What is an Ethical Hacker?

Ethical Hacking is often referred to as the process of penetrating one’s own computer/s or computers to which one has official permission to do so as to determine if vulnerabilities exist and to undertake preventive, corrective, and protective countermeasures before an actual compromise to the system takes place. Around the world, partners and customers look to EC-Council to deliver the highest quality exams and certifications. EC-Council has developed a number of policies to support the goals of EC-Council certification program, including:

Certified Ethical Hacker Certification v13

A Certified Ethical Hacker is a skilled professional who understands and knows how to look for weaknesses and vulnerabilities in target systems and uses the same knowledge and tools as a malicious hacker, but in a lawful and legitimate manner to assess the security posture of a target system(s). The Certified Ethical Hacker credential certifies individuals in the specific network security discipline of Ethical Hacking from a vendor-neutral perspective.

The purpose of the Certified Ethical Hacker credential is to

Establish and govern minimum standards for credentialing professional information security specialists in ethical hacking measures.

Inform the public that credentialed individuals meet or exceed the minimum standards.

Reinforce ethical hacking as a unique and self-regulating profession.

Certification Target Audience

The Certified Ethical Hacker certification will fortify the application knowledge of security officers, auditors, security professionals, site administrators, and anyone who is concerned about the integrity of the network infrastructure.

Exam Information

The Certified Ethical Hacker exam (312-50) is available at the ECC Exam Centre and Pearson Vue testing centers. For VUE, please visit https://www.vue.com/eccouncil. EC-Council reserves the right to revoke the certification status of candidates that do not comply with all EC-Council examination policies found here.

CEH Exam Details

Duration: 4 Hours Questions: 125

Passing Criteria

In order to maintain the high integrity of our certification exams, EC-Council Exams are provided in multiple forms (i.e., different question banks). Each form is carefully analyzed through beta testing with an appropriate sample group under the purview of a committee of subject matter experts that ensure that each of our exams not only have academic rigor but also have “real world” applicability. We also have a process to determine the difficulty rating of each question. The individual rating then contributes to an overall “Cut Score” for each exam form. To ensure each form has equal assessment standards, cut scores are set on a “per exam form” basis. Depending on which exam form is challenged, cut scores can range from 60% to 85%. For VUE, please visit https://www.vue.com/eccouncil. EC-Council reserves the right to revoke the certification status of candidates that do not comply with all EC-Council examination policies found here.

Clause: Age Requirements and Policies Concerning Minors

Minors are not permitted to take the EC-Council exam without a written consent/indemnity letter signed by their parent or legal guardian, along with a supporting letter from their institution of learning. Only candidates from a nationally accredited institution of learning shall be considered. Minor/Adult legal ages are defined by the country of residence/origin for the candidate. For further clarification or to submit a letter of consent, please contact certmanager@eccouncil.org. EC-Council reserves the right to revoke the certification status of candidates in case of non-compliance with this policy.

Disclaimer

- EC-Council reserves the right to impose additional restriction to comply with the policy.

- EC-Council reserves the right to modify certification policies without notice.

- EC-Council reserves the right to revoke the certification of any person determined to be in breach of this policy.

F&Q

To be eligible to apply to sit for the Certified Ethical Hacker Exam, a candidate must either:

  • Hold a Certified Ethical Hacker certification of version 1 to 7. * (Prior to being ANAB-accredited, EC-Council’s certifications were named based on versions – CEHV1, CEHV2, etc. During that time, candidates who attempted the certification exams were vetted for eligibility. In order to avoid “being double bill”, the EC-Council Certification department shall issue a waiver of the application fee of any candidate who has a CEH V1- CEH V7 certification and wishes to attempt the Certified Ethical Hacker ANAB-accredited certification.)
  • or have a minimum of 2 years of work experience in the InfoSec domain (You will need to pay USD 100 as a non-refundable application fee);
  • Or have attended an official EC-Council training (All candidates are required to pay the $100 application fee; however, your training fee shall include this fee)

Note:

  • As various consumer laws across the world prohibit any type of “price fixing”, the EC-Council Certification department is unable to prescribe minimum pricing for its exams. This allows a free market approach which benefits our certification community.
  • As the price of an exam voucher is many times bundled with official training by our accredited partners, the price may vary depending on the region, training facilities, training partner, the trainer's experience, cost of proctoring the exam, and even the mode of training of the partner.
  • It is imperative that we make it clear that no student shall be deemed to have any added advantage whatsoever from one mode of training to another in order to challenge the Certified Ethical Hacker exam, as the exam is a standard exam for everyone, regardless of the method of training.
  • Should any training partner attempt to tell you otherwise, we ask that you lodge an official complaint with the EC-Council certification department so that the necessary action can be taken against the training partner.

On an average, application processing time would be between 5-10 working days once the verifiers on the application respond to EC-Council’s requests for information.


  • No, the $100 application fee is not refundable
  • The application process is valid for 3 months from the date of approval.
  • Yes, the application form is mandatory for all test takers who want to take the exam directly without undergoing training.

    Note: For those who are attending official training, details will be collected as part of your training through the training evaluation feedback form.

  • Once your application is approved you can proceed to purchase your exam voucher either from EC-Council Online Store or from one of our authorised training channels.
  • Yes, the application form is mandatory for all test takers who want to take the exam directly without undergoing training.

    Note: For those who are attending official training, details will be collected as part of your training through the training evaluation feedback form.

  • No, it’s not an open book exam.
  • The exam voucher code is valid for 1 year from the date of receipt.
  • For those attempting the exam remotely through Remote Proctoring Service (RPS), The exam will be proctored remotely by an authorised proctor.
  • The Exam is a 4 hour session.
  • In order to maintain the high integrity of our certifications exams, EC-Council Exams are provided in multiple forms (I.e. different question banks). Each form is carefully analyzed through beta testing with an appropriate sample group under the purview of a committee of subject matter experts that ensure that each of our exams not only have academic rigor but also have “real world” applicability. We also have a process to determine the difficulty rating of each question . The individual rating then contributes to an overall “Cut Score” for each exam form. To ensure each form has equal assessment standards, cut scores are set on a “per exam form” basis. Depending on which exam form is challenged, cut scores can range from 60% to 85%.
  • Sessions should be booked at least 3 days in advance of the desired exam date.
  • Note: All exam sessions are proctored through EC-Council Remote Proctoring Service.
  • Once you are ready to proceed with your exam, please ensure you understand the below:

    • You need to run an equipment test.
    • You need to carry an identification proof.
    • You should hold an valid exam voucher.
  • Sessions should be booked at least 3 days in advance of the desired exam date.
  • Note: All exam sessions are proctored through EC-Council Remote Proctoring Service.

  • Yes, the Certified Ethical Hacker is a part of the Continuing Professional Education Scheme.

What You Will Learn

C|EH is divided into 20 modules and delivered through a carefully curated training plan that typically spans across 5 days. As you progress through your training, each module offers extensive hands-on lab components that allow you to practice the techniques and procedures taught in the program in real-time on live machines.

Ethical Hacking Labs With over 220 hands-on labs, conducted in our cyber range environment, you will have the opportunity to practice every learning objective in the course on live machines and vulnerable targets. Pre-loaded with over 3,500 hacking tools and a variety of operating systems, you will gain unprecedented exposure to and hands-on experience with the most common security tools, latest vulnerabilities, and widely used operating systems on the market. Our range is web accessible, allowing you to study and practice from anywhere with a connection.

How You Will Get Certified

Prove Your Skills and Abilities With Online, Practical Examinations

Certified Ethical Hacker Certification

The C|EH exam is a 4-hour exam with 125 multiple-choice questions. This knowledge-based exam will test your skills in Information Security Threats and Attack Vectors, Attack Detection, Attack Prevention, Procedures, Methodologies and more!

ceh-v12-white-logo

C|EH Practical is a 6-hour, rigorous exam that requires you to demonstrate the skills and abilities of ethical hacking techniques such as:

  • Port scanning tools (e.g., Nmap, Hping)
  • Vulnerability detection
  • Attacks on a system (e.g., DoS, DDoS, session hijacking, webserver and web application attacks, SQL injection, wireless threats)
  • SQL injection methodology and evasion techniques
  • Web application security tools (e.g., Acunetix WVS)
  • SQL injection detection tools (e.g., IBM Security AppScan)
  • Communication protocols

This is the next step to becoming a C|EH Master after you have achieved your C|EH certification. Within C|EH Practical, you have a limited amount of time to complete 20 challenges that test your skills and proficiency in a performance-based cyber range. This exam is NOT a simulation and incorporates a live corporate network of VMs and applications with solutions to uncover vulnerabilities.

