Study Guide

EC-Council EHE (112-52): Study Guide and Exam Overview

Prepare for the EC-Council Ethical Hacking Essentials (EHE) exam 112-52: verified exam facts, official domain weights, and a worked practice exercise.

Updated September 202610 min readStudy GuideCEH Exam
Gabrielle Wallace

Gabrielle Wallace

CEH Exam Editorial Team

Prepare for EHE by learning each attack alongside the countermeasure that defeats it, anchoring the foundational frameworks (CIA triad, AAA, hacking phases, Cyber Kill Chain, MITRE ATT&CK), and practicing classification decisions in the official sandboxed labs. The exam is a two-hour, 75-question multiple-choice test with a 70% passing score, delivered under proctoring.

What the Ethical Hacking Essentials credential covers

EHE is EC-Council's introductory cybersecurity certification in ethical hacking and penetration testing fundamentals, designed for people starting a security career.

Ethical Hacking Essentials (EHE) is an entry-level course and certification from EC-Council, the organization behind the Certified Ethical Hacker (CEH) credential. It introduces threats, vulnerabilities, password cracking, social engineering, web application attacks, cloud, IoT and OT security, and penetration testing basics.

EC-Council positions EHE as a first step on the path toward CEH. Completing the course and passing the proctored exam earns the certification; the material does not replace CEH-level depth. If your goal is advanced ethical hacking work, treat EHE as groundwork rather than an endpoint.

The course combines video lessons, guided labs, and a capture-the-flag (CTF) capstone project, in which you solve challenge objectives inside a controlled target system. EC-Council describes the capstone as a way to apply the whole syllabus against realistic but sandboxed targets.

Official sources: Ethical Hacking Essentials (EHE) | Path to CEH v13 Certification — EC-Council EHE program page, retrieved 2026-09-15; Ethical Hacking Essentials (EHE) | Path to CEH v13 Certification — EC-Council EHE train-and-certify page, retrieved 2026-09-15

Exam facts: code, format, duration, and cost

The EHE exam is code 112-52: 75 multiple-choice questions in 2 hours, passing at 70%, delivered under proctoring. The individual course bundle is listed at $299 and includes an exam voucher.

EC-Council's certification page lists exam 112-52 with 75 questions, a 2-hour duration, a multiple-choice format, and a 70% passing score. All EC-Council Essentials Series exams are fully proctored, meaning an authorized supervisor monitors the session to protect exam integrity.

The $299 individual offering bundles the ecourseware (listed at over 1,000 pages), 47 labs (35 core plus 12 self-study), the CTF-style capstone, one year of ecourseware access, six months of lab access, and a proctored exam voucher valid for one year. EC-Council notes that enterprises, individuals, and universities have different pricing plans, so confirm your category before purchasing.

The certification is valid for three years from the date of your successful exam attempt. After that term, EC-Council says you recertify by passing the EHE exam again; no Continuing Education fees or ECE credits are required to maintain the credential during the three years.

There is no separate application gate: EC-Council states there are no eligibility criteria and no prior educational or experience requirements for EHE.

  • Exam code: 112-52
  • Questions: 75, multiple choice
  • Duration: 2 hours
  • Passing score: 70%
  • Delivery: proctored, supervised by EC-Council
  • Validity: three years from the exam date; recertify by retaking the exam

Official sources: Ethical Hacking Essentials (EHE) | Path to CEH v13 Certification — EC-Council EHE train-and-certify page, retrieved 2026-09-15; Ethical Hacking Essentials — https://cert.eccouncil.org/ethical-hacking-essentials.html; Ethical Hacking Essentials (EHE) | Path to CEH v13 Certification — EC-Council EHE program page, retrieved 2026-09-15

Who should take it

EHE targets complete beginners: students, career switchers, and IT professionals moving into cybersecurity, with no prerequisites required.

EC-Council describes the intended audience as high school, college, and university students, graduates, career starters and changers, and IT or technology teams with little or no security experience. Working professionals who want a structured entry point into security are also named.

Because no prior cybersecurity knowledge or IT work experience is required, plan your study on the assumption that definitions and frameworks are new material. Budget time for the hands-on labs rather than relying on reading alone; the course's own design pairs each module with lab exercises for exactly that reason.

Official sources: Ethical Hacking Essentials (EHE) | Path to CEH v13 Certification — EC-Council EHE train-and-certify page, retrieved 2026-09-15

Exam blueprint: twelve domains and their weights

The official EHE v1 exam blueprint divides the exam into twelve domains weighted from 4% to 12%, with network-level and web application attacks carrying the most weight.

EC-Council publishes the tested scope in the EHE v1 Exam Blueprint for exam 112-52. The blueprint's twelve domains parallel the course modules, but the blueprint, not the module list, defines what the exam measures. EC-Council's candidate FAQ also states that official courseware and exams are developed independently, so use the course to learn the material and the blueprint to plan for the test.

The weights below show where study time pays off most: Network Level Attacks and Web Application Attacks each carry 12%, while Penetration Testing Fundamentals carries 4%. Every domain is examinable, so cover all twelve; treat the weights as priorities, not as permission to skip domains.

