CEH v13 certification is EC-Council’s ethical hacking credential for professionals who assess systems lawfully, identify vulnerabilities, and recommend defenses. The knowledge exam contains 125 multiple-choice questions and lasts four hours. Candidates who pass it earn the CEH certification; the optional six-hour practical exam has 20 challenges and leads to CEH Master when both exams are passed. Eligibility is available through official training or an approved self-study application based on information-security experience. Costs vary by voucher type, location, taxes, and training provider.
The Certified Ethical Hacker certification is awarded by EC-Council. It validates knowledge of ethical hacking, vulnerability assessment, attack methods, security testing, and defensive controls.
Ethical hackers use controlled techniques to find weaknesses in networks, systems, applications, cloud platforms, and devices. Testing must always be performed with written authorization.
The latest program is widely known as CEH v13. EC-Council also presents it as CEH AI because the updated curriculum includes artificial intelligence skills, modern attack techniques, and AI-supported ethical hacking activities.
Feature
Details
Certification provider
EC-Council
Certification
Certified Ethical Hacker
Current version
CEH v13 / CEH AI
Knowledge exam
125 multiple-choice questions
Exam duration
4 hours
Exam code
312-50
Passing score
60% to 85%, depending on the exam form
Practical exam
20 hands-on challenges
Practical duration
6 hours
Practical delivery
Aspen/iLabs cyber range
CEH Master
Requires both exams
The knowledge exam awards the standard CEH certification. The practical exam is optional. Candidates who pass both exams may earn the CEH Master designation.
The CEH v13 syllabus contains 20 modules:
Introduction to Ethical Hacking
Footprinting and Reconnaissance
Scanning Networks
Enumeration
Vulnerability Analysis
System Hacking
Malware Threats
Sniffing
Social Engineering
Denial-of-Service
Session Hijacking
Evading IDS, Firewalls, and Honeypots
Hacking Web Servers
Hacking Web Applications
SQL Injection
Hacking Wireless Networks
Hacking Mobile Platforms
IoT and OT Hacking
Cloud Computing
Cryptography
The first modules teach information gathering, network scanning, enumeration, and vulnerability identification.
The system-hacking modules cover password attacks, Metasploit, privilege escalation, buffer overflows, persistence, malware, and post-exploitation.
The web-security section includes web servers, web applications, APIs, OWASP risks, access-control weaknesses, fuzzing, and SQL injection.
The final modules address wireless security, mobile devices, IoT, operational technology, cloud platforms, containers, Kubernetes, IAM, encryption, PKI, digital signatures, and cryptanalysis.
EC-Council describes the current program as covering 20 modules, 221 hands-on labs, and more than 550 attack techniques.
The knowledge exam is the main certified ethical hacker test. It checks your understanding of:
Information-security threats
Attack vectors
Detection techniques
Prevention methods
Ethical hacking procedures
Security-testing methodologies
The exam contains 125 multiple-choice questions and lasts four hours. It is available through ECC Exam and Pearson VUE.
EC-Council publishes a passing-score range of 60% to 85%. The exact passing score depends on the exam form, so candidates should not rely on an outdated fixed percentage.
The CEH Practical is a separate six-hour assessment delivered through the Aspen/iLabs cyber range.
It includes 20 practical challenges involving areas such as:
Port scanning
Vulnerability detection
Web-server attacks
Web-application testing
SQL injection
Wireless attacks
Malware analysis
Cryptography
Network protocols
Log analysis
The CEH Practical is not required for the standard CEH certification. Passing both the knowledge exam and practical exam leads to the CEH Master designation.
The CEH v13 exam cost depends on the exam delivery method and the package you choose.
The official EC-Council Store listed the following prices when checked in September 2026:
Exam option
Listed price
CEH Pearson VUE exam voucher
$1,199
CEH RPS exam voucher
$950
CEH Practical exam
$550
ECC Exam plus CEH Practical
$1,250
Pearson VUE plus CEH Practical
$1,499
These prices may change. Your total ethical hacker certification cost may also include:
Training fees
Courseware
Lab access
Exam retakes
Taxes
Currency conversion
Testing-center charges
Self-study eligibility fees
Candidates should confirm the current price and voucher conditions before making a purchase.
Candidates usually qualify through one of two routes.
Candidates who complete approved EC-Council training may attempt the exam without applying through the self-study route.
