EC-Council · EHE
Validates foundational understanding of ethical hacking and penetration testing concepts, covering information security fundamentals, threats and vulnerabilities, password cracking, web application attacks, IoT and OT security, cloud computing threats, and penetration testing methodology.
Practice Questions
627
≈ 5 practice exams
Duration
120 minutes
Passing Score
70%
Difficulty
FoundationalLast Updated
Sep 2026
Ethical Hacking Essentials (exam code 112-52) tests 12 modules, and EC-Council does not publish per-module weightings, so this bank of 627 practice questions spreads coverage across all 12 rather than guessing at a split: information security and ethical hacking fundamentals, threats and vulnerability assessment, password cracking, social engineering, network-level attacks, web application attacks, wireless, mobile, IoT and OT security, cloud computing threats, and penetration testing fundamentals. The heaviest lifting on the real exam comes from recognizing attack techniques and their countermeasures, so explanations here focus on why an attack works and what stops it, not tool-name trivia.
On test day you face 75 multiple-choice questions in 2 hours, delivered through the EC-Council Exam Center with remote proctoring. The passing score is a flat 70 percent, which means 53 of 75 correct, with no scaled scoring and no per-module minimums. There are no eligibility requirements: no prior IT or security experience, no application, no age of experience windows. That makes EHE one of the few security certifications you can register for on day one of a career change.
EC-Council sells the official EHE course as a $299 bundle: 12 modules of ecourseware (1-year access), lab access for 6 months with 47 labs including a CTF-style capstone, and an exam voucher valid for 1 year. A standalone exam voucher runs about $75 through EC-Council's exam portal if you prefer to self-study. The certification is valid for 3 years, and renewal is simply retaking the exam, with no CPE credits or annual maintenance fees during the term.
EHE is the entry point of EC-Council's Essentials Series, which now spans nine foundational certifications including Network Defense Essentials (NDE), Digital Forensics Essentials (DFE), and the newer AI Essentials. The intended ladder from here is Certified Ethical Hacker: CEH v13 jumps to 125 questions over 4 hours with a scaled cut score, so EHE is where you build the vocabulary and attack-lifecycle intuition first. Start with the 30 free questions, then work through the full 627-question bank until your accuracy holds steady across all 12 modules.
The Ethical Hacking Essentials (EHE) is an entry-level cybersecurity certification from EC-Council, designed to validate foundational knowledge of ethical hacking principles, penetration testing concepts, and information security fundamentals. Delivered under EC-Council's Essentials Series, it covers a broad spectrum of attack surfaces and defensive countermeasures across 12 modules, including network-level attacks, web application vulnerabilities, social engineering, wireless security, IoT and operational technology (OT) threats, and cloud computing risks. The certification carries exam code 112-52 and is valid for three years, with no continuing education fees or EC-Council Continuing Education Credits (ECEs) required during that period.
EHE serves as a structured on-ramp for individuals new to the cybersecurity field, bridging the gap between general IT knowledge and the more advanced Certified Ethical Hacker (CEH) credential. The course includes 15 hours of premium learning content and 11 hands-on labs, ensuring candidates gain both conceptual understanding and practical exposure to real-world attack techniques and countermeasures.
EHE is aimed at individuals who are beginning their journey in cybersecurity and information security. There are no formal IT or cybersecurity experience requirements, making it accessible to career changers, recent graduates, and students exploring the field. Job roles that align with this certification include entry-level security analyst, junior penetration tester, IT support professional seeking to pivot into security, and cybersecurity student.
The credential is also well-suited for professionals in adjacent IT roles—such as system administrators or network technicians—who want to formalize their understanding of attacker methodologies and threat landscapes. It is frequently pursued as a first step before attempting the CEH or other intermediate-level certifications.
There are no formal eligibility requirements or prerequisites to register for the EHE exam. EC-Council explicitly states that no prior IT or cybersecurity experience is necessary, making this one of the most accessible credentials in the EC-Council portfolio.
However, candidates benefit from a basic understanding of how computers and networks operate, including familiarity with operating system concepts, IP addressing, and common internet protocols. Those with some exposure to IT fundamentals—through coursework, self-study, or personal projects—will find the material easier to absorb and retain during preparation.
The EHE exam (code 112-52) consists of 75 multiple-choice questions and must be completed within 120 minutes. A passing score of 70% is required. The exam is administered through EC-Council's ECC Exam Center and can be taken online in a proctored environment. The exam cost is $49.99 for the exam voucher through select channels, though pricing may vary by region and training bundle.
The certification is valid for three years from the date of a successful attempt. Recertification is achieved by retaking the exam at the end of the three-year validity period. No continuing education credits or fees are required to maintain the credential during its active term.
Earning the EHE credential demonstrates to employers that a candidate possesses structured, vendor-validated knowledge of ethical hacking fundamentals, which can differentiate entry-level applicants in a competitive cybersecurity job market. The certification is recognized as a stepping stone toward higher-value EC-Council credentials, most notably the Certified Ethical Hacker (CEH), which is widely required or preferred for penetration tester, security analyst, and red team roles. EHE holders are positioned for roles such as junior security analyst, cybersecurity support specialist, and IT risk analyst.
