202+ Free CEH Practice Questions
Pass your Certified Ethical Hacker (CEH v13) exam on the first try — instant access, no signup required.
Choose Your Practice Session
Select how many questions you want to practice
Questions by Category
Key Facts: CEH Exam
125
Exam Questions
EC-Council
70%
Passing Score
EC-Council
4 hours
Exam Duration
EC-Council
$1,199+
Exam Fee (with training)
EC-Council
20
Modules Covered
CEH v13
3 years
Certification Validity
ECE required
The CEH (Certified Ethical Hacker) exam has 125 multiple-choice questions in 4 hours with a passing score of 70%. CEH v13 covers 20 modules across 9 domains: Information Security (6%), Reconnaissance (15%), Scanning (10%), Enumeration (10%), System Hacking (15%), Malware (10%), Sniffing (10%), Social Engineering (8%), DoS (5%), Session Hijacking (5%), Evading Security (7%), Web Server Hacking (5%), Web App Hacking (10%), SQL Injection (7%), Wireless Hacking (5%), Mobile Hacking (4%), IoT/OT Hacking (3%), Cloud Computing (4%), and Cryptography (5%).
About the CEH Exam
The Certified Ethical Hacker (CEH v13) is the world's most comprehensive ethical hacking certification, validating skills in identifying and exploiting vulnerabilities across 20 modules including reconnaissance, scanning, system hacking, malware threats, social engineering, web application attacks, wireless hacking, IoT/OT hacking, cloud computing, and cryptography. CEH v13 introduces AI-powered ethical hacking tools and techniques.
Questions
125 scored questions
Time Limit
4 hours
Passing Score
70%
Exam Fee
$1,199-$1,699 (includes training) (EC-Council / Pearson VUE)
CEH Exam Content Outline
Information Security & Ethics
Ethical hacking concepts, security controls, penetration testing methodologies, laws and compliance, CEH hacking phases
Footprinting & Reconnaissance
Passive and active reconnaissance, DNS footprinting, Google hacking, social engineering reconnaissance, network scanning
Scanning, Enumeration & Vulnerability Analysis
Network scanning techniques, port scanning, banner grabbing, enumeration protocols (SNMP, LDAP, SMB), vulnerability assessment
System Hacking
Password cracking, privilege escalation, rootkits, keyloggers, backdoors, steganography, covering tracks
Malware Threats
Viruses, worms, Trojans, ransomware, fileless malware, malware analysis and detection techniques
Sniffing
Packet sniffing, ARP spoofing, MAC flooding, DHCP attacks, sniffing countermeasures
Social Engineering
Psychological manipulation, phishing, pretexting, insider threats, identity theft, social engineering countermeasures
Denial of Service & Session Hijacking
DoS/DDoS attacks, botnets, session hijacking techniques, TCP sequence prediction, session fixation
Evading IDS, Firewalls & Honeypots
IDS/IPS evasion, firewall evasion techniques, honeypots, intrusion detection methods
Web Application & Server Hacking
Web server attacks, web app vulnerabilities, OWASP Top 10, XSS, CSRF, injection attacks
SQL Injection
SQL injection types, blind SQL injection, SQLMap, parameterized queries, WAF bypass techniques
Wireless, Mobile, IoT & Cloud Hacking
WEP/WPA/WPA2 attacks, wireless encryption, mobile platform vulnerabilities, IoT/OT threats, cloud security, container security
How to Pass the CEH Exam
What You Need to Know
- Passing score: 70%
- Exam length: 125 questions
- Time limit: 4 hours
- Exam fee: $1,199-$1,699 (includes training)
Keys to Passing
- Complete 500+ practice questions
- Score 80%+ consistently before scheduling
- Focus on highest-weighted sections
- Use our AI tutor for tough concepts
CEH Study Tips from Top Performers
Frequently Asked Questions
What is the CEH exam format?
The CEH (ANSI) exam consists of 125 multiple-choice questions to be completed in 4 hours. The passing score is 70%. Questions cover 20 modules across ethical hacking concepts, reconnaissance, scanning, enumeration, system hacking, malware, sniffing, social engineering, DoS, web application attacks, SQL injection, wireless hacking, mobile platforms, IoT, cloud computing, and cryptography.
How much does the CEH certification cost?
The CEH exam voucher costs approximately $1,199-$1,699 when purchased with official EC-Council training. Self-study candidates can apply for an eligibility application ($100) and purchase the exam separately ($950). CEH Practical (6-hour hands-on lab exam) costs $550. CEH Master requires passing both exams.
What are the CEH v13 new features?
CEH v13 introduces AI-powered ethical hacking tools and techniques, expanded cloud security coverage (AWS, Azure, GCP), enhanced IoT and OT hacking modules, updated web application attack vectors, modern malware analysis techniques, and hands-on labs with the latest hacking tools. The curriculum covers over 550 attack techniques across 20 modules.
What are the CEH eligibility requirements?
To sit for the CEH exam without training, you need 2+ years of information security experience and must pay a $100 eligibility application fee. Alternatively, you can attend official EC-Council training (live, online, or through an accredited partner) which waives the eligibility requirement.
How do I maintain my CEH certification?
CEH certification is valid for 3 years. To maintain it, you must earn 120 ECE (EC-Council Continuing Education) credits within the 3-year period and pay an $80 annual membership fee. ECE credits can be earned through training, conferences, teaching, research, and other professional activities.
What is the difference between CEH ANSI and CEH Practical?
CEH ANSI is a 4-hour, 125-question multiple-choice exam testing theoretical knowledge. CEH Practical is a 6-hour hands-on exam where candidates must demonstrate skills in a live lab environment performing ethical hacking tasks. CEH Master is awarded to those who pass both exams. CEH Practical tests actual hands-on ability rather than just knowledge.
What jobs can I get with a CEH certification?
CEH certification prepares you for roles including Ethical Hacker, Penetration Tester, Security Analyst, SOC Analyst, Vulnerability Assessor, Security Consultant, and Red Team Member. CEH is recognized by the DoD 8140 (8570) for cybersecurity positions and is often required for government cybersecurity contracts.