Previous cybersecurity experience is not mandatory for candidates who complete the required official training. Depending on the delivery method, candidates may need to provide a Certificate of Attendance before purchasing a voucher.
Candidates who do not complete official training generally need:
At least two years of information-security experience
A completed eligibility application
Supporting evidence of experience
A non-refundable $100 eligibility fee
Approval from EC-Council
Relevant experience may include network security, system administration, vulnerability assessment, security operations, cloud security, or penetration testing.
Always check the latest candidate handbook because application rules may change.
A strong certified ethical hacker training course should include lessons, practical labs, practice questions, mock exams, and instructor support.
Self-paced training is suitable for learners who prefer flexible study hours. It allows you to repeat complex lessons and review weak topics.
The main challenge is consistency. Create a weekly schedule and reserve time for lab practice instead of watching lessons only.
CEH training online allows candidates to study through live classes, recorded lessons, guided labs, mock tests, and remote instructor support.
This format is useful if you need:
A fixed study schedule
Instructor explanations
Practical demonstrations
Lab guidance
Exam-focused revision
Support with difficult topics
A CEH bootcamp compresses the core curriculum into an intensive schedule. EC-Council describes its official course as a five-day, 40-hour program, although training providers may use different schedules.
A bootcamp can help experienced IT professionals review the syllabus quickly. Beginners may need additional weeks for practice and revision.
Before intensive preparation, review:
TCP/IP networking
Common ports and protocols
Linux and Windows basics
Web applications
Databases
Authentication
Access control
Basic scripting
The modules are connected. Reconnaissance supports scanning. Scanning supports enumeration. Enumeration supports vulnerability analysis and system testing.
For each topic:
Learn the concept.
Practise it in an authorized lab.
Identify the evidence created by the activity.
Study the relevant defense.
Complete practice questions.
Review every incorrect answer.
Study period
Main focus
Weeks 1–2
Reconnaissance, scanning, enumeration, and vulnerability analysis
Weeks 3–4
System hacking, malware, sniffing, social engineering, DoS, and session hijacking
Weeks 5–6
Web servers, web applications, SQL injection, and wireless security
Week 7
Mobile, IoT, OT, cloud computing, and cryptography
Week 8
Mock exams, weak areas, and final revision
Use only legal labs, sandboxes, and systems that you own or have permission to test.
CEH v13 may be useful for beginners, network professionals, system administrators, SOC analysts, and cybersecurity professionals moving toward ethical hacking.
It can support preparation for roles such as:
Security analyst
SOC analyst
Vulnerability assessment analyst
Network security engineer
Junior penetration tester
Cybersecurity consultant
Ethical hacker
However, certification alone does not guarantee employment. Employers may also look for practical experience, reporting skills, scripting ability, cloud knowledge, and communication skills.
Build your profile with:
Authorized lab reports
Vulnerability findings
Remediation recommendations
Network-security diagrams
Security-testing documentation
Small scripting projects
The CEH credential generally follows a three-year certification cycle. Candidates must earn the required EC-Council Continuing Education credits to maintain the certification.
The EC-Council handbook states that candidates must earn 120 ECE credits within three years. Review the latest ECE policy for current renewal requirements and fees.
CEH certification is an ethical hacking credential awarded by EC-Council. It validates knowledge of reconnaissance, scanning, vulnerability analysis, system hacking, web security, wireless security, cloud security, mobile security, IoT, OT, and cryptography.
Yes. Beginners can prepare for CEH v13, but basic networking, operating-system, and cybersecurity knowledge will make the course easier to understand.
The official-store price varies by delivery method. The listed knowledge-exam prices include $950 for RPS delivery and $1,199 for Pearson VUE. Training and taxes may cost extra.
No. The knowledge exam earns the standard CEH certification. The practical exam is required for the CEH Master designation.
The syllabus includes 20 modules covering reconnaissance, scanning, enumeration, vulnerability analysis, system hacking, malware, web security, SQL injection, wireless, mobile, IoT, OT, cloud computing, and cryptography.
Official training does not require previous cybersecurity experience. The self-study route generally requires two years of information-security experience and EC-Council approval.
Prepare for the CEH v13 certification with updated study materials, guided online training, practical lessons, practice questions, mock exams, and instructor support.
Visit PassYourCert’s CEH v13 training page to review the available preparation options and start your ethical hacking certification journey.