CEH v11 Exam Guide: Scope, Eligibility, Delivery, and a Practical Study Plan
CEH v11 validates foundational ethical-hacking knowledge across reconnaissance, vulnerability analysis, system and network attacks, web and cloud security, cryptography, and defensive countermeasures. It is intended for candidates building or formalizing hands-on information-security capability, especially those with some IT-security experience. This guide helps you decide whether the v11 route matches your goal, confirm the correct eligibility and delivery process, and turn the 20-module scope into a manageable study sequence without relying on leaked questions or memorization alone.
What does CEH v11 validate?
CEH v11 tests whether you understand the methods, tools, attack surfaces, and countermeasures used in an authorized ethical-hacking engagement. The official v11 listing describes a 20-module program covering more than 550 attack techniques, while the wider curriculum combines knowledge-based learning with practical lab work. Source: https://iclass.eccouncil.org/product/certified-ethical-hacker/
The credential is owned and created by EC-Council, as stated in the candidate handbook. That distinction matters when you plan your preparation: EC-Council’s eligibility, voucher, examination, and certification policies are the controlling requirements, while third-party courses and practice tests are study aids rather than substitutes for those policies. Source: https://www.eccouncil.org/wp-content/uploads/2023/02/CEH-Handbook-v4.0.pdf
The exam is not evidence that a candidate may attack systems without permission. Ethical hacking requires defined authorization, scope, rules of engagement, safe handling of findings, and appropriate reporting. Study every offensive technique alongside its purpose, limitation, detection opportunity, and mitigation.
Who should choose this exam?
CEH v11 is a reasonable fit for an IT or cybersecurity practitioner who wants a structured survey of ethical-hacking concepts and can connect attack techniques to network, system, application, and organizational risk. EC-Council recommends a minimum of 2 years of IT-security experience before attempting CEH; this is a recommendation, not a claim that every candidate has the same background. Source: https://ethicalhacking.eccouncil.org/
Candidates coming from networking, system administration, security operations, vulnerability management, or junior penetration-testing roles can usually organize their existing knowledge around the exam modules. A beginner can still study the material, but should expect to learn networking, operating-system basics, authentication, web applications, and security controls before attempting advanced attack topics.
Choose a different preparation starting point if you cannot yet explain TCP/IP behavior, common Windows and Linux administration concepts, basic web requests, access control, and the difference between a vulnerability, an exploit, a threat, and a control. Those gaps will make every later module slower.
Use the experience recommendation as a readiness check
Treat the recommended 2 years of IT-security experience as a diagnostic rather than a shortcut. If you have less experience, compensate with a longer foundation phase, controlled labs, and deliberate review of unfamiliar terminology. Do not schedule the exam simply because you have watched a course or collected notes.
Which skills and modules require the most attention?
The v11 curriculum moves from the ethical-hacking process and reconnaissance into scanning, enumeration, vulnerability analysis, system and malware topics, network interception, social engineering, denial of service, session attacks, perimeter evasion, web servers, web applications, databases, wireless, mobile, IoT and OT, cloud computing, and cryptography. Your study plan should preserve that progression because later techniques depend on earlier discovery and security fundamentals. Source: https://ethicalhacking.eccouncil.org/
Module 1 establishes information-security issues, ethical hacking, controls, relevant laws, and standard procedures. Modules 2 through 5 develop the discovery workflow: footprinting and reconnaissance, scanning networks, enumeration, and vulnerability analysis. These modules are the basis for deciding what a target exposes before attempting an attack.
Modules 6 through 12 cover system hacking, malware threats, sniffing, social engineering, denial of service, session hijacking, and evading IDS, firewalls, and honeypots. Study them as attack-and-defense pairs. For example, do not memorize a sniffing tool name without understanding what traffic exposure enables the attack and which encryption, segmentation, or monitoring decisions reduce the risk.
Modules 13 through 20 broaden the target environment: web servers, web applications, SQL injection, wireless networks, mobile platforms, IoT and OT, cloud computing, and cryptography. These areas are easy to leave until the end because they feel specialized. That is a mistake; reserve dedicated review time for them instead of treating them as a final vocabulary list.
Build a technique-to-countermeasure notebook
For each topic, record five items: the asset or protocol involved, the attacker’s objective, the observable weakness, the relevant tool or method, and the countermeasure. Add one sentence explaining when the technique would not apply. This format exposes shallow recognition and helps you distinguish similar attacks.
Do not infer blueprint percentages
The supplied official research does not provide CEH v11 domain-weight percentages. Therefore, this guide does not assign percentages to the 20 modules or compare bare percentages. Use the official examination information or candidate materials available when you register to confirm the current blueprint for the version you intend to take.
