Certified Ethical Hacker (CEH): Complete Guide 2025
312-50
The Certified Ethical Hacker (CEH) certification from EC-Council validates your ability to assess the security posture of an organization by identifying vulnerabilities using the same knowledge and tools as a malicious hacker — but in a lawful and legitimate manner. Structured across 20 learning modules and covering more than 550 attack techniques, CEH gives you the core knowledge to succeed as a cybersecurity professional.
Exam Details
Resources
Everything you need to pass
Comprehensive preparation materials for your Certified Ethical Hacker (CEH) exam
Exam Content
Exam Domains & Topics
Master these 20 domains to pass your exam
Introduction to Ethical Hacking
Fundamentals of information security, ethical hacking concepts, cyber kill chain methodology, MITRE ATT&CK framework, and relevant laws and standards.
Footprinting and Reconnaissance
Techniques and tools for gathering information about target networks, including OSINT, DNS footprinting, and social engineering reconnaissance.
Scanning Networks
Network scanning techniques for host, port, service, and OS discovery, including methods to bypass IDS and firewalls.
Enumeration
Enumerating network resources including NetBIOS, SNMP, LDAP, NFS, DNS, SMTP, and SMB services.
Vulnerability Analysis
Identifying security loopholes using vulnerability scoring systems, databases, scanning tools, and AI-powered assessment.
System Hacking
System hacking methodologies including password cracking, privilege escalation, steganography, and covering tracks.
Malware Threats
Types of malware including trojans, viruses, worms, ransomware, fileless malware, and APTs with static and dynamic analysis.
Sniffing
Packet-sniffing techniques including MAC flooding, ARP poisoning, MITM attacks, DNS poisoning, and countermeasures.
Social Engineering
Social engineering concepts and techniques including phishing, impersonation, identity theft, and AI-powered attacks.
Denial-of-Service
DoS and DDoS attack techniques, botnet operations, and detection/protection strategies.
Session Hijacking
Session hijacking techniques at application and network levels including TCP/IP hijacking, session ID compromise, and countermeasures.
Evading IDS, Firewalls, and Honeypots
Techniques for evading intrusion detection systems, firewalls, and honeypots, and related countermeasures.
Hacking Web Servers
Web server attack methodology including reconnaissance, DNS hijacking, web cache poisoning, and server hardening.
Hacking Web Applications
Web application hacking methodology covering OWASP Top 10, API security, web service attacks, and security testing.
SQL Injection
SQL injection attack techniques, evasion methods, and countermeasures for protecting database-driven applications.
Hacking Wireless Networks
Wireless network security including encryption cracking, Bluetooth hacking, and wireless attack countermeasures.
Hacking Mobile Platforms
Mobile platform attack vectors for Android and iOS, mobile device management, and mobile security guidelines.
IoT and OT Hacking
IoT and Operational Technology attack surfaces, vulnerabilities, hacking methodologies, and security countermeasures.
Cloud Computing
Cloud computing concepts, threats, attacks on cloud services (AWS, Azure, GCP), and cloud security best practices.
Cryptography
Encryption algorithms, PKI, digital signatures, cryptanalysis techniques, and cryptographic attack countermeasures.
Who Should Take This Exam?
- Cybersecurity professionals looking to validate ethical hacking skills
- IT administrators wanting to understand offensive security
- Penetration testers seeking industry-recognized certification
- Security auditors and consultants
- Network engineers transitioning to security roles
Study Timeline
8-12 weeks
Recommended duration
Foundation · Weeks 1-2
Review exam objectives & core concepts
Deep Dive · Weeks 3-6
Study each domain with hands-on labs
Practice & Review · Weeks 7-8
Take practice exams & target weak areas
Career
Career Opportunities
Roles and salary potential for Certified Ethical Hacker (CEH) certified professionals
Related Job Titles
$98,000
Average Annual Salary
From the Blog
Related Articles
Guides and insights for Certified Ethical Hacker (CEH) professionals
Is CompTIA Security+ Worth It in 2026? Honest ROI, Salary, and Job Demand Analysis
CompTIA Security+ remains one of the most recognized entry-level cybersecurity certifications in 2026, but that doesn’t mean it’s the right move for everyone. This guide breaks down the real value of Security+, including exam cost, salary impact, DoD relevance, job demand, and when the certification delivers a strong return on investment.
Cybersecurity Career Path 2025: From Beginner to Expert
Wondering how to break into cybersecurity or level up your existing career? This comprehensive guide maps out the entire cybersecurity career path from complete beginner to senior expert, including certifications, salaries, and the exact steps successful professionals take.
