CEH v13 Certification: Cost, Syllabus, Exam & Training Guide

 



CEH v13 certification is EC-Council’s ethical hacking credential for professionals who assess systems lawfully, identify vulnerabilities, and recommend defenses. The knowledge exam contains 125 multiple-choice questions and lasts four hours. Candidates who pass it earn the CEH certification; the optional six-hour practical exam has 20 challenges and leads to CEH Master when both exams are passed. Eligibility is available through official training or approved self-study application based on information-security experience. Costs vary by voucher type, location, taxes, and training provider.

What Is a CEH Certification?

The Certified Ethical Hacker (CEH) certification is awarded by EC-Council to candidates who demonstrate knowledge of ethical hacking methods, attack techniques, vulnerability assessment, security controls, and defensive countermeasures.

Ethical hacking means testing systems with documented authorization from the owner. A certified ethical hacker may use techniques associated with malicious attackers, but the purpose is to identify weaknesses, reduce risk, and improve security.

The latest version is commonly called CEH v13. EC-Council also presents the program as CEH AI because artificial intelligence skills are integrated into ethical hacking training and the five-phase hacking framework:

  1. Reconnaissance

  2. Scanning

  3. Gaining access

  4. Maintaining access

  5. Covering tracks

EC-Council introduced CEH v13 in 2024 as an updated version with AI-related learning, newer attack techniques, and broader coverage of cloud, mobile, IoT, OT, and modern application security.

For the complete official program description, visit theofficial EC-Council CEH v13 program page.

CEH v13 Certification at a Glance

Feature

Details

Certification provider

EC-Council

Certification name

Certified Ethical Hacker

Version

CEH v13 / CEH AI

Knowledge exam

125 multiple-choice questions

Knowledge exam duration

4 hours

Exam code

312-50 through ECC Exam or Pearson VUE

Passing score

60% to 85%, depending on the exam form

Practical exam

20 practical challenges

Practical exam duration

6 hours

Practical delivery

Aspen/iLabs cyber range

Practical exam status

Optional for the standard CEH credential

CEH Master

Requires both the knowledge and practical exams

Passing the knowledge-based exam earns the CEH certification. The practical exam is an additional assessment. Candidates who pass both exams can earn the CEH Master designation.

What Makes CEH v13 Different?

CEH v13 is broader than a traditional network-security examination. It combines foundational security knowledge with attack methodology across multiple environments.

The training program includes:

  • 20 learning modules

  • 221+ hands-on labs

  • 550 attack techniques

  • Access to thousands of hacking and security tools in EC-Council’s cyber range

  • AI-supported ethical hacking activities

  • Web, cloud, mobile, wireless, IoT, and OT security topics

  • A practical engagement environment for applying learned skills

The important distinction is that the knowledge exam is not the same as the practical exam. The knowledge exam measures understanding through multiple-choice questions. The practical exam measures application through timed cyber-range challenges.

CEH v13 Syllabus: All 20 Modules

The CEH syllabus follows the ethical hacking lifecycle, beginning with information gathering and continuing through exploitation, post-exploitation, cloud security, and cryptography.

Module

Main topics

1. Introduction to Ethical Hacking

Security fundamentals, hacker types, laws, ethics, risk management, MITRE ATT&CK, Cyber Kill Chain, and AI-driven hacking

2. Footprinting and Reconnaissance

OSINT, search engines, WHOIS, DNS, social networks, dark web research, and AI-powered reconnaissance

3. Scanning Networks

Host discovery, port scanning, service discovery, OS detection, banner grabbing, and scan countermeasures

4. Enumeration

NetBIOS, SNMP, LDAP, NFS, DNS, SMTP, RPC, SMB, FTP, and enumeration defenses

5. Vulnerability Analysis

Vulnerability databases, scoring systems, vulnerability research, scanning, reporting, and vulnerability-management processes

6. System Hacking

Password attacks, Metasploit, buffer overflow, privilege escalation, persistence, log clearing, and post-exploitation

7. Malware Threats

Trojans, viruses, ransomware, worms, fileless malware, APTs, and static and dynamic malware analysis

8. Sniffing

Packet capture, ARP poisoning, MAC flooding, DHCP starvation, VLAN hopping, DNS poisoning, and detection

9. Social Engineering

Phishing, impersonation, identity theft, mobile-based attacks, human vulnerabilities, and countermeasures

10. Denial-of-Service

DoS, DDoS, botnets, attack detection, protection tools, and mitigation services

11. Session Hijacking

Session IDs, TCP/IP hijacking, application-level attacks, network-level attacks, detection, and prevention