What are the CEH v11 examination details?
The supplied official examination information describes a knowledge exam as multiple choice, with 125 questions, a 4 hours duration, online delivery via the ECC exam portal, and a passing score ranging from 60% to 85%. Because the same official site also prominently presents newer CEH material, confirm that these details apply to the CEH v11 attempt you are scheduling before relying on them. Source: https://ethicalhacking.eccouncil.org/
The Pearson VUE voucher page separately describes Pearson VUE testing-center delivery, with the exam proctor physically present at the venue. It also says self-study candidates must apply for eligibility before purchasing a voucher, while candidates who completed official training must submit a Certificate of Attendance before purchasing the voucher. Source: https://store.eccouncil.org/product/ceh-vue-exam-voucher/
These statements describe different routes or examination information on official EC-Council properties. Do not assume that an online portal option and a Pearson VUE center option are interchangeable for your particular v11 registration. Check the authorization or voucher instructions attached to your candidate account and version.
The official v11 iClass package listing includes a certification exam and a CEH Practical Exam. That listing does not by itself establish that every CEH v11 candidate receives the same package components, so confirm what your selected purchase or training route includes before budgeting or planning labs. Source: https://iclass.eccouncil.org/product/certified-ethical-hacker/
Check version, route, and inclusions before paying
Before purchasing anything, write down the exact credential name, version, exam route, eligibility status, delivery method, and included resources. The official iClass catalog also contains current CEH material, including CEH v13, so a page that mentions CEH generally should not be treated as proof that it describes v11. Source: https://iclass.eccouncil.org/product/certified-ethical-hacker/
Voucher facts that affect scheduling
The official Pearson VUE voucher page lists the voucher at $1,199.00, says it is non-transferable, and states that it is valid for a year from its release date. It also states that orders received on working days are processed within 48 hours. Verify the live store page and applicable eligibility process before making a purchase because commercial terms can change. Source: https://store.eccouncil.org/product/ceh-vue-exam-voucher/
What is the difference between the knowledge and practical routes?
The knowledge exam measures recognition and understanding of ethical-hacking concepts, attack vectors, prevention procedures, and methodologies. The official practical-exam description states that the practical exam is optional and that it rewards a higher level of certification; the v11 package listing also includes a CEH Practical Exam, so confirm the relationship between your package and the certification level before selecting it. Source: https://ethicalhacking.eccouncil.org/
The practical examination is described as a 6 hours assessment containing 20 real-world challenges. That is a materially different preparation problem from answering multiple-choice questions: you must interpret evidence, choose a safe sequence, use tools correctly, and document what you discovered. Source: https://ethicalhacking.eccouncil.org/
If your immediate objective is the knowledge credential, prioritize the knowledge-exam scope first. If you intend to pursue the practical route, introduce timed, scenario-based lab work after you can perform the underlying tasks reliably. Do not use a practical challenge as a replacement for learning concepts such as authorization, cryptography, risk, and countermeasures.
Decide based on the role you want to perform
Choose the knowledge route as your first target when you need a broad credential and are still consolidating fundamentals. Add practical preparation when your role expects demonstrable technical execution or when the certification level you seek requires it. The official sources do not establish that passing one route automatically makes the other unnecessary, so confirm the exact certification path with EC-Council.
How should you prepare the 20 modules?
Use a three-pass method: learn the concept, perform a controlled task, and then retrieve the explanation without notes. This prevents a common failure mode in CEH preparation—recognizing a tool or attack name but being unable to identify its target, prerequisite, evidence, or defense. The official learning framework emphasizes knowledge training, hands-on practice, and applying learning in a mock engagement. Source: https://ethicalhacking.eccouncil.org/
On the first pass, follow the module order and create a short concept map. Link reconnaissance to scanning, scanning to enumeration, enumeration to vulnerability analysis, and vulnerability analysis to an authorized attack decision. For each later domain, link the attack to the relevant protocol, platform, application behavior, or control.
On the second pass, use an isolated lab or the authorized training environment. The official CEH material advertises 221 hands-on labs, 550 attack techniques, and more than 4,000 hacking and security tools. Those figures describe the official offering; they are not a requirement that you independently obtain every tool. Source: https://ethicalhacking.eccouncil.org/
On the third pass, close the notes and answer scenario prompts. Explain why one technique fits a situation and another does not. Then state the defensive implication. If you cannot explain the answer, mark the topic for review rather than guessing repeatedly until the option looks familiar.
Study offensive and defensive knowledge together
After every attack topic, answer four questions: What is being targeted? What condition makes the attack possible? What evidence might appear? Which control reduces exposure or limits impact? This habit is especially useful for SQL injection, session hijacking, wireless attacks, malware, cloud threats, and perimeter-evasion topics.