While the EHE itself is a foundational credential and does not command the same salary premium as CEH or OSCP, it validates commitment to the field and provides a recognized credential for candidates building their first cybersecurity resume. Entry-level cybersecurity roles in the United States typically range from $55,000 to $85,000 annually, and holding a recognized certification from EC-Council can accelerate hiring and interview opportunities, particularly at organizations that already use EC-Council training for their security teams.
5 sample questions with answers and explanations. The full bank has 627 questions, enough for 5 full-length practice exams.
Preview — answers shown1. A Linux system stores user password hashes in /etc/shadow with the format $6$randomsalt$hashedvalue. Which hashing algorithm is being used? (Select one!)
Explanation
The identifier $6$ indicates SHA-512 hashing in Linux /etc/shadow format. The format is $id$salt$hash where the id specifies the algorithm: $1$ for MD5, $5$ for SHA-256, and $6$ for SHA-512. SHA-512 is a strong cryptographic hash function providing 512-bit output and is currently recommended for password storage with proper salting. MD5 uses $1$ identifier and is considered weak with known collisions. SHA-1 is not commonly used in /etc/shadow format and is cryptographically broken. SHA-256 uses $5$ identifier and provides 256-bit output, which is strong but less secure than SHA-512 for password hashing.
2. A company stores customer credit card data and must comply with security standards. Which regulation specifically governs payment card data protection? (Select one!)
Explanation
PCI DSS (Payment Card Industry Data Security Standard) is the specific standard governing protection of cardholder data with 12 requirements including encryption, access controls, network segmentation, and regular security testing. GDPR regulates EU personal data privacy. SOX addresses financial reporting for publicly traded companies. HIPAA protects healthcare information (PHI) in the United States.
3. An ethical hacker uses John the Ripper to crack Linux password hashes. The /etc/shadow file contains the hash: $6$saltytext$hashvalue. Which hashing algorithm is used? (Select one!)
Explanation
Linux shadow file hash format uses $id$salt$hash where the ID indicates the algorithm. ID 6 represents SHA-512 (sha512crypt). ID 1 represents MD5, ID 5 represents SHA-256, and SHA-1 is not used in standard Linux shadow files. SHA-512 is the current recommended hashing algorithm for Linux systems providing strong password protection.
4. A security analyst examines network traffic and observes a series of packets with the FIN, PSH, and URG flags all set. Which type of port scan is being performed? (Select one!)
Explanation
XMAS scan sets the FIN, PSH, and URG flags simultaneously, creating a packet that lights up like a Christmas tree on protocol analyzers. This scan type exploits RFC 793 behavior where closed ports should respond with RST packets while open ports should ignore the malformed packet. NULL scan sends packets with no flags set. FIN scan uses only the FIN flag. ACK scan uses only the ACK flag to map firewall rules.
5. An ethical hacker uses Nmap with flags that send TCP packets with FIN, PSH, and URG flags set to bypass a non-stateful firewall. Which scan type is being performed? (Select one!)
Explanation
XMAS scan uses the -sX flag in Nmap and sets the FIN, PSH, and URG flags simultaneously, making the packet light up like a Christmas tree on protocol analyzers. This technique exploits RFC 793 behavior where closed ports respond with RST packets while open ports drop the packet, allowing port identification. XMAS scans can bypass non-stateful firewalls that only check for SYN flags. SYN scan only sets the SYN flag for half-open connections. ACK scan sets only the ACK flag to map firewall rules. NULL scan sends packets with no flags set at all, not the FIN+PSH+URG combination.
75 multiple-choice questions in 2 hours (exam code 112-52), delivered through the EC-Council Exam Center with remote proctoring.
70 percent, which is 53 of 75 questions correct. It is a flat cut score, not scaled, and there are no per-module minimums.
The official course bundle is $299 and includes 1-year ecourseware access, 6 months of labs, and an exam voucher valid for 1 year. A standalone exam voucher is about $75 through EC-Council's exam portal.
No. EC-Council sets no eligibility criteria for EHE: no prior IT or cybersecurity experience, no application, and no minimum education requirement.
EHE is the foundational tier: 75 questions, 2 hours, a flat 70 percent to pass, no prerequisites. CEH v13 is the professional tier: 125 questions over 4 hours with a scaled cut score and eligibility requirements (official training or 2 years of experience). EC-Council positions EHE as the on-ramp to CEH.
Yes, after 3 years. Renewal is retaking and passing the current EHE exam. No CPE credits or continuing education fees are required during the 3-year term.
12 modules: information security fundamentals, ethical hacking fundamentals, threats and vulnerability assessment, password cracking, social engineering, network-level attacks, web application attacks, wireless attacks, mobile attacks, IoT and OT attacks, cloud computing threats, and penetration testing fundamentals.
If you are starting from zero, yes: it is one of the cheapest proctored security certifications with no prerequisites, and it maps directly onto the CEH syllabus you would face next. If you already have hands-on security experience, most employers weight CEH, Security+, or PenTest+ higher, so EHE is best treated as a first credential, not a destination.
Certified Application Security Engineer .NET (CASE-.NET)
CASE-.NET · 625 questions
EC-Council Certified Incident Handler (ECIH)
ECIH · 590 questions
EC-Council Certified Encryption Specialist (ECES)
ECES · 627 questions
ICS/SCADA Cybersecurity
ICS-SCADA · 627 questions
Certified Application Security Engineer Java (CASE-Java)
CASE-Java · 623 questions
Network Defense Essentials (NDE)
NDE · 627 questions
$17.99
One-time access to this exam