Cybersecurity
Certified Ethical Hacker (CEH)
Certified Ethical Hacker
Free CEH practice questions 30 questions with full answer explanations. No sign-up. Start practice →Overview
The Certified Ethical Hacker (CEH) covers the tools and techniques of offensive security from a defender's standpoint: reconnaissance, scanning, exploitation, web and wireless attacks, and more. It is broad and knowledge-based, with an optional hands-on practical exam.
CEH is well recognised by HR and meets some government baselines, which is its main strength. Practitioners often debate its depth versus hands-on alternatives, so weigh it against more practical offensive certifications if a red-team role is your goal.
✓ Who it is for
- Defenders (SOC analysts, blue-teamers, sysadmins) who want a structured grounding in how attacks work
- People whose target job posting or employer specifically names CEH
- Government and contractor roles needing a DoD 8140-recognised baseline
- Newcomers to offensive security who prefer a broad, concept-first overview before hands-on labs
✕ Who it is not for
- Beginners without networking/security fundamentals (do Security+ or Network+ first).
- Budget-conscious learners - CEH is among the most expensive certs here, with eligibility/training costs on top.
- Those who want defensive/blue-team focus rather than offensive.
Exam structure
| Reconnaissance and scanning | Footprinting, enumeration, vulnerability analysis |
|---|---|
| System and network hacking | Gaining and maintaining access |
| Web, application and wireless attacks | Common exploitation techniques |
| Cloud, IoT and cryptography | Emerging and supporting areas |
Realistic study time
- Security background 60-90 hours over 2-3 months
- New to offensive security 120-160 hours
Bars show relative effort, not a guarantee. Your time depends on background and study method.
Turn this into a week-by-week schedule with the Study Plan Generator.
What it really costs
Fees change and vary by region. Confirm the current amount on the official site before you register.
Want your full out-of-pocket figure? Try the Cost Calculator.
Salary & career value
Indicative ranges for orientation only - not surveyed data, and not financial or career advice. Sources and date below.
US security professionals who hold CEH commonly report indicative pay around ~$90k-135k, varying a lot by role (SOC/analyst lower, penetration tester/engineer higher). CEH is broad-knowledge rather than hands-on, so pay tracks the actual job title.
Pass rate: Not published. EC-Council does not release an official CEH pass rate, so quoted percentages are third-party estimates rather than verified data. There is no single fixed passing score either: EC-Council sets a cut score per exam form (it states these typically fall in the 60 to 85 percent range), and the exact cut score for your form is shown on the exam portal before you begin.
Indicative annual pay (USD), each role's typical band on a shared scale.
Other markets (indicative)
| United Kingdom | ~£40k-75k |
|---|---|
| Germany | ~€55k-80k |
Jobs that often ask for it:
- Security Analyst
- Penetration Tester
- Security Engineer
- SOC Analyst
- Cybersecurity Consultant
Is it worth it?
It depends heavily on why you need it. CEH is well recognised by HR and recruiters and meets several compliance and US DoD 8140 baselines, so it can be worth it when a job posting names it or your employer reimburses it. It also gives a structured tour of offensive concepts if you are coming from a defensive or analyst background. Where it disappoints is proving you can actually exploit systems: it is largely knowledge-based, expensive once eligibility or training is added, and many hiring managers for hands-on pentest roles rate practical, performance-based certifications more highly. Skip it if your goal is a working red-team role and a recognised brand name is not a requirement.
Not sure this is the right exam for you? Compare your options with the Exam Finder.
Compare CEH with other exams
Independent, like-for-like comparisons to help you choose the right one.
Career paths featuring CEH
What to do next
CEH proves breadth of offensive concepts; hands-on roles often value practical labs more. Compare with Security+ for a cheaper entry, or move toward CISSP for seniority.
On exam day
Proctored online by EC-Council or at a Pearson VUE centre; 125 multiple-choice questions in 4 hours.
Keeping your certification
Valid 3 years under EC-Council's ECE scheme: earn 120 ECE credits across the cycle and pay the annual membership fee.
FAQ
- Is CEH respected?
- It is well recognised by HR and meets some compliance baselines. Among hands-on practitioners, opinions vary, and practical offensive certifications are often rated more highly for red-team work.
- Do I need experience or training for CEH?
- Yes. You either take official EC-Council training or apply for eligibility with two years of security experience.
- How is CEH maintained?
- Through EC-Council Continuing Education (ECE) credits over a three-year cycle.
- Is CEH worth it?
- It helps pass HR and government filters and proves breadth of offensive concepts, but on its own it does not prove hands-on exploitation skill. It is expensive, so weigh it against practical, hands-on certifications.
- Can I self-study for CEH?
- You can study the concepts yourself, but EC-Council generally requires official training or proof of experience to be eligible to sit the exam without their course.
- What jobs can CEH help me get?
- Security analyst, junior penetration tester and roles that list CEH for compliance. Hands-on offensive roles usually also want demonstrated practical skill.
- How much does CEH cost in total?
- It is among the most expensive here: roughly US$1,199 for the exam plus eligibility or training that often runs to US$1,000 or more.
Related exams
- CompTIA Security+ (SY0-701) - CompTIA
- CompTIA CySA+ (CS0-003) - CompTIA