So you typed “ethical hacking practice exam” into Google. You’re probably not after some dry definition — you want something that actually feels like the CEH v13 exam, a rough idea of where you stand right now, and maybe a hint about what to brush up on before you drop $1,199 on the real certification through EC-Council. Fair enough. That’s exactly what this ethical hacking practice exam guide covers, with 30 original questions, a full breakdown of the CEH passing score, and everything else the standard “10 sample questions” pages tend to skip.
Here’s the short version: an ethical hacking practice exam is a stand-in for the real CEH test. It touches the same areas — reconnaissance, scanning, enumeration, system hacking, malware, and web application security — and doing a few of these before your real exam does something a textbook never will. It shows you where you’re actually shaky, gets you used to working under a ticking clock, and takes some of the “unknown” out of exam day.
Quick answer: think of an ethical hacking practice exam as a rough copy of the actual CEH test — same territory, really: reconnaissance, scanning, enumeration, system hacking, malware, web application security, all of it. Run through a decent set of mock questions before your real attempt and a few things happen almost automatically. You start noticing which topics you actually know versus which ones you’re just guessing on. Your pacing gets better because you’re not seeing the format for the first time on exam day. And honestly, a lot of the nervousness around CEH v13 just comes from not knowing what to expect — practice questions take a chunk of that away too.
Quick Facts: CEH v13 at a Glance

| Detail | Info |
|---|---|
| Exam | CEH v13 |
| Questions | 125 |
| Time Limit | 4 Hours |
| Exam Code | 312-50 |
| Passing Score | Scaled (varies by version) |
| Provider | EC-Council |
| Certification Validity | 3 Years |
| Practical Option | CEH Practical (hands-on) |
What Is an Ethical Hacking Practice Exam?
Think of it as a dress rehearsal. It’s built to feel like the real CEH exam — same structure, similar difficulty, same spread of topics — just without anything actually riding on it. You’re answering multiple-choice questions from the same domains EC-Council tests, which means you’re not just reading about penetration testing anymore. You’re being asked to actually use it.
None of this works if you’re leaning on leaked exam dumps, by the way. Sure, dumps might get you a passing score. But you’ll walk out with a certificate and not much actual skill behind it — and that gap shows up fast in a real interview or on the job.
Who Should Take This Practice Exam?
- Beginners just getting their footing in cybersecurity
- Students a few weeks out from their scheduled CEH exam
- Security analysts brushing up before recertification
- SOC analysts moving toward a more offensive security role
- Network engineers curious about the attacker’s side of things
- System administrators who want to understand what they’re defending against
- Penetration testers prepping for CEH alongside other certifications
CEH Exam Overview
Right now, in 2026, CEH v13 is the version you’ll actually be sitting for. Before getting deep into prep, it’s worth knowing roughly what the exam looks like on the surface. As things stand, the CEH knowledge exam runs 125 multiple-choice questions. That said, EC-Council does tweak formats and objectives from one release to the next, so don’t just take this number as gospel — a quick check of the official exam page before you register is worth the two minutes it takes.
- Exam code: 312-50 (ECC EXAM), also offered through Pearson VUE
- Format: Multiple choice, computer-based
- Number of questions: 125
- Duration: 4 hours
- Delivery: Online proctored or in-person at a testing center
- Cost: Roughly $1,199 USD, depending on how you register
- Validity: 3 years, after which you’ll need continuing education credits or a retake
CEH v13 also leans more heavily into AI-assisted tools than earlier versions did, which makes sense given how a lot of real-world penetration testing works now — automated recon, AI-assisted vulnerability triage, that kind of thing.
What Is the CEH Passing Score?
This is one of the most searched questions about the exam, and it trips people up because CEH doesn’t work like a lot of other certifications. Unlike exams with one fixed passing number, EC-Council uses a scaled scoring system.
In plain terms, your actual passing mark depends on which version of the exam you happen to draw and how tough that particular question set turns out to be. Most candidates end up needing somewhere between 60% and 85% to clear it, though where exactly you land in that range comes down to your specific form. The whole point of scaling it this way is fairness — since everyone’s question pool is a bit different, this keeps the bar roughly even for all of them.
