Certified Ethical Hacker (CEH) (312-50) Exam Blueprint

312-50

125Questions
240 minDuration
70/60% to 85%Passing Score
$550Price
3 yearsValid For
1Languages
Practice Certified Ethical Hacker (CEH) on QuizForge

Exam Domains

1.0 Introduction to Ethical Hacking Weight not published
  • 1.1Understand the fundamentals of information security, ethical hacking, and relevant laws.
    Elements of Information Security; Classification of Attacks; Ethical Hacking; AI-Driven Ethical Hacking; Cyber Kill Chain Methodology; MITRE ATT&CK Framework; Risk Management; Threat Intelligence Lifecycle; Incident Management; Compliance Standards (e.g., PCI DSS, GDPR)
2.0 Footprinting and Reconnaissance Weight not published
  • 2.1Perform footprinting and reconnaissance using advanced techniques and tools.
    Footprinting using search engines, social media, and internet research services; Footprinting using AI; Whois, DNS, and email footprinting; Dark Web Footprinting; Competitive Intelligence Gathering; Footprinting through social engineering; AI-Powered OSINT Tools
3.0 Scanning Networks Weight not published
  • 3.1Perform network scanning techniques and countermeasures.
    Host, port, service, and OS discovery; Scanning beyond IDS and firewall; Scanning using AI; Service version discovery; OS discovery; Scanning detection and prevention
4.0 Enumeration Weight not published
  • 4.1Perform enumeration techniques on network services and systems.
    NetBIOS, SNMP, LDAP, NFS, DNS, SMTP, RPC, SMB, and FTP enumeration; Enumeration using AI; DNS cache snooping; NFS, SMTP, and DNSSEC zone walking; Enumeration countermeasures
5.0 Vulnerability Analysis Weight not published
  • 5.1Identify vulnerabilities and assess their impact.
    Vulnerability classification; Vulnerability scoring systems; Vulnerability management lifecycle; Vulnerability research; Vulnerability scanning and analysis; AI-Powered vulnerability assessment tools
6.0 System Hacking Weight not published
  • 6.1Perform system hacking to exploit vulnerabilities.
    Password cracking; Buffer overflow attacks; Privilege escalation; Steganography and steganalysis; Covering tracks and clearing logs; AI-Powered vulnerability exploitation
7.0 Malware Threats Weight not published
  • 7.1Understand and analyze malware and countermeasures.
    Malware types (e.g., Trojan, ransomware, worms); APT and fileless malware; Malware analysis techniques; AI-Powered malware detection tools; Malware countermeasures
8.0 Sniffing Weight not published
  • 8.1Perform sniffing techniques and countermeasures.
    MAC flooding, ARP poisoning, and MITM attacks; Network sniffing using tools; Detecting ARP poisoning; Sniffer detection techniques; Promiscuous detection tools
9.0 Social Engineering Weight not published
  • 9.1Understand social engineering techniques and countermeasures.
    Phishing, impersonation, and identity theft; Social engineering using AI; Mobile-based social engineering; Countermeasures against phishing and social engineering
10.0 Denial-of-Service Weight not published
  • 10.1Perform DoS and DDoS attacks and countermeasures.
    DoS and DDoS attack techniques; Botnets and attack toolkits; DoS/DDoS detection and protection; DDoS protection services
11.0 Session Hijacking Weight not published
  • 11.1Perform session hijacking and countermeasures.
    Session hijacking techniques; TCP/IP hijacking; Session hijacking detection; Prevention techniques
12.0 Evading IDS, Firewalls, and Honeypots Weight not published
  • 12.1Perform evasion techniques against IDS, firewalls, and honeypots.
    IDS/Firewall evasion techniques; Honeypot deployment; Bypassing firewall rules using tunneling; IDS/Firewall evasion countermeasures
13.0 Hacking Web Servers Weight not published
  • 13.1Perform attacks on web servers and countermeasures.
    Web server reconnaissance; Web server footprinting; Web server attacks; Web server security tools
14.0 Hacking Web Applications Weight not published
  • 14.1Perform attacks on web applications and countermeasures.
    OWASP Top 10 application security risks; Web application vulnerability scanning; Web application attacks; Web API hacking; Web application security testing
15.0 SQL Injection Weight not published
  • 15.1Perform SQL injection attacks and countermeasures.
    SQL injection techniques; Error-based and blind SQL injection; SQL injection detection tools; SQL injection countermeasures
16.0 Hacking Wireless Networks Weight not published
  • 16.1Perform attacks on wireless networks and countermeasures.
    Wireless network footprinting; Wireless traffic analysis; Cracking WPA2 networks; Wi-Fi encryption cracking; Wireless attack countermeasures
17.0 Hacking Mobile Platforms Weight not published
  • 17.1Perform attacks on mobile platforms and countermeasures.
    OWASP Top 10 mobile risks; Android and iOS hacking; Mobile device management; Mobile security guidelines; Mobile security tools
18.0 IoT and OT Hacking Weight not published
  • 18.1Perform attacks on IoT and OT systems and countermeasures.
    IoT architecture and threats; IoT hacking methodologies; OT vulnerabilities and attacks; IoT and OT security tools
19.0 Cloud Computing Weight not published
  • 19.1Perform attacks on cloud computing systems and countermeasures.
    Cloud computing threats; Container vulnerabilities; Cloud network security; Cloud security controls; Cloud security tools
20.0 Cryptography Weight not published
  • 20.1Understand encryption algorithms and cryptography tools.
    Cryptography ciphers; Public Key Infrastructure (PKI); Email and disk encryption; Cryptanalysis methods; Cryptography attacks

Exam Details

Question TypesMultiple Choice
FormatLinear
Online ProctoringAvailable
ID RequirementsOne valid, government-issued photo ID with full name and photo. ID must match the name used during registration.
RenewalRequired -- Earn 120 ECE (EC-Council Continuing Education) credits over 3-year cycle. ECE credits earned through courses, conferences, publications, or EC-Council activities.
Prerequisites2 years of information security work experience (waived with official EC-Council training) (recommended)
Retake PolicyNo official waiting period specified between retakes. Full exam fee required for each retake.
LanguagesEnglish

Official Study Resources