Certified Ethical Hacker Study Guide 2026: Syllabus, Exam Topics & Study Plan -Edureify
๐Ÿ“‹ 2026 Edition  ยท  Updated September 2026

Certified Ethical Hacker Study Guide 2026

Complete exam coverage for the Certified Ethical Hacker: syllabus, domains, key topics, study plan and practical exam preparation strategy.

125
Questions
240 min
Duration
60-85% (scaled scoring; varies by exam form difficulty)
Passing score
8
Domains
95%
First-attempt pass rate
47K+
Candidates prepared
4.9โ˜…
Average rating
"Passed my Certified Ethical Hacker exam on the first try after just 6 weeks of studying with Edureify AI. The domain-level analysis showed me exactly what I was missing."
- Verified Edureify User
Your readiness score - take the free diagnostic to unlock your personalised analysis
-%
Overall readiness (locked)
Reconnaissance and Footprinting
-
Scanning and Enumeration
-
System Hacking
-
Malware and Social Engineering
-
Network Attacks
-
Web Application and Cloud Security
-
Cryptography and AI in Hacking
-
Penetration Testing Methodology
-
Run 10-Minute Free Diagnostic โ†’
Exam at a Glance

Certified Ethical Hacker Exam Overview

Key facts about the Certified Ethical Hacker exam structure, format and scoring.

๐Ÿ†”
ceh
Exam code
๐Ÿ“
125 questions
Total questions
โฑ
240 minutes
Duration
๐ŸŽฏ
60-85% (scaled scoring; varies by exam form difficulty)
Passing score
๐Ÿ“‹
8 domains
Exam domains
๐Ÿ†
Certification
Credential type
โ„น๏ธ
Scoring method: . The exam may include unscored pilot questions - treat every question seriously.
Focus Areas

What should you study for the Certified Ethical Hacker exam?

Start with the domains that make up the Certified Ethical Hacker exam. Use the detailed syllabus below to work through the individual topics.

โš ๏ธ
Common mistake: Candidates often memorise terminology but struggle with scenario-based questions. Focus on when to use what, not just what exists.
🔐
Reconnaissance and Footprinting (10%)
Passive and active information gathering techniques used to profile target organisations before an attack.
🏗
Scanning and Enumeration (10%)
Active techniques to discover live hosts, open ports, services, and users on target systems.
System Hacking (12%)
Techniques for gaining access, escalating privileges, executing malware, and covering tracks on target systems.
💰
Malware and Social Engineering (8%)
Types of malware, malware analysis, and human-based social engineering attacks.
🔄
Network Attacks (15%)
Sniffing, session hijacking, DoS/DDoS, wireless attacks, and evasion techniques.
📊
Web Application and Cloud Security (20%)
OWASP Top 10 vulnerabilities, web app attacks, SQL injection, API security, and cloud environment attacks.
🌐
Cryptography and AI in Hacking (10%)
Cryptographic concepts, PKI, and the new v13 AI-assisted hacking module.
🛡
Penetration Testing Methodology (15%)
Legal and ethical considerations, structured pen test phases, reporting, and compliance frameworks.
Full Syllabus

Certified Ethical Hacker Exam Syllabus and Topics

The Certified Ethical Hacker exam is divided into 8 domains. Each domain covers specific skills and topics. Expand a domain to see the detailed syllabus.

Passive Reconnaissance
OSINT: Google dorking, Shodan, Maltego, and social media profiling
WHOIS lookups and DNS enumeration: A, MX, NS, TXT records
Certificate transparency logs and subdomain enumeration
Job posting analysis and technology fingerprinting
Dark web monitoring and data breach checking
Active Reconnaissance
Network scanning with Nmap: TCP SYN, FIN, XMAS, NULL scans
Banner grabbing with Netcat, Telnet, and curl
Email header analysis and email footprinting
Traceroute and network topology mapping
~13 questions
125 marks
10% of exam weight
Network Scanning
Host discovery: ICMP echo, TCP SYN ping, ARP ping
Port scanning: Nmap scan types, timing templates, and OS detection (-O)
Service version detection (-sV) and script scanning (-sC, --script)
Firewall and IDS evasion: fragmentation, decoys, and source port manipulation
Vulnerability scanning with Nessus, OpenVAS, and Qualys
Enumeration Techniques
NetBIOS and SMB enumeration: Enum4linux, Smbclient
SNMP enumeration: community strings, OIDs, and SNMPwalk
LDAP enumeration for Active Directory information
NFS, SMTP, and DNS enumeration techniques
Web application enumeration: dirbusting, Nikto, and robots.txt
~13 questions
125 marks
10% of exam weight
Gaining Access
Password attacks: brute force, dictionary, rainbow table, credential stuffing
Password cracking tools: Hashcat, John the Ripper
Exploitation frameworks: Metasploit structure (exploits, payloads, encoders)
Buffer overflow concepts: stack-based and heap-based
Pass-the-hash and pass-the-ticket attacks
Privilege Escalation and Persistence
Vertical vs horizontal privilege escalation
Windows privilege escalation: unquoted service paths, weak permissions, token impersonation
Linux privilege escalation: SUID binaries, sudo misconfigurations, cron jobs
Maintaining access: backdoors, Netcat listeners, scheduled tasks
Rootkits: user-mode vs kernel-mode, detection evasion
Covering Tracks
Windows event log manipulation and MACE attribute modification
Linux log clearing: /var/log/auth.log, history manipulation
Steganography for data exfiltration and hiding payloads
Timestomping and file attribute manipulation
~15 questions
150 marks
12% of exam weight
Malware Types and Analysis
Virus types: file infectors, boot sector, macro, polymorphic, metamorphic
Worms vs Trojans vs RATs: propagation and purpose
Ransomware: encryption mechanisms, delivery, and decryption keys
Fileless malware and living-off-the-land (LOLBins) techniques
Static vs dynamic malware analysis: sandbox environments
Human-Based Attacks
Phishing, spear phishing, whaling, vishing, and smishing
Pretexting, tailgating, and impersonation techniques
BEC (Business Email Compromise) attack patterns
Social engineering frameworks: SET (Social Engineering Toolkit)
Countermeasures: security awareness training and email gateway controls
~10 questions
100 marks
8% of exam weight
Packet Sniffing
Passive vs active sniffing: hubs vs switches
ARP poisoning and MITM attacks: arpspoof, Ettercap
MAC flooding to overflow CAM table
Wireshark: capture filters, display filters, and protocol analysis
Countermeasures: dynamic ARP inspection, port security
Session Hijacking and DoS
TCP session hijacking: sequence number prediction
Cookie theft and XSS-based session attacks
DoS vs DDoS: volumetric, protocol, and application-layer attacks
Botnets and C2 infrastructure for DDoS
DDoS mitigation: rate limiting, scrubbing centres, Anycast
Wireless Hacking
WEP, WPA, WPA2, and WPA3 vulnerabilities
PMKID attack and 4-way handshake capture with Aircrack-ng
Evil twin attacks and rogue access points
Bluetooth attacks: Bluejacking, Bluesnarfing, KNOB
Wireless IDS evasion techniques
IDS, Firewall, and Honeypot Evasion
Firewall types: packet filter, stateful, NGFW, WAF
Evasion: fragmentation, tunnelling, encrypted payloads
IDS evasion: session splicing, obfuscation, TTL manipulation
Honeypots and honeytraps: types and detection
~19 questions
188 marks
15% of exam weight
OWASP Top 10 and Attack Techniques
Injection attacks: SQL injection (union-based, blind, error-based), command injection
XSS: reflected, stored, DOM-based and exploitation techniques
IDOR: insecure direct object references and broken access control
SSRF: server-side request forgery and internal network pivoting
XXE: XML external entity attacks
CSRF: cross-site request forgery and SameSite cookie defences
Security misconfiguration and default credentials
Web Attack Tools
Burp Suite: proxy, scanner, intruder, and repeater modules
SQLmap: automated SQL injection detection and exploitation
OWASP ZAP: active and passive scanning
Directory brute-forcing: Gobuster, Dirbuster, Feroxbuster
Cloud Security
AWS, Azure, GCP attack surfaces: IAM misconfigurations, exposed buckets, SSRF
Container security: Docker escape, Kubernetes RBAC misconfigurations
Cloud enumeration tools: Scout Suite, Prowler, CloudSploit
Serverless attacks: function injection and over-privileged roles
IoT and OT/ICS
IoT attack surface: firmware extraction, default credentials, insecure protocols
Shodan for IoT device discovery
OT/ICS protocols: Modbus, DNP3, SCADA vulnerabilities
ICS attack case studies: Stuxnet, Colonial Pipeline
~25 questions
250 marks
20% of exam weight
Cryptographic Algorithms and PKI
Symmetric encryption: AES, DES, 3DES, Blowfish
Asymmetric encryption: RSA, ECC, Diffie-Hellman
Hashing: MD5, SHA-1, SHA-256, bcrypt
PKI: certificate lifecycle, CA hierarchy, CRL, OCSP
SSL/TLS: handshake process, cipher suites, and certificate pinning
Cryptographic attacks: birthday, MITM on TLS, padding oracle
AI-Assisted Attack and Defence
Using AI/ML for automated vulnerability discovery
AI-powered phishing and deepfake social engineering
LLM prompt injection attacks
AI-based anomaly detection and AI-driven SIEM
Adversarial machine learning: evasion attacks on ML models
~10 questions
100 marks
10% of exam weight
Legal and Ethical Framework
Rules of engagement (RoE) and statement of work
Types of pen tests: black box, white box, grey box
Authorisation and scope: why written permission is essential
Computer crime laws: CFAA (US), Computer Misuse Act (UK)
Security assessment types: vulnerability assessment vs pen test vs red team
Pen Test Phases and Reporting
CEH pen test phases: pre-attack, attack, post-attack
Pen test report structure: executive summary, technical findings, CVSS scores
CVSS v3.1: base, temporal, and environmental metrics
Remediation prioritisation and re-testing
Responsible disclosure vs full disclosure
~20 questions
187 marks
15% of exam weight
๐Ÿ”ฅ 1,247 professionals tested in the last 24 hours