In plain terms, your actual passing mark depends on which version of the exam you happen to draw and how tough that particular question set turns out to be. Most candidates end up needing somewhere between 60% and 85% to clear it, though where exactly you land in that range comes down to your specific form. The whole point of scaling it this way is fairness — since everyone’s question pool is a bit different, this keeps the bar roughly even for all of them.
In plain terms, your actual passing mark depends on which version of the exam you happen to draw and how tough that particular question set turns out to be. Most candidates end up needing somewhere between 60% and 85% to clear it, though where exactly you land in that range comes down to your specific form. The whole point of scaling it this way is fairness — since everyone’s question pool is a bit different, this keeps the bar roughly even for all of them. So if you hear two people compare notes and get different passing percentages, that’s normal — it doesn’t mean the exam was easier for one of them.
CEH Practical Exam Explained
The standard CEH exam is multiple choice, but there’s a separate, tougher option: the CEH Practical. If you’re weighing whether to add it to your certification plan, here’s what it actually involves.
- Duration: 6 hours
- Environment: A live, browser-based lab, not a testing center with a keyboard and a question bank
- Format: 20 practical challenges across real attack scenarios
- Scoring: Pass/fail based on how many challenges you complete correctly
- Focus: Actually performing tasks — scanning, exploiting, escalating privileges, and reporting — rather than describing how you’d do them
How it differs from the standard CEH exam: the knowledge exam checks whether you understand concepts and can recognize the right answer among four options. The Practical checks whether you can actually do the thing, in a live environment, against the clock.
Who should take it: anyone who wants their CEH to actually mean something on a resume beyond a multiple-choice pass. It’s especially worth it for people aiming at penetration testing or red team roles, where employers care more about hands-on ability than exam trivia.
Preparation tips: spend real time in labs before attempting this one. TryHackMe and Hack The Box rooms that focus on full attack chains (recon through privilege escalation) are a much closer match to the Practical’s format than any multiple-choice practice test will be.
What Topics Are Covered?
CEH questions come from a set list of domains. EC-Council doesn’t publish an exact percentage breakdown for every version, but here’s roughly how things tend to be weighted based on the current blueprint:
| Domain | Approximate Weight |
|---|---|
| Reconnaissance & Footprinting | 15% |
| Scanning Networks | 12% |
| Enumeration | 10% |
| System Hacking & Privilege Escalation | 15% |
| Malware Threats | 10% |
| Sniffing & Social Engineering | 10% |
| Web Application Security | 12% |
| Cryptography | 8% |
| Cloud & Wireless Security | 8% |
Treat these as ballpark figures rather than fixed rules. EC-Council tweaks weighting between versions, so the official exam blueprint is your best bet if you need exact numbers.
Free Ethical Hacking Practice Exam: 30 Original Questions

This is the real point of an ethical hacking practice exam — enough questions, organized by domain, that you actually get a feel for where you stand. All 30 are original, written fresh rather than pulled from any real exam or dump, and every one comes with an explanation so you understand the reasoning, not just the letter.
Reconnaissance (Questions 1–5)
Which reconnaissance technique involves gathering information without directly touching the target system?
A) Active scanning B) Passive footprinting C) Port scanning D) Banner grabbing
Answer: B. Passive footprinting is all about working from what’s already out there — WHOIS lookups, social media, job postings, cached pages — none of which requires touching the target’s actual systems. That’s exactly why it stays under the radar. Related tools: Whois, Recon-ng.
2. Which of these is considered an active reconnaissance technique?
A) Reading a company’s public job listings B) Pinging a target’s IP range C) Searching cached Google pages D) Reviewing a company’s LinkedIn page
Answer: B. The moment you’re pinging or probing a target directly, you’ve crossed into active recon territory — you’re now touching their systems rather than just observing from a distance, which is what separates this from the passive stuff we just covered. Related tool: Nmap (ping sweep).
3. What information can DNS enumeration typically reveal during footprinting?
A) Employee salaries B) Subdomains and mail server records C) Firewall rule sets D) Password hashes
Answer: B. DNS records tend to give away more than people expect — subdomains, mail servers, and every now and then a peek at internal naming conventions too. It’s solid groundwork to have in hand before scanning even starts. Related tools: dnsenum, Sublist3r.
