The EC-Council CEH certification validates your expertise and opens doors to higher-paying roles in IT and cybersecurity. Whether you are just starting your study journey or doing a final review, this guide breaks down everything you need to know to pass the CEH exam.
Exam Overview
- Certification: EC-Council CEH
- Exam Code: CEH
- Vendor: EC-Council
- Cost: $1,199 USD (exam voucher)
- Duration: 240 minutes
- Questions: 125 questions
- Passing Score: 60-85% (scaled scoring)
- Format: Multiple choice
- Prerequisites: 2 years IT security experience or EC-Council training
Domain Breakdown
Understanding the exam domains and their weights is critical for efficient study planning. Focus more time on heavily-weighted domains while ensuring you cover all areas.
Domain 1: Reconnaissance & Scanning (21%)
- 1.1 Understand information security and ethical hacking fundamentals
- 1.2 Perform footprinting and reconnaissance using passive and active techniques
- 1.3 Conduct network scanning to identify live hosts, ports, and services
- 1.4 Enumerate systems to extract usernames, shares, and network resources
Key concepts: OSINT Tools, DNS Footprinting, Whois Lookups, Nmap Scanning, TCP/UDP Scanning, Banner Grabbing, SNMP Enumeration, LDAP Enumeration
Domain 2: System & Network Attacks (22%)
- 2.1 Analyze vulnerabilities using automated tools and manual techniques
- 2.2 Exploit system vulnerabilities to gain and maintain access
- 2.3 Understand malware threats including trojans, viruses, and worms
- 2.4 Perform sniffing attacks and analyze network traffic
Key concepts: Password Cracking, Privilege Escalation, Rootkits, Trojans, Virus Types, Packet Sniffing, ARP Poisoning, MAC Flooding
Domain 3: Web Application Attacks (20%)
- 3.1 Apply social engineering techniques and countermeasures
- 3.2 Exploit web server vulnerabilities and misconfigurations
- 3.3 Attack web applications using OWASP Top 10 techniques
- 3.4 Perform SQL injection attacks against database-driven applications
Key concepts: Social Engineering, Phishing Attacks, Web Server Exploits, OWASP Top 10, SQL Injection, XSS Attacks, CSRF Attacks, Parameter Tampering
Domain 4: Wireless/Mobile/IoT/Cloud (20%)
- 4.1 Hack wireless networks and bypass wireless encryption
- 4.2 Exploit mobile platform vulnerabilities on Android and iOS
- 4.3 Attack IoT and OT devices and protocols
- 4.4 Identify cloud computing threats and attack vectors
Key concepts: WPA/WPA2/WPA3 Cracking, Evil Twin Attacks, Mobile Malware, Android Rooting, iOS Jailbreaking, IoT Protocols, SCADA/ICS Attacks, Cloud Enumeration
Domain 5: Cryptography & Defense (17%)
- 5.1 Evade IDS, firewalls, and honeypots using evasion techniques
- 5.2 Apply cryptographic concepts and attack cryptographic implementations
- 5.3 Understand defensive security measures and countermeasures
- 5.4 Perform vulnerability assessment and penetration testing methodology
Key concepts: IDS Evasion, Firewall Bypassing, Honeypot Detection, Symmetric Encryption, Asymmetric Encryption, PKI/Certificates, Hash Functions, Cryptanalysis
Recommended Study Timeline
Plan for approximately 10-16 weeks of dedicated study. Here is a suggested weekly breakdown:
- Week 1: Modules 1-2: Information Security fundamentals, Ethical Hacking methodology, Cyber Kill Chain
- Week 2: Modules 3-4: Footprinting & Reconnaissance — OSINT, DNS, Whois, social media recon
- Week 3: Modules 5-6: Scanning Networks — Nmap, host discovery, port scanning, OS fingerprinting
- Week 4: Module 7: Enumeration — NetBIOS, SNMP, LDAP, NTP, DNS zone transfers
- Week 5: Module 8: Vulnerability Analysis — Nessus, OpenVAS, vulnerability scoring, CVE databases
- Week 6: Modules 9-10: System Hacking — Password attacks, privilege escalation, rootkits, steganography
- Week 7: Modules 11-12: Malware Threats & Sniffing — Trojans, viruses, Wireshark, ARP poisoning
- Week 8: Modules 13-14: Social Engineering & DoS — Phishing, pretexting, DDoS tools, botnets
- Week 9: Modules 15-16: Session Hijacking & IDS/Firewall Evasion — Token theft, tunneling, fragmentation
- Week 10: Modules 17-18: Web Servers & Web Apps — Directory traversal, OWASP Top 10, XSS, CSRF
- Week 11: Module 19: SQL Injection — Union-based, blind, time-based, error-based, sqlmap
- Week 12: Modules 20-21: Wireless & Mobile Hacking — WPA cracking, evil twin, Android/iOS exploits
- Week 13: Modules 22-23: IoT/OT & Cloud — SCADA, MQTT, AWS/Azure attacks, container security, cryptography
- Week 14: Full Review: Practice exams, Weak areas, Lab exercises, Exam logistics
Top Study Tips
- Start with the official exam objectives. Download them from the EC-Council website and use them as your study checklist. Every exam question maps to a specific objective.
- Use active recall over passive reading. Instead of re-reading notes, test yourself with practice questions after each study session. This dramatically improves retention.
- Focus on heavily-weighted domains first. Domains with higher percentages appear more on the exam. Master these before moving to lower-weighted areas.
- Build hands-on experience. Set up a lab environment and practice the skills you are studying. Hands-on experience is especially valuable for performance-based questions.
- Take practice exams under real conditions. Time yourself, eliminate distractions, and simulate the exam environment. Review every wrong answer and understand why it was wrong.
Practice Resources
Test your knowledge with our free tools:
Take our free EC-Council CEH practice quiz
- CVSS Calculator — Practice scoring vulnerabilities
- Password Strength Checker — Test password security
Career Impact
The EC-Council CEH certification demonstrates validated expertise to employers. Certified professionals typically see:
- Higher starting salaries compared to non-certified peers
- More interview callbacks as the certification signals commitment and competence
- Faster career progression with a recognized credential on your resume
- Access to roles that specifically require or prefer EC-Council CEH certification
What to Study Next
After earning your EC-Council CEH certification, consider these natural next steps:
- Deepen your specialization with an advanced certification in the same vendor track
- Broaden your skills with a certification from a complementary domain
- Visit our Career Paths page for detailed certification roadmaps
Get Organized with a Study Planner
A structured study plan makes the difference between passing and failing. Our fillable PDF study planners include domain trackers, weekly schedules, and progress tracking designed specifically for EC-Council CEH exam prep.
This guide is independently created for educational purposes. EC-Council trademarks belong to their respective owners. FixTheVuln is not affiliated with or endorsed by EC-Council.
Explore More
Exam Syllabus & Domain Breakdown
Review the complete certification syllabus, domain weights, and free training resources.
View Full Certification Guide →FixTheVuln Store
CEH Exam Prep? Get the Study Planner
Comprehensive planner for EC-Council certifications. Attack methodology trackers, tool cheat sheets, and lab guides.
Shop CEH PlannerAlso available: CEH, CHFI, CND
CyberFolio
Building cybersecurity skills? Track them in one place.
Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.
Build Your Portfolio →