Study Guide

CEH Practical Exam Guide: Format, Skills, Prep

Prepare for the EC-Council CEH (Practical) exam: six hours, 20 challenges in the iLabs Cyber Range, the skills tested, eligibility, and a focused study plan.

Updated September 202610 min readStudy GuideCEH Exam
Gabrielle Wallace

Gabrielle Wallace

CEH Exam Editorial Team

The CEH Practical is a six-hour, open-book hands-on exam with 20 challenges delivered in EC-Council's iLabs Cyber Range, scored between 60% and 85%. It is optional: passing the CEH knowledge exam alone earns the CEH certification, while passing both exams earns the CEH (Master) designation. Prepare against the official practical blueprint — nine weighted domains — together with the tested-skills list EC-Council publishes.

What the CEH Practical exam is

The CEH Practical is the hands-on companion to the CEH knowledge exam. It is optional, ANAB-accredited, and US DoD 8140 approved; passing both exams earns the CEH (Master) designation.

EC-Council awards the Certified Ethical Hacker certification when you pass the four-hour, 125-question knowledge exam. The practical exam is an additional, optional step: EC-Council states that achieving CEH Master level requires taking this practical exam on top of the knowledge exam.

The practical was created to let ethical hackers prove applied skills rather than recalled definitions. EC-Council describes it as a rigorous exam in which you apply techniques such as threat vector identification, network scanning, OS detection, vulnerability analysis, system hacking, and web application hacking to solve a security audit challenge.

The credential carries external recognition. EC-Council lists the Certified Ethical Hacker (Practical) among its ISO/IEC 17024-accredited programs, and the US Department of Defense recognizes CEH Practical under DoD 8140 for roles including All-Source Analyst, Cyber Defense Analyst, Cyber Defense Incident Responder, Vulnerability Assessment Analyst, and Research & Development Specialist.

Official sources: CEH Certification | Certified Ethical Hacker AI Course | EC-Council — Exam details section (knowledge and practical exam tables); CEH Master Certification | Ethical Hacking Credential | EC-Council — CEH practical exam details table, skills list, and FAQs; EC-Council | Cyber Security Courses Online | Cybersecurity Training — FAQs: recognition of CEH Practical by the US Department of Defense

Format: six hours, 20 challenges, live virtual machines

Expect 20 practical challenges in 6 hours, delivered in the iLabs Cyber Range (Aspen availability), open book, with a passing score between 60% and 85%.

This is not a simulation exam. EC-Council states the practical mimics a real corporate network using live virtual machines, networks, and applications, and replicates a complex organization network including DMZs and firewalls. You work under a time limit, just as you would in a real engagement.

The exam is open book, which means you may consult reference material during the six hours. In practice, the time limit is the real constraint: twenty challenges leave roughly eighteen minutes each, so preparation should build speed in recognizing what a challenge is asking before you look anything up.

Because the environment uses live machines, tool fluency matters more than tool memorization. You will be presented with various scenarios and asked to demonstrate the application of the knowledge acquired in the CEH course.

FeatureVerified detail
Duration6 hours
Challenges20 practical challenges
DeliveryiLabs Cyber Range (availability: Aspen – iLabs)
Exam typeOpen book
Passing score60% to 85%
EnvironmentLive VMs mimicking a corporate network, including DMZ and firewalls

Official sources: CEH Master Certification | Ethical Hacking Credential | EC-Council — CEH practical exam details table, skills list, and FAQs; CEH Certification | Certified Ethical Hacker AI Course | EC-Council — Exam details section (knowledge and practical exam tables)

Skills the challenges test

EC-Council publishes a tested-skills list and an official blueprint for the practical: port scanning tools, vulnerability detection, system attacks, SQL injection methodology, web application security tools, and communication protocols, weighted across nine domains.

The official CEH page lists what the practical exam tests: port scanning tools such as Nmap and Hping, vulnerability detection, attacks on a system including DoS, DDoS, session hijacking, web server and web application attacks, SQL injection, and wireless threats, SQL injection methodology and evasion techniques, web application security tools such as Acunetix WVS, SQL injection detection tools such as IBM Security AppScan, and communication protocols.

EC-Council also describes what CEH (Practical) credential holders are proven to be able to do. That list extends the tested-skills list with OS banner grabbing, service and user enumeration, steganography and steganalysis, covering tracks, malware use in exploitation, packet sniffing, directory traversal, parameter tampering, XSS, and cryptography attacks.

EC-Council also publishes an official blueprint (v1) for the practical that assigns the 20 questions across nine weighted domains, so you can budget study time by published weight rather than guesswork. The blueprint and the tested-skills list together are your preparation map. For anything beyond the published passing range, such as per-challenge scoring, rely on EC-Council's official pages or your training provider. The DoD 8140 recognition applies to the credential itself, not to specific exam sections.

