Ethical Hacking Practice Exam: Free CEH Mock Test, Questions & Study Guide (2026)

ethical hacking practice exam

So you typed “ethical hacking practice exam” into Google. You’re probably not after some dry definition — you want something that actually feels like the CEH v13 exam, a rough idea of where you stand right now, and maybe a hint about what to brush up on before you drop $1,199 on the real certification through EC-Council. Fair enough. That’s exactly what this ethical hacking practice exam guide covers, with 30 original questions, a full breakdown of the CEH passing score, and everything else the standard “10 sample questions” pages tend to skip.

Here’s the short version: an ethical hacking practice exam is a stand-in for the real CEH test. It touches the same areas — reconnaissance, scanning, enumeration, system hacking, malware, and web application security — and doing a few of these before your real exam does something a textbook never will. It shows you where you’re actually shaky, gets you used to working under a ticking clock, and takes some of the “unknown” out of exam day.

Quick answer: think of an ethical hacking practice exam as a rough copy of the actual CEH test — same territory, really: reconnaissance, scanning, enumeration, system hacking, malware, web application security, all of it. Run through a decent set of mock questions before your real attempt and a few things happen almost automatically. You start noticing which topics you actually know versus which ones you’re just guessing on. Your pacing gets better because you’re not seeing the format for the first time on exam day. And honestly, a lot of the nervousness around CEH v13 just comes from not knowing what to expect — practice questions take a chunk of that away too.

Quick Facts: CEH v13 at a Glance

CEH certification exam preparation workstation
DetailInfo
ExamCEH v13
Questions125
Time Limit4 Hours
Exam Code312-50
Passing ScoreScaled (varies by version)
ProviderEC-Council
Certification Validity3 Years
Practical OptionCEH Practical (hands-on)

What Is an Ethical Hacking Practice Exam?

Think of it as a dress rehearsal. It’s built to feel like the real CEH exam — same structure, similar difficulty, same spread of topics — just without anything actually riding on it. You’re answering multiple-choice questions from the same domains EC-Council tests, which means you’re not just reading about penetration testing anymore. You’re being asked to actually use it.

None of this works if you’re leaning on leaked exam dumps, by the way. Sure, dumps might get you a passing score. But you’ll walk out with a certificate and not much actual skill behind it — and that gap shows up fast in a real interview or on the job.

Who Should Take This Practice Exam?

  • Beginners just getting their footing in cybersecurity
  • Students a few weeks out from their scheduled CEH exam
  • Security analysts brushing up before recertification
  • SOC analysts moving toward a more offensive security role
  • Network engineers curious about the attacker’s side of things
  • System administrators who want to understand what they’re defending against
  • Penetration testers prepping for CEH alongside other certifications

CEH Exam Overview

Right now, in 2026, CEH v13 is the version you’ll actually be sitting for. Before getting deep into prep, it’s worth knowing roughly what the exam looks like on the surface. As things stand, the CEH knowledge exam runs 125 multiple-choice questions. That said, EC-Council does tweak formats and objectives from one release to the next, so don’t just take this number as gospel — a quick check of the official exam page before you register is worth the two minutes it takes.

  • Exam code: 312-50 (ECC EXAM), also offered through Pearson VUE
  • Format: Multiple choice, computer-based
  • Number of questions: 125
  • Duration: 4 hours
  • Delivery: Online proctored or in-person at a testing center
  • Cost: Roughly $1,199 USD, depending on how you register
  • Validity: 3 years, after which you’ll need continuing education credits or a retake

CEH v13 also leans more heavily into AI-assisted tools than earlier versions did, which makes sense given how a lot of real-world penetration testing works now — automated recon, AI-assisted vulnerability triage, that kind of thing.

What Is the CEH Passing Score?

This is one of the most searched questions about the exam, and it trips people up because CEH doesn’t work like a lot of other certifications. Unlike exams with one fixed passing number, EC-Council uses a scaled scoring system.

In plain terms, your actual passing mark depends on which version of the exam you happen to draw and how tough that particular question set turns out to be. Most candidates end up needing somewhere between 60% and 85% to clear it, though where exactly you land in that range comes down to your specific form. The whole point of scaling it this way is fairness — since everyone’s question pool is a bit different, this keeps the bar roughly even for all of them.


In plain terms, your actual passing mark depends on which version of the exam you happen to draw and how tough that particular question set turns out to be. Most candidates end up needing somewhere between 60% and 85% to clear it, though where exactly you land in that range comes down to your specific form. The whole point of scaling it this way is fairness — since everyone’s question pool is a bit different, this keeps the bar roughly even for all of them.

In plain terms, your actual passing mark depends on which version of the exam you happen to draw and how tough that particular question set turns out to be. Most candidates end up needing somewhere between 60% and 85% to clear it, though where exactly you land in that range comes down to your specific form. The whole point of scaling it this way is fairness — since everyone’s question pool is a bit different, this keeps the bar roughly even for all of them. So if you hear two people compare notes and get different passing percentages, that’s normal — it doesn’t mean the exam was easier for one of them.

CEH Practical Exam Explained

The standard CEH exam is multiple choice, but there’s a separate, tougher option: the CEH Practical. If you’re weighing whether to add it to your certification plan, here’s what it actually involves.

  • Duration: 6 hours
  • Environment: A live, browser-based lab, not a testing center with a keyboard and a question bank
  • Format: 20 practical challenges across real attack scenarios
  • Scoring: Pass/fail based on how many challenges you complete correctly
  • Focus: Actually performing tasks — scanning, exploiting, escalating privileges, and reporting — rather than describing how you’d do them

How it differs from the standard CEH exam: the knowledge exam checks whether you understand concepts and can recognize the right answer among four options. The Practical checks whether you can actually do the thing, in a live environment, against the clock.

Who should take it: anyone who wants their CEH to actually mean something on a resume beyond a multiple-choice pass. It’s especially worth it for people aiming at penetration testing or red team roles, where employers care more about hands-on ability than exam trivia.

Preparation tips: spend real time in labs before attempting this one. TryHackMe and Hack The Box rooms that focus on full attack chains (recon through privilege escalation) are a much closer match to the Practical’s format than any multiple-choice practice test will be.

What Topics Are Covered?

CEH questions come from a set list of domains. EC-Council doesn’t publish an exact percentage breakdown for every version, but here’s roughly how things tend to be weighted based on the current blueprint:

DomainApproximate Weight
Reconnaissance & Footprinting15%
Scanning Networks12%
Enumeration10%
System Hacking & Privilege Escalation15%
Malware Threats10%
Sniffing & Social Engineering10%
Web Application Security12%
Cryptography8%
Cloud & Wireless Security8%

Treat these as ballpark figures rather than fixed rules. EC-Council tweaks weighting between versions, so the official exam blueprint is your best bet if you need exact numbers.

Free Ethical Hacking Practice Exam: 30 Original Questions

Cybersecurity exam and penetration testing practice environment

This is the real point of an ethical hacking practice exam — enough questions, organized by domain, that you actually get a feel for where you stand. All 30 are original, written fresh rather than pulled from any real exam or dump, and every one comes with an explanation so you understand the reasoning, not just the letter.

Reconnaissance (Questions 1–5)

Which reconnaissance technique involves gathering information without directly touching the target system?
A) Active scanning B) Passive footprinting C) Port scanning D) Banner grabbing

Answer: B. Passive footprinting is all about working from what’s already out there — WHOIS lookups, social media, job postings, cached pages — none of which requires touching the target’s actual systems. That’s exactly why it stays under the radar. Related tools: Whois, Recon-ng.

2. Which of these is considered an active reconnaissance technique?
A) Reading a company’s public job listings B) Pinging a target’s IP range C) Searching cached Google pages D) Reviewing a company’s LinkedIn page

Answer: B. The moment you’re pinging or probing a target directly, you’ve crossed into active recon territory — you’re now touching their systems rather than just observing from a distance, which is what separates this from the passive stuff we just covered. Related tool: Nmap (ping sweep).

3. What information can DNS enumeration typically reveal during footprinting?
A) Employee salaries B) Subdomains and mail server records C) Firewall rule sets D) Password hashes

Answer: B. DNS records tend to give away more than people expect — subdomains, mail servers, and every now and then a peek at internal naming conventions too. It’s solid groundwork to have in hand before scanning even starts. Related tools: dnsenum, Sublist3r.

4. Why do attackers use search engines and social media during footprinting?
A) To bypass firewalls B) To gather publicly available information about employees and infrastructure C) To directly access internal networks D) To crack passwords

Answer: B. This falls under what’s usually called OSINT, or open-source intelligence — basically piecing together bits of publicly available info until they add up to a genuinely useful picture of the target. Related tool: theHarvester.

5. Which CVE-related resource would a tester check during the footprinting phase to understand known risks tied to a company’s public-facing technology?
A) CVSS scoring guide B) National Vulnerability Database C) Company payroll system D) Employee handbook

Answer: B. Cross-referencing CVE entries against whatever public-facing tech a target is running — server software, CMS version, and so on — is a quick way to flag likely weak spots before you even get to the deeper scanning phase.

Scanning (Questions 6–10)

6. An attacker runs an Nmap scan and finds port 22 open. What’s this port typically used for? A) HTTP B) SSH C) FTP D) DNS Answer: B. Port 22 defaults to SSH, used for encrypted remote administration. An open port here is worth a second look — it might mean weak credentials or an outdated version sitting behind it. Related tool: Nmap.

7. Which Nmap scan type is typically used to identify a host’s operating system? A) -sS B) -O C) -sU D) -p- Answer: B. The -O flag tells Nmap to attempt OS fingerprinting based on how the target responds to specific packets.

8. What’s the main difference between a TCP SYN scan and a full TCP connect scan? A) SYN scans are slower B) SYN scans don’t complete the full three-way handshake, making them stealthier C) Connect scans can’t detect open ports D) There’s no real difference Answer: B. A SYN scan (half-open scan) sends a SYN packet and drops the connection before completing the handshake, which is quieter and less likely to get logged as a full connection.

9. Which tool would you typically use to scan a web server specifically for outdated software and common misconfigurations? A) Hydra B) Nikto C) Aircrack-ng D) John the Ripper Answer: B. Nikto is built specifically for web server scanning — flagging outdated software versions, risky files, and common misconfigurations.

10. What does a CVSS score help a tester understand after a scan turns up a vulnerability? A) The exact exploit code needed B) How severe the vulnerability is, on a standardized scale C) Which employee is responsible D) The company’s revenue Answer: B. CVSS (Common Vulnerability Scoring System) gives vulnerabilities a standardized severity score, which helps prioritize what to fix or exploit first.

Enumeration (Questions 11–15)

11. What’s the main purpose of enumeration in ethical hacking? A) Encrypting data in transit B) Extracting usernames, shares, and services from a live system C) Removing malware from a host D) Testing firewall rules only Answer: B. Enumeration happens after scanning, and it’s about actively digging up detail — user accounts, shared resources, running services — the stuff scanning alone doesn’t show you.

12. Which protocol is commonly targeted during NetBIOS enumeration on Windows networks? A) SMTP B) SMB C) SNMP D) ICMP Answer: B. SMB (Server Message Block) is closely tied to NetBIOS on Windows and often reveals shared folders, usernames, and system details when enumerated.

13. What is a “null session” in the context of enumeration? A) An encrypted connection B) An unauthenticated connection to a system that can still leak information C) A firewall rule D) A type of malware Answer: B. A null session lets someone connect to certain Windows services without credentials, sometimes leaking usernames or share names — a classic enumeration target.

14. Which enumeration technique targets SNMP-enabled devices? A) SNMP community string guessing B) DNS zone transfer C) ARP spoofing D) Port knocking Answer: A. Many devices still use default or weak SNMP community strings, and guessing them can expose configuration data.

15. Why is enumeration considered riskier for an attacker than passive reconnaissance? A) It takes longer B) It requires direct interaction with the target, increasing the chance of detection C) It doesn’t work on modern systems D) It’s illegal in every case Answer: B. Because enumeration involves actively querying the target system, it leaves a bigger footprint in logs and monitoring tools than passive recon does.