12. Evading IDS, Firewalls, and Honeypots

IDS/IPS, firewalls, tunneling, endpoint evasion, honeypots, and evasion countermeasures

13. Hacking Web Servers

Web-server architecture, reconnaissance, directory discovery, server attacks, DNS hijacking, and defenses

14. Hacking Web Applications

OWASP risks, APIs, web services, access-control attacks, fuzzing, encoding, and application testing

15. SQL Injection

Error-based, union, blind, inferential, advanced, and AI-assisted SQL injection techniques

16. Hacking Wireless Networks

Wi-Fi discovery, wireless traffic analysis, WPA2 security, rogue access points, and wireless defenses

17. Hacking Mobile Platforms

Android, iOS, rooting, jailbreaking, SMS phishing, OTP hijacking, MDM, and mobile security

18. IoT and OT Hacking

IoT protocols, industrial systems, IIoT, OT vulnerabilities, device traffic analysis, and attack methods

19. Cloud Computing

AWS, Azure, Google Cloud, containers, Kubernetes, serverless computing, IAM, cloud attacks, and controls

20. Cryptography

Symmetric and asymmetric encryption, hashing, PKI, digital signatures, cryptanalysis, blockchain, and quantum threats

The CEH v13 syllabus includes both attack techniques and countermeasures. A strong candidate should understand how an attack works, what evidence it creates, how to detect it, and how to reduce the risk.

CEH v13 Exam Format

CEH Knowledge Exam

The knowledge exam is the main certified ethical hacker test. It measures your understanding of ethical hacking concepts, attack vectors, detection methods, prevention techniques, procedures, and methodologies.

Exam element

Details

Questions

125 multiple-choice questions

Duration

4 hours

Delivery

ECC Exam or Pearson VUE

Exam code

312-50

Passing score

60% to 85%

Credential earned

CEH certification

The passing score is not always a fixed percentage because EC-Council uses different exam forms and scoring standards. Candidates should use the score guidance provided for their specific examination form rather than relying on an unofficial “fixed pass mark.”

CEH Practical Exam

The CEH Practical is a separate, hands-on exam delivered through the Aspen/iLabs cyber range.

Exam element

Details

Practical challenges

20

Duration

6 hours

Format

Performance-based cyber-range assessment

Delivery

Aspen/iLabs

Passing score

60% to 85%

Purpose

Demonstrate practical ethical hacking ability

The practical assessment can include network scanning, vulnerability detection, system attacks, web-server testing, web-application security, SQL injection, wireless security, malware analysis, cryptography, and log analysis.

CEH v13 Exam Cost and Ethical Hacker Certification Cost

The total ethical hacker certification cost depends on whether you choose ECC Exam, Pearson VUE, RPS delivery, practical testing, training, taxes, and preparation materials.

The following prices were listed by the official EC-Council Store when checked:

Purchase option

Listed price

What it covers

CEH Pearson VUE exam voucher

$1,199

Knowledge exam at a Pearson VUE testing center

CEH RPS exam voucher

$950

Remotely proctored knowledge exam

CEH Practical exam

$550

Six-hour practical cyber-range exam

ECC Exam + CEH Practical package

$1,250

Knowledge exam and practical exam

Pearson VUE + CEH Practical package

$1,499

Pearson VUE knowledge exam and practical exam

These are official store prices shown at the time of writing. Prices may change based on region, currency, taxes, delivery method, promotions, and EC-Council policy. The combined exam packages listed by EC-Council do not include study material.

Additional Costs to Consider

Your final CEH v13 exam cost may include:

  • Training or a live instructor-led course

  • Study material and official courseware

  • Practice tests and lab access

  • Exam retake fees

  • Taxes or regional charges

  • Travel costs for a Pearson VUE testing center

  • The $100 non-refundable eligibility application fee for certain self-study candidates

Candidates should confirm the current price directly with EC-Council or an authorized training provider before payment.

CEH v13 Eligibility Requirements

There are two primary routes to the knowledge exam.

Route 1: Complete Official Training

Candidates who complete an approved EC-Council training course may attempt the exam without applying through the self-study eligibility route. Official training is available for different experience levels and does not require previous cybersecurity experience.

Training may be delivered through:

  • EC-Council-authorized training centers

  • Instructor-led online training

  • Academic institutions

  • Approved learning platforms

Candidates may need to submit a Certificate of Attendance or other training documentation before purchasing the exam voucher.

Route 2: Apply as a Self-Study Candidate

Candidates who do not attend official training generally need:

  1. At least two years of information-security experience

  2. A completed exam eligibility application

  3. Evidence supporting the claimed experience

  4. A $100 non-refundable eligibility application fee

  5. Approval from EC-Council before purchasing the official voucher

Relevant experience may include network security, vulnerability assessment, penetration testing, security operations, cloud security, or related information-security work. Review the latest candidate handbook before applying because eligibility procedures may be updated.

