Certified Ethical Hacker (CEH)
The Certified Ethical Hacker is the most recognised and most argued-about credential covered here. Recruiters and public-sector lists name it constantly; a great many working testers hold it in low regard.
Both of those are true, and they are true about different jobs.
Exam facts
- Exam code
- 312-50
- Level
- Professional
- Field
- Cybersecurity
- Duration
- 240 minutes
- Questions
- 125 multiple-choice questions
- Passing score
- a cut score set per exam form between 60 % and 85 % — EC-Council does not publish a single passing mark
- Languages
- English
- Price
- 1,199 USD (read 12 September 2026)
- Validity
- 3 years, renewable
- Exam delivery
- Pearson VUE or the EC-Council Exam Centre (remote proctored); an exam voucher from EC-Council or bundled with accredited training
Prerequisites: Official EC-Council CEH training, or two years of information-security work experience plus an approved eligibility application (100 USD fee). Holders of CEH v1–v7 may also apply.
Renewal: 120 EC-Council Continuing Education credits within three years plus an annual fee of 80 USD; a lapsed certificate is revoked and requires a new exam
Source: exam page at EC-Council · Price: Pearson VUE exam voucher in the EC-Council Store (read 2026-09-12); the remote ECC Exam Centre voucher is quoted at 950 USD by resellers; self-study candidates add a 100 USD application fee; official training bundles cost far more
How to prepare
1. The vendor's free learning path
EC-Council publishes the exam objectives and a learning path free of charge — the authoritative source for scope and weighting. Open the learning path (opens in a new tab)
2. Online courses
Courses and practice questions from the directory that target exactly this exam — details, price and the provider link (affiliate) are on the course page.
3. A practice test in the exam format
MeasureUp sells a practice test for 312-50 with questions in the exam format, an explanation for every answer and a timed mode; the price shows in your currency on the shop page. Affiliate link.
Practice test for 312-50 at MeasureUp (opens in a new tab)Book the exam
Delivered by Pearson VUE or the EC-Council Exam Centre (remote proctored); an exam voucher from EC-Council or bundled with accredited training. Schedule with EC-Council (opens in a new tab)
Affiliate disclosure: the course and practice-test links above are affiliate links — buying through them may earn us a commission at no extra cost to you. The vendor's learning path and booking links carry no commission.
You cannot simply book it
Most certificates covered here can be bought and sat in the same week. This one has a gate. You qualify either by completing EC-Council's official training, which bundles the exam, or by documenting two years of information-security work and paying a non-refundable application fee for the eligibility review. The two routes lead to the same paper and to very different bills, and the voucher you eventually hold is valid for a year. Anyone comparing the headline voucher price against a certificate they can book on a Tuesday afternoon is comparing different products.
- Version 13 is the current edition, marketed with an artificial-intelligence label, and the exam code has not changed.
- Four hours for 125 multiple-choice questions, in English only.
- No single passing mark. EC-Council sets a cut score per exam form somewhere between 60 and 85 percent, so two candidates can face different thresholds on different days.
- A separate practical exam exists, six hours long with twenty hands-on challenges, and it is not this certificate.
The disagreement, stated fairly
Recruiters and public-sector lists name this credential constantly. Working penetration testers, as a group, hold it in low regard. Both camps are right, and they are describing different jobs. A written paper cannot measure whether somebody can compromise a system, and offensive work is judged on exactly that, so the practitioners are correct that it proves less than the name suggests. The recruiters are correct that procurement lists and screening filters are real obstacles and this credential clears them. The useful question is not which camp to believe but which door you are trying to open.
| You want to… | What this credential does for you |
|---|---|
| Get past a screening list that names it | Everything; nothing else substitutes |
| Become a tester at a specialist firm | Little; they hire on demonstrated engagements |
| Understand attacks from the defensive side | A great deal, and cheaply relative to training |
| Prove you can break into a system | Nothing; that is the practical exam or a reported engagement |
What it costs to keep, and what happens if you stop
A lapsed credential is revoked rather than suspended
Maintaining it means 120 continuing-education credits within three years plus an annual fee, and EC-Council's policy revokes rather than pauses a credential that falls out of compliance. That is stricter than most bodies covered here, where a lapse can usually be repaired. Anyone treating this as a one-off purchase should understand that the certificate has an ongoing subscription attached to it.
Put the pieces together before deciding. The voucher is the largest line, the application fee applies only on the experience route, and the annual fee and the credit requirement run for as long as you hold the certificate. Against that, the eligibility gate and the four-hour paper are the same for everyone. Where the credential is genuinely strong is engagement conduct: authorisation, scope and how to respond when a discovery lands outside them. Those questions are the ones self-taught candidates miss, and the ones an employer most needs a new tester to get right.
