ExamDetail Logo
HomeExamsCertificationCertified Ethical Hacker (CEH v12) Exam Guide: Fees, Syllabus & Passing Score
Cybersecurity

Certified Ethical Hacker (CEH v12) Exam Guide: Fees, Syllabus & Passing Score

Everything you need to know: Eligibility, application dates, syllabus, and official notification for 2026.

ongoing

Never Miss an Update!

Get instant notifications for Certified Ethical Hacker (CEH v12) Exam Guide: Fees, Syllabus & Passing Score dates, admit cards, and results directly on your phone.

Join WhatsApp Channel
Exam: On-Demand Booking
EC-Council
Last Updated: 28 August 2026

Certified Ethical Hacker (CEH v12) — Complete Certification Guide

The Certified Ethical Hacker (CEH v12/v13) by EC-Council is the world's most recognized vendor-neutral credential for penetration testing and offensive security. Compliant with DoD 8140/8570 Directive and ANSI/ISO/IEC 17024 standards, the CEH program immerses security professionals into the hacker mindset to uncover vulnerabilities before malicious cybercriminals exploit them.


1. CEH Exam Overview & Dual Credential Track

EC-Council offers two complementary examination paths culminating in the CEH Master credential:

ParameterCEH (Knowledge / ANSI Exam 312-50)CEH (Practical Exam)
Exam Format125 Multiple-Choice Questions (MCQs)20 Live Hands-On Lab Challenges
Exam Duration4 Hours (240 Minutes)6 Hours (360 Minutes)
Passing Score60% to 85% (Scaled score based on form difficulty)70% (14 out of 20 Challenges Solved)
Exam DeliveryECC Exam Portal / Pearson VUE / Online ProctoredAspen CyberQ Live Cloud Range
Direct Global Fee$1,199 USD (Voucher only)$550 USD (Standalone Practical)
India Partner Bundle₹38,000 – ₹50,000 INR (Training + Labs + Voucher)Included in CEH Elite packages
Combined DesignationPass ANSI Exam → Certified Ethical HackerPass Both → CEH (Master)
Validity & Renewal3 Years (120 ECE Credits + $80/year AMF)3 Years (Aligned with CEH cycle)

2. The 5 Phases of Ethical Hacking Blueprint

The CEH curriculum is structured around the five chronological phases of offensive security:

PhaseKey Tools UsedTested Core Objectives
1. Reconnaissance (Footprinting)Google Dorking, Whois, Shodan, Maltego, theHarvesterPassive & active intelligence gathering, DNS records, public metadata, employee OSINT.
2. Scanning & EnumerationNmap, Hping3, Nessus, Netdiscover, MasscanPort scanning, OS fingerprinting, banner grabbing, SNMP/SMB enumeration, network mapping.
3. Gaining Access (Exploitation)Metasploit, Burp Suite, SQLmap, Hydra, HashcatWeb application attacks (SQLi, XSS, CSRF), privilege escalation, buffer overflows, password cracking.
4. Maintaining AccessNetcat, Meterpreter, Rootkits, Trojans, BackdoorsEstablishing persistent shells, covert channels, pivoting across internal network subnets.
5. Clearing TracksAuditpol, CCleaner, Bash history clearing, Log wipesOverwriting event logs, altering timestamp metadata (timestomp), disabling security audit trails.

3. Official 20 Modules Syllabus Breakdown

The CEH v12 curriculum spans 20 specialized knowledge modules:

  1. Module 01: Introduction to Ethical Hacking & Cyber Laws
  2. Module 02: Footprinting and Reconnaissance
  3. Module 03: Scanning Networks (Nmap SYN, FIN, NULL, Xmas scans)
  4. Module 04: Enumeration (NetBIOS, SNMP, LDAP, NTP, SMTP)
  5. Module 05: Vulnerability Analysis (CVSS v3.1 scoring, scoring metrics)
  6. Module 06: System Hacking (Password cracking, privilege escalation, steganography)
  7. Module 07: Malware Threats (Trojans, Worms, Fileless Malware, Ransomware)
  8. Module 08: Sniffing (Wireshark filters, ARP poisoning, MAC flooding)
  9. Module 09: Social Engineering (Phishing, Vishing, USB drops, Identity theft)
  10. Module 10: Denial-of-Service (DDoS, SYN flood, Slowloris, Botnets)
  11. Module 11: Session Hijacking (TCP hijacking, Cross-site scripting, SSL stripping)
  12. Module 12: Evading IDS, Firewalls, and Honeypots (Fragmented packets, decoy scans)
  13. Module 13: Hacking Web Servers (Apache/IIS misconfigurations, directory traversal)
  14. Module 14: Hacking Web Applications (OWASP Top 10, SQLi, IDOR, SSRF)
  15. Module 15: SQL Injection (Union-based, Boolean-based, Time-based blind, Out-of-band)
  16. Module 16: Hacking Wireless Networks (WEP/WPA2/WPA3 cracking, Evil Twin, Rogue APs)
  17. Module 17: Hacking Mobile Platforms (Android rooting, iOS jailbreaking, MDM vulnerabilities)
  18. Module 18: IoT and OT Hacking (SCADA/ICS protocols, Modbus, Zigbee attacks)
  19. Module 19: Cloud Computing (AWS/Azure security misconfigurations, S3 bucket enumeration)
  20. Module 20: Cryptography (Symmetric/Asymmetric encryption, RSA, ECC, PKI, Digital Signatures)

4. Key Nmap Flags Tested on the Exam

Candidates frequently encounter exact command-line syntax questions on the CEH exam:

Nmap Command FlagDescription & Technical Mechanism
nmap -sS <target>TCP SYN (Stealth) Scan: Sends SYN packet, waits for SYN-ACK, responds with RST (doesn't complete handshake).
nmap -sT <target>TCP Connect Scan: Completes full 3-way handshake (SYN → SYN-ACK → ACK). Highly logged by target.
nmap -sU <target>UDP Scan: Sends UDP packets to identify open DNS, SNMP, and DHCP services.
nmap -sX <target>Xmas Tree Scan: Sets FIN, PSH, and URG flags simultaneously (lights up like a Christmas tree).
nmap -sN <target>Null Scan: Sends packet with zero flags turned on to bypass simple packet filters.
nmap -Pn <target>Skip Host Discovery: Treats all hosts as online (bypasses ICMP ping block).
nmap -O <target>OS Detection: Fingerprints target operating system using TCP/IP stack behavior.
nmap -A <target>Aggressive Scan: Enables OS detection, version scanning, script scanning, and traceroute simultaneously.

5. Career Opportunities & Salary Benchmarks

Role / DesignationIndia (INR)United States (USD)United Kingdom (GBP)
SOC Analyst (L1 / L2)₹5.0 LPA – ₹9.5 LPA$75,000 – $98,000£38,000 – £52,000
Penetration Tester / Vulnerability Assessor₹8.0 LPA – ₹16.0 LPA$95,000 – $130,000£50,000 – £72,000
Cybersecurity Consultant₹14.0 LPA – ₹26.0 LPA$115,000 – $155,000£65,000 – £90,000

Source: EC-Council Certified Ethical Hacker | Official Portal: eccouncil.org

Advertisement

Important Dates

Exam Timeline

Notification ReleasedOngoing (365 Days)
Application StartsOpen Anytime
Application EndsNo Deadline
Exam DateOn-Demand Booking

Eligibility Criteria

Age Limit
Age Criteria

18+ years (Minors 13–17 require parental consent and school authorization)

Qualification
Education

Option A: Attend official EC-Council accredited training. Option B: 2 years verifiable InfoSec experience + $100 eligibility application fee.

Attempts
Limits

Retake attempt 2 immediately; Attempts 3 to 5 require a 14-day waiting period between each attempt ($499 retake fee).

Advertisement

How to Apply

Follow this step-by-step guide to fill the Certified Ethical Hacker (CEH v12) Exam Guide: Fees, Syllabus & Passing Score application form correctly.

Documents Required

  • Scanned Passport Size Photo (20-50kb, JPG)
  • Scanned Signature (10-20kb, JPG)
  • Class 10th & 12th Marksheets
  • Category Certificate (if applicable)

Syllabus & Pattern

Download Official Syllabus

The detailed syllabus and exam pattern are available in the official notification PDF.

Download Notification PDF

Frequently Asked Questions

Official Links & Resources

Advertisement