Exam domain (blueprint v1)Weight
1. Information Security Fundamentals6%
2. Ethical Hacking Fundamentals6%
3. Information Security Threats and Vulnerability Assessment10%
4. Password Cracking Techniques and Countermeasures6%
5. Social Engineering Techniques and Countermeasures8%
6. Network Level Attacks and Countermeasures12%
7. Web Application Attacks and Countermeasures12%
8. Wireless Attacks and Countermeasures10%
9. Mobile Attacks and Countermeasures8%
10. IoT and OT Attacks and Countermeasures10%
11. Cloud Computing Threats and Countermeasures8%
12. Penetration Testing Fundamentals4%

Official sources: Blue Print — https://cert.eccouncil.org/images/doc/EHEv1%20Exam%20Blueprint.pdf; EC-Council candidate FAQ: exam preparation and blueprint updates — Exam Preparation:

Build the conceptual anchors first

Two preparation habits pay off: learn what each named foundational term covers from your courseware, and place attacker actions in the correct hacking phase before comparing answers.

Modules 1 and 2 supply the foundational vocabulary: the CIA triad, the AAA model, threat vectors, layered defense strategies including Zero Trust and Defense-in-Depth, cryptography concepts, and information security laws and standards. The official page names these concepts without defining them, so work through the ecourseware until you can state each term's meaning in your own words. These named principles recur as classification anchors throughout the later attack modules.

The ethical hacking lifecycle runs, in EC-Council's description, from reconnaissance to covering tracks, and Module 4 details its stages: footprinting and OSINT, scanning and enumeration, vulnerability scanning, gaining access, maintaining access, and covering tracks. Being able to place an attacker action in the right phase is a reusable skill across scenario questions.

Cyber Kill Chain, MITRE ATT&CK, and IoC analysis are named in the official skills list as methodologies for understanding adversary behavior. Know that these frameworks exist, what the course uses them for, and where the courseware introduces each; the ecourseware and downloadable brochure carry the structural detail the public page omits.

  • CIA triad, AAA model, threat vectors, and layered defense strategies including Zero Trust and Defense-in-Depth
  • Cryptography fundamentals: symmetric and asymmetric encryption, hash functions, digital signatures
  • Hacking lifecycle phases from reconnaissance to covering tracks
  • Cyber Kill Chain, MITRE ATT&CK, and IoC analysis as adversary-behavior methodologies

Official sources: Ethical Hacking Essentials (EHE) | Path to CEH v13 Certification — EC-Council EHE program page, retrieved 2026-09-15; Ethical Hacking Essentials (EHE) | Path to CEH v13 Certification — EC-Council EHE train-and-certify page, retrieved 2026-09-15

Pair each attack with its countermeasure

For every module that introduces attacks, learn the matching countermeasures in the same session rather than as a separate review later.

The official skills list is built as pairs: malware types alongside malware countermeasures, cracking techniques alongside cracking countermeasures, sniffing, denial-of-service, and session hijacking alongside their detection methods and defenses, and so on through wireless, mobile, IoT, OT, and cloud. Studying the pairs together means you never answer a countermeasure question from a memorized list alone.

This is a study recommendation, not an official requirement. Adapt the pace to your schedule, but keep the pairing discipline: when you finish a module's attack techniques, immediately write down, in your own words, the defenses the course gives for them.

One caution belongs here: practice attack techniques only in authorized, isolated environments such as the course's sandboxed labs and CTF challenges. Never run techniques against systems you do not have explicit permission to test; the penetration testing module's own ethical guidelines apply to your study habits.

Official sources: Ethical Hacking Essentials (EHE) | Path to CEH v13 Certification — EC-Council EHE program page, retrieved 2026-09-15; Ethical Hacking Essentials (EHE) | Path to CEH v13 Certification — EC-Council EHE train-and-certify page, retrieved 2026-09-15

Worked example: classifying a network attack

Classify scenario questions by objective first: denying availability, intercepting traffic, or taking over a session. The exercise below works through that classification step by step.

Module 7 packs three attack families into one module, which makes it the easiest place to blur distinctions on exam day. The exercise works through the classification logic end to end, including why each distractor fails.

Worked example

You are observing an authorized lab exercise. An attacker machine sends thousands of connection requests per second at a single test web server. Within minutes the server stops responding to legitimate users. No existing login session is touched and no traffic between other machines is redirected. Which attack class does this scenario describe, and why are session hijacking and ARP poisoning not correct answers?

Show answer

The scenario describes a denial-of-service (DoS) attack. If the request flood originated from many coordinated machines, it would be a distributed DoS (DDoS) attack.

The central fact is loss of availability: the server's resources are exhausted by request flooding, so legitimate users cannot reach it. That is exactly what the course's DoS material targets, preventing access to system resources for legitimate users. Session hijacking fails as an answer because its objective is to seize control of an existing, valid TCP communication session, and the scenario explicitly states no session was taken over. ARP poisoning fails because its mechanism is redirecting communication between two machines by manipulating address resolution, and the scenario describes no redirection at all. When you classify a scenario like this, name the objective first (deny, intercept, or take over), then match the mechanism the scenario actually describes to it.