  • Reconnaissance and scanning: attack vectors, network scanning to find live and vulnerable machines, OS banner grabbing, service and user enumeration
  • Vulnerability and system hacking: vulnerability analysis, system hacking, steganography and steganalysis, covering tracks, malware-based exploitation
  • Network attacks: packet sniffing, session hijacking, DoS and DDoS, wireless threats
  • Web and database: web server and web application attacks including directory traversal, parameter tampering, and XSS; SQL injection methodology and evasion
  • Tooling: port scanning tools (Nmap, Hping), web application security tools (Acunetix WVS), SQL injection detection tools (IBM Security AppScan)

Official sources: CEH Certification | Certified Ethical Hacker AI Course | EC-Council — Exam details section (knowledge and practical exam tables); CEH Master Certification | Ethical Hacking Credential | EC-Council — CEH practical exam details table, skills list, and FAQs; Blue Print — https://cert.eccouncil.org/images/doc/CEH-Practical-Exam-Blueprintv1.pdf

The official blueprint: nine weighted domains

EC-Council publishes an exam blueprint (v1) for the practical with nine weighted domains totaling 20 questions. Network and perimeter hacking carries the largest share at 25%, and mobile/IoT/OT (10%) and cloud (5%) are formally in scope.

EC-Council's published blueprint for the Certified Ethical Hacker (Practical) exam, blueprint v1, breaks the 20 challenges into nine weighted domains. Knowing the weights lets you budget preparation time from the issuer's own document rather than from hearsay.

Each blueprint domain maps onto specific course modules, so the 20-module CEH course remains the natural study background — it is also the preparatory course EC-Council names for this certification. Treat the blueprint as the scope authority for this exam and the course outline as supporting material: EC-Council notes that official courseware and exam content are developed independently, and exam material can include content not covered in training.

The blueprint is labeled v1. EC-Council updates exam content over time and releases a new blueprint when objectives change, so check the current document before you finalize your plan.

Blueprint domainQuestionsWeight
Information Security and Ethical Hacking15%
Reconnaissance Techniques (footprinting, scanning, enumeration)315%
System Hacking Phases and Attack Techniques (vulnerability analysis, system hacking, malware)315%
Network and Perimeter Hacking (sniffing, social engineering, DoS, session hijacking, IDS/firewall/honeypot evasion)525%
Web Application Hacking (web servers, web applications, SQL injection)315%
Tools/Systems/Programs (wireless networks)15%
Mobile Platform, IoT and OT Hacking210%
Cloud Computing15%
Cryptography15%

Official sources: Blue Print — https://cert.eccouncil.org/images/doc/CEH-Practical-Exam-Blueprintv1.pdf; EC-Council candidate FAQ: exam preparation and blueprint updates — Exam Preparation:; Certified Ethical Hacker (Practical) — https://cert.eccouncil.org/certified-ethical-hacker-practical.html

Eligibility and how to book

You qualify through official EC-Council CEH training or an experience-based application with a USD 100 fee; once approved, you buy the voucher, receive a dashboard code, and book a proctored session at least three days ahead. Passing the knowledge exam is required for the CEH (Master) title, not listed as a booking condition for the practical itself.

EC-Council's certification page for the practical lists two eligibility routes: a minimum of two years of work experience in the InfoSec domain, which requires a USD 100 non-refundable application fee, or attendance at official EC-Council CEH training, where the same application fee is included in your training fee. Application processing typically takes 5 to 10 working days once your verifiers respond, and an approved application stays valid for 3 months.

Once approved, you purchase your exam voucher from the EC-Council Online Store and receive an Aspen dashboard access code with scheduling instructions. The code is valid for one year from receipt and is not transferable. Book your session at least 3 days in advance; cancellation requests need 24 hours' notice, rescheduling is possible up to 72 hours before the session, you have a 15-minute grace period to show up, and after three no-shows you need special permission from EC-Council's certification director to proceed.

Keep the credential hierarchy separate from booking. To earn the CEH (Master) designation you must pass both the CEH knowledge exam and this practical exam, but the practical's own eligibility criteria name official training or InfoSec experience rather than a knowledge-exam pass. On cost, EC-Council states the practical exam price may vary and directs you to your course provider or a training advisor for current pricing.

Official sources: Certified Ethical Hacker (Practical) — https://cert.eccouncil.org/certified-ethical-hacker-practical.html; CEH Master Certification | Ethical Hacking Credential | EC-Council — CEH practical exam details table, skills list, and FAQs

Preparing for a timed, live-machine exam

Practice in isolated, authorized labs against deliberately vulnerable machines, and fix a time plan — a triage pass and a per-challenge budget — before exam day.

Twenty challenges in six hours reward a plan you set in advance. Decide before exam day how you will move through the set, what per-challenge time budget you will respect, and when you will stop and move on — this is preparation advice, not an official exam rule.

Set up a host-only lab with deliberately vulnerable virtual machines, or use a vendor-provided practice range, and run timed mini-sessions: enumerate a service completely, verify one finding, attempt one controlled exploitation. Keep brief notes per command so that writing anything required by a challenge does not consume your clock.

The exercise below works through one complete time plan with explicit rules and a unique answer. It is a scheduling drill, not a scoring method: EC-Council publishes a passing score range, not per-challenge weights, in the sources for this guide.