4. Why do attackers use search engines and social media during footprinting?
A) To bypass firewalls B) To gather publicly available information about employees and infrastructure C) To directly access internal networks D) To crack passwords
Answer: B. This falls under what’s usually called OSINT, or open-source intelligence — basically piecing together bits of publicly available info until they add up to a genuinely useful picture of the target. Related tool: theHarvester.
5. Which CVE-related resource would a tester check during the footprinting phase to understand known risks tied to a company’s public-facing technology?
A) CVSS scoring guide B) National Vulnerability Database C) Company payroll system D) Employee handbook
Answer: B. Cross-referencing CVE entries against whatever public-facing tech a target is running — server software, CMS version, and so on — is a quick way to flag likely weak spots before you even get to the deeper scanning phase.
Scanning (Questions 6–10)
6. An attacker runs an Nmap scan and finds port 22 open. What’s this port typically used for? A) HTTP B) SSH C) FTP D) DNS Answer: B. Port 22 defaults to SSH, used for encrypted remote administration. An open port here is worth a second look — it might mean weak credentials or an outdated version sitting behind it. Related tool: Nmap.
7. Which Nmap scan type is typically used to identify a host’s operating system? A) -sS B) -O C) -sU D) -p- Answer: B. The -O flag tells Nmap to attempt OS fingerprinting based on how the target responds to specific packets.
8. What’s the main difference between a TCP SYN scan and a full TCP connect scan? A) SYN scans are slower B) SYN scans don’t complete the full three-way handshake, making them stealthier C) Connect scans can’t detect open ports D) There’s no real difference Answer: B. A SYN scan (half-open scan) sends a SYN packet and drops the connection before completing the handshake, which is quieter and less likely to get logged as a full connection.
9. Which tool would you typically use to scan a web server specifically for outdated software and common misconfigurations? A) Hydra B) Nikto C) Aircrack-ng D) John the Ripper Answer: B. Nikto is built specifically for web server scanning — flagging outdated software versions, risky files, and common misconfigurations.
10. What does a CVSS score help a tester understand after a scan turns up a vulnerability? A) The exact exploit code needed B) How severe the vulnerability is, on a standardized scale C) Which employee is responsible D) The company’s revenue Answer: B. CVSS (Common Vulnerability Scoring System) gives vulnerabilities a standardized severity score, which helps prioritize what to fix or exploit first.
Enumeration (Questions 11–15)
11. What’s the main purpose of enumeration in ethical hacking? A) Encrypting data in transit B) Extracting usernames, shares, and services from a live system C) Removing malware from a host D) Testing firewall rules only Answer: B. Enumeration happens after scanning, and it’s about actively digging up detail — user accounts, shared resources, running services — the stuff scanning alone doesn’t show you.
12. Which protocol is commonly targeted during NetBIOS enumeration on Windows networks? A) SMTP B) SMB C) SNMP D) ICMP Answer: B. SMB (Server Message Block) is closely tied to NetBIOS on Windows and often reveals shared folders, usernames, and system details when enumerated.
13. What is a “null session” in the context of enumeration? A) An encrypted connection B) An unauthenticated connection to a system that can still leak information C) A firewall rule D) A type of malware Answer: B. A null session lets someone connect to certain Windows services without credentials, sometimes leaking usernames or share names — a classic enumeration target.
14. Which enumeration technique targets SNMP-enabled devices? A) SNMP community string guessing B) DNS zone transfer C) ARP spoofing D) Port knocking Answer: A. Many devices still use default or weak SNMP community strings, and guessing them can expose configuration data.
15. Why is enumeration considered riskier for an attacker than passive reconnaissance? A) It takes longer B) It requires direct interaction with the target, increasing the chance of detection C) It doesn’t work on modern systems D) It’s illegal in every case Answer: B. Because enumeration involves actively querying the target system, it leaves a bigger footprint in logs and monitoring tools than passive recon does.
System Hacking (Questions 16–20)
16. Which of these best describes privilege escalation? A) Gaining higher-level access than originally granted B) Encrypting a victim’s files for ransom C) Scanning a subnet for live hosts D) Intercepting network packets Answer: A. Privilege escalation is about climbing from a limited foothold — say, a regular user account — up to admin or root. It’s often the real target after the initial break-in.