Official sources: Ethical Hacking Essentials (EHE) | Path to CEH v13 Certification — EC-Council EHE train-and-certify page, retrieved 2026-09-15

Preparation steps and where to practice

Use the official labs and CTF capstone as your practice environment, study the twelve modules in sequence with countermeasures attached, and finish with full practice sets.

A workable sequence: spend your first sessions on Modules 1 and 2 until the frameworks and phases are automatic. Then move through the attack modules, attaching each countermeasure list the same day you learn the attacks. Cover web, wireless, and mobile next, then IoT, OT, and cloud, and close with penetration testing fundamentals, which integrates everything.

The course includes 47 guided labs and CTF-style challenges run in a sandboxed environment with virtual machines and secured networks. EC-Council states the labs come with guides, screenshots, and videos. Use them rather than improvising practice targets; the sandbox exists so you can experiment without legal or safety risk.

When you can classify a short scenario into the correct attack class quickly, name countermeasures for each module area from memory, and explain how the hacking phases, Kill Chain, and ATT&CK differ, you are in a good position to attempt full practice sets. These are learning milestones you set for yourself, not score predictions.

Official sources: Ethical Hacking Essentials (EHE) | Path to CEH v13 Certification — EC-Council EHE program page, retrieved 2026-09-15; Ethical Hacking Essentials (EHE) | Path to CEH v13 Certification — EC-Council EHE train-and-certify page, retrieved 2026-09-15

Next credentials and career routes

EC-Council identifies CEH as the next step after EHE and offers seven other Essentials courses; the issuer claims EHE supports entry-level roles such as security analyst or junior penetration tester.

EC-Council's own guidance names the Certified Ethical Hacker (CEH) as the next crucial step for learners who want to progress in ethical hacking. On EC-Council's certification roadmap, CEH sits in the Core band, which the roadmap describes as involving more than two years of networking knowledge, so plan the gap between the two credentials realistically.

Alongside EHE, the Essentials Series covers seven further courses: network defense, digital forensics, cloud security, IoT security, SOC, threat intelligence, and DevSecOps. Taking several gives broad foundational coverage before you specialize; EC-Council's certification roadmap places all of them at the foundational, no-experience level.

On employment, EC-Council states that EHE equips candidates for starting entry-level positions such as security analyst or junior penetration tester. That is the issuer's claim; hiring outcomes depend on your local market, overall skills, and experience, so treat it as direction rather than a guarantee.

Official sources: EC-Council | Cyber Security Courses Online | Cybersecurity Training — EC-Council homepage and certification roadmap, retrieved 2026-09-15; Ethical Hacking Essentials (EHE) | Path to CEH v13 Certification — EC-Council EHE train-and-certify page, retrieved 2026-09-15

Final checklist and official sources

Before the exam, plan study time from the blueprint weights, complete the labs, and keep the 70% passing score and three-year validity in mind as you schedule.

Work through this list in order and you will have covered both the knowledge and the administration the credential requires.

  • Review the EHE v1 Exam Blueprint and allocate study time by domain weight
  • Study all twelve domains, pairing attacks with countermeasures in the same session
  • Complete the guided labs and the CTF capstone in the sandboxed environment
  • Confirm pricing for your category (individual, enterprise, or university)
  • Schedule the proctored 112-52 exam while your voucher's one-year validity is open
  • Remember the 70% passing score and three-year validity; check cert.eccouncil.org for current policies before test day

Official sources: Ethical Hacking Essentials — https://cert.eccouncil.org/ethical-hacking-essentials.html; Blue Print — https://cert.eccouncil.org/images/doc/EHEv1%20Exam%20Blueprint.pdf

Official sources

Facts checked against EC-Council's official EHE pages:

Next steps

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for EC-Council Ethical Hacking Essentials (EHE).

What is a proctored exam, and are EHE exams proctored?
A proctored exam is supervised by an authorized individual, called a proctor, who monitors test-takers to prevent misconduct. EC-Council states that all Essentials Series exams, including EHE, are fully proctored.
What does the $299 purchase include?
EC-Council lists the individual offering as including the ecourseware, 47 labs (35 core and 12 self-study), a CTF-style capstone, one year of ecourseware access, six months of lab access, and a proctored exam voucher valid for one year. Enterprises and universities have separate pricing plans.
Is EHE recognized by education or government bodies?
EC-Council's EHE page lists approvals from the education departments of Florida, Virginia, Ohio, and Arkansas as an industry-recognized credential, and describes broader EC-Council endorsements including ACE and ANAB. Recognition for your specific purpose, such as college credit, should be confirmed with the institution involved.
Can I practice the attack techniques on my own machines or networks?
No, not on systems you lack permission to test. EC-Council delivers its labs and CTF challenges inside a sandboxed environment with virtual machines and secured networks for exactly this reason. Restrict all practice to authorized, isolated labs, including your own.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.