Upon Completing the C|EH (Master) program, which consists of C|EH and C|EH (Practical), the C|EH (Master) designation is awarded. C|EH Masters have shown proficiency at a master level in the knowledge, skills, and abilities of ethical hacking with a total 6 hours of testing to prove their competency. Top top 10 performers in both C|EH and C|EH Practical exams are showcased on the C|EH Master Global Ethical Hacking Leaderboard.

How You Will Engage

The C|EH v12 program helps you develop real-world experience in ethical hacking through the hands-on C|EH practice environment. C|EH Engage equips you with the skills to prove that you have what it takes to be a great ethical hacker.

Your security assessment objectives will be presented as a series of flags (questions you must answer in the Cyber Range by performing ethical hacking activities on the target organization).

New to C|EH v12, students will embark on their first emulated ethical hacking engagement. This 4-phase engagement requires students to think critically and test the knowledge and skills gained by capturing a series of flags in each phase, demonstrating the live application of skills and abilities in a consequence-free environment through EC-Council’s new Cyber Range.

As you complete your training and hands-on labs, C|EH Engage lets you apply everything you have learned in a mock ethical hacking engagement. This 4-part security engagement gives you a real ethical hacking engagement experience from start to finish against an emulated organization. Using our capture-the-flag-style range, you will complete your engagement by answering “flag” questions as you progress

Where You Will Compete

The C|EH Global Challenges occur every month, providing capture-the-flag style competitions that expose students to various new technologies and platforms, from web applications, OT, IoT, SCADA, and ICS systems to cloud and hybrid environments.

.Our Compete structure lets ethical hackers fight their way to the top of the leaderboard each month in these 4-hour curated CTFs. Objective-based flags are designed around the ethical hacking process, keeping skills current, testing critical thinking abilities, and covering the latest vulnerabilities and exploits as they are discovered. Hosted 100% online in EC-Council’s Cyber Range, candidates race the clock in scenario-based engagements against fully developed network and application environments with real operating systems, real networks, tools, and vulnerabilities to practice, engage, compete, build, and hone their cyber skills against various new target organizations.

Course Outline

20 Modules that help you master the foundations of Ethical Hacking and prepare to challenge the CEH certification exam

Module 01: Introduction to Ethical Hacking

Module 02: Foot Printing and Reconnaissance

Module 03: Scanning Networks

Module 04: Enumeration

Module 05: Vulnerability Analysis

Module 06: System Hacking

Module 07: Malware Threats

Module 08: Sniffing

Module 09: Social Engineering

Module 10: Denial-of-Service

Module 11: Session Hijacking

Module 12: Evading IDS, Firewalls, and Honeypots

Module 13: Hacking Web Servers

Module 14: Hacking Web Applications

Module 15: SQL Injection

Module 16: Hacking Wireless Networks

Module 17: Hacking Mobile Platforms

Module 18: IoT and OT Hacking

Module 19: Cloud Computing

Module 20: Cryptography

Common Job Roles for C|EH

Mid-Level Information Security Auditor

Cybersecurity Analyst level 1, level 2, & level 3

Cybersecurity Auditor

Network Security Engineer

Security Administrator

SOC Security Analyst

IT Security Administrator

Security Analyst

Cyber Defense Analyst

Network Engineer

Vulnerability Assessment Analyst

Senior Security Consultant

Warning Analyst

Information Security Manager

Information Security Analyst 1

Senior SOC Analyst

Security Analyst L1

Solution Architect

Infosec Security Administrator

Cybersecurity Consultant

TOP