How to Pass the CEH v13 (2026): Study Plan for the Certified Ethical Hacker Exam
A study plan for EC-Council's Certified Ethical Hacker (CEH v13) — the 20 modules, the AI additions, exam format and variable cut score, and how to know you're ready.
The Certified Ethical Hacker (CEH) is EC-Council's flagship offensive-security credential — a broad tour of the attacker's toolkit taught from a defender's seat. The current version, CEH v13 (marketed as "CEH AI"), threads AI through the program: both AI-driven attack techniques and using AI to streamline the ethical-hacking workflow. This is a plan to pass the knowledge exam efficiently, focused on exam-level understanding of techniques, tools, and defenses.
What's in the exam
CEH v13 spans 20 modules and hundreds of attack techniques, organized along the phases of an engagement:
- Reconnaissance — footprinting, scanning, enumeration
- System hacking & malware — gaining access, privilege escalation, trojans/worms/ransomware
- Network hacking — sniffing, social engineering, DoS, session hijacking, evading IDS/firewalls/honeypots
- Web & application hacking — web servers, web apps (OWASP Top 10), SQL injection
- Wireless, mobile, IoT & OT hacking
- Cloud computing & cryptography
EC-Council doesn't publish per-module percentages on its product page, but reconnaissance, network hacking, and web-application hacking carry the most weight in practice — they're the phases with the most techniques and tools. New in v13: AI-assisted attack and defense concepts woven across the modules.
The study plan (6–8 weeks)
CEH rewards recognizing techniques, tools, and the right countermeasure — breadth over depth. Budget 6–8 weeks.
Weeks 1–2 — Foundations and reconnaissance. Ethical-hacking concepts, the phases of an attack, the cyber kill chain, and footprinting/scanning/enumeration — the tools (Nmap, etc.) and what each reveals. This is heavily tested; get fluent.
Weeks 3–4 — System, malware, and network hacking. Gaining access, privilege escalation, malware types, sniffing, social engineering, DoS, and session hijacking. Learn each technique and its defense — the exam pairs them.
Weeks 5–6 — Web, wireless, cloud, and crypto. Web-server and web-app attacks (know the OWASP Top 10), SQL injection, wireless (WPA3), mobile/IoT/OT, cloud attacks, and cryptography (AES/SHA-2, PKI, and recognizing modern schemes). Add the v13 AI concepts.
Weeks 7–8 — Full practice. Timed, full-length question sets across all modules, reviewing every miss. This is a recall-heavy exam; question reps are the highest-leverage prep.
Exam logistics
- Knowledge exam (312-50): 125 multiple-choice questions in 4 hours.
- Passing score is a variable cut score, 60%–85%, depending on the difficulty of your exam form — there is no fixed 70% pass mark despite what many sites claim.
- Cost: the exam voucher is around $1,199 USD (remote-proctor options run lower); training bundles cost more.
- Validity: 3 years, renewed via EC-Council Continuing Education (120 ECE credits per cycle) plus the annual membership fee.
- There's a separate hands-on CEH Practical exam; passing both earns CEH Master.
The practice-test loop
CEH is a broad recognition exam — timed questions with explanations are the fastest way to lock in the technique/tool/defense triads it tests. The loop:
- Take a timed set on the module group you're studying.
- Review every question — including correct ones — and read why each distractor is wrong.
- Repeat until you're consistently scoring in the mid-80s on fresh questions, comfortably above the highest cut score.
CertBase's CEH bank is built for that: vendor-neutral, exam-level questions across all the CEH domains — technique, tool, and defense recognition (no exploit code or weaponized payloads), current on OWASP Top 10 (2021), WPA3, and modern crypto — each with a detailed explanation of the correct answer and every distractor. Rebuilt and independently verified in July 2026, one-time purchase, lifetime access, free samples on the exam page, and a 30-day money-back guarantee.
Are you ready?
- ✅ You can name an attack technique and its countermeasure from a scenario
- ✅ Reconnaissance/scanning tools and what they reveal are second nature
- ✅ You know the OWASP Top 10 and can recognize common web attacks
- ✅ You're consistently scoring in the mid-80s on fresh, timed questions
FAQ
What's the current version of CEH? CEH v13, marketed as "CEH AI," is current — it adds AI-driven attack and defense content across the 20 modules. The exam code (312-50) is unchanged. v12 is superseded.
What's the passing score for CEH? There's no fixed passing percentage. EC-Council uses a variable cut score between 60% and 85%, set per exam form based on difficulty — so aim comfortably above 85% on practice.
How many questions and how long is the exam? The knowledge exam is 125 multiple-choice questions in 4 hours. A separate 6-hour hands-on CEH Practical exists; passing both earns CEH Master.
How long is CEH valid? Three years, renewed via EC-Council Continuing Education (120 credits per cycle) plus the annual membership fee.
Related Posts
How to Pass AWS Solutions Architect Associate SAA-C03 (2026): Study Plan & Domain Strategy
A domain-weighted study plan for the AWS Certified Solutions Architect – Associate (SAA-C03): where the points are, a 5-week schedule, scenario-question tactics, and how to know you're ready.
How to Pass Azure Fundamentals AZ-900 (2026): A 2-Week Study Plan
A focused, domain-weighted study plan for Microsoft Azure Fundamentals AZ-900 — where the points are, a 2-week schedule, exam logistics, and how to know you're ready.
How to Pass the CISSP (2026): Study Plan, Domain Weights & the Manager Mindset
A study plan for the ISC2 CISSP — the eight domains and their 2026 weights, the 3-hour CAT format, the 'think like a manager' mindset that decides borderline questions, and how to know you're ready.