CEH · ● Active · Associate-Professional · EC-Council
Exam facts
| Field | Value |
|---|---|
| Cost | $1,199 USD (knowledge exam standalone) or $550 USD (if NOT taking official EC-Council iWeek training); FREE exam with iLabs subscription; regional pricing varies |
| Duration | 240 minutes (4 hours) |
| Questions | 125 multiple choice |
| Passing | 70% (87.5 correct answers) |
| Format | Multiple choice, proctored |
| Delivery | Pearson VUE (online and testing center) |
| Languages | English (primary); Japanese, Chinese available in select regions |
| Valid | 3 years from pass date |
| Renewal | Retake exam OR earn qualifying CEH hands-on credential (CEH Practical) OR maintain active EC-Council membership with continuing education units (CEUs) |
| Prerequisites | None formal; recommended: 2+ years information security experience |
| Released | CEH v13 launched Q1 2024 (supersedes v12 from 2021) |
| Retiring | N/A — v13 is current as of May 2026 |
Vendor source — EC-Council Certified Ethical Hacker ↗
Official exam guide — CEH v13 Exam Blueprint & Courseware ↗
Exam objectives — CEH v13 Knowledge Domains ↗
About
The Certified Ethical Hacker (CEH) v13 is EC-Council's flagship penetration testing and ethical hacking credential, aimed at security professionals pursuing hands-on offensive security roles. Launched in Q1 2024, CEH v13 refreshes the v12 curriculum to include AI-augmented hacking techniques, cloud-native reconnaissance, IoT/OT attack methodologies, and modern C2 frameworks. The certification spans 14 knowledge domains: reconnaissance, network scanning, enumeration, system hacking, malware analysis, sniffing, social engineering, DoS attacks, session hijacking, web application hacking, wireless penetration testing, mobile device hacking, IoT/OT hacking, cloud security assessment, cryptography, and AI-driven cybersecurity concepts.
CEH is vendor-neutral but heavily weighted toward hands-on labs and practical scenarios (supported by the optional separate CEH Practical exam, a 6-hour lab-based assessment). Industry perception remains mixed: CEH is praised for breadth and accessibility (especially for career-changers), but criticized as "broad but shallow" compared to Offensive Security's OSCP (which is hands-on-only, 24-hour exam). CEH is commonly held by SOC analysts, vulnerability assessors, and junior penetration testers; it stacks well with CompTIA Security+ and is frequently required or preferred by government contractors and larger security teams.
Domain context — Security & Cybersecurity
Offensive penetration testing and ethical hacking. EC-Council's ecosystem is one of the largest and most accessible in ethical hacking, with flexible pricing (FREE via iLabs), optional hands-on labs, and global training availability.
Read full deep dive — Security & Cybersecurity Domain →
Topics covered
CEH v13 exam blueprint covers 14 domains with approximately equal weight per knowledge area:
- Information Security Fundamentals & Ethics — Legal frameworks, ethics, compliance, information security principles
- Reconnaissance & Footprinting — Passive/active reconnaissance, OSINT, information gathering, domain enumeration
- Network Scanning & Enumeration — Network mapping, port scanning (nmap), service enumeration, vulnerability scanning
- System Hacking & Intrusion — Privilege escalation, password attacks, hash cracking, system compromise techniques
- Malware Analysis & Threat Intelligence — Malware classification, behavioral analysis, reverse engineering, AV evasion
- Network Sniffing & Packet Analysis — Packet capture, protocol analysis, man-in-the-middle, ARP spoofing, DNS spoofing
- Social Engineering & Physical Security — Phishing, pretexting, physical penetration, organizational security testing
- Denial-of-Service (DoS) Attacks — DDoS techniques, botnet mechanics, mitigation strategies
- Session Hijacking & Replay Attacks — Session theft, cookie manipulation, replay attack methodologies
- Web Application & Server Hacking — OWASP Top 10, SQL injection, XSS, authentication bypass, API exploitation
- Wireless Network Penetration Testing — WPA/WPA2 cracking, rogue access points, wireless reconnaissance
- Mobile Device & IoT Hacking — Mobile OS vulnerabilities, Android/iOS exploitation, IoT device assessment
- Cloud Computing Security Assessment — AWS/Azure/GCP misconfiguration, cloud-native attacks, container security
- Cryptography & Encryption — Symmetric/asymmetric encryption, hashing, digital signatures, key management
Source: EC-Council CEH v13 Knowledge Domains ↗
Common skills at Security & Cybersecurity · Associate-Professional
Shared competencies for offensive security roles at this level — not specific to CEH.