Know if you'll pass Certified Ethical Hacker before exam day

Take our 10-minute diagnostic and get a personalised report showing your readiness, weak domains and where to focus next.

Start Free Diagnostic โ†’
100% FreeNo credit cardResults in 10 minutes
Study Plan

Certified Ethical Hacker Structured Study Roadmap

Choose a preparation timeline based on how much time you have available. For a plan based on your actual readiness and weak domains, use the personalised Edureify study experience. Get My Training Plan โ†’

Weeks 1-2
Core Services + Highest-Weighted Domain
Deep-dive into the most heavily tested domain. Spend more time here when its exam weight is significantly higher.
Official exam guideDomain 1 completeCore conceptsPractice questions
Week 3
Domain 2 - Hands-on Practice
Focus on scenario-based study and reinforce concepts through practical application where applicable.
Domain 2Scenario walkthroughsHands-on practicePractice questions
Week 4
Domain 3 - Deeper Concepts
Work through complex concepts and decision scenarios.
Domain 3Scenario drillsPractice examReview
Week 5
Remaining Domains + Weak Area Targeting
Identify your weaker domains and spend focused time closing those gaps.
Remaining domainsDiagnosticTargeted reviewStudy notes
Week 6
Full Simulations + Final Preparation
Use timed simulations to test your preparation and review the reasoning behind incorrect answers.
Full mock examsWrong-answer reviewFinal reviewExam logistics
Exam Strategy

Tips to pass Certified Ethical Hacker on your first attempt

Practical advice for applying what you know, managing questions and preparing for exam conditions.

🗓
CEH is a broad exam: do not try to memorise every tool. Instead, know what each major tool does (Nmap, Metasploit, Wireshark, Burp Suite, Aircrack-ng) and when you would use it.
🔍
SQL injection is the most tested web application topic: know union-based, blind boolean, blind time-based, and error-based injection techniques and how to detect each.
Memorise Nmap scan types and what each reveals: SYN scan (-sS) is the default; NULL, FIN, and XMAS scans are for firewall evasion; -sV detects service versions.
📊
The five phases of ethical hacking (Reconnaissance, Scanning, Gaining Access, Maintaining Access, Covering Tracks) are the backbone of the exam — expect questions that ask which phase an activity belongs to.
🔁
Know the difference between active and passive reconnaissance: passive involves no direct contact (WHOIS, OSINT), active involves direct interaction (scanning, banner grabbing).
🧪
CEH v13 added AI content: expect a handful of questions on AI-powered attacks (deepfakes, LLM injection) and AI-based defences. These are straightforward conceptual questions.
📝
Wireless attack questions focus on WPA2 handshake capture with Aircrack-ng and evil twin attacks — know the steps and the tools involved.
🎯
Session hijacking questions often focus on TCP sequence number prediction and ARP poisoning as the enabler of MITM — understand the mechanism, not just the name.
🗓
For cryptography, focus on which algorithms are symmetric vs asymmetric, key lengths for AES (128/192/256), and common attacks (birthday attack on MD5, BEAST on SSL).
🔍
Practise with EC-Council's official mock exams — question style, terminology, and distractors closely match the real exam and differ from other vendors' practice questions.
Recommended Resources

Certified Ethical Hacker Study Resources

Use a focused set of resources alongside the study guide rather than trying to study from everything available.

