Back to Blog
EC-CouncilCEHEthical Hacking

Is the CEH Exam Hard to Pass? A Realistic Difficulty Guide for 312-50

CEH is wide, not deep: twenty modules, each worth a few questions, so there is nowhere to hide a weak area. Format, cut score, eligibility, the module list, and a plan that fits the exam.

September 5, 2026
8 min read

Is the CEH Exam Hard to Pass? A Realistic Difficulty Guide for 312-50

The Certified Ethical Hacker exam is hard for a reason that surprises people: it is wide, not deep. 312-50 covers twenty modules in four hours, and each module contributes only a handful of questions, so there is nowhere to hide a weak area. You can know Metasploit inside out and still fail on cryptography, cloud and IoT questions you thought were filler.

The second surprise is that CEH is mostly a knowledge exam. Despite the name, the multiple-choice exam does not have you hack anything. Tool names, switches, output formats, attack terminology and defensive countermeasures are what get tested. Hands-on skill helps you remember them, but it is not what is scored.

This guide is about the 312-50 knowledge exam: format, cut score, the module list, where candidates fail, the eligibility route that trips up self-studiers, and a plan that fits the exam rather than the course.

CEH 312-50 at a glance

Exam312-50, Certified Ethical Hacker (the knowledge exam; CEH Practical is a separate six-hour lab exam)
Time4 hours
Questions125 multiple choice
Passing scoreSet per exam form. EC-Council states cut scores range from 60 to 85 percent; plan for 70 percent or better
FeeExam voucher around $1,199 USD, often bundled with official training. Self-study candidates also pay a $100 eligibility application fee
ValidityThree years, maintained with 120 EC-Council Continuing Education credits
EligibilityTwo years of information security work experience approved through the application, or attendance at official EC-Council training

The eligibility rule catches people every year. If you do not attend official training, you must apply, prove two years of security experience and pay the application fee before you can buy the voucher. Budget the time; approval is not instant.

The per-form cut score is the other thing to understand. EC-Council uses multiple exam forms of different difficulty and sets the pass mark for each, which is why you will see people online who "passed with 62 percent" and others who needed 80. You do not know which form you get. Prepare to clear 75 percent on realistic practice sets and the form will not matter.

What CEH actually tests

The current blueprint spreads 125 questions across twenty modules. Our bank groups them the same way. The weights below are the published shares of the exam.

  • Introduction to Ethical Hacking (6 percent): hacking phases, attack classifications, laws and standards, the ethical framework.
  • Footprinting and Reconnaissance (6 percent): OSINT, WHOIS, DNS enumeration, search engine hacking, and the tools for each.
  • Scanning Networks (5 percent): Nmap in detail, scan types, banner grabbing, evasion.
  • Enumeration (5 percent): NetBIOS, SNMP, LDAP, NTP, SMTP and DNS enumeration.
  • Vulnerability Analysis (5 percent): assessment types, scoring systems, scanner output.
  • System Hacking (7 percent): password attacks, privilege escalation, persistence, covering tracks.
  • Malware Threats (5 percent): trojans, viruses, worms, fileless malware, analysis techniques.
  • Sniffing (5 percent): ARP poisoning, MAC flooding, DHCP attacks, sniffing tools and countermeasures.
  • Social Engineering (5 percent): human-based and computer-based techniques, insider threats, countermeasures.
  • Denial-of-Service (5 percent): DoS and DDoS techniques, botnets, detection and mitigation.
  • Session Hijacking (4 percent): application and network level hijacking, and the defences.
  • Evading IDS, Firewalls and Honeypots (5 percent): detection systems, evasion techniques, honeypot identification.
  • Hacking Web Servers (4 percent) and Hacking Web Applications (6 percent): the OWASP-style attack catalogue, web server misconfigurations, the methodology.
  • SQL Injection (5 percent): injection types, blind injection, evasion, countermeasures.
  • Hacking Wireless Networks (4 percent): encryption weaknesses, wireless attacks, Bluetooth, countermeasures.
  • Hacking Mobile Platforms (4 percent): Android and iOS attack surfaces, MDM, mobile security guidelines.
  • IoT and OT Hacking (4 percent): IoT attack surfaces, OT protocols and attacks, countermeasures.
  • Cloud Computing (5 percent): container and serverless threats, cloud attacks, cloud security tools.
  • Cryptography (5 percent): algorithms, PKI, email and disk encryption, cryptanalysis.

