About UsCertification Vendors
Contact us
HydraNode logo

HydraNode

Your trusted source for IT certification preparation. Experience advanced AI-powered practice exams, study guides, and personalized learning paths for 375+ certifications.

Popular Certifications

CompTIA A+CompTIA Security+AWS Solutions ArchitectCisco CCNACISSPPMPCompTIA Network+Azure FundamentalsAWS Cloud PractitionerCisco CCNP EnterpriseView All Certifications →

By Provider

CompTIAAWSMicrosoftCisco(ISC)²Google CloudOracleVMwareRed HatIBMView All Providers →

By Category

Cloud ComputingCybersecurityNetworkingProject ManagementData & AnalyticsSoftware DevelopmentDatabase AdministrationInfrastructureBusiness AnalysisDevOpsView All Categories →

Popular Guides

Best IT Certifications 2025Highest Paying CertificationsEntry-Level CertificationsFree IT CertificationsCybersecurity GuideAWS Certifications GuideCloud Computing CertificationsCompTIA Certifications GuideAzure Certifications GuideView All Guides →

Company

About UsCertificationsCompare CertificationsContact Us

Legal

Privacy PolicyTerms of ServiceCookie Policy

© 2025 HydraNode.ai. All Rights Reserved.

Trusted by thousands of IT professionals worldwide

    HomeCertificationsCertified Ethical Hacker (CEH)Exam Objectives
    Prasenjit Sarkar
    By Prasenjit Sarkar·Last verified: 2026-07-23
    EC-Council Exam BlueprintASSOCIATE

    Certified Ethical Hacker (CEH) Exam Objectives

    312-50

    The CEH v13 exam (312-50v13) covers 20 modules spanning the full ethical hacking methodology — from information gathering to advanced topics like cloud security, IoT/OT hacking, and AI-powered attacks.

    Each domain is weighted differently on the exam. System Hacking and Hacking Web Applications carry the highest weight at 7% each, while foundational modules like Introduction to Ethical Hacking carry 4%. Understanding these weights helps you prioritize your study time effectively.

    The exam consists of 125 multiple-choice questions with a 4-hour time limit. Questions are scenario-based and test practical application of ethical hacking tools and techniques, not just theoretical knowledge.

    View All DomainsStudy Guide

    Exam Overview

    Total Domains20
    DifficultyASSOCIATE
    Questions125
    Passing Score70%

    Exam Domains

    All Exam Objectives

    20 domains covering 100% of the exam

    1

    Introduction to Ethical Hacking

    6% of exam

    Fundamentals of information security, ethical hacking concepts, cyber kill chain methodology, MITRE ATT&CK framework, and relevant laws and standards.

    Key Concepts

    Information SecurityCyber Kill ChainMITRE ATT&CKRisk ManagementThreat IntelligencePCI DSSGDPR
    6%

    ~8 questions

    2

    Footprinting and Reconnaissance

    6% of exam

    Techniques and tools for gathering information about target networks, including OSINT, DNS footprinting, and social engineering reconnaissance.

    Key Concepts

    OSINTDNS FootprintingWhois LookupGoogle HackingDark Web FootprintingEmail Footprinting
    6%

    ~8 questions

    3

    Scanning Networks

    5% of exam

    Network scanning techniques for host, port, service, and OS discovery, including methods to bypass IDS and firewalls.

    Key Concepts

    Port ScanningHost DiscoveryOS FingerprintingNmapService DiscoveryIDS Evasion
    5%

    ~6 questions

    4

    Enumeration

    5% of exam

    Enumerating network resources including NetBIOS, SNMP, LDAP, NFS, DNS, SMTP, and SMB services.

    Key Concepts

    NetBIOSSNMP EnumerationLDAPNFSDNS Zone TransferSMB Enumeration
    5%

    ~6 questions

    5

    Vulnerability Analysis

    5% of exam

    Identifying security loopholes using vulnerability scoring systems, databases, scanning tools, and AI-powered assessment.

    Key Concepts

    CVSSCVE DatabaseVulnerability ScanningNessusVulnerability LifecycleRisk Assessment
    5%

    ~6 questions

    6

    System Hacking

    7% of exam

    System hacking methodologies including password cracking, privilege escalation, steganography, and covering tracks.

    Key Concepts

    Password CrackingPrivilege EscalationMetasploitBuffer OverflowSteganographyRootkitsKeyloggers
    7%

    ~9 questions

    7

    Malware Threats

    5% of exam

    Types of malware including trojans, viruses, worms, ransomware, fileless malware, and APTs with static and dynamic analysis.

    Key Concepts

    TrojansRansomwareAPTFileless MalwareStatic AnalysisDynamic AnalysisAI-based Malware
    5%

    ~6 questions

    8

    Sniffing

    5% of exam

    Packet-sniffing techniques including MAC flooding, ARP poisoning, MITM attacks, DNS poisoning, and countermeasures.

