Certified Ethical Hacker (CEH) (312-50)

EC-COUNCIL · 312-50 · Certification Hub

Questions125
Passing Score70%
Question TypesMultiple choice (one answer), Multiple choice (multiple answers)

Certification Summary

The EC-Council Certified Ethical Hacker 312-50 exam is for people working as penetration testers or security auditors. You take this exam to show you can manually test a school network for gaps before a real attacker finds them.

Reconnaissance, system hacking, network perimeter, and web application hacking account for seventy-four percent of your score. The other questions cover mobile, IoT, cloud, and cryptography. You will spend your time picking the right Nmap scan flag or Burp Suite configuration to bypass a specific security control.

Official blueprint weighting

Information Security and Ethical Hacking Overview6%
Reconnaissance Techniques21%
System Hacking Phases and Attack Techniques17%
Network and Perimeter Hacking14%
Web Application Hacking16%
Wireless Network Hacking6%
Mobile Platform, IoT, and OT Hacking8%
Cloud Computing6%
Cryptography6%

Domain 1: Information Security and Ethical Hacking Overview - 6%

This is the definition stuff you need to memorize before the real work starts.

Don't overthink this part. It is just the vocabulary list for the rest of the exam. Know the difference between a white hat and a black hat because the test wants to see if you understand the legal boundaries. If you spend too much time here, you are wasting energy. Just learn the CIA triad and the basic compliance rules so you do not get tripped up on the easy questions.

Domain 2: Reconnaissance Techniques - 21%

This is where you figure out who the caller is before they even open their mouth.

Recon is about gathering intel without triggering the alarms. You need to know how to use Google dorks and public databases to build a profile. If you skip the passive recon steps, you will miss the obvious clues that make the later stages easier. The trap here is thinking you need a fancy tool for everything. Most of the time, the info is sitting in plain sight on a public server that someone forgot to lock down.

Domain 3: System Hacking Phases and Attack Techniques - 17%

This is the core of the ticket. It is about getting in and staying in.

System hacking is a step by step process. You scan, you find the hole, you exploit it, and then you hide your tracks. If you miss the escalation phase, you are stuck with user rights and cannot do anything useful. Watch out for questions about password cracking and log clearing. If the system logs show your activity, you failed. Keep your eyes on the privilege levels and how they change during the attack.

Domain 4: Network and Perimeter Hacking - 14%

The perimeter is the firewall and the switches that keep the bad guys out.

Network hacking is mostly about sniffing traffic and finding weak points in the perimeter. You have to know how ARP poisoning and DoS attacks work because those are the most common things that break a network. Don't get stuck on the theory of how a switch works. Focus on what happens when you spoof a MAC address or flood a port. If the network goes down, the ticket volume goes up, and you are the one cleaning it up.

Domain 5: Web Application Hacking - 16%

Web apps are where the most dangerous holes usually live.

SQL injection and cross site scripting are the big ones. If you don't know how to sanitize an input field, you will fail these questions. The exam loves to throw code snippets at you that look like gibberish. Look for the input that isn't checked by the server. It is usually the simplest path to a data breach. Don't let the complex web architecture distract you from the basic lack of input validation.

Domain 6: Wireless Network Hacking - 6%

Wireless is just a network with the cables ripped out.

Wireless security is mostly about cracking the encryption keys. If you understand how WPA2 and WPA3 handle handshakes, you have the answer. People leave their routers wide open or use weak passwords, and that is how you get in. The trap is getting too deep into the radio frequency math. You just need to know how to capture the traffic and crack the key.

Domain 7: Mobile Platform, IoT, and OT Hacking - 8%

Everything is connected now, and almost none of it is secure.

These devices are the weakest link in the chain because they rarely get patched. IoT devices are basically small computers with zero security settings. Know the basics of how mobile app sandboxing works and why OT systems are so fragile. If you try to run a heavy scan on an OT system, you will crash the whole plant. The test wants to know if you understand the impact of your actions on these specific devices.

Domain 8: Cloud Computing - 6%

Cloud is just someone else's server, but the rules change.

The cloud is about shared responsibility. You need to know what you are responsible for and what the provider covers. If you misconfigure an S3 bucket, that is on you. The exam will test if you know how to lock down access keys and manage permissions. Don't get confused by the marketing terms for cloud services. Just remember that if the permissions are wrong, the data is exposed.

Domain 9: Cryptography - 6%

Encryption is the only thing standing between a hack and a total disaster.

You do not need to be a math genius. You just need to know which algorithm is for what. Know the difference between symmetric and asymmetric keys and when to use a hash. If you can identify where the weak link is in a crypto chain, you are golden. Don't spend days studying the history of ciphers. Focus on which keys are used for encryption versus digital signatures.

Where you stand

Official exam domains only. Timed evidence moves Ready. Flashcards and labs stay on this certification as a whole. Reading a cheat sheet or case file does not count here.

Log in to fill this chart from your exam, study, and Proof history.

DomainExamStudyCalibrationProof
Information Security and Ethical Hacking Overview6% of examno timed itemsNoneNone
Reconnaissance Techniques21% of examno timed itemsNoneNone
System Hacking Phases and Attack Techniques17% of examno timed itemsNoneNone
Network and Perimeter Hacking14% of examno timed itemsNoneNone
Web Application Hacking16% of examno timed itemsNoneNone
Wireless Network Hacking6% of examno timed itemsNoneNone
Mobile Platform, IoT, and OT Hacking8% of examno timed itemsNoneNone
Cloud Computing6% of examno timed itemsNoneNone
Cryptography6% of examno timed itemsNoneNone
Flashcards (this cert)0 / 136 mastered
Labs (this cert)0 / 0 passed

Resource Center

Complete the check below to request missing content.

Articles

Articles

Enhanced learning for this exam: breakdowns, guides, and tips written so you can reason through new scenarios instead of only recalling facts.

No shared articles for this exam yet. Be the first to write a breakdown, guide, or tips piece.

Request articles
Labs

No labs available

Request labs
Cheat Sheets

No cheat sheets available

Request cheat sheets