Nineteen of those twenty modules are at 4 to 7 percent. That flatness is the difficulty. A candidate who skips the four "boring" modules at the end (wireless, mobile, IoT and OT, cloud, cryptography) has given away roughly a fifth of the exam.

Where candidates lose points

Tool switches. CEH asks which Nmap flag performs a particular scan, what a specific Hping3 command does, which Metasploit command sets a payload. Memorise the commonly tested commands for Nmap, Hping3, Netcat, John the Ripper, Hashcat, Wireshark filters, and the SQL injection strings. Our bank has a lot of these because the exam does.

Terminology traps. Vishing versus phishing versus smishing; a worm versus a trojan; a stateful versus a stateless firewall; a whaling attack versus spear phishing. The exam writers know candidates blur these and write distractors accordingly.

The "which phase" questions. Reconnaissance, scanning, gaining access, maintaining access, covering tracks. Given an activity, which phase is it? These are cheap points if you learn the phases as sequences of concrete actions rather than labels.

Reading speed. Four hours for 125 questions sounds generous, and it is, but the question stems are long and often contain irrelevant detail. Candidates who finish early tend to have misread; candidates who run out of time tend to have re-read every stem three times.

Try three real CEH practice questions

Straight from our 312-50 bank, unedited, with every option explained behind the toggle.

How long to study

  • Working penetration tester or SOC analyst: 40 to 60 hours over four weeks, almost all of it on the modules you do not use daily and on tool syntax you normally look up.
  • General security professional, security-adjacent sysadmin: 80 to 120 hours over eight to ten weeks, with lab time to make the tools concrete.
  • Newcomer with networking basics: 150 to 200 hours over four to six months, and CEH may not be the right first exam; Security+ covers the foundations CEH assumes and costs a quarter as much.

A study plan that fits a twenty-module exam

Weeks 1 to 2: modules 1 to 5. The methodology and the reconnaissance-to-enumeration chain. Build a lab with Kali Linux and one deliberately vulnerable target and run every scan type in Nmap while watching it in Wireshark. Keep a notebook of commands and what their output looks like.

Weeks 3 to 4: modules 6 to 12. System hacking through evasion. Crack a password hash with two different tools, capture an ARP-poisoned session, set up a basic IDS and trigger it. The point is memory, not mastery.

Weeks 5 to 6: modules 13 to 20. Web, SQL injection, wireless, mobile, IoT and OT, cloud, cryptography. This is where self-studiers skimp, and where the exam collects its failures. Give each module a full evening.

Week 7 onward: question volume. CEH rewards volume more than most exams because so much of it is recognition. Work through the whole free bank, then take timed sets of 125 in four hours. Review every miss by module. Our timed CEH practice exam scores you by module so the last week is targeted.

Exam day

You can sit 312-50 at a Pearson VUE centre or online through EC-Council's proctoring. Four hours is long; eat first, and plan a rhythm of 30 questions per 50 minutes with a break in the buffer. Flag anything over a minute and come back. The exam does not penalise wrong answers, so nothing is left blank.

Retakes, renewal and the real cost

Retake policies are set by EC-Council and include waiting periods that lengthen after repeated failures, and each attempt is a new voucher, so a failed CEH is one of the more expensive failures in IT certification. Once passed, you keep the credential by logging 120 continuing education credits over three years and paying the annual membership fee.

The total cost of a self-study CEH is realistically the application fee, the voucher, a lab, and the study time. It is a serious investment, which is another argument for not sitting it until practice scores are reliably above 75 percent.

Is CEH hard to pass?

It is hard to pass without covering all twenty modules, and easy to underestimate because the individual questions are not deep. Breadth, tool syntax and terminology are the whole game.

The free CEH exam dumps are grouped by module with explanations for every option, the CEH certification guide covers cost, eligibility and the full module list, and the timed exam will tell you which modules still need an evening.

Free exam dumps for this article

Share this article

Help others discover this content

Ready to Start Your Certification Journey?

Explore our comprehensive practice exams and study guides for over 375+ IT certifications.