practical exam, rehearse evidence capture and concise reporting. In both cases, avoid changing answers solely because a question feels difficult.
Complete the scheduling and equipment checks required by the official delivery route. Confirm the correct appointment, required identification, environment, and contact procedure from current EC-Council instructions. Keep the handbook and official support details accessible, but do not assume an unofficial checklist overrides them.
What should you do after a weak practice result or failed attempt?
Use a weak result as a diagnostic map. Group misses by blueprint objective, then separate knowledge gaps from reading errors, pacing problems, and lab-execution problems. A retake should follow corrective study, not simply another purchase. Rebuild the weakest two or three areas first, verify them with labs or explanation, and then return to mixed practice.
If the problem was breadth, resume module-by-module review and use spaced retrieval. If it was application, replace passive reading with controlled scenarios. If it was pacing, practice short timed blocks and learn when to mark a question for later. If it was administrative, review the Candidate Handbook and official retake policy before selecting a new appointment.
EC-Council’s handbook includes retakes and extensions, and its store lists a retake voucher for candidates approved through the relevant application process. Because eligibility, approval, voucher validity, and policy conditions are administrative matters, confirm the current terms directly before paying or scheduling.
What is the most practical next action?
Download the current blueprint and Candidate Handbook, check whether your experience and eligibility route fit, and perform a short baseline across every listed objective. Then choose a study path based on the gap: foundations first for newcomers, blueprint-led review for experienced practitioners, or lab-heavy preparation for anyone pursuing the practical assessment and CEH Master outcome.
Build a simple decision record with four entries: target exam or exams, current weak domains, lab environment, and intended scheduling window. Revisit it after your first full pass through the modules. If your weaknesses are concentrated in reconnaissance, system hacking, or web application hacking, give those domains deliberate priority while still sampling the full blueprint.
Finally, schedule through the official route only when you can explain the main attack and defense relationships, complete authorized investigations methodically, and identify the administrative conditions of your attempt. CEH preparation is strongest when the credential decision, study sequence, and lab practice all point toward the same role or next career step.
Conclusion
CEH preparation should produce more than recognition of attack terminology. It should help you reason from target and evidence to technique, impact, and countermeasure inside an authorized engagement. Use the current blueprint for coverage, the official modules for structure, labs for application, and the Candidate Handbook for scheduling decisions. Decide separately whether the knowledge exam meets your goal or whether the practical assessment and CEH Master pathway justify additional scenario-based preparation.
Related exams
- 312-38 exam — Certified Network Defender (CND)
- 312-75 exam — Certified EC-Council Instructor (CEI)
- 312-76 exam — Disaster Recovery Professional Practice Test
- EC0-350 exam — Ethical Hacking and Countermeasures V8