Use tools as evidence generators, not flashcards
A tool name is useful only when you understand its input, output, limitations, and ethical use. In your notes, pair each tool with the discovery or validation task it supports. Avoid collecting long command lists that you cannot interpret; the practical value lies in the reasoning around the result.
What should a realistic CEH v11 roadmap look like?
A workable roadmap has four stages: establish foundations, complete the discovery and attack modules, consolidate specialized environments and defenses, and finish with mixed review and authorized practice. Set the length of each stage according to your background and available study time rather than copying a fixed calendar. The sequence matters more than an artificial deadline.
Stage 1: establish the foundation
Start with Module 1 and review networking, operating systems, identity, access control, risk, security controls, and basic legal and procedural boundaries. Build a glossary in your own words. Your checkpoint is the ability to describe an ethical-hacking engagement from authorization through reporting without confusing reconnaissance, exploitation, and remediation.
Next, refresh the network and application behavior needed for later work: common protocols, ports and services, name resolution, authentication and sessions, operating-system permissions, database interaction, and basic encryption concepts. Keep this phase active; use small authorized exercises instead of reading only.
Stage 2: master the discovery workflow
Study Modules 2 through 5 as one investigation: footprinting and reconnaissance, scanning networks, enumeration, and vulnerability analysis. Practice turning observations into hypotheses, then validating those hypotheses safely. Record false positives and explain why a discovered service does or does not represent a meaningful risk.
At the end of this stage, perform a mock assessment against a permitted lab target. Begin with scope and asset inventory, collect information, identify exposed services, assess vulnerabilities, and write a concise finding with impact and remediation. EC-Council describes applying learning in a mock ethical-hacking engagement as part of its framework. Source: https://ethicalhacking.eccouncil.org/
Stage 3: cover attacks and target environments
Work through Modules 6 through 12, then Modules 13 through 20. Use a rotating pattern: learn the attack, test the concept in a safe environment, study detection and countermeasures, and revisit the associated terminology the next day. This keeps the plan from becoming a long sequence of disconnected modules.
Give extra review to transitions between domains. A web application may depend on a web server, database, session mechanism, identity store, cloud service, or cryptographic control. Questions framed around those relationships are harder than isolated definitions, so practice explaining the complete path from weakness to consequence.
Stage 4: consolidate and schedule
Create a weakness log from practice results. Group errors by cause: missing concept, confusing similar terms, misreading the scenario, forgetting a countermeasure, or spending too long on a question. Review the cause first, then the fact. Schedule only after your results show stable understanding across every module, not just strength in networking or familiar tools.
In the final review, use mixed questions and short scenario explanations rather than rereading the entire course. Revisit legal and procedural material, terminology, attack ordering, and defensive responses. Confirm your eligibility, version, delivery route, voucher status, identification requirements, and appointment details from the official instructions before the exam.
How can you use labs without creating unsafe habits?
Practice only in systems you own or are explicitly authorized to test. Use isolated virtual machines, an approved Cyber Range, or the official lab environment; never transfer an exercise to a public target because it appears vulnerable. Lab work should develop repeatable reasoning—scope, observe, test, verify, clean up, and report—not reckless tool execution.
A useful lab record
For every exercise, record the objective, authorized target, starting assumptions, commands or tool categories used, observable result, interpretation, cleanup action, and defensive lesson. Do not save unnecessary credentials or sensitive data. When an exercise fails, document what the failure taught you about prerequisites or limitations.
Use the official practical ecosystem deliberately
The official material describes hands-on labs and a Cyber Range for applying ethical-hacking skills. The v11 single-video package listing includes six months of CyberQ Labs access and one year of access to the online self-paced streaming course. Treat those as package-specific inclusions and verify them on the product you are actually considering. Source: https://iclass.eccouncil.org/product/certified-ethical-hacker-ceh-single-video-course/
Which preparation mistakes cost candidates time?
The most expensive mistakes are studying only tool names, postponing weak modules, confusing current CEH pages with v11 requirements, and buying a voucher before confirming eligibility and delivery. Correct these by tracking evidence: every topic should have a concept explanation, a controlled application, a countermeasure, and a clear source for any official exam detail.
Mistake: treating a question bank as the curriculum
Practice questions can reveal gaps, but they cannot replace the official objectives or lab reasoning. Avoid dumps, leaked questions, and claims that memorization guarantees a pass. Instead, investigate why each answer is correct, why the alternatives are wrong, and what change in the scenario would alter the answer.
Mistake: learning exploitation without reporting
A technically correct action is incomplete if you cannot state the affected asset, evidence, impact, likelihood context, and remediation direction. Add a short finding report to your study routine. This also helps you separate a scanner result from a confirmed vulnerability.