17. What’s the difference between vertical and horizontal privilege escalation? A) There is no difference B) Vertical means gaining higher-level access; horizontal means accessing another account at the same privilege level C) Horizontal is always more dangerous D) Vertical only applies to Linux Answer: B. Vertical escalation moves you up the privilege chain (user to admin); horizontal escalation moves you sideways into another account with similar access.
18. Which tool is commonly used to crack password hashes offline? A) Wireshark B) John the Ripper C) Nikto D) Burp Suite Answer: B. John the Ripper is built for cracking password hashes offline, testing them against wordlists or brute-force patterns.
19. What’s a rootkit primarily designed to do? A) Encrypt files for ransom B) Hide the presence of malicious activity or access on a system C) Scan for open ports D) Send phishing emails Answer: B. Rootkits are built for stealth — keeping an attacker’s continued access hidden from normal detection methods.
20. Why do penetration testers document every step of a system hacking phase carefully? A) It’s optional and rarely done B) For legal, reporting, and reproducibility reasons C) Documentation slows down the test unnecessarily D) Clients never read reports Answer: B. Clear documentation protects the tester legally, supports the final report, and lets someone reproduce or verify the findings later.
Malware (Questions 21–25)
21. Which type of malware disguises itself as legitimate software to get access? A) Worm B) Trojan C) Ransomware D) Rootkit Answer: B. A Trojan works through deception. It looks harmless, even useful, while quietly carrying a hidden payload.
22. What makes a worm different from a virus? A) Worms need a host file to spread; viruses don’t B) Worms can self-replicate and spread across networks without a host file C) Worms only affect mobile devices D) There’s no real difference Answer: B. Worms spread on their own across networks, while a virus typically needs to attach itself to a host file or program to propagate.
23. What does ransomware typically do once it infects a system? A) Steals bandwidth quietly B) Encrypts files and demands payment for the decryption key C) Deletes the operating system instantly D) Only affects mobile apps Answer: B. Ransomware locks victims out of their own files through encryption, then demands payment (often in cryptocurrency) for the decryption key.
24. What makes a zero-day vulnerability different from other vulnerabilities? A) It’s been patched for less than a day B) It’s unknown to the vendor and has no fix available yet C) It only affects legacy systems D) It can only be exploited locally Answer: B. Zero-days are risky exactly because the vendor hasn’t had a chance to patch them yet. Whoever’s exploiting one is working ahead of any real defense.
25. Which of these is a common sign of a rootkit infection? A) Faster boot times B) Hidden processes or files that don’t show up through normal system tools C) Increased battery life on laptops D) More available disk space Answer: B. Rootkits are designed to stay invisible to standard tools, so unusual gaps or inconsistencies (processes you can’t find through normal means) are a red flag.
Web Application Security (Questions 26–30)
26. In a SQL injection attack, which character is most commonly used to mess with a query’s logic? A) # B) ‘ C) % D) & Answer: B. A single quote often breaks a query out of its string parameter, which lets an attacker slip in their own logic if the input isn’t properly sanitized. Related tool: SQLMap.
27. What does XSS (Cross-Site Scripting) primarily allow an attacker to do? A) Crack password hashes B) Inject malicious scripts into web pages viewed by other users C) Scan open network ports D) Bypass firewall rules directly Answer: B. XSS lets an attacker run malicious scripts in another user’s browser session, often through unsanitized input fields.
28. Which entry in the OWASP Top 10 covers issues like SQL injection and command injection? A) Broken Access Control B) Injection C) Security Misconfiguration D) Cryptographic Failures Answer: B. Injection flaws, including SQL and command injection, are grouped together under the OWASP Top 10’s Injection category.
29. Which tool is most associated with intercepting and modifying web traffic during testing? A) Burp Suite B) Aircrack-ng C) OpenVAS D) Hydra Answer: A. Burp Suite is built specifically for intercepting, inspecting, and modifying HTTP requests between browser and server, making it a staple for web app testing.
30. What’s the main risk of a broken authentication vulnerability on a web application? A) Slower page load times B) Attackers can bypass login controls or hijack sessions C) Increased hosting costs D) Reduced SEO ranking Answer: B. Broken authentication issues let attackers get around login controls entirely or take over active sessions, which is a serious access-control failure.
