EC-Council · CEH
Validates proficiency in ethical hacking techniques and tools across 20 security domains, including reconnaissance, network scanning, vulnerability analysis, system hacking, malware threats, social engineering, web application attacks, SQL injection, cryptography, and cloud and IoT security.
Practice Questions
594
≈ 4 practice exams
Duration
240 minutes
Passing Score
70%
Difficulty
AssociateLast Updated
Feb 2026
This Certified Ethical Hacker practice test helps you review reconnaissance, scanning, enumeration, exploitation concepts, web application attacks, malware, wireless security, cloud security, and defensive countermeasures. The goal is to improve your ability to identify the right technique or tool from a scenario, not simply remember labels.
Use the free questions to benchmark your starting point, then practice in focused sessions by reviewing every explanation after submission. CEH preparation benefits from repetition because many answer choices are close; understanding why the wrong options fail is essential for raising your score.
The Certified Ethical Hacker (CEH), now in its 13th version (CEH v13), is EC-Council's flagship offensive security certification that validates a professional's ability to identify, exploit, and remediate vulnerabilities using the same tools and techniques as malicious hackers — but within a lawful, authorized context. Spanning 20 security domains and over 550 attack techniques, CEH v13 covers the full spectrum of ethical hacking methodology: from footprinting and reconnaissance through system hacking, malware analysis, social engineering, web application attacks, SQL injection, wireless network exploitation, and cloud and IoT security. The curriculum also integrates AI-driven hacking techniques, making CEH v13 the first ethical hacking certification to incorporate AI and machine learning as core competencies. Launched in September 2024, CEH v13 reflects the evolving threat landscape with updated modules on cloud environments (AWS, Azure), OT/ICS systems, and AI-powered offensive tools. The certification is globally recognized, listed on the U.S. Department of Defense (DoD) Approved Baseline Certifications list (DoD 8570/8140), and is administered through EC-Council's exam code 312-50.
CEH is designed for mid-career IT and security professionals who want to formalize and validate their offensive security knowledge. Primary target roles include penetration testers, security analysts, SOC analysts, network security engineers, security auditors, security consultants, and IT managers responsible for defensive strategy. Candidates typically have a background in networking, operating systems, or system administration and are looking to transition into or advance within offensive and red-team security roles. The certification is also widely pursued by professionals in government, defense contracting, and financial services who need credentials recognized by the DoD or regulated-industry compliance frameworks.
EC-Council does not enforce a formal degree requirement, but candidates must satisfy one of two eligibility paths. The first path requires completing an official EC-Council-accredited CEH training course, after which the candidate is automatically eligible to sit the exam. The second path allows self-study candidates with at least two years of verifiable information security work experience to apply directly by submitting an eligibility application form and paying a $100 non-refundable fee for EC-Council review. Regardless of path, candidates are strongly expected to have working knowledge of TCP/IP networking, Windows and Linux operating systems, and foundational security concepts. Familiarity with tools such as Nmap, Wireshark, and Metasploit is practically necessary to succeed on both the knowledge exam and the optional practical exam.
The CEH knowledge exam (exam code 312-50) consists of 125 multiple-choice questions to be completed in 240 minutes (4 hours). Questions are a mix of knowledge-based and scenario-based multiple-choice items. The exam is delivered either online via remote proctoring through EC-Council's portal or in person at Pearson VUE testing centers worldwide. Scoring uses a scaled model, meaning the exact passing threshold varies by exam form difficulty — typically falling between 60% and 85%, with approximately 70% as a general benchmark. The certification is valid for three years, after which holders must earn 120 EC-Council Continuing Education (ECE) credits or retake the exam. Separately, EC-Council offers the CEH Practical, a 6-hour, 20-challenge hands-on exam conducted in a live cyber range; passing both the knowledge exam and the practical earns the CEH Master designation.