- Vulnerability identification and assessment across networks, systems, and applications
- Hands-on exploitation techniques (network-based and application-based)
- Information gathering and OSINT using industry-standard tools (Nmap, Metasploit, Burp Suite, Wireshark)
- Privilege escalation and post-exploitation / persistence mechanisms
- Social engineering and phishing campaign execution (authorized testing only)
- Report writing and remediation recommendations for stakeholders
- Security tool proficiency: packet analyzers, vulnerability scanners, exploitation frameworks
- Basic cryptography understanding and encryption bypass scenarios
- Wireless network assessment and common wireless attack vectors
Recommended courses at Security & Cybersecurity · Associate-Professional
| Provider | Title | Cost | URL |
|---|---|---|---|
| EC-Council (Official) | CEH v13 iWeek / iLearn Training | $2,500–$3,500 USD | ↗ |
| EC-Council (Official) | iLabs Hands-On Labs (Exam Prep) | $500–$1,200 USD (subscription) | ↗ |
| Cybrary | Certified Ethical Hacker (CEH) v13 | Free (basic) / $399/yr (premium) | ↗ |
| Udemy (Heath Martin) | Certified Ethical Hacker (CEH) v13 Complete Course | $15–$80 USD | ↗ |
| Udemy (Ali Abdaal / Networking Academy) | Kali Linux & Ethical Hacking Masterclass | $15–$80 USD | ↗ |
| INE (formerly eLearnSecurity) | Certified Ethical Hacker (CEH) v13 | $499–$999 USD | ↗ |
| TryHackMe | Penetration Testing Path (complementary labs) | Free / $300/yr (premium) | ↗ |
| HackTheBox | Penetration Tester Learning Path | Free / $250/yr (premium labs) | ↗ |
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| Boson | EC-Council CEH v13 Practice Exam | $129–$199 USD | ↗ |
| MeasureUp | EC-Council Certified Ethical Hacker v13 Practice Tests | $99–$149 USD | ↗ |
| Whizlabs | CEH v13 Practice Exam | $39–$99 USD | ↗ |
| EC-Council (Official) | iLabs Hands-On Virtual Labs + Practice Questions | $500–$1,200 USD (subscription) | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| CEH Certified Ethical Hacker All-in-One Exam Guide, Fifth Edition | Matt Walker | McGraw-Hill | 2023 | 978-1264269945 | ↗ |
| EC-Council Certified Ethical Hacker (CEH) v13 Official Courseware | EC-Council | EC-Council Press | 2024 | N/A | ↗ |
| The Hacker Playbook 3 | Peter Kim | CreateSpace Independent Publishing | 2018 | 978-1980901770 | ↗ |
| Web Application Security Testing Cookbook | Paco Hope & Ben Walther | O'Reilly Media | 2008 | 978-0596514839 | ↗ |
| The Basics of Hacking and Penetration Testing | Patrick Engebretson | Syngress | 2013 | 978-1597496544 | ↗ |
Typical job titles at Security & Cybersecurity · Associate-Professional
Penetration Tester · Ethical Hacker · Vulnerability Assessment Specialist · Security Analyst (Offensive) · Red Teamer · Security Engineer (Junior) · Web Application Security Tester
(Job titles drawn from current job-board postings that list CEH as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $85K–$140K (penetration tester / ethical hacker / security analyst) | Glassdoor ↗ · Robert Half ↗ · Levels.fyi ↗ |
| ZAR | R120K–R220K (penetration tester / ethical hacker in major metros) | Pnet ↗ · PayScale ZA ↗ · CareerJunction ↗ |
| GBP | £60K–£95K (penetration tester, UK market) | IT Jobs Watch ↗ · Hays ↗ |
| EUR | €70K–€110K (Germany/Netherlands/France, pentester / ethical hacker) | Indeed DE ↗ · LinkedIn Salary Explorer ↗ |
| AUD | A$110K–A$160K (penetration tester, Australia) | Seek ↗ · PayScale AU ↗ |
Salary note: CEH holders typically occupy mid-tier offensive security roles (junior penetration tester, security analyst, vulnerability assessor). Salary progression depends heavily on hands-on experience and certifications (OSCP, CRTP, CRTO elevate earning potential by 20–40%). CEH alone is considered "broad but shallow" in the industry; pairing it with OSCP or GIAC GPEN significantly increases market value.
