Exampractice
Cybersecurity

How to Prepare for the CEH Exam

A phase-by-phase CEH study plan: sequencing the v13 domains, choosing resources, using practice tests properly and knowing when you're ready to book.

Alexander Novak · 8 min read
Four-stage CEH study pipeline from foundations through domain study and labs to timed practice tests

Preparing for the Certified Ethical Hacker (CEH) exam is a coverage problem. The 312-50 knowledge exam asks 125 multiple-choice questions in 4 hours across the whole attack lifecycle — reconnaissance through cryptography — and EC-Council's cut score is a moving band between 60% and 85%, not a fixed mark you can aim to scrape. So an effective plan has one job: get you genuinely competent in every domain, including the ones your day job never touches, and prove it under timed conditions before you spend a voucher.

This guide gives you that plan: a four-phase structure, a prioritised domain sequence, a resource shortlist, and a practice-test method that measures readiness instead of flattering it. Background questions — eligibility routes, exact costs, the Practical exam, renewal — are the territory of the CEH certification guide for beginners, and if you're still deciding whether the exam's demands suit you at all, read how hard the CEH exam is before investing study weeks here.

Before you start: three decisions that shape the plan

1. Confirm your route and materials version

Your eligibility route (official EC-Council training, or the $100 application with two years' infosec experience) decides whether courseware is handed to you or chosen by you. Either way, verify that everything you study is aligned to CEH v13 — the current version as of 2026, which integrates AI-driven techniques such as AI-assisted OSINT, vulnerability assessment and malware analysis into the standard exam. v12 was retired for new candidates when v13 launched in late 2024, and older-version materials leave gaps precisely where the exam is newest.

2. Set a timeline by coverage, not by weeks

EC-Council publishes no official preparation-hours figure, and any fixed number you read is someone else's circumstances. Build your timeline backwards from coverage instead: count the domains, subtract the ones you already work in daily, and allocate study blocks to what remains, with extra weight on the areas furthest from your experience. A network administrator and a SOC analyst can follow the same plan below with completely different week counts and both be right.

3. Audit your foundations honestly

CEH assumes fluency in TCP/IP, common ports and protocols, and Windows and Linux administration basics. If reading a port-scan output or navigating a Linux shell is not routine for you, schedule a foundations phase before touching CEH-specific material — skipping it is the most expensive shortcut in this exam, because every scenario question will tax you twice.

The four-phase CEH study plan

Phase 1 — Baseline and gap map

Start by finding out where you actually stand, not where you assume you stand.

  1. Download or list the CEH v13 exam domains from EC-Council's official page and turn them into a checklist.
  2. Rate yourself per domain: work with it daily / understand it / have only heard of it.
  3. Take an untimed set of sample questions across all domains — free CEH sample questions are enough at this stage — purely to calibrate your self-ratings against reality.
  4. Sort domains into three study tiers: unknown (study first and longest), familiar-but-untested (study second), daily-use (revise last).

The output of Phase 1 is a personal gap map. Everything after this is just executing it.

Phase 2 — Domain-by-domain study

Work through your tiers in order. A sequence that works well for most candidates, because each block builds vocabulary the next one uses:

  1. Footprinting, reconnaissance and scanning — the attack lifecycle's front end and the exam's conceptual spine; scan types and enumeration outputs recur everywhere.
  2. System hacking, malware and sniffing — core offensive techniques and their artefacts.
  3. Social engineering and denial-of-service — lighter technically, heavy on classification questions that are easy marks once organised.
  4. Web application and wireless attacks — technique-dense; give these real time even if you're infrastructure-focused.
  5. Mobile, cloud and IoT — the domains specialists habitually skip, and a reliable source of avoidable lost marks.
  6. Cryptography — definitional and mechanism questions; study it last so it stays fresh.

Weave the v13 AI-related techniques into their host domains as you meet them rather than treating "AI" as a separate cram topic — that's how the exam itself presents them.

For each domain, follow the same loop: read or watch the material, make your own one-page summary (tools, flags, ports, countermeasures — the exact details CEH questions name), then answer a small block of topic-specific questions to confirm the domain moved from "read" to "usable". If a domain's question block goes badly, loop once more before moving on; unresolved weak domains compound.

Phase 3 — Hands-on reinforcement

CEH's knowledge exam is multiple-choice, but candidates who have run the tools remember them at a different depth than candidates who have only read about them. You don't need a penetration-testing lab of OSCP grade — for contrast, preparing for OSCP is almost entirely lab work — but you should:

  • Build a small home lab (two or three virtual machines: an attack box and deliberately vulnerable targets).
  • Run the staple tools from your domain summaries against your own lab — scanning, enumeration, sniffing, password attacks — and read the actual output.
  • If you're on the official training route, treat the included labs as mandatory, not optional extras.