Practical Scenario Questions
CEH isn’t just definitions — it wants you to reason through actual situations. Here’s the kind of scenario question you’ll run into on both the standard and practical exams.
Scenario: During a scan, you find TCP port 445 open on a Windows machine. What do you check next?
Port 445 runs SMB (Server Message Block), Windows’ file and printer sharing service. An open 445 deserves attention right away — it’s been at the center of some major exploits, EternalBlue being the obvious one, which is what powered WannaCry. The logical next step is enumerating the SMB service to figure out its version, checking for null session issues, and looking up any known CVEs tied to that build using a resource like the National Vulnerability Database.
Scenario: You spot an outdated web application with an admin panel that has no visible authentication. What’s your move?
Don’t jump straight to exploiting it. The right call is to document what you’ve found, check whether it’s even inside the agreed scope of your engagement, and cross-reference the app version against OWASP resources or known CVE listings. Ethical hacking runs on rules of engagement — stepping outside scope, even with good intentions, can land you in real legal trouble.
Common CEH Mistakes
A lot of people don’t fail CEH because the material’s impossible — it’s usually how they prepped:
- Memorizing dumps instead of understanding the concepts. Dumps might line up with old question banks, but CEH changes its wording often enough that memorized answers fall apart the second a question is phrased differently.
- Skipping hands-on labs. Reading about Nmap syntax is not the same as actually running scans against a real target in a lab.
- Ignoring networking basics. If your grip on TCP/IP, subnetting, or the OSI model is shaky, half the exam gets harder than it needs to be.
- Weak Linux command-line skills. Kali Linux runs most of the practical side of this work, and fumbling basic commands slows you down badly when it counts.
- Bad time management. With 125 questions in 4 hours, getting stuck on a few tough ones can eat into time you need elsewhere.
Essential Tools for the Ethical Hacking Practice Exam
You’ll see these tools referenced throughout CEH questions, often without much explanation. Here’s a quick-reference table so you’re not guessing what each one actually does.
| Tool | Purpose |
|---|---|
| Nmap | Network scanning and host discovery |
| Metasploit | Exploitation framework |
| Wireshark | Packet analysis |
| Burp Suite | Web application testing |
| Hydra | Password/brute-force testing |
| SQLMap | Automated SQL injection testing |
| Nessus | Vulnerability scanning |
| Nikto | Web server scanning |
| OpenVAS | Open-source vulnerability scanning |
| Aircrack-ng | Wireless network security testing |
| John the Ripper | Offline password cracking |
Best CEH Labs to Practice On
Reading about these tools only gets you so far. Real prep happens in labs, and a handful of platforms come up again and again for good reason:
- TryHackMe — beginner-friendly, guided rooms that build up gradually, good if you’re still finding your footing
- Hack The Box — more advanced, less hand-holding, better once your fundamentals are solid
- VulnHub — downloadable vulnerable VMs you run locally, good for offline practice
- OverTheWire — wargame-style challenges that build Linux and networking fundamentals through repetition
- PortSwigger Web Security Academy — free, and genuinely excellent for understanding SQL injection, XSS, and other web vulnerabilities in depth
- OWASP Juice Shop — a deliberately vulnerable web app built specifically for practicing web security concepts hands-on
How to Pass CEH First Attempt
There’s no real shortcut, but there’s a sensible way to structure things:
- Build your study plan around the domains, not random topics. Spend more time on the heavily weighted ones — reconnaissance and system hacking, for instance.
- Pair every concept with a lab. Reading about port scanning doesn’t count. Go run Nmap against something.
- Take practice exams under real time pressure at least a week out from your scheduled test, so the pacing isn’t a surprise.
- Actually review your wrong answers. Understand why the right one is right, not just what it was.
- Spend your last few days on your weak domains, instead of re-studying everything evenly.