Mistake: ignoring version ambiguity
EC-Council’s current public training page highlights CEH v13, while the iClass catalog contains a CEH v11 listing. Do not combine current-version claims with v11 preparation assumptions. Save the exact v11 product or candidate information you are using and confirm the exam version before registration. Sources: https://ethicalhacking.eccouncil.org/ and https://iclass.eccouncil.org/product/certified-ethical-hacker/
Mistake: scheduling before checking administration rules
Self-study eligibility, official-training documentation, voucher validity, testing-center delivery, and handbook policies can affect your schedule. Read the voucher instructions and candidate handbook before purchase. The handbook covers attempts, retakes and extensions, credential renewal, continuing education, accommodations, and appeals. Source: https://www.eccouncil.org/wp-content/uploads/2023/02/CEH-Handbook-v4.0.pdf
How should you manage the exam session?
For the knowledge exam, use a two-pass approach: answer clear questions first, flag uncertain items, and return to scenarios that require comparison or calculation. Protect time for review, but do not let one unfamiliar tool or term consume the session. For a practical attempt, read the complete challenge, preserve evidence, and follow the authorized task sequence rather than rushing to the first apparent exploit.
Before booking
Confirm the exact version and exam type; verify whether your route uses the ECC exam portal or Pearson VUE; complete the required eligibility step; check what documentation is needed; and confirm voucher validity. If you select official training, retain the Certificate of Attendance if the voucher instructions require it.
On the final study day
Do not attempt to learn an entire unfamiliar module overnight. Review your error log, attack-versus-countermeasure pairs, legal and procedural boundaries, and the relationships among reconnaissance, scanning, enumeration, vulnerability analysis, exploitation, and reporting. Prepare the identification and appointment information required by the delivery channel you confirmed.
What should you do after completing the exam or course?
Use the result and your study record to choose the next skill, not merely the next credential. If reconnaissance and vulnerability analysis were strong but cloud, mobile, web, or cryptography topics were weak, build that domain through authorized labs and focused reading. If practical execution was the weakness, repeat the engagement workflow with better evidence handling and reporting.
Keep the official policy source available
The candidate handbook is the right place to check certification administration topics such as retakes, extensions, renewal, continuing education, accommodations, and appeals. Those policies should not be inferred from a training provider’s marketing page or from another candidate’s experience. Source: https://www.eccouncil.org/wp-content/uploads/2023/02/CEH-Handbook-v4.0.pdf
Use continuing practice responsibly
EC-Council describes continuing activities that expose learners to new tools, attack vectors, and emerging vulnerabilities while supporting continuing education and keeping skills current. The official site also describes year-long access to 12 CTF challenges in its CEH Engage offering. Verify whether such access is included in your selected v11 package before treating it as part of your plan. Source: https://ethicalhacking.eccouncil.org/
What are the next three actions?
First, confirm that you are preparing for CEH v11 rather than a newer CEH listing. Second, map the 20 modules to your own strengths and gaps, then begin with foundations and the discovery workflow. Third, verify eligibility and delivery before buying or scheduling. Those actions prevent the most avoidable errors: studying the wrong scope, neglecting prerequisites, and purchasing an unusable route.
A practical checklist
Save the official v11 product page and candidate handbook. Confirm whether you are using self-study or official training. Complete the applicable eligibility process. Decide whether the knowledge exam alone or a practical route matches your objective. Build a module tracker with concept, lab, countermeasure, and review columns. Start an error log on your first practice session.
When the tracker shows consistent coverage, review the live official voucher and scheduling instructions, confirm the version and delivery method, and schedule only when the appointment fits the validity period and your preparation evidence. Keep all testing to authorized environments and use the credential as a foundation for disciplined security work, not as permission to attack systems.
Conclusion
CEH v11 preparation is most effective when treated as a connected ethical-hacking workflow rather than a list of attack names. Confirm the version and administrative route first, build fundamentals before tools, study each technique with its evidence and countermeasure, and use authorized labs to test your reasoning. The official sources should settle eligibility, delivery, voucher, package, and certification-policy questions; your study record should settle whether you are ready to schedule.
Related exams
- 212-89 exam — EC Council Certified Incident Handler (ECIH v3)
- 312-39 exam — Certified SOC Analyst (CSA)
- 312-49v10 exam — Computer Hacking Forensic Investigator (CHFI-v10)
- 312-50v11 exam — Certified Ethical Hacker Exam (CEH v11)
- 312-85 exam — Certified Threat Intelligence Analyst (CTIA)
- 412-79v10 exam — EC-Council Certified Security Analyst (ECSA) V10