Exam Domains
1.0 Introduction to Ethical Hacking
Weight not published
- 1.1Understand the fundamentals of information security, ethical hacking, and relevant laws.
Elements of Information Security; Classification of Attacks; Ethical Hacking; AI-Driven Ethical Hacking; Cyber Kill Chain Methodology; MITRE ATT&CK Framework; Risk Management; Threat Intelligence Lifecycle; Incident Management; Compliance Standards (e.g., PCI DSS, GDPR)
2.0 Footprinting and Reconnaissance
Weight not published
- 2.1Perform footprinting and reconnaissance using advanced techniques and tools.
Footprinting using search engines, social media, and internet research services; Footprinting using AI; Whois, DNS, and email footprinting; Dark Web Footprinting; Competitive Intelligence Gathering; Footprinting through social engineering; AI-Powered OSINT Tools
3.0 Scanning Networks
Weight not published
- 3.1Perform network scanning techniques and countermeasures.
Host, port, service, and OS discovery; Scanning beyond IDS and firewall; Scanning using AI; Service version discovery; OS discovery; Scanning detection and prevention
4.0 Enumeration
Weight not published
- 4.1Perform enumeration techniques on network services and systems.
NetBIOS, SNMP, LDAP, NFS, DNS, SMTP, RPC, SMB, and FTP enumeration; Enumeration using AI; DNS cache snooping; NFS, SMTP, and DNSSEC zone walking; Enumeration countermeasures
5.0 Vulnerability Analysis
Weight not published
6.0 System Hacking
Weight not published
7.0 Malware Threats
Weight not published
- 7.1Understand and analyze malware and countermeasures.
Malware types (e.g., Trojan, ransomware, worms); APT and fileless malware; Malware analysis techniques; AI-Powered malware detection tools; Malware countermeasures
8.0 Sniffing
Weight not published
9.0 Social Engineering
Weight not published
10.0 Denial-of-Service
Weight not published
11.0 Session Hijacking
Weight not published
12.0 Evading IDS, Firewalls, and Honeypots
Weight not published
13.0 Hacking Web Servers
Weight not published
14.0 Hacking Web Applications
Weight not published
15.0 SQL Injection
Weight not published
16.0 Hacking Wireless Networks
Weight not published
17.0 Hacking Mobile Platforms
Weight not published
18.0 IoT and OT Hacking
Weight not published
19.0 Cloud Computing
Weight not published
20.0 Cryptography
Weight not published
Exam Details
Question TypesMultiple Choice
FormatLinear
Online ProctoringAvailable
ID RequirementsOne valid, government-issued photo ID with full name and photo. ID must match the name used during registration.
RenewalRequired -- Earn 120 ECE (EC-Council Continuing Education) credits over 3-year cycle. ECE credits earned through courses, conferences, publications, or EC-Council activities.
Prerequisites2 years of information security work experience (waived with official EC-Council training) (recommended)
Retake PolicyNo official waiting period specified between retakes. Full exam fee required for each retake.
LanguagesEnglish