    Key Concepts

    ARP PoisoningMAC FloodingMITM AttackDHCP StarvationDNS PoisoningWireshark
    5%

    ~6 questions

    9

    Social Engineering

    5% of exam

    Social engineering concepts and techniques including phishing, impersonation, identity theft, and AI-powered attacks.

    Key Concepts

    PhishingImpersonationPretextingBaitingIdentity TheftAnti-Phishing
    5%

    ~6 questions

    10

    Denial-of-Service

    5% of exam

    DoS and DDoS attack techniques, botnet operations, and detection/protection strategies.

    Key Concepts

    DoSDDoSBotnetsVolumetric AttacksApplication Layer AttacksDDoS Mitigation
    5%

    ~6 questions

    11

    Session Hijacking

    4% of exam

    Session hijacking techniques at application and network levels including TCP/IP hijacking, session ID compromise, and countermeasures.

    Key Concepts

    Session TokensTCP HijackingCookie TheftXSS Session HijackingCSRFSession Fixation
    4%

    ~5 questions

    12

    Evading IDS, Firewalls, and Honeypots

    5% of exam

    Techniques for evading intrusion detection systems, firewalls, and honeypots, and related countermeasures.

    Key Concepts

    IDS EvasionFirewall BypassHoneypotsTunnelingFragmentationNAC Evasion
    5%

    ~6 questions

    13

    Hacking Web Servers

    4% of exam

    Web server attack methodology including reconnaissance, DNS hijacking, web cache poisoning, and server hardening.

    Key Concepts

    Web Server AttacksDNS HijackingCache PoisoningDirectory TraversalBanner GrabbingServer Hardening
    4%

    ~5 questions

    14

    Hacking Web Applications

    6% of exam

    Web application hacking methodology covering OWASP Top 10, API security, web service attacks, and security testing.

    Key Concepts

    OWASP Top 10XSSCSRFAPI SecurityWeb FuzzingInput Validation
    6%

    ~8 questions

    15

    SQL Injection

    5% of exam

    SQL injection attack techniques, evasion methods, and countermeasures for protecting database-driven applications.

    Key Concepts

    SQL Injection TypesBlind SQLiUnion-based SQLiSQLMapParameterized QueriesWAF Evasion
    5%

    ~6 questions

    16

    Hacking Wireless Networks

    4% of exam

    Wireless network security including encryption cracking, Bluetooth hacking, and wireless attack countermeasures.

    Key Concepts

    WPA/WPA2 CrackingWPA3Bluetooth AttacksEvil TwinRogue APAircrack-ng
    4%

    ~5 questions

    17

    Hacking Mobile Platforms

    4% of exam

    Mobile platform attack vectors for Android and iOS, mobile device management, and mobile security guidelines.

    Key Concepts

    Android HackingiOS AttacksMDMMobile MalwareBYOD SecurityApp Sandboxing
    4%

    ~5 questions

    18

    IoT and OT Hacking

    4% of exam

    IoT and Operational Technology attack surfaces, vulnerabilities, hacking methodologies, and security countermeasures.

    Key Concepts

    IoT ArchitectureSCADA/ICSIoT ProtocolsOT SecurityFirmware AnalysisIoT Botnets
    4%

    ~5 questions

    19

    Cloud Computing

    5% of exam

    Cloud computing concepts, threats, attacks on cloud services (AWS, Azure, GCP), and cloud security best practices.

    Key Concepts

    AWS SecurityAzure SecurityGCP SecurityContainer SecurityServerless AttacksCloud Pentesting
    5%

    ~6 questions

    20

    Cryptography

    5% of exam

    Encryption algorithms, PKI, digital signatures, cryptanalysis techniques, and cryptographic attack countermeasures.

    Key Concepts

    Symmetric EncryptionAsymmetric EncryptionPKIDigital SignaturesHashingCryptanalysis
    5%

    ~6 questions

    Strategy

    Study Strategy by Domain Weight

    Prioritize your study time based on exam weightings

    Highest Priority

    System Hacking

    7%

    Allocate approximately 6 hours of study time

    Introduction to Ethical Hacking

    6%

    Allocate approximately 5 hours of study time

    Footprinting and Reconnaissance

    6%

    Allocate approximately 5 hours of study time

    Hacking Web Applications

    6%

    Allocate approximately 5 hours of study time

    Scanning Networks

    5%

    Allocate approximately 4 hours of study time

    Enumeration

    5%

    Allocate approximately 4 hours of study time

    More Resources

    Continue Preparing

    Practice Exam
    Study Guide
    How to Pass
    Free Practice Test

    Sources

    • Official Certified Ethical Hacker (CEH) Exam Page — EC-Council
    • About HydraNode — Our Methodology