Security Plus vs CEH: Which Certification is Right for You in 2025?
Torn between Security+ and CEH? This comprehensive guide breaks down everything from salary expectations to exam difficulty, helping you choose the cybersecurity certification that aligns with your career goals in 2025.
Compare
Certification Comparisons
See how Certified Ethical Hacker (CEH) compares to other certifications
Prerequisites
Two years of work experience in Information Security or attend official EC-Council training.
Certified Ethical Hacker (CEH) FAQs
Common questions about the 312-50 certification exam
The Certified Ethical Hacker (CEH) is a professional certification offered by EC-Council that validates your expertise in the relevant technology domain. The exam code is 312-50. This certification demonstrates your ability to design, implement, and manage solutions using EC-Council technologies.
The Certified Ethical Hacker (CEH) exam typically contains 125 questions. These questions are a mix of multiple-choice and scenario-based questions designed to test both theoretical knowledge and practical application.
The passing score for the Certified Ethical Hacker (CEH) exam is 70%. Note that EC-Council uses a scaled scoring system, so focus on understanding all exam domains thoroughly rather than just achieving the minimum score.
The Certified Ethical Hacker (CEH) exam duration is 240 minutes (4 hours). This includes time for reviewing your answers. We recommend practicing with timed mock exams to manage your time effectively.
The Certified Ethical Hacker (CEH) exam costs $1,199 USD. Prices may vary by region and are subject to change. EC-Council occasionally offers discounts or voucher programs for certification exams.
The Certified Ethical Hacker (CEH) certification is valid for 3 years. To maintain your certification, you'll need to recertify before it expires, either by passing the current exam version or through EC-Council's continuing education program.
While EC-Council doesn't always require formal prerequisites, we recommend having hands-on experience with the relevant technologies. Familiarity with core concepts and practical experience will significantly improve your chances of passing the exam.
Yes, the Certified Ethical Hacker (CEH) exam is proctored and can be taken either at a testing center or online through remote proctoring. Online proctoring allows you to take the exam from home while being monitored via webcam. Ensure you have a quiet, private space with a stable internet connection if choosing the online option.
If you don't pass the Certified Ethical Hacker (CEH) exam on your first attempt, you can retake it. EC-Council typically has a waiting period between attempts (usually 14 days for the first retake). Use this time to review the areas where you struggled and take additional practice exams.
To prepare for the Certified Ethical Hacker (CEH) exam, we recommend: 1) Review the official exam guide and objectives, 2) Gain hands-on experience with the technologies, 3) Use practice exams to identify knowledge gaps, 4) Study each exam domain thoroughly, and 5) Join study groups or forums to discuss challenging topics with other candidates.
About the Certified Ethical Hacker (CEH) Certification
The Certified Ethical Hacker (CEH) (312-50) is a associate-level certification offered by EC-Council. This certification validates your expertise in cybersecurity and is recognized globally by employers seeking qualified professionals. The exam consists of 125 questions to be completed in 240 minutes, with a passing score of 70%. The exam fee is $1,199 USD, and the certification is valid for 3 years.
Why Get Certified Ethical Hacker (CEH) Certified?
- Career Advancement: Certified professionals earn an average of $98,000 per year. EC-Council-certified professionals are among the most sought-after in the cybersecurity industry.
- Industry Recognition: EC-Council certifications are respected worldwide by employers, demonstrating verified competency in cybersecurity technologies and practices.
- Skill Validation: The Certified Ethical Hacker (CEH) exam rigorously tests your knowledge across 20 domains, ensuring you have the practical skills employers demand.
Certified Ethical Hacker (CEH) Exam Format & Details
The 312-50 exam is designed to test both theoretical knowledge and practical application. Candidates are given 240 minutes to complete the exam, which contains approximately 125 questions. A score of 70% is required to pass. As an associate-level certification, it requires a solid understanding of the core technologies and some hands-on experience. Prerequisites include: Two years of work experience in Information Security or attend official EC-Council training..
Exam Domains & Topics
The Certified Ethical Hacker (CEH) exam covers 20 key domains. Understanding the weight of each domain helps you allocate your study time effectively:
- Introduction to Ethical Hacking (6% of exam) — Fundamentals of information security, ethical hacking concepts, cyber kill chain methodology, MITRE ATT&CK framework, and relevant laws and standards.
- Footprinting and Reconnaissance (6% of exam) — Techniques and tools for gathering information about target networks, including OSINT, DNS footprinting, and social engineering reconnaissance.
