EC-Council · 212-82
Validates entry-level cybersecurity knowledge and hands-on skills across network defense, ethical hacking, forensics, incident response, cloud, risk, and security operations.
Practice Questions
630
≈ 5 practice exams
Duration
3 hours (FAQ: 185 minutes)
Passing Score
60-85% by exam form
Difficulty
FoundationalLast Updated
Oct 2026
CCT is EC-Council's entry-level, hands-on cybersecurity credential. The current exam-details block lists exam code 212-82 and 60 total items: 50 multiple-choice questions followed by 10 practical questions. Its course spans 22 modules, from threats, attacks, networking, cloud, wireless, mobile, IoT and cryptography through monitoring, incident response, forensics, continuity, and risk.
EC-Council's current page is internally inconsistent about timing: the exam-details block says three hours, while the FAQ says 185 minutes. It also describes remote proctoring in one section and exclusive ECC Exam Centre delivery in another. Candidates should therefore confirm the exact duration and delivery shown in their booking; the published passing range is 60-85%, depending on the exam form.
This 630-question CCT bank supports broad concept review, but the live exam also requires practical performance. Start with 30 free questions, then pair theory practice with the official labs and hands-on work in scanning, traffic and log analysis, system and network security, incident response, and basic forensic tasks.
EC-Council's Certified Cybersecurity Technician is an entry-level program combining broad foundational coverage with practical work. The current exam code is 212-82, and the course includes 85 hands-on labs across 22 modules.
The live assessment has two sections: 50 multiple-choice questions and 10 hands-on practical questions. CCT is accredited by ANAB under ISO/IEC 17024.
EC-Council positions CCT for high-school and university students, career changers, working professionals, and IT practitioners moving into cybersecurity. It is intended for technician-level responsibilities such as applying controls, troubleshooting, monitoring, escalating incidents, and supporting risk assessments.
There are no eligibility criteria or specific prerequisites for the course or exam. EC-Council says basic knowledge of IT networking and cybersecurity concepts is beneficial.
The official page lists 60 items: 50 multiple-choice and 10 hands-on practical. Its exam-details block says three hours and remote proctoring, while its FAQ says 185 minutes and exclusive ECC Exam Centre availability; candidates should confirm their appointment details. The published passing range is 60-85%, depending on the exam form.
CCT documents entry-level cybersecurity knowledge and practical exposure. It can support a move into technician, junior security operations, or IT roles with security duties, but it should be presented alongside demonstrable lab work and real operational experience rather than as proof of senior capability.
5 sample questions with answers and explanations. The full bank has 630 questions, enough for 5 full-length practice exams.
Preview — answers shown1. An attacker sends a TCP packet with the FIN, PSH, and URG flags set to probe a target network. What type of Nmap scan is being performed? (Select one!)
Explanation
Xmas scan sets the FIN, PSH, and URG flags, making the packet light up like a Christmas tree on protocol analyzers. This technique exploits RFC 793 behavior where closed ports should respond with RST while open ports should not respond. TCP SYN scan only sets the SYN flag. NULL scan sends packets with no flags set. ACK scan sets only the ACK flag and is used for firewall rule mapping rather than port state determination.
2. An enterprise implements 802.11ac wireless networking for a large office building. What is the maximum theoretical throughput that 802.11ac can achieve? (Select one!)
Explanation
802.11ac (Wi-Fi 5) operates in the 5 GHz band and provides a maximum theoretical throughput of 6.9 Gbps using Multi-User MIMO (MU-MIMO) and wider channels. This represents a significant improvement over previous standards. 600 Mbps is the maximum for 802.11n. 54 Mbps is the maximum for 802.11a and 802.11g. 9.6 Gbps is the maximum for 802.11ax (Wi-Fi 6).
3. An enterprise implements 802.1X network access control with certificate-based authentication providing the strongest security. Which EAP method should be configured? (Select one!)
Explanation
EAP-TLS uses certificate-based mutual authentication and is considered the strongest EAP method because both client and server authenticate using digital certificates. PEAP (Protected EAP) uses passwords within a TLS tunnel providing moderate security. EAP-TTLS offers flexible inner authentication methods but typically uses passwords rather than certificates. LEAP is a Cisco proprietary protocol with known vulnerabilities and is deprecated.
4. A penetration tester performs reconnaissance and needs to query DNS records to identify mail servers for a target domain. Which DNS record type should be queried? (Select one!)
Explanation
MX (Mail Exchange) records specify the mail servers responsible for accepting email for a domain, including priority values for multiple servers. This is essential for identifying email infrastructure during reconnaissance. A records map domain names to IPv4 addresses. CNAME records create domain aliases. TXT records contain text information, often used for SPF and DKIM but not for identifying mail servers directly.
5. A security team implements Kerberos authentication for a Windows Active Directory domain. Which default port does the Key Distribution Center use for authentication services? (Select one!)
Explanation
Kerberos uses port 88 (TCP and UDP) for the Key Distribution Center authentication services that issue Ticket Granting Tickets and service tickets. The authentication process involves obtaining a TGT from the Authentication Server, then requesting service tickets for specific resources. Port 53 is used for DNS services. Port 389 is used for LDAP directory services. Port 636 is used for LDAPS (LDAP over SSL/TLS). Blocking port 88 will prevent Kerberos authentication in Active Directory environments.
EC-Council lists Certified Cybersecurity Technician as exam 212-82.
The current EC-Council page lists 60 items in two sections: 50 multiple-choice questions and 10 hands-on practical questions.
EC-Council currently publishes conflicting figures: its exam-details block says three hours while its FAQ says 185 minutes. Confirm the duration displayed for your appointment.
EC-Council publishes a range of 60-85%. Its certification policy uses different cut scores for different exam forms, so a single universal percentage is not accurate.
No. EC-Council lists no eligibility criteria or specific prerequisite, although basic IT networking and cybersecurity knowledge is beneficial.
No. The current format combines 50 multiple-choice questions with 10 hands-on practical items, so candidates need practical as well as conceptual preparation.
Computer Hacking Forensic Investigator (CHFI)
CHFI · 589 questions
Certified Cloud Security Engineer (CCSE)
CCSE · 624 questions
Certified Network Defender (CND)
CND · 562 questions
EC-Council Certified DevSecOps Engineer (ECDE) v2
ECDE · 609 questions
Digital Forensics Essentials (DFE)
DFE · 626 questions
EC-Council Certified Disaster Recovery Professional (EDRP)
EDRP · 623 questions
$17.99
One-time access to this exam