Eligibility for CEH Practical

EC-Council states that there are no predefined eligibility criteria for candidates interested in attempting the CEH Practical. However, self-study candidates may still need to satisfy applicable eligibility requirements when purchasing a voucher through a particular route.

Is CEH v13 Suitable for Beginners?

Yes. The certified ethical hacker v13 program can suit beginners, but “no mandatory experience” does not mean “no preparation is needed.”

Before beginning, beginners should understand:

  • TCP/IP networking

  • Common ports and protocols

  • Windows and Linux basics

  • Authentication and access control

  • Web applications and databases

  • Basic scripting concepts

  • Security terminology

  • The difference between vulnerability assessment and penetration testing

A beginner can learn these foundations during a structured course. However, candidates who already understand networking and operating systems will usually progress faster through the technical modules.

Certified Ethical Hacker Training Course Options

A certified ethical hacker training course should combine theory, demonstrations, labs, review questions, and exam-focused revision.

Common options include:

Self-Paced Training

Self-paced learning works well for candidates with flexible schedules and previous IT experience. It allows you to repeat difficult topics and study at your own speed.

The main risk is inconsistency. Without a study schedule, learners often complete videos but do not practice enough.

Live Online Training

CEH training online provides instructor guidance, scheduled lessons, demonstrations, question-solving sessions, and support from anywhere with an internet connection.

This format is useful when you need:

  • A fixed study timetable

  • Direct explanations

  • Help with difficult modules

  • Guided lab practice

  • Accountability before the exam

CEH Bootcamp

A CEH bootcamp compresses the core curriculum into an intensive schedule. EC-Council describes its official course as a five-day, 40-hour program, although individual providers may use different formats.

Bootcamps are useful for experienced IT professionals who can study full-time. They may be difficult for beginners because 20 modules cannot be mastered through attendance alone.

Instructor-Led or In-Person Training

In-person training can provide direct collaboration, group discussions, and immediate troubleshooting. EC-Council also lists instructor-led online, self-study, masterclass, and training-partner delivery options.

How to Prepare for the CEH v13 Exam

Use a preparation method that connects every concept to a security decision.

Step 1: Build the Technical Foundation

Review networking, Linux, Windows, web applications, databases, and authentication before starting intensive exam preparation.

Step 2: Follow the Syllabus in Order

The early modules support the later ones. Reconnaissance, scanning, enumeration, and vulnerability analysis form the foundation for system, web, wireless, mobile, cloud, and IoT testing.

Step 3: Use a Concept-Lab-Defense Cycle

For each topic:

  1. Learn the security concept.

  2. Reproduce it in an authorized lab.

  3. Identify the evidence created by the activity.

  4. Study the defensive control.

  5. Complete practice questions.

  6. Explain the topic without looking at your notes.

This method is more reliable than memorizing tool names or command syntax without understanding the underlying process.

Step 4: Use a Practical Study Schedule

A focused eight-week plan may look like this:

Weeks

Study focus

1–2

Ethical hacking fundamentals, reconnaissance, scanning, enumeration, vulnerability analysis

3–4

System hacking, malware, sniffing, social engineering, DoS, session hijacking, perimeter security

5–6

Web servers, web applications, SQL injection, wireless, mobile, IoT, and OT

7

Cloud computing, cryptography, AI topics, and weak areas

8

Full-length practice tests, timed revision, error review, and exam readiness

Step 5: Keep an Error Log

Record every missed question under one of these categories:

  • Knowledge gap

  • Misread question

  • Confused terminology

  • Incorrect defensive control

  • Weak attack sequence

  • Guessing under time pressure

Reviewing the error pattern is more valuable than repeatedly taking the same practice test.

How to Use AI While Preparing for CEH v13

CEH v13 includes AI-related ethical hacking topics, but candidates should use AI carefully.

AI can help you:

  • Summarize complex security concepts

  • Generate revision questions

  • Compare attack methods

  • Explain unfamiliar commands

  • Create defensive checklists

  • Review a lab report for clarity

AI should not replace:

  • Hands-on lab practice

  • Independent reasoning

  • Authorization checks

  • Source verification

  • Secure handling of sensitive information

Never paste real credentials, private company data, production logs, or confidential vulnerability details into an external AI system.

Is CEH v13 Certification Worth It?

CEH v13 can be valuable when you need a broad ethical hacking foundation and a recognized certification from EC-Council.