What a question looks like
Written by us in the exam's style. It is not a real question from any question bank, and we do not publish those.
You have written authorisation to assess a client's external systems. During reconnaissance you identify a system that appears to belong to the client but resolves to infrastructure operated by a third party not named in the agreement. What is the correct course of action?
Every technically interesting answer is wrong. Authorisation is the boundary of the engagement, and a host outside it stays outside it regardless of who appears to own the name. Candidates who prepared on practical labs rather than on engagement conduct consistently misjudge this, and it is the class of question where the certificate genuinely earns its place.
What it costs to get and to keep
| Item | Amount | Note |
|---|---|---|
| Exam voucher | 1199 USD | EC-Council's store price for the Pearson VUE voucher, which is valid for a year once purchased. A remote testing option is quoted lower by resellers; the vendor's own page for it was unavailable when we checked (read 12 September 2026) |
| Application fee, experience route | 100 USD | non-refundable, and payable only if you qualify by documented experience rather than by taking the official training (read 12 September 2026) |
| Annual maintenance fee | 80 USD | payable each year the credential is held (read 12 September 2026) |
| Continuing education | not published | 120 credits within three years. Falling out of compliance results in revocation rather than a lapse you can repair (read 12 September 2026) |
How much preparation, from where you are
- You work in defence and want to understand offence
- A stronger reason to sit it than becoming a tester. The breadth is genuinely useful for reading a report, scoping an engagement you have commissioned, and knowing which findings deserve alarm.
- You are targeting government or contracting work
- Check the requirement rather than the reputation. Where a list names this credential, practitioner opinion of it is irrelevant to whether you get the interview.
- You want to become a penetration tester and are paying yourself
- Think carefully. Specialist consultancies hire on demonstrated practical work, and the money here would go a long way toward a practical, reported engagement that hiring managers weigh more heavily.
What passing this does not prove
- Whether you can compromise anything, which is the work itself.
- Whether you could write a report a client can act on.
- Judgement under a live engagement's time pressure.
- Anything about the defensive side you would be assessing.
Against the alternatives
- PT0-003 — CompTIA PenTest+
- Similar in shape and cheaper, with a stronger process and scoping syllabus. Weaker recruiter recognition in the markets where this credential is named by list.
- SY0-701 — CompTIA Security+
- The entry certificate, far cheaper and more widely useful for getting a first security role. Sit that first unless something specifically demands this.
- CS0-004 — CompTIA CySA+
- The defensive counterpart, with considerably more seats behind it. If employability rather than interest is the deciding factor, defence hires more people.
312-50 — quick answers
Is the criticism from practitioners fair?
Partly. A written exam cannot measure whether somebody can compromise a system, and offensive work is judged on exactly that, so testers are right that it proves less than its name suggests. They are wrong that it therefore has no value, because recruiter filters and procurement lists are real obstacles and this credential clears them.
Can I sit it without taking the official training?
Yes, through the experience route, which requires a documented information-security background and a separate non-refundable application fee. That route is usually cheaper than the bundled training and it is not automatic: the application is assessed.
What happens if I let it lapse?
It is revoked rather than suspended, which is stricter than most bodies here. Getting it back means starting again. Between the annual fee and the credit requirement, treat it as a subscription rather than a purchase and decide up front whether you want to keep paying.
Why is there no fixed passing score?
EC-Council sets a cut score for each exam form, within a published band, on the basis of that form's difficulty. The intent is fairness across forms; the effect on you is that a practice-test percentage is only a rough guide, and aiming at the top of the band is the only safe target.
Should I take the practical exam instead?
If your goal is to demonstrate that you can compromise systems, the six-hour practical with its twenty challenges answers that question and this paper does not. If your goal is to clear a list or to understand offence from the defensive side, the written exam is the one the list names. Many people who need both take them in that order.
What comes next
Concepts this exam draws on
Glossary entries with the reason each one matters for 312-50.
- Web Server
Hacking web servers and web applications are two of the twenty modules.
- SSL/TLS
Cryptography and attacks on transport security close the syllabus.
- Penetration Testing
The exam is a written examination of the engagement this concept describes, from scoping to reporting.
- Phishing
Social engineering modules cover the pretexts and channels attackers use to obtain a first foothold.
- Vulnerability Management
Scanning and vulnerability analysis are examined as the phase before exploitation.
- Firewall
Evading and identifying firewalls and detection systems is a named module.
- Encryption
Cryptography is a module of its own, examined at the level of algorithms and their misuse.
- Hashing
Password cracking modules turn on how hashes are stored and attacked.
Last reviewed 12 September 2026 · Getting Digital
