CEH Exam Guide 2026: Format, Cost, Salary & 8-Week Prep Plan
Ethical hacking has gone from a niche IT specialty to one of the most in-demand career tracks in the world, and the Certified Ethical Hacker (CEH) credential from EC-Council remains the most widely recognized entry point into it. If you are weighing whether to sit the exam this year, this CEH exam guide 2026 walks through exactly what the test covers, what it costs, how it compares to alternatives like OSCP, and how to build a realistic study plan that fits around a full-time job.
This is not a marketing pitch for the certification. It is a practical breakdown built from EC-Council's own exam documentation and current third-party prep guides, written for candidates in India, the United States, the Gulf, Southeast Asia, and Europe who are all chasing the same shortage of qualified defenders.
Why CEH still matters in 2026
The global cybersecurity workforce gap has not closed — it has held stubbornly at more than 3.5 million unfilled roles worldwide, according to industry workforce studies cited by EC-Council. Every region is short-staffed: Bengaluru, Pune, and Hyderabad are absorbing security hires as fast as product companies can post the roles; Gulf enterprises are standing up new security operations centers ahead of national cybersecurity mandates; and North American and European employers are still listing "CEH preferred" on penetration testing, SOC, and cloud security postings years after the certification's peak hype cycle.
CEH's staying power comes down to three things. First, it is vendor-neutral and methodology-based, so it teaches the full attacker lifecycle — reconnaissance, scanning, gaining access, maintaining access, and covering tracks — rather than a single tool or platform. Second, it maps to recognized frameworks like the US Department of Defense's DoD 8570/8140 baseline, which makes it a checkbox credential for government and defense-adjacent contracts. Third, it is genuinely a reasonable first certification: the knowledge exam does not require you to already have penetration testing experience, unlike more advanced hands-on certs.
That said, CEH is not a magic ticket to a six-figure job on its own. It works best as a structured way to learn ethical hacking methodology and prove baseline competence to a recruiter's applicant tracking system and a hiring manager's shortlist — then you build on it with labs, projects, and either the CEH Practical or a harder hands-on cert like OSCP.
For official program details, see EC-Council's Certified Ethical Hacker page.
CEH exam format and domains, in plain terms
EC-Council currently runs two separate exams under the CEH umbrella, and candidates frequently confuse them. Here is the breakdown as of the current v13 / "CEH AI" iteration.
The CEH Knowledge exam (the one most people mean by "CEH")
- Format: 125 multiple-choice questions, each with four answer options and exactly one correct answer
- Duration: 4 hours (240 minutes), which works out to roughly 1 minute 55 seconds per question — the time limit is generous, so breadth of recall is the real challenge, not speed
- Delivery: Pearson VUE testing centers or remote proctoring through the ECC exam portal
- Passing score: EC-Council uses an adaptive cut score rather than a single published percentage. Depending on which exam form you draw, the passing threshold typically falls somewhere between 60% and 85%, calibrated to that form's difficulty
- Domain coverage: 20 domains spanning the entire ethical hacking workflow, including footprinting and reconnaissance, scanning networks, enumeration, vulnerability analysis, system hacking, malware threats, sniffing, social engineering, denial-of-service, session hijacking, evading IDS/firewalls/honeypots, hacking web servers and web applications, SQL injection, wireless network hacking, mobile platform hacking, IoT and OT hacking, cloud computing security, and cryptography
- What's new for this iteration: EC-Council markets the current version as the first ethical hacking certification built around AI, adding modules on AI-assisted attack techniques and AI-driven defense alongside expanded cloud and IoT/OT content, across roughly 20 learning modules and 550+ documented attack techniques
The CEH Practical exam (optional, hands-on)
This is where CEH tries to answer the "can you actually do this" criticism leveled at multiple-choice security certifications.
- Format: 20 real-world hands-on challenges performed live on EC-Council's iLabs cyber range — think cracking password hashes, identifying and exploiting web application vulnerabilities, performing SQL injection, and completing scanning/enumeration tasks against live targets
- Duration: 6 hours
- Passing score: commonly cited around 70%
- Why it matters: passing both the Knowledge exam and the Practical earns you the CEH Master designation, which is the credential that actually demonstrates applied skill to a hiring manager rather than just recall of methodology
What it costs
Budget matters when you are comparing certifications, so here is the current fee structure:
- CEH Knowledge exam voucher: roughly $1,199 at a physical Pearson VUE center, or around $950 if you use remote online proctoring directly through EC-Council
- A $100 non-refundable eligibility application fee applies if you are self-studying rather than going through an EC-Council Authorized Training Center
- CEH Practical exam: approximately $550
- CEH Master (Knowledge + Practical combined): roughly $1,749 in exam fees alone, before training materials
- Official training packages range from around $1,699 for a single on-demand course to $2,499+ for live online instruction
If your employer is footing the bill, ask specifically whether they're paying for Knowledge only or the full Master track — the difference changes both your prep timeline and what the credential signals on your resume.
Career paths CEH actually opens up
CEH rarely lands you directly in an elite red-team seat, but it is a legitimate stepping stone into several roles that recruiters and applicant tracking systems actively filter for:
Penetration tester / junior pentester. CEH's methodology coverage — recon through reporting — maps almost directly onto how consulting and internal pentest teams structure engagements. Entry-level pentest roles frequently list CEH as a preferred or accepted credential alongside (or in place of) a degree requirement.
SOC analyst. Security operations centers hire heavily for Tier 1 and Tier 2 analysts who understand attacker behavior well enough to triage alerts. CEH's attack-vector knowledge is directly relevant here, and it pairs naturally with SOC-specific interview prep — if you're weighing a SOC path alongside or instead of pentesting, ClavePrep's guide on cybersecurity analyst and SOC interview questions is a useful next read once you've got the certification roadmap sorted.
Cloud security analyst. With cloud modules now built into the current CEH blueprint, the certification increasingly serves as a baseline credential for hybrid cloud security roles, especially at companies migrating legacy infrastructure and needing staff who understand both traditional and cloud attack surfaces.
Red team specialist / vulnerability assessor. For candidates already targeting more advanced offensive roles, CEH functions as the "prove you understand the fundamentals" layer before pursuing OSCP, GPEN, or CRTP.
Salary data worth knowing
Compensation varies enormously by region, seniority, and whether you hold CEH alone or stack it with hands-on experience, but the directional data is consistent:
- CEH holders in the US report an average base salary around $96,490, with entry-level professionals around $72,000 and senior specialists commanding $200,000+
- A Global Knowledge salary survey found CEH delivers roughly an 18% pay premium over non-certified peers, with entry-level jumps of about $10,000 (from $65K to $75K) and mid-level jumps of about $17,000 (from $85K to $102K)
- Broader penetration testing roles in 2026 average $95,000 to $140,000 in the US, with certified professionals earning 15–25% more than uncertified peers
- Outside the US, purchasing-power-adjusted compensation is climbing fastest in India's tech hubs (Bengaluru, Pune, Hyderabad), the UAE and wider Gulf as national cybersecurity initiatives mature, and Australia's Sydney/Melbourne corridor
See EC-Council's own breakdown at Ethical Hacker (CEH) Salary: What to Expect for the source data behind these figures.
CEH vs OSCP: which one should you actually pursue
This comparison comes up in nearly every ethical hacking career forum, and the honest answer is "it depends on where you are in your career."
CEH is a knowledge and methodology exam — 125 multiple-choice questions testing whether you understand attack phases, tools, and defensive concepts across 20 domains. OSCP (Offensive Security Certified Professional) is a brutal 24-hour hands-on practical exam that requires you to actually compromise machines in a live environment, with no multiple-choice safety net.
If you are new to cybersecurity, CEH is generally the better first move: it structures your learning across the full attack lifecycle, it's recognized for compliance frameworks like DoD 8570, and it doesn't assume you already have exploitation experience. OSCP assumes you can already do the work and tests whether you can do it under pressure — most candidates who succeed on OSCP have already built hands-on lab hours through platforms like Hack The Box or TryHackMe.
If you're specifically targeting a dedicated penetration testing or red team role, OSCP holders typically command a premium and are viewed as having proven, not just studied, offensive skills. Many experienced practitioners end up holding both: CEH as the broad foundation and resume credential, OSCP as proof of applied capability.
A realistic 8-week CEH prep plan
Cramming 20 domains into a week or two rarely works, and burning six months on a single exam risks losing momentum. Eight weeks, with consistent daily effort and dedicated lab time, is a realistic middle ground for someone working full-time.
Weeks 1–2: Foundations and footprinting. Cover information security fundamentals, footprinting and reconnaissance, and scanning networks. Set up your lab environment now — a Kali Linux VM plus a couple of intentionally vulnerable targets (Metasploitable, DVWA, or a free-tier Hack The Box account) so every concept has a hands-on counterpart from day one.
Weeks 3–4: Enumeration through system hacking. Work through enumeration techniques, vulnerability analysis, and system hacking (password attacks, privilege escalation, and covering tracks). This is the densest technical stretch — expect to spend real lab time here, not just flashcards.
Weeks 5–6: Malware, network attacks, and web/app hacking. Cover malware threats, sniffing, social engineering, denial-of-service, session hijacking, evading defenses, and the web server/web application/SQL injection domains — historically some of the heaviest-weighted material on the exam. If you only have time to deep-dive one cluster of domains with hands-on labs, make it this one.
Week 7: Wireless, mobile, IoT/OT, cloud, and cryptography. These domains are individually lighter on the exam but collectively substantial. Prioritize cloud security concepts given how much recent CEH content weighting has shifted toward cloud and AI-assisted attack techniques.
Week 8: Full-length practice exams and weak-area triage. Run at least two full 125-question timed practice exams under real exam conditions. Log every missed question by domain, then spend the final days closing your two or three weakest domains rather than re-reviewing material you already know cold. If you're pursuing CEH Master, this is also when to book iLabs time and rehearse the Practical exam's challenge format.
Throughout the eight weeks, treat lab practice as non-negotiable, even though the Knowledge exam is multiple-choice. Candidates who only memorize flashcards tend to freeze on scenario-based questions that describe a symptom (unusual outbound traffic, a specific log pattern) and ask you to identify the attack technique — those questions reward pattern recognition built through hands-on repetition, not rote memorization.
Sample question types and how to approach them
EC-Council doesn't publish real exam questions, but the question styles are well documented by test-takers and training providers. Here's what to expect and how to reason through each type.
Scenario-based identification. "A security analyst notices repeated small variations in packet timing from an internal host to an external IP over port 53." These questions describe attacker behavior and ask you to name the technique (in this case, likely DNS tunneling). Approach: build a mental map linking observable symptoms to attack categories during your prep, rather than memorizing definitions in isolation.
Tool-to-purpose matching. Questions ask which tool accomplishes a specific task — for example, matching Nmap, Nessus, Wireshark, Burp Suite, or Metasploit to the correct phase of an engagement. Approach: organize your notes by attack phase (recon, scanning, exploitation, post-exploitation) and list the two or three canonical tools for each phase rather than trying to memorize every tool CEH's curriculum mentions.
"Best next step" methodology questions. These present a stage in an engagement and ask what a penetration tester should do next according to proper methodology — testing whether you understand sequencing (you don't exploit before you've enumerated, you don't report before you've validated findings). Approach: internalize the standard attack lifecycle order and default to it unless the scenario gives you a clear reason to deviate.
Definitional and conceptual questions. Straightforward recall — defining terms like "zero-day," distinguishing symmetric versus asymmetric cryptography, or identifying compliance frameworks. These are the most memorization-friendly questions and the ones flashcard-style review handles well.
Legal and ethical scope questions. CEH tests your understanding of authorization, scope, and the legal boundaries of penetration testing — questions about what makes hacking "ethical" in the first place, including rules of engagement and reporting obligations. Approach: treat this material seriously even though it feels obvious; a surprising number of candidates lose points here by rushing past it in prep.
Common mistakes candidates make
Treating it as a pure memorization exam. The multiple-choice format tempts people into flashcard-only prep. Scenario questions punish this approach because they test application, not recall.
Skipping lab time entirely. Even for the Knowledge-only track, hands-on practice with the actual tools dramatically improves your ability to answer scenario and tool-matching questions correctly, and it's essential preparation if you plan to add the Practical exam later.
Underestimating the newer domains. Cloud security, IoT/OT, and AI-assisted attack content have expanded significantly in the current CEH iteration. Candidates who prep from older study guides or outdated question banks often get blindsided by this material.
Booking the exam too early. Because the passing threshold is adaptive and unpublished, a rushed attempt with shaky fundamentals is a costly way to find out where your gaps are. Two full-length timed practice exams scoring comfortably above your target range is a reasonable readiness signal.
Ignoring interview prep until after the certification lands. A CEH badge gets your resume past some filters, but the interview is where the offer actually gets decided. Rehearsing how you'll talk through your methodology, your lab projects, and past incidents (real or simulated) matters just as much as the exam itself.
Turning the certification into interview offers
Passing CEH proves you know the material — the next hurdle is proving it convincingly in a live interview, where recruiters and hiring managers ask you to walk through actual scenarios rather than pick from four options. This is where structured practice pays off. ClavePrep's AI mock interview tools let you rehearse security-specific behavioral and technical questions with realistic follow-ups, and if you're translating hands-on lab work or a CTF project into a compelling story, the STAR response builder helps you structure it so a non-technical interviewer can follow the impact.
It's also worth double-checking that your resume actually gets read before you get to the interview stage — the ATS resume checker flags formatting and keyword issues that keep otherwise qualified security candidates from clearing automated screening. And if you want a broader sense of how ClavePrep's prep tools fit together across the job search, the how it works page walks through the full flow from resume to offer.
Frequently asked questions
How many questions are on the CEH exam and how long do I get? The CEH Knowledge exam has 125 multiple-choice questions and a 4-hour time limit. That works out to just under two minutes per question on average, so most candidates find time pressure is not the main obstacle — knowledge breadth across all 20 domains is.
What is a good CEH exam passing score? EC-Council uses an adaptive cut score rather than one fixed number, and published guidance puts the range at roughly 60% to 85% depending on the difficulty of the specific exam form you receive. There's no way to know your exact target in advance, so aim to consistently score comfortably above 80% on full-length practice exams before booking the real thing.
How much does the CEH certification cost in total? Expect roughly $950 to $1,199 for the Knowledge exam voucher depending on delivery method, plus a $100 application fee if you're self-studying outside an authorized training center. Adding the optional Practical exam (around $550) to earn CEH Master brings total exam fees to roughly $1,749, before any training course costs.
Is CEH worth it in 2026, or should I go straight for OSCP? For most people starting out, CEH is worth it as a structured foundation and a resume credential recognized across compliance-heavy industries and government-adjacent roles. If you already have hands-on offensive security experience and are targeting a dedicated penetration testing or red team role, OSCP will carry more weight with specialist hiring managers. Many professionals eventually hold both.
How do I become an ethical hacker without a computer science degree? CEH is explicitly designed to not require a traditional CS background — EC-Council's eligibility path accepts relevant work experience or completion of official training in place of a degree. Build a home lab, work through free platforms like TryHackMe or Hack The Box to develop hands-on comfort, then use CEH's structured domain list as your study roadmap. A degree helps in some markets but is increasingly optional for security roles that prioritize demonstrated skill.
What salary can I expect with a CEH certification? US-based CEH holders report an average base salary around $96,490, with a realistic range from about $72,000 at entry level to $200,000+ for senior specialists, and certification alone is associated with roughly an 18% pay premium over non-certified peers. Regional figures vary substantially, with strong and accelerating demand in India's tech hubs, the Gulf, and Australia.
Do I need the CEH Practical exam, or is the Knowledge exam enough? The Knowledge exam alone gets you the standard CEH credential, which is sufficient for many analyst and junior security roles, especially ones prioritizing compliance recognition. The Practical exam (and the resulting CEH Master designation) matters more if you're targeting hands-on penetration testing or red team roles where hiring managers want proof of applied exploitation skill, not just methodology knowledge.
How long should I study for the CEH exam? An 8-week plan with consistent daily study and dedicated lab time is realistic for most working professionals, assuming you already have basic networking and IT fundamentals. If you're starting from scratch on networking concepts, budget an extra 2–4 weeks before diving into the CEH-specific domains.
Whichever path you take from here — Knowledge exam only, full CEH Master, or CEH as a stepping stone toward OSCP — the certification is only half the job search. Pair it with deliberate interview rehearsal, and you'll walk into that penetration testing or SOC analyst interview able to explain not just what you know, but how you think through a live attack scenario under pressure.
