CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingWhat the Certified Ethical Hacker certification covers, who qualifies, what the 312-50 exam looks like, and what CEH actually costs in 2026.

The Certified Ethical Hacker (CEH) is EC-Council's flagship security certification, earned by passing a four-hour, 125-question multiple-choice exam (code 312-50). It certifies that you understand how attackers break into systems — reconnaissance, scanning, exploitation, malware, social engineering — so you can test and defend them legally. As of 2026 the current version is CEH v13, which EC-Council markets as "CEH AI" because AI-driven attack and analysis techniques now run through the curriculum.
This guide is a full orientation for beginners: what the certification actually is, whether you're eligible, how the exam works, what it costs, and how the credential is maintained. If your main question is how difficult the exam is, that deserves its own discussion — see how hard the CEH exam really is — and once you're committed, there's a separate CEH study plan and preparation guide. This article stays on the "what am I signing up for?" question.
CEH is a vendor-neutral credential from EC-Council, a certification body best known for its ethical hacking and digital forensics programmes. Holding CEH signals that you can think like an attacker: you know the phases of a hack, the tools used at each phase, and the countermeasures that stop them. It is a knowledge-first certification — the core exam tests what you know through multiple-choice questions rather than asking you to compromise live machines.
That distinction matters when you compare it with hands-on credentials. OffSec's OSCP, for instance, is a 24-hour practical exploitation exam; if you're weighing the two, the OSCP certification guide covers that credential in the same depth as this one covers CEH. CEH's strength is breadth and recognition: it surveys the whole attack landscape rather than drilling deep into exploitation technique.
CEH sits at the point where general IT or security knowledge turns into offensive-security literacy. Typical candidates include security analysts who want to understand attacks they currently only see in alerts, network and system administrators moving toward security roles, and career changers with a couple of years of infosec exposure who need a recognised credential on their CV. It is not a first-ever IT certification — EC-Council's eligibility rules (below) effectively assume you already have some security grounding.
CEH v13 is organised around the attack lifecycle. In practical terms, you'll study:
The v13 "CEH AI" positioning means AI-powered techniques — AI-assisted OSINT, vulnerability assessment and malware analysis among them — are woven into the curriculum and the knowledge exam itself. One point beginners frequently get wrong: there is no separate AI exam. You earn CEH the same way as before, by passing the 312-50 knowledge exam; the AI content simply lives inside it. v13 replaced v12 in late 2024, and v12 is retired for new candidates, so make sure any course or book you buy is aligned to v13.
EC-Council does not let anyone simply book the exam. You qualify through one of two routes:
Here's a simple decision framework for choosing between them:
A realistic example: a security operations centre (SOC) analyst with three years on the job can apply directly, pay the $100 fee, self-study, and sit the exam — total outlay stays close to the voucher price. A helpdesk technician with 18 months' experience, by contrast, has no experience-route option and must budget for official training or wait.
The core credential rests on one exam:
There is no single published pass mark. EC-Council uses banded cut scores between 60% and 85%, depending on the difficulty of the specific question form you're served. If you've read that "CEH requires 70%", treat it as a myth — the real threshold varies by exam form and EC-Council does not disclose which form you'll get. Plan to be comfortably strong across all domains rather than aiming to scrape a fixed number. What that banding means for your realistic chances of passing is exactly the territory of our CEH difficulty breakdown.
The multiple-choice exam is only half of EC-Council's ethical-hacking ladder. The optional CEH Practical is a six-hour hands-on exam of 20 challenges performed on EC-Council's iLabs Cyber Range — you demonstrate techniques against real targets instead of answering questions about them. Pass both the knowledge exam and the Practical and you earn the CEH Master designation.
Beginners don't need to decide about the Practical on day one. Earn the base credential first; if your goal is hands-on penetration-testing work, the Practical (or a fully practical certification such as OSCP) becomes the logical next question. EC-Council does not publish a standalone Practical voucher price on the pages we reviewed, so confirm current pricing with EC-Council directly before budgeting for it.
CEH pricing depends heavily on which route and delivery option you choose. As of 2026, EC-Council's store lists the exam voucher at $1,199 for Pearson VUE delivery and $950 for the ECC remote-proctored portal. Self-study candidates add the $100 eligibility application fee. Official training bundles are listed as "starting at" $1,699 (single on-demand course), $2,499 (live online) and $3,499 (unlimited on-demand) — final quotes come through EC-Council's sales process and vary by region, so treat those as floors, not totals.
| Route | Typical components | Listed cost (USD, 2026) |
|---|---|---|
| Self-study, remote exam | Eligibility application + ECC portal voucher | $100 + $950 |
| Self-study, test centre | Eligibility application + Pearson VUE voucher | $100 + $1,199 |
| Official training | Bundle including training and exam | From $1,699–$3,499 depending on format |
All figures vary by country and package — confirm current pricing on EC-Council's official site and store before committing. Retake vouchers exist on the EC-Council store, but we haven't verified a current retake price, so budget conservatively if you're not confident of a first-attempt pass.
Whether that outlay is justified for your situation — against alternatives, and given CEH's role as a human-resources screening filter — is a separate judgement, covered in our verdict on whether CEH is worth it in 2026.
CEH is valid for three years. To keep it, you participate in EC-Council's Continuing Education (ECE) scheme: earning continuing-education credits over each three-year cycle — widely reported as 120 credits, logged in EC-Council's ASPEN portal — alongside an annual EC-Council membership fee widely reported at around $80 per year. EC-Council does not publish these renewal specifics prominently on a single public policy page, so confirm the current requirements in your ASPEN account or with EC-Council support; what's certain is that letting the requirements lapse leads to suspension of the certification. Factor renewal into your long-term cost picture: CEH is a subscription to maintain, not a one-off purchase.
Before spending anything, run through this readiness checklist:
If you answered yes across the board, CEH is a reasonable and well-recognised target. If the foundation questions gave you pause, spend time on networking and operating-system fundamentals first — a broad entry-level option such as the EXIN Ethical Hacking Foundation also exists for testing the waters at lower stakes.
The roles CEH typically opens, and which certifications logically follow it, are mapped in the CEH career path guide; pay data for CEH holders lives in the CEH salary guide.
312-50 is the exam code for the CEH knowledge exam. You'll see it on vouchers, scheduling systems and study materials. Versioned listings (312-50v12, v13 and so on) refer to the curriculum version the exam form is based on — as of 2026 you'll be tested on v13 content.
Not directly through the experience route, which requires two years of information-security experience. The training route has no experience requirement, but the exam still assumes working knowledge of networks and operating systems, so complete beginners usually benefit from foundational study before attempting CEH.
The AI material changes what's covered rather than creating an extra hurdle — it's integrated into the same 125-question exam. Since v12 is retired for new candidates, the practical takeaway is simply to study v13-aligned materials.
No. The Practical is optional. The base CEH certification comes from the knowledge exam alone; the Practical only matters if you want the CEH Master designation or a hands-on proof point.
You now have the full shape of the certification: a broad, multiple-choice, attack-lifecycle exam with two entry routes, a real cost range from roughly $1,050 self-study to several thousand dollars with training, and a three-year renewal cycle. Your sensible next moves are, in order: confirm your eligibility route, check current pricing on EC-Council's official pages, and gauge the exam's demands before booking anything. To get a feel for how CEH-style questions are written, you can browse free CEH (312-50) sample questions — ExamPractice offers free samples on its exam pages, with fuller question sets and a timed simulation available to subscribers. When you're ready to build an actual study schedule, the CEH preparation guide picks up exactly where this orientation ends.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading