Skip to main content
Back to Blog
Study Guides

How to Pass the CEH v13 (2026): Study Plan for the Certified Ethical Hacker Exam

A study plan for EC-Council's Certified Ethical Hacker (CEH v13) — the 20 modules, the AI additions, exam format and variable cut score, and how to know you're ready.

CertBase Team
4 min read

The Certified Ethical Hacker (CEH) is EC-Council's flagship offensive-security credential — a broad tour of the attacker's toolkit taught from a defender's seat. The current version, CEH v13 (marketed as "CEH AI"), threads AI through the program: both AI-driven attack techniques and using AI to streamline the ethical-hacking workflow. This is a plan to pass the knowledge exam efficiently, focused on exam-level understanding of techniques, tools, and defenses.

What's in the exam

CEH v13 spans 20 modules and hundreds of attack techniques, organized along the phases of an engagement:

  • Reconnaissance — footprinting, scanning, enumeration
  • System hacking & malware — gaining access, privilege escalation, trojans/worms/ransomware
  • Network hacking — sniffing, social engineering, DoS, session hijacking, evading IDS/firewalls/honeypots
  • Web & application hacking — web servers, web apps (OWASP Top 10), SQL injection
  • Wireless, mobile, IoT & OT hacking
  • Cloud computing & cryptography

EC-Council doesn't publish per-module percentages on its product page, but reconnaissance, network hacking, and web-application hacking carry the most weight in practice — they're the phases with the most techniques and tools. New in v13: AI-assisted attack and defense concepts woven across the modules.

The study plan (6–8 weeks)

CEH rewards recognizing techniques, tools, and the right countermeasure — breadth over depth. Budget 6–8 weeks.

Weeks 1–2 — Foundations and reconnaissance. Ethical-hacking concepts, the phases of an attack, the cyber kill chain, and footprinting/scanning/enumeration — the tools (Nmap, etc.) and what each reveals. This is heavily tested; get fluent.

Weeks 3–4 — System, malware, and network hacking. Gaining access, privilege escalation, malware types, sniffing, social engineering, DoS, and session hijacking. Learn each technique and its defense — the exam pairs them.

Weeks 5–6 — Web, wireless, cloud, and crypto. Web-server and web-app attacks (know the OWASP Top 10), SQL injection, wireless (WPA3), mobile/IoT/OT, cloud attacks, and cryptography (AES/SHA-2, PKI, and recognizing modern schemes). Add the v13 AI concepts.

Weeks 7–8 — Full practice. Timed, full-length question sets across all modules, reviewing every miss. This is a recall-heavy exam; question reps are the highest-leverage prep.

Exam logistics

  • Knowledge exam (312-50): 125 multiple-choice questions in 4 hours.
  • Passing score is a variable cut score, 60%–85%, depending on the difficulty of your exam form — there is no fixed 70% pass mark despite what many sites claim.
  • Cost: the exam voucher is around $1,199 USD (remote-proctor options run lower); training bundles cost more.
  • Validity: 3 years, renewed via EC-Council Continuing Education (120 ECE credits per cycle) plus the annual membership fee.
  • There's a separate hands-on CEH Practical exam; passing both earns CEH Master.

The practice-test loop

CEH is a broad recognition exam — timed questions with explanations are the fastest way to lock in the technique/tool/defense triads it tests. The loop:

  1. Take a timed set on the module group you're studying.
  2. Review every question — including correct ones — and read why each distractor is wrong.
  3. Repeat until you're consistently scoring in the mid-80s on fresh questions, comfortably above the highest cut score.

CertBase's CEH bank is built for that: vendor-neutral, exam-level questions across all the CEH domains — technique, tool, and defense recognition (no exploit code or weaponized payloads), current on OWASP Top 10 (2021), WPA3, and modern crypto — each with a detailed explanation of the correct answer and every distractor. Rebuilt and independently verified in July 2026, one-time purchase, lifetime access, free samples on the exam page, and a 30-day money-back guarantee.

Are you ready?

  • ✅ You can name an attack technique and its countermeasure from a scenario
  • ✅ Reconnaissance/scanning tools and what they reveal are second nature
  • ✅ You know the OWASP Top 10 and can recognize common web attacks
  • ✅ You're consistently scoring in the mid-80s on fresh, timed questions

FAQ

What's the current version of CEH? CEH v13, marketed as "CEH AI," is current — it adds AI-driven attack and defense content across the 20 modules. The exam code (312-50) is unchanged. v12 is superseded.

What's the passing score for CEH? There's no fixed passing percentage. EC-Council uses a variable cut score between 60% and 85%, set per exam form based on difficulty — so aim comfortably above 85% on practice.

How many questions and how long is the exam? The knowledge exam is 125 multiple-choice questions in 4 hours. A separate 6-hour hands-on CEH Practical exists; passing both earns CEH Master.

How long is CEH valid? Three years, renewed via EC-Council Continuing Education (120 credits per cycle) plus the annual membership fee.

CEHEC-Councilethical hackingcybersecuritystudy planhow to pass

Related Posts