System Hacking (Questions 16–20)

16. Which of these best describes privilege escalation? A) Gaining higher-level access than originally granted B) Encrypting a victim’s files for ransom C) Scanning a subnet for live hosts D) Intercepting network packets Answer: A. Privilege escalation is about climbing from a limited foothold — say, a regular user account — up to admin or root. It’s often the real target after the initial break-in.

17. What’s the difference between vertical and horizontal privilege escalation? A) There is no difference B) Vertical means gaining higher-level access; horizontal means accessing another account at the same privilege level C) Horizontal is always more dangerous D) Vertical only applies to Linux Answer: B. Vertical escalation moves you up the privilege chain (user to admin); horizontal escalation moves you sideways into another account with similar access.

18. Which tool is commonly used to crack password hashes offline? A) Wireshark B) John the Ripper C) Nikto D) Burp Suite Answer: B. John the Ripper is built for cracking password hashes offline, testing them against wordlists or brute-force patterns.

19. What’s a rootkit primarily designed to do? A) Encrypt files for ransom B) Hide the presence of malicious activity or access on a system C) Scan for open ports D) Send phishing emails Answer: B. Rootkits are built for stealth — keeping an attacker’s continued access hidden from normal detection methods.

20. Why do penetration testers document every step of a system hacking phase carefully? A) It’s optional and rarely done B) For legal, reporting, and reproducibility reasons C) Documentation slows down the test unnecessarily D) Clients never read reports Answer: B. Clear documentation protects the tester legally, supports the final report, and lets someone reproduce or verify the findings later.

Malware (Questions 21–25)

21. Which type of malware disguises itself as legitimate software to get access? A) Worm B) Trojan C) Ransomware D) Rootkit Answer: B. A Trojan works through deception. It looks harmless, even useful, while quietly carrying a hidden payload.

22. What makes a worm different from a virus? A) Worms need a host file to spread; viruses don’t B) Worms can self-replicate and spread across networks without a host file C) Worms only affect mobile devices D) There’s no real difference Answer: B. Worms spread on their own across networks, while a virus typically needs to attach itself to a host file or program to propagate.

23. What does ransomware typically do once it infects a system? A) Steals bandwidth quietly B) Encrypts files and demands payment for the decryption key C) Deletes the operating system instantly D) Only affects mobile apps Answer: B. Ransomware locks victims out of their own files through encryption, then demands payment (often in cryptocurrency) for the decryption key.

24. What makes a zero-day vulnerability different from other vulnerabilities? A) It’s been patched for less than a day B) It’s unknown to the vendor and has no fix available yet C) It only affects legacy systems D) It can only be exploited locally Answer: B. Zero-days are risky exactly because the vendor hasn’t had a chance to patch them yet. Whoever’s exploiting one is working ahead of any real defense.

25. Which of these is a common sign of a rootkit infection? A) Faster boot times B) Hidden processes or files that don’t show up through normal system tools C) Increased battery life on laptops D) More available disk space Answer: B. Rootkits are designed to stay invisible to standard tools, so unusual gaps or inconsistencies (processes you can’t find through normal means) are a red flag.

Web Application Security (Questions 26–30)

26. In a SQL injection attack, which character is most commonly used to mess with a query’s logic? A) # B) ‘ C) % D) & Answer: B. A single quote often breaks a query out of its string parameter, which lets an attacker slip in their own logic if the input isn’t properly sanitized. Related tool: SQLMap.

27. What does XSS (Cross-Site Scripting) primarily allow an attacker to do? A) Crack password hashes B) Inject malicious scripts into web pages viewed by other users C) Scan open network ports D) Bypass firewall rules directly Answer: B. XSS lets an attacker run malicious scripts in another user’s browser session, often through unsanitized input fields.

28. Which entry in the OWASP Top 10 covers issues like SQL injection and command injection? A) Broken Access Control B) Injection C) Security Misconfiguration D) Cryptographic Failures Answer: B. Injection flaws, including SQL and command injection, are grouped together under the OWASP Top 10’s Injection category.

29. Which tool is most associated with intercepting and modifying web traffic during testing? A) Burp Suite B) Aircrack-ng C) OpenVAS D) Hydra Answer: A. Burp Suite is built specifically for intercepting, inspecting, and modifying HTTP requests between browser and server, making it a staple for web app testing.