It may be a good fit if you are:

  • Beginning a cybersecurity career

  • Moving from networking or system administration into security

  • Preparing for vulnerability-assessment work

  • Working toward a SOC, security analyst, or junior penetration-testing role

  • Required to hold a recognized baseline certification

  • Looking for structured EC-Council ethical hacking training

However, the certification alone does not prove that you can independently conduct a complex penetration test. Employers may also evaluate your experience, communication skills, lab work, reporting ability, scripting, and knowledge of cloud and application security.

To strengthen your profile, build a small portfolio containing:

  • Authorized lab findings

  • Remediation reports

  • Network-security diagrams

  • Web-application testing notes

  • Secure scripts

  • Vulnerability prioritization examples

  • Clear executive summaries for nontechnical readers

CEH Certification vs CEH Master

Credential

Requirement

What it demonstrates

CEH certification

Pass the four-hour knowledge exam

Understanding of ethical hacking concepts and methodologies

CEH Master

Pass the knowledge exam and six-hour practical exam

Knowledge plus performance in practical cyber-range challenges

The practical exam is not required to earn the standard CEH credential. It is required for the CEH Master designation.

CEH Certification Validity and Renewal

EC-Council certifications generally operate on a three-year certification cycle. CEH holders must earn the required ECE credits during the cycle to renew their credential. The current candidate handbook states a requirement of 120 ECE credits per certification within three years.

Check the latest EC-Council ECE policy for current renewal fees, credit categories, and submission requirements.

Common CEH v13 Preparation Mistakes

Memorizing Tools Without Understanding the Attack

The exam tests methodology and decision-making, not only tool names. Understand why a tool is selected, what it reveals, and how defenders detect its activity.

Ignoring Legal and Ethical Topics

A security test without permission can become an unauthorized intrusion. Study authorization, scope, rules of engagement, privacy, evidence handling, and reporting.

Treating the Practical Exam as Mandatory

The practical exam is valuable, but it is separate from the standard CEH certification. Decide whether you need only CEH or the additional CEH Master designation.

Trusting an Outdated Passing Score

Passing scores can vary by exam form. Do not rely on old articles that claim one universal percentage.

Buying the Wrong Voucher

Check the delivery method, exam type, expiration period, testing location, and eligibility requirements before purchasing.

Practicing on Real Targets

Use only systems you own or have explicit written permission to test. Use labs, sandboxes, and authorized cyber ranges for practice.

Frequently Asked Questions

What is a CEH certification?

CEH certification is an ethical hacking credential from EC-Council. It validates knowledge of reconnaissance, scanning, vulnerability analysis, system hacking, web security, wireless security, mobile security, cloud security, IoT/OT security, and cryptography.

What is the CEH v13 exam cost?

The CEH v13 exam cost depends on the voucher type. The official store currently lists prices such as $1,199 for Pearson VUE, $950 for RPS delivery, and $550 for the separate practical exam. Prices can change.

How much is the ethical hacker certification cost?

The total cost may include training, courseware, exam vouchers, taxes, practical testing, retakes, and self-study eligibility fees. A training package may cost more than the exam voucher alone.

How many questions are on the CEH exam?

The knowledge exam contains 125 multiple-choice questions and lasts four hours.

What is the CEH passing score?

EC-Council lists a passing-score range of 60% to 85%, depending on the exam form. The exact score should be confirmed for your scheduled examination.

Is the CEH Practical exam required?

No. Passing the knowledge exam earns the standard CEH certification. The practical exam is optional and is required for the CEH Master designation.

Does CEH v13 require previous cybersecurity experience?

Official training does not require previous cybersecurity experience. Candidates applying through the self-study route generally need at least two years of information-security experience and approval from EC-Council.

Is CEH v13 good for beginners?

Yes, but beginners should first develop basic networking, Linux, Windows, web, and security knowledge. A structured training course can make the learning process easier.

What topics are included in the CEH syllabus?

The syllabus includes 20 modules covering reconnaissance, scanning, enumeration, vulnerability analysis, system hacking, malware, sniffing, social engineering, web security, SQL injection, wireless, mobile, IoT, OT, cloud computing, and cryptography.

How long is CEH certification valid?

The CEH credential generally follows a three-year cycle and requires continuing education credits for renewal. Review the current EC-Council ECE policy for exact requirements.

Start Your CEH v13 Preparation

Choose your exam route first: official training or approved self-study. Then confirm the current voucher price, eligibility rules, exam delivery method, and syllabus before booking.

For structured preparation, updated study resources, mock tests, and guided online support, exploreCEH v13 certification training with PassYourCert.


Comments

Popular posts from this blog

How Long to Study for CEH Certification: A Complete Guide

All About CompTIA Data+

The Role of a Client Success Manager in Driving Growth