Practice exercise

You are planning your session for a six-hour (360-minute) exam with 20 challenges. The following rules are your own plan, not official exam rules: reserve the final 30 minutes for review and submission; split the remaining time so the first pass gets twice as much time as the second pass; give every challenge an equal share of the first pass; revisit only the 6 challenges you expect to leave unfinished, splitting the second-pass time equally among them. How many minutes do you get per challenge in each pass?

Show answer

About 11 minutes per challenge in the first pass and about 18 minutes per revisited challenge in the second pass.

All figures follow from the stated premises. Working time is 360 − 30 = 330 minutes. A 2:1 split of 330 gives 220 minutes for the first pass and 110 for the second. The first pass divides 220 by 20 challenges, or 11 minutes each. The second pass divides 110 by 6 revisited challenges, roughly 18.3 minutes each. Check: 220 is twice 110, and 220 + 110 + 30 = 360. If your own expectations differ — a different number of revisits or a different review reserve — rerun the same arithmetic with your values. The point is to arrive with a tested time budget rather than improvising under the clock.

Official sources: CEH Certification | Certified Ethical Hacker AI Course | EC-Council — Exam details section (knowledge and practical exam tables); CEH Master Certification | Ethical Hacking Credential | EC-Council — CEH practical exam details table, skills list, and FAQs

Working within legal and authorized boundaries

Every technique the practical tests must be practiced only on systems you own or are explicitly authorized to test — isolated labs and vendor ranges exist for exactly this purpose.

The CEH program frames ethical hacking as penetrating your own computers, or systems to which you have official permission, to determine whether vulnerabilities exist and address them before a compromise. Your preparation environment should match that standard: host-only virtual networks with deliberately vulnerable images, EC-Council's own labs and cyber range, or other ranges you are explicitly authorized to use. Confirm permission and scope before every practice session.

This boundary is also practical exam preparation. The challenges take place in a controlled corporate-network replica, so training yourself to confirm scope and authorization before acting is a habit that transfers directly to the exam environment.

Official sources: Certified Ethical Hacker - Cert (EC-Council certification site) — Exam details, eligibility criteria and application FAQs; CEH Master Certification | Ethical Hacking Credential | EC-Council — CEH practical exam details table, skills list, and FAQs

Your next steps

Confirm your eligibility route, secure the exam attempt through training or an approved application, then prepare against the official module outline and tested-skills list.

A short checklist to move from reading to booking:

  • Check the official CEH (Practical) exam blueprint so your plan covers all nine weighted domains, including mobile/IoT/OT and cloud computing.
  • Choose your eligibility route: official EC-Council CEH training (application fee included) or the experience-based application with its USD 100 non-refundable fee.
  • Book through the Aspen dashboard code you receive after voucher purchase, scheduling at least 3 days ahead and noting the 24-hour cancellation and 72-hour rescheduling windows.
  • Pass the CEH knowledge exam first if you are pursuing the CEH (Master) designation.
  • Build timed lab practice around the tested-skills list: scanning tools, enumeration, vulnerability analysis, system attacks, SQL injection, web application tools, and cryptography techniques.
  • For anything this guide does not verify — per-challenge scoring, current pricing, retake terms — rely on EC-Council's official CEH Master and certification pages rather than secondary sources.

Official sources: Certified Ethical Hacker (Practical) — https://cert.eccouncil.org/certified-ethical-hacker-practical.html; Blue Print — https://cert.eccouncil.org/images/doc/CEH-Practical-Exam-Blueprintv1.pdf; CEH Master Certification | Ethical Hacking Credential | EC-Council — CEH practical exam details table, skills list, and FAQs; CEH Certification | Certified Ethical Hacker AI Course | EC-Council — Exam details section (knowledge and practical exam tables); Certified Ethical Hacker - Cert (EC-Council certification site) — Exam details, eligibility criteria and application FAQs

Official sources

Facts checked against EC-Council sources:

Next steps

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for EC-Council Certified Ethical Hacker (CEH) Practical.

Do I have to take the CEH Practical exam?
No. EC-Council awards the CEH certification when you pass the knowledge exam; the practical exam is optional but leads to the higher CEH (Master) designation when combined with it. If your goal is the Master credential, the practical is mandatory by definition.
How is the practical different from the CEH knowledge exam?
The knowledge exam is four hours of 125 multiple-choice questions on the ECC exam portal or at Pearson VUE centers. The practical is six hours of 20 hands-on challenges in the iLabs Cyber Range against live virtual machines. One tests recalled knowledge; the other tests applied technique under time pressure in a simulated corporate network.
Does the practical exam cover every CEH topic area?
Yes — the official blueprint (v1) spans nine weighted domains covering everything from reconnaissance through cryptography, including mobile/IoT/OT and cloud computing. Weight your preparation by the published percentages rather than deprioritizing any domain.
What happens if I fail a challenge during the six hours?
EC-Council publishes a passing score range of 60% to 85%; the sources for this guide do not break scoring down per challenge. The practical response to a stuck challenge is the same as in any timed technical exam: timebox the attempt, note your partial evidence, and move to another challenge.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.