Skills validated
CEH-specific — technologies, tools, and methodologies this exam actually tests.
- Nmap (network scanning and enumeration)
- Metasploit Framework (exploitation and payload delivery)
- Burp Suite (web application testing)
- Wireshark (packet analysis and network sniffing)
- hashcat / John the Ripper (password cracking and hash analysis)
- Aircrack-ng (wireless network penetration testing)
- Kali Linux (offensive security distribution and tool suite)
- OWASP Top 10 web vulnerabilities (SQL injection, XSS, CSRF, authentication bypass, etc.)
- Windows / Linux system exploitation and privilege escalation
- Social engineering and phishing campaign mechanics
- ARP spoofing, DHCP starvation, DNS spoofing, man-in-the-middle attacks
- Cryptographic concepts (symmetric, asymmetric, hashing, digital signatures)
- Cloud platform reconnaissance (AWS S3 misconfigurations, Azure overpermissioning, GCP service account abuse)
- Malware analysis fundamentals and reverse engineering concepts
- Wireless WPA/WPA2 cracking and rogue access point techniques
Related certifications
- Stacks with: CompTIA Security+ (SY0-701) ↗ · CompTIA PenTest+ (PT0-003) ↗
- Prerequisite for (hands-on track): Offensive Security OSCP (PEN-200) ↗ · GIAC GPEN (GIAC Penetration Tester) ↗ · Practical Penetration Tester (eLearnSecurity / INE) ↗
- Alternative at this level: Offensive Security OSWP (Wireless-100) ↗ · GIAC GWAPT (GIAC Web Application Penetration Tester) ↗
- Equivalents at this level: CompTIA PenTest+ (PT0-003) ↗ — CompTIA's competing mid-level penetration testing cert
- Industry positioning note: CEH is broadly recognized and heavily taught globally (especially in Asia-Pacific), but in North America and Western Europe it is often viewed as "entry-level pentest" compared to OSCP or CRTP, which require more hands-on lab work.
- Vendor overview: EC-Council Vendor Overview ↗
Sources
- EC-Council CEH v13 Certification Main Page: https://eccouncil.org/train-certify/certified-ethical-hacker-ceh/
- EC-Council iLearn Training Portal: https://eccouncil.org/train-certify/certified-ethical-hacker-ceh/ilearn/
- EC-Council iLabs Hands-On Labs: https://eccouncil.org/ilabs/
- Cybrary CEH v13 Course: https://www.cybrary.it/course/certified-ethical-hacker-ceh/
- Boson CEH v13 Practice Exam: https://www.boson.com/practice-exam/ec-council-ceh-practice-exam
- MeasureUp CEH v13 Practice Tests: https://www.measureup.com/ec-council-certified-ethical-hacker-ceh-v13.html
- Whizlabs CEH v13 Practice Exam: https://www.whizlabs.com/ceh-v13/
- Matt Walker, CEH Certified Ethical Hacker All-in-One Exam Guide (Fifth Edition), McGraw-Hill, 2023: https://www.mhprofessional.com/9781264269945-ceh-certified-ethical-hacker-all-in-one-exam-guide-fifth-edition-ebook
- Glassdoor Penetration Tester Salary Data: https://www.glassdoor.com/Salaries/penetration-tester-salary-SRCH_KO0,20.htm
- Robert Half IT Security Salary Guide (2026): https://www.roberthalf.com/us/en/salary-guide/it-security
- ZA Job Market (Pnet): https://pnet.co.za/
- UK IT Jobs Watch (Penetration Tester): https://www.itjobswatch.co.uk/
Last verified: 2026-05-01
Parent ecosystem: EC-Council Pentesting & Ethical Hacking
Parent domain: Security & Cybersecurity
Vendor overview: EC-Council Vendor Overview