30. What’s the main risk of a broken authentication vulnerability on a web application? A) Slower page load times B) Attackers can bypass login controls or hijack sessions C) Increased hosting costs D) Reduced SEO ranking Answer: B. Broken authentication issues let attackers get around login controls entirely or take over active sessions, which is a serious access-control failure.

Practical Scenario Questions

CEH isn’t just definitions — it wants you to reason through actual situations. Here’s the kind of scenario question you’ll run into on both the standard and practical exams.

Scenario: During a scan, you find TCP port 445 open on a Windows machine. What do you check next?

Port 445 runs SMB (Server Message Block), Windows’ file and printer sharing service. An open 445 deserves attention right away — it’s been at the center of some major exploits, EternalBlue being the obvious one, which is what powered WannaCry. The logical next step is enumerating the SMB service to figure out its version, checking for null session issues, and looking up any known CVEs tied to that build using a resource like the National Vulnerability Database.

Scenario: You spot an outdated web application with an admin panel that has no visible authentication. What’s your move?

Don’t jump straight to exploiting it. The right call is to document what you’ve found, check whether it’s even inside the agreed scope of your engagement, and cross-reference the app version against OWASP resources or known CVE listings. Ethical hacking runs on rules of engagement — stepping outside scope, even with good intentions, can land you in real legal trouble.

Common CEH Mistakes

A lot of people don’t fail CEH because the material’s impossible — it’s usually how they prepped:

  • Memorizing dumps instead of understanding the concepts. Dumps might line up with old question banks, but CEH changes its wording often enough that memorized answers fall apart the second a question is phrased differently.
  • Skipping hands-on labs. Reading about Nmap syntax is not the same as actually running scans against a real target in a lab.
  • Ignoring networking basics. If your grip on TCP/IP, subnetting, or the OSI model is shaky, half the exam gets harder than it needs to be.
  • Weak Linux command-line skills. Kali Linux runs most of the practical side of this work, and fumbling basic commands slows you down badly when it counts.
  • Bad time management. With 125 questions in 4 hours, getting stuck on a few tough ones can eat into time you need elsewhere.

Essential Tools for the Ethical Hacking Practice Exam

You’ll see these tools referenced throughout CEH questions, often without much explanation. Here’s a quick-reference table so you’re not guessing what each one actually does.

ToolPurpose
NmapNetwork scanning and host discovery
MetasploitExploitation framework
WiresharkPacket analysis
Burp SuiteWeb application testing
HydraPassword/brute-force testing
SQLMapAutomated SQL injection testing
NessusVulnerability scanning
NiktoWeb server scanning
OpenVASOpen-source vulnerability scanning
Aircrack-ngWireless network security testing
John the RipperOffline password cracking

Best CEH Labs to Practice On

Reading about these tools only gets you so far. Real prep happens in labs, and a handful of platforms come up again and again for good reason:

  • TryHackMe — beginner-friendly, guided rooms that build up gradually, good if you’re still finding your footing
  • Hack The Box — more advanced, less hand-holding, better once your fundamentals are solid
  • VulnHub — downloadable vulnerable VMs you run locally, good for offline practice
  • OverTheWire — wargame-style challenges that build Linux and networking fundamentals through repetition
  • PortSwigger Web Security Academy — free, and genuinely excellent for understanding SQL injection, XSS, and other web vulnerabilities in depth
  • OWASP Juice Shop — a deliberately vulnerable web app built specifically for practicing web security concepts hands-on

How to Pass CEH First Attempt

There’s no real shortcut, but there’s a sensible way to structure things:

  1. Build your study plan around the domains, not random topics. Spend more time on the heavily weighted ones — reconnaissance and system hacking, for instance.
  2. Pair every concept with a lab. Reading about port scanning doesn’t count. Go run Nmap against something.
  3. Take practice exams under real time pressure at least a week out from your scheduled test, so the pacing isn’t a surprise.
  4. Actually review your wrong answers. Understand why the right one is right, not just what it was.
  5. Spend your last few days on your weak domains, instead of re-studying everything evenly.