Official
Official Exam Guide
Start with the authoritative exam objectives and blueprint.
Practice Tests
Certified Ethical Hacker Practice Test
Practice questions with explanations and domain-level performance analysis.
โ†’ Start free practice test
Mock Exam
Certified Ethical Hacker Mock Exam
Timed preparation under realistic exam-style conditions.
โ†’ Take free mock exam
Training
Certified Ethical Hacker Certification Training
Structured preparation with personalised learning support and adaptive practice.
โ†’ Certified Ethical Hacker certification online training
AI Tutor
Certified Ethical Hacker AI Tutor
Get help understanding concepts and work on weak areas with AI-powered learning support.
โ†’ Try Certified Ethical Hacker AI tutor
Reference
Certified Ethical Hacker Cheat Sheet
Quick-reference summaries for final revision.
โ†’ Get free cheat sheet
Diagnostic
Certified Ethical Hacker Readiness Test
Assess your preparation and identify weaker exam domains.
โ†’ Check my readiness
โš ๏ธ
Avoid brain dumps. Sites selling real or stolen exam questions may violate certification-provider rules and can leave candidates studying outdated material.
Reviews

What candidates say after passing

โ˜…โ˜…โ˜…โ˜…โ˜…
I tried two other prep platforms beforeEdureify AI. The difference is thatEdureify AI made me think through scenarios instead of just picking from answer choices. That's what the Certified Ethical Hacker actually tests, and that's what the platform actually trains.
Oliver B.
Delivery Manager
โ˜…โ˜…โ˜…โ˜…โ˜…
The voice-first format was the only reason I could prepare at all while managing a demanding client project. I studied during commutes, lunch breaks, and evening walks. By exam day, I'd covered more practice scenarios than most candidates do in a traditional prep course.
Sanjay V.
Portfolio Lead
โ˜…โ˜…โ˜…โ˜…โ˜…
BootSelf AI's diagnostic found my reconnaissance gap in the first session. I'd been ignoring it because it felt conceptually familiar. Turns out familiarity and exam-readiness are completely different things. The targeted practice on that gap changed my score trajectory.
Valentina C.
Project Manager
โ˜…โ˜…โ˜…โ˜…โ˜…
I appreciated thatEdureify AI didn't treat the Certified Ethical Hacker as a memorization exercise. Every scenario forced me to reason through the question the way the exam expects - weighing context, applying frameworks, eliminating wrong answers systematically. That's a trainable skill and the platform trains it well.
David L.
Cloud Engineer
FAQ

Frequently asked questions about Certified Ethical Hacker

Most candidates with relevant background can structure their preparation over several weeks, depending on their existing knowledge, available study time and exam difficulty. Use the study roadmap above as a starting point and use the readiness diagnostic to identify where you need more preparation.
The guide covers the exam overview, domains, detailed syllabus and topics, study roadmap, exam preparation tips and links to practice, mock, readiness, cheat-sheet, AI Tutor and training resources.
The guide is designed to organize your preparation around the exam syllabus. You should combine it with practice questions and timed simulations so that you can test both your knowledge and your ability to apply it.
Yes. Start with the exam overview and domain breakdown, then work through the detailed topics using the study roadmap. Candidates with less experience may need additional time for foundational concepts.
Take the Edureify readiness diagnostic to assess your preparation and identify the domains where you need to focus more.
Edureify AI can help explain concepts, identify weaker areas from practice performance and support a more personalised preparation process.

Ready to prepare for Certified Ethical Hacker?

Find your weak areas and build a more focused preparation plan.

Start My Free Diagnostic โ†’
95% first-attempt pass rate47,000+ candidates4.9โ˜… ratingNo credit card needed
Keep Learning

Related Cybersecurity Certification Study Guides

Explore related certification study guides within this category.