The CEH certification is one of the most widely recognized offensive security credentials globally, directly qualifying holders for roles such as penetration tester, security analyst, cybersecurity engineer, SOC analyst, security consultant, and information security manager. Salary data from PayScale and Glassdoor indicates CEH-certified professionals earn an average base salary ranging from approximately $86,000 to over $147,000 in the United States, with penetration testers typically earning $95,000–$145,000 and information security managers reaching $90,000–$175,000. CEH holders who transition from network administration roles report salary increases of up to 54% according to EC-Council data. The certification's inclusion on the U.S. Department of Defense Approved Baseline Certifications list (DoD 8570/8140) makes it a mandatory or strongly preferred credential for government, military, and defense contractor positions — an advantage not shared by many competing certifications. Compared to alternatives like CompTIA PenTest+ (entry-level) or OSCP (more hands-on/advanced), CEH occupies a well-recognized middle ground that balances breadth of knowledge with industry name recognition, making it particularly effective for professionals entering or advancing within offensive security who need a credential that resonates with HR and hiring managers across both the public and private sectors.
5 sample questions with answers and explanations. The full bank has 594 questions, enough for 4 full-length practice exams.
Preview — answers shown1. An ethical hacker performs a DNS zone transfer attempt against a target domain. Which TCP port must be open on the DNS server for this attack to succeed? (Select one!)
Explanation
DNS zone transfers use TCP port 53, not the more common UDP port 53 used for standard DNS queries. Zone transfers require reliable transport due to potentially large data transfers containing all DNS records for a domain. The attack uses commands like dig axfr @nameserver domain.com or nslookup with query=AXFR. UDP 53 is used for normal DNS queries. TCP 389 is LDAP. TCP 636 is LDAPS.
2. A penetration tester wants to perform an Nmap scan that is extremely stealthy to avoid IDS detection, even at the cost of scan speed. Which timing template should be used? (Select one!)
Explanation
The -T0 (Paranoid) timing template is the slowest and stealthiest option, waiting approximately 5 minutes between each probe. This timing is designed for IDS evasion in highly sensitive environments where detection must be avoided at all costs. -T3 is Normal timing and the default. -T4 is Aggressive timing for fast networks. -T5 is Insane timing which is very fast but may miss ports and trigger IDS systems.
3. An organization implements 3DES encryption for legacy system compatibility. What is the effective key strength when using 3DES with three independent keys? (Select one!)
Explanation
Despite 3DES using three 56-bit keys for a total of 168 bits, the effective security strength is only 112 bits due to meet-in-the-middle attacks. This is why 3DES is deprecated in modern security standards despite having a larger nominal key size than some current algorithms. The 56-bit strength represents single DES which is completely broken. While the total key material is 168 bits, this does not represent actual security strength. 256 bits represents AES-256, a completely different algorithm.
4. During a penetration test, an attacker uses Maltego to map relationships between domain names, IP addresses, and email addresses. What are these data objects called in Maltego? (Select one!)
Explanation
Entities are the data objects in Maltego representing items like domains, IP addresses, people, and email addresses. Transforms are the processes that operate on entities to discover relationships and gather additional information. Nodes is a generic graph term but not Maltego-specific terminology. Pivots describe the action of exploring relationships but are not the data objects themselves.
5. An IoT security researcher discovers smart home devices communicating using MQTT protocol on the default port without TLS encryption. On which port is this unencrypted MQTT traffic occurring? (Select one!)
Explanation
MQTT uses port 1883 for unencrypted communication and port 8883 for encrypted MQTT over TLS. The default port 1883 represents a significant security risk as all messages are transmitted in cleartext. Port 8883 is the secure MQTT port with TLS encryption. Port 5683 is used by CoAP, another IoT protocol. Port 502 is used by Modbus, an industrial control system protocol.
CEH is one of EC-Council's most heavily monitored exams, and confirmed cheating results in permanent loss of the certification and removal from EC-Council's public CEH registry, with a ban from EC-Council's other programs possible for serious violations.
There is an obvious irony in an ethical-hacking credential being earned unethically, and employers in this field notice. CertCompanion's CEH bank has 594 practice questions, 30 free, covering the same 20 domains EC-Council actually tests, from reconnaissance to cloud and IoT security.
Certified SOC Analyst (CSA)
CSA · 570 questions
Certified Threat Intelligence Analyst (CTIA)
CTIA · 740 questions
Certified Chief Information Security Officer (CCISO)
CCISO · 578 questions
Certified EC-Council Instructor (CEI)
CEI · 611 questions
Computer Hacking Forensic Investigator (CHFI)
CHFI · 589 questions
Certified Cloud Security Engineer (CCSE)
CCSE · 624 questions
$17.99
One-time access to this exam