Ethical Hacking Practice Exam vs Real CEH Exam
| Aspect | Practice Exam | Real CEH Exam |
|---|---|---|
| Stakes | None | Certification depends on it |
| Question source | Third-party or self-made | Official EC-Council question bank |
| Environment | Usually untimed or self-paced | Strict 4-hour window |
| Feedback | Often has instant explanations | Pass/fail, nothing more |
| Cost | Often free | Around $1,199 USD |
| Purpose | Diagnostic, skill-building | Official certification |
Free vs Paid Practice Exams
| Factor | Free Practice Exams | Paid Practice Exams |
|---|---|---|
| Question volume | Usually smaller sets | Often 1,000+ questions |
| Explanations | Sometimes limited | Usually detailed |
| Domain coverage | May not hit every domain evenly | Usually structured across the full blueprint |
| Update frequency | Inconsistent | Regularly refreshed for new exam versions |
| Cost | $0 | Roughly $30–$150, depending on provider |
Free tests are a decent starting point just to see where you stand. Paid ones tend to pay off if you’re serious about covering every domain properly before exam day.
CEH vs Security+ vs OSCP
CEH rarely gets chosen in isolation — most people weigh it against CompTIA Security+ or OSCP at some point. Here’s how they actually compare:
| Factor | CEH | Security+ | OSCP |
|---|---|---|---|
| Level | Intermediate | Entry-level | Advanced |
| Format | Multiple choice (+ optional practical) | Multiple choice | Fully hands-on, 24-hour exam |
| Focus | Broad offensive security concepts | General security fundamentals | Deep, practical penetration testing |
| Best for | IT pros moving into security roles | Complete beginners | Experienced testers proving hands-on skill |
| Cost | ~$1,199 | ~$392 | ~$1,749 (with training) |
| Industry view | Widely recognized, sometimes seen as more theoretical | Solid foundational credential | Highly respected for practical skill |
If you’re brand new to security, Security+ makes sense first. CEH sits in the middle — good for breadth and for opening doors in job listings that specifically ask for it. OSCP is the one that most directly proves you can do the work, not just answer questions about it.
Is the CEH Practice Exam Worth It?
Yes — with one caveat. A practice exam genuinely helps you spot blind spots and get comfortable with how questions are phrased and how the clock feels. What it can’t do is replace real lab time or a solid handle on networking basics. It’s one part of prep, not the whole strategy.
=> What Is the Difference Between Onsite and Offsite SEO?
FAQs
Is the CEH practice exam free? There are a few free options out there, including EC-Council’s own readiness quiz and various third-party sample question sets. Paid bundles with bigger question banks exist too, if you want more thorough coverage.
Is CEH difficult? Moderately, especially if you’re coming in without prior networking or security background. The real challenge is breadth — you need working knowledge across ten-plus areas rather than deep expertise in just one.
How many practice exams should I take? No fixed number, but two or three full-length timed ones before the real test should give you a decent read on where you stand and how your pacing looks.
Is CEH v13 harder? It covers more AI-related tooling and newer attack techniques than earlier versions, so there’s more to learn, but the overall structure and difficulty level stay roughly the same.
Can I pass without experience? It’s doable with disciplined study and consistent lab time, though people with some IT or networking background usually find the material easier to absorb.
Are practice exams enough on their own? Not really. Pair them with hands-on labs and a solid grasp of networking and Linux, or you’ll hit a ceiling fast.
Is the practical exam different? Yes. The standard CEH exam is multiple choice. The CEH Practical drops you into a live environment where you actually scan, exploit, and report on findings across 20 challenges.
What is the CEH passing score? There’s no single fixed number — EC-Council uses a scaled scoring system, and candidates typically need somewhere around 60% to 85% depending on the exam form they receive.
How long should I study? Most people spend six to twelve weeks prepping, depending on where they’re starting from and how much time they can put in each week.
Final Thoughts
An ethical hacking practice exam by itself won’t hand you a pass, but it’s one of the more honest ways to see where you actually stand before spending over a thousand dollars on the real CEH exam. Pair mock questions with real lab time, skip the memorized dumps, and spend your last stretch of prep on whatever domain is still shaky. That mix — practice, labs, and being honest with yourself about the gaps — is genuinely what gets people through CEH v13 on the first try.
Disclaimer: Exam formats, question counts, passing scores, and domain weighting can change over time at EC-Council’s discretion. Always check current exam details against official EC-Council resources before booking your test. The practice questions above are original and not pulled from any real exam question bank.




