This guide covers the official CEH exam objectives, providing a structured learning path from foundational concepts to advanced ethical hacking techniques.
This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.
18 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.
Start Chapter 1Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.
Go to practice testEvery 312-50term defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.
Browse glossaryExam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.
View exam guideIntroduction to Ethical Hacking
Objective 1.1 · Understand the fundamentals of ethical hacking, including the roles and responsibilities of an ethical hacker, legal implications, and the ethics of hacking.
Footprinting and Reconnaissance
Objective 2.1 · Gather information about a target system using passive and active reconnaissance techniques, including footprinting methods.
Scanning Networks
Objective 2.2 · Perform network scanning to discover live hosts, open ports, and services using tools like Nmap and various scanning techniques.
Vulnerability Analysis
Objective 3.1 · Identify and assess vulnerabilities in systems and networks using automated tools and manual techniques.
System Hacking
Objective 4.1 · Understand techniques for gaining unauthorized access to systems, including password cracking, privilege escalation, and executing applications.
Malware Threats
Objective 4.2 · Analyze different types of malware, including viruses, worms, trojans, ransomware, and their propagation methods.
Sniffing
Objective 5.1 · Capture network traffic and analyze packet data using sniffing tools and techniques, including ARP poisoning.
Social Engineering
Objective 5.2 · Understand social engineering tactics, including phishing, pretexting, and other psychological manipulation techniques.
Denial of Service (DoS) and Distributed Denial of Service (DDoS)
Objective 5.3 · Understand DoS/DDoS attack methods, tools, and mitigation strategies.
Session Hijacking
Objective 5.4 · Describe session hijacking techniques and countermeasures to protect against them.
Evading IDS, Firewalls, and Honeypots
Objective 6.1 · Understand intrusion detection systems, firewalls, honeypots, and techniques to evade them.
Hacking Web Applications
Objective 7.2 · Exploit vulnerabilities in web applications, including SQL injection, XSS, CSRF, and authentication flaws.
SQL Injection
Objective 7.3 · Perform and defend against SQL injection attacks on web applications.
Hacking Wireless Networks
Objective 8.1 · Understand wireless encryption standards, attack vectors, and tools used to compromise wireless networks.
Hacking Mobile Platforms
Objective 9.1 · Explore vulnerabilities and attack methods specific to mobile operating systems and mobile device management (MDM).
IoT and OT Hacking
Objective 10.1 · Identify security issues in IoT and OT environments and understand attack vectors specific to these systems.
Cloud Computing and Cryptography
Objective 11.1 · Learn about cloud security threats and cryptographic techniques used to protect data in transit and at rest.
Penetration Testing and Reporting
Objective 12.1 · Plan, execute, and document a penetration test, including report writing and post-test cleanup.
Free 312-50 practice questions with full explanations. Test what you learn chapter by chapter.
312-50 Practice Questions