Ethical Hacking Practice Exam vs Real CEH Exam

AspectPractice ExamReal CEH Exam
StakesNoneCertification depends on it
Question sourceThird-party or self-madeOfficial EC-Council question bank
EnvironmentUsually untimed or self-pacedStrict 4-hour window
FeedbackOften has instant explanationsPass/fail, nothing more
CostOften freeAround $1,199 USD
PurposeDiagnostic, skill-buildingOfficial certification

Free vs Paid Practice Exams

FactorFree Practice ExamsPaid Practice Exams
Question volumeUsually smaller setsOften 1,000+ questions
ExplanationsSometimes limitedUsually detailed
Domain coverageMay not hit every domain evenlyUsually structured across the full blueprint
Update frequencyInconsistentRegularly refreshed for new exam versions
Cost$0Roughly $30–$150, depending on provider

Free tests are a decent starting point just to see where you stand. Paid ones tend to pay off if you’re serious about covering every domain properly before exam day.

CEH vs Security+ vs OSCP

CEH rarely gets chosen in isolation — most people weigh it against CompTIA Security+ or OSCP at some point. Here’s how they actually compare:

FactorCEHSecurity+OSCP
LevelIntermediateEntry-levelAdvanced
FormatMultiple choice (+ optional practical)Multiple choiceFully hands-on, 24-hour exam
FocusBroad offensive security conceptsGeneral security fundamentalsDeep, practical penetration testing
Best forIT pros moving into security rolesComplete beginnersExperienced testers proving hands-on skill
Cost~$1,199~$392~$1,749 (with training)
Industry viewWidely recognized, sometimes seen as more theoreticalSolid foundational credentialHighly respected for practical skill

If you’re brand new to security, Security+ makes sense first. CEH sits in the middle — good for breadth and for opening doors in job listings that specifically ask for it. OSCP is the one that most directly proves you can do the work, not just answer questions about it.

Is the CEH Practice Exam Worth It?

Yes — with one caveat. A practice exam genuinely helps you spot blind spots and get comfortable with how questions are phrased and how the clock feels. What it can’t do is replace real lab time or a solid handle on networking basics. It’s one part of prep, not the whole strategy.

=> What Is the Difference Between Onsite and Offsite SEO?

FAQs

Is the CEH practice exam free? There are a few free options out there, including EC-Council’s own readiness quiz and various third-party sample question sets. Paid bundles with bigger question banks exist too, if you want more thorough coverage.

Is CEH difficult? Moderately, especially if you’re coming in without prior networking or security background. The real challenge is breadth — you need working knowledge across ten-plus areas rather than deep expertise in just one.

How many practice exams should I take? No fixed number, but two or three full-length timed ones before the real test should give you a decent read on where you stand and how your pacing looks.

Is CEH v13 harder? It covers more AI-related tooling and newer attack techniques than earlier versions, so there’s more to learn, but the overall structure and difficulty level stay roughly the same.

Can I pass without experience? It’s doable with disciplined study and consistent lab time, though people with some IT or networking background usually find the material easier to absorb.

Are practice exams enough on their own? Not really. Pair them with hands-on labs and a solid grasp of networking and Linux, or you’ll hit a ceiling fast.

Is the practical exam different? Yes. The standard CEH exam is multiple choice. The CEH Practical drops you into a live environment where you actually scan, exploit, and report on findings across 20 challenges.

What is the CEH passing score? There’s no single fixed number — EC-Council uses a scaled scoring system, and candidates typically need somewhere around 60% to 85% depending on the exam form they receive.

How long should I study? Most people spend six to twelve weeks prepping, depending on where they’re starting from and how much time they can put in each week.

Final Thoughts

An ethical hacking practice exam by itself won’t hand you a pass, but it’s one of the more honest ways to see where you actually stand before spending over a thousand dollars on the real CEH exam. Pair mock questions with real lab time, skip the memorized dumps, and spend your last stretch of prep on whatever domain is still shaky. That mix — practice, labs, and being honest with yourself about the gaps — is genuinely what gets people through CEH v13 on the first try.

Disclaimer: Exam formats, question counts, passing scores, and domain weighting can change over time at EC-Council’s discretion. Always check current exam details against official EC-Council resources before booking your test. The practice questions above are original and not pulled from any real exam question bank.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top