- Scanning Networks (5% of exam) — Network scanning techniques for host, port, service, and OS discovery, including methods to bypass IDS and firewalls.
- Enumeration (5% of exam) — Enumerating network resources including NetBIOS, SNMP, LDAP, NFS, DNS, SMTP, and SMB services.
- Vulnerability Analysis (5% of exam) — Identifying security loopholes using vulnerability scoring systems, databases, scanning tools, and AI-powered assessment.
- System Hacking (7% of exam) — System hacking methodologies including password cracking, privilege escalation, steganography, and covering tracks.
- Malware Threats (5% of exam) — Types of malware including trojans, viruses, worms, ransomware, fileless malware, and APTs with static and dynamic analysis.
- Sniffing (5% of exam) — Packet-sniffing techniques including MAC flooding, ARP poisoning, MITM attacks, DNS poisoning, and countermeasures.
- Social Engineering (5% of exam) — Social engineering concepts and techniques including phishing, impersonation, identity theft, and AI-powered attacks.
- Denial-of-Service (5% of exam) — DoS and DDoS attack techniques, botnet operations, and detection/protection strategies.
- Session Hijacking (4% of exam) — Session hijacking techniques at application and network levels including TCP/IP hijacking, session ID compromise, and countermeasures.
- Evading IDS, Firewalls, and Honeypots (5% of exam) — Techniques for evading intrusion detection systems, firewalls, and honeypots, and related countermeasures.
- Hacking Web Servers (4% of exam) — Web server attack methodology including reconnaissance, DNS hijacking, web cache poisoning, and server hardening.
- Hacking Web Applications (6% of exam) — Web application hacking methodology covering OWASP Top 10, API security, web service attacks, and security testing.
- SQL Injection (5% of exam) — SQL injection attack techniques, evasion methods, and countermeasures for protecting database-driven applications.
- Hacking Wireless Networks (4% of exam) — Wireless network security including encryption cracking, Bluetooth hacking, and wireless attack countermeasures.
- Hacking Mobile Platforms (4% of exam) — Mobile platform attack vectors for Android and iOS, mobile device management, and mobile security guidelines.
- IoT and OT Hacking (4% of exam) — IoT and Operational Technology attack surfaces, vulnerabilities, hacking methodologies, and security countermeasures.
- Cloud Computing (5% of exam) — Cloud computing concepts, threats, attacks on cloud services (AWS, Azure, GCP), and cloud security best practices.
- Cryptography (5% of exam) — Encryption algorithms, PKI, digital signatures, cryptanalysis techniques, and cryptographic attack countermeasures.
Who Should Take the Certified Ethical Hacker (CEH) Exam?
This certification is designed for professionals in the following roles:
- Cybersecurity professionals looking to validate ethical hacking skills
- IT administrators wanting to understand offensive security
- Penetration testers seeking industry-recognized certification
- Security auditors and consultants
- Network engineers transitioning to security roles
Career Opportunities & Salary
Earning the Certified Ethical Hacker (CEH) certification opens doors to roles such as Ethical Hacker, Penetration Tester, Security Analyst, Cybersecurity Consultant, SOC Analyst, and 1 more. Certified professionals earn an average salary of $98,000 per year, reflecting the high demand for cybersecurity skills in today's job market.
Recertification & Renewal
The Certified Ethical Hacker (CEH) certification is valid for 3 years. To maintain your credential, you will need to meet EC-Council's renewal requirements before your certification expires. This may include earning continuing education credits, passing a recertification exam, or earning a higher-level certification.
Exam Registration & Cost
The 312-50 exam costs $1,199 USD. You can register through EC-Council's official website or an authorized testing center. Most candidates choose between in-person testing at a Pearson VUE or PSI center and online proctored exams taken from home. Be sure to review the exam policies, including identification requirements and prohibited items, before your test date.
How to Prepare for 312-50
We recommend 8-12 weeks of dedicated study time to prepare for the Certified Ethical Hacker (CEH) exam. Start by reviewing the official exam objectives, then work through each domain systematically. Regular practice with exam-style questions is essential for building confidence and identifying weak areas. Combine reading with hands-on practice to develop both theoretical knowledge and practical skills.
Hydranode offers comprehensive preparation materials including practice exams, study guides, and free practice tests to help you pass on your first attempt. Our AI-powered practice questions are designed to match the format and difficulty of the actual 312-50 exam, giving you realistic preparation and instant feedback on your performance.