The goal is modest and specific: when a question quotes a tool's flag or output, you recognise it from your own terminal rather than from a flashcard. If the hands-on side of security is what draws you, note one sentence of signposting: the six-hour CEH Practical and the CEH Master designation exist beyond the knowledge exam, and the beginner's CEH guide explains where they fit.

Phase 4 — Timed practice and weak-domain targeting

This phase decides whether you book the exam or book more study time.

  1. Sit a full-length, timed mock: 125 questions in 4 hours, no pauses, no references. ExamPractice offers free sample questions for the CEH 312-50 exam, with fuller question sets and a timed practice-test simulation mode available to subscribers.
  2. Analyse the result by domain, not by total. Your overall percentage matters less than the shape: a 78% built on two collapsed domains is riskier than a flat 74%, because you can't predict your form's cut score within the 60–85% band.
  3. For every wrong answer, classify the cause: didn't know the concept, confused two similar concepts, missed a tool detail, or misread the question. Each cause has a different fix — restudy, comparison notes, lab time, or pacing discipline respectively.
  4. Return to Phase 2 for your two weakest domains, then take another timed mock. Repeat this loop until the weak-domain pattern disappears.

Use practice questions to test understanding of the exam objectives — never to memorise answers. A memorised bank fails you the moment the real exam rephrases a concept, and reasoning through unfamiliar questions is precisely the skill the 312-50 rewards.

Choosing your study resources

You need surprisingly few resources, chosen deliberately:

  • The official domain list from EC-Council's CEH v13 page — your syllabus and your Phase 1 checklist. Non-negotiable.
  • One primary learning source — official EC-Council courseware if you're on the training route; otherwise one current, v13-aligned CEH study guide or video course. One. A second primary source duplicates effort without adding coverage.
  • Your own domain summaries — the highest-value resource on this list, because writing them is where the organisation happens.
  • A lab environment — virtual machines you built yourself (Phase 3).
  • A question bank with timed-mode simulation — for Phase 4's mocks and weak-domain analysis.

Signals a resource deserves your money: it states v13 alignment, it organises content by the official domains, and its practice questions explain why answers are right. Signals to walk away: promises of "real exam questions", pass guarantees, or version-unspecified material.

Common preparation mistakes

  • Studying breadth-last. Leaving mobile, cloud, IoT and cryptography for "if there's time" — there never is, and the variable cut score punishes holes.
  • Collecting resources instead of finishing one. Three half-read study guides cover less than one completed guide plus your own notes.
  • Doing only untimed questions. Untimed accuracy overstates readiness; the exam is a four-hour sitting and your mocks must be too.
  • Grinding questions before studying. Question banks are a measuring instrument; used as a primary textbook they teach answer patterns, not concepts.
  • Ignoring the answer explanations. The learning in a practice question lives in the explanation of the wrong options, not in the green tick.
  • Booking on a hunch. With voucher prices in the hundreds of dollars, the mock-based readiness gate below is much cheaper than an unplanned retake.

When are you ready to book?

Run this gate honestly. Book the exam when all of the following are true:

  • Two consecutive full-length timed mocks with no collapsed domains — every domain individually solid, not just a healthy average
  • Overall mock scores sitting comfortably above the top of the 60–85% cut-score band, giving you margin whichever form you draw
  • You can explain, from memory, the attack lifecycle with representative tools and countermeasures per phase
  • Tool-detail questions (flags, ports, outputs) no longer feel like guesswork
  • Your error analysis shows misreads and slips, not concept gaps

If the gate says yes, schedule while everything is fresh — a long gap between readiness and exam day quietly erodes the breadth you built. If it says no, it will also tell you exactly which domains to loop back to, which is the plan working as designed.

Your final fortnight

Spend the last two weeks consolidating rather than expanding: one timed mock at the start of the fortnight to set the agenda, targeted revision of whatever it flags, a lighter second mock a few days out, then domain summaries and rest. Confirm your logistics early — remote proctoring via the ECC Exam Portal has different set-up requirements from a Pearson VUE test centre, and exam-day technical stress is the one variable this plan can't revise away. Walk in knowing your preparation already answered the only question that matters: not "will I pass?", but "is there any domain where I'd be surprised by a question?" If you've followed the four phases, the answer is no — and once the certificate arrives, the CEH career path guide covers what it opens next.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like