What the EC-Council CEH v13 312-50v13 is and who it is for
The Certified Ethical Hacker is EC-Council’s flagship ethical hacking certification. It tests whether you can think like an attacker across the whole hacking methodology: reconnaissance and scanning, then exploitation, post exploitation and covering your tracks. Version 13 is the current release, and it adds AI powered attack techniques, AI driven defensive tools, cloud security hacking, IoT attack vectors and operational technology hacking to the older material. CEH is mapped to the U.S. DoD and recognised across more than 45 cybersecurity job roles.
It suits you if you are moving into penetration testing, red team or security testing work, if you already defend networks and want the attacker’s view of them, or if an employer or contract lists CEH by name.
Check your eligibility before you book. EC-Council requires two years of information security experience for the self study pathway. If you do not have that, you need to complete official EC-Council training first.
EC-Council CEH v13 312-50v13 at a glance
| Item | Detail |
|---|---|
| Exam code | 312-50v13 |
| Questions | 125 |
| Time allowed | 4 hours |
| Passing score | 60 to 85%, depending on the exam form you receive |
| Where you sit it | EC-Council Exam Centre or Pearson VUE |
| Certification valid for | 3 years |
What is on the exam
CEH v13 is built from 20 modules. EC-Council does not publish a percentage weight for each one, so treat them as roughly equal and expect questions from all of them. They fall naturally into five groups.
Foundations and reconnaissance. Introduction to ethical hacking, footprinting and reconnaissance, scanning networks, enumeration and vulnerability analysis. This is the front end of an engagement: the legal and methodological framing, gathering information passively and actively, identifying live hosts, open ports and services, pulling user and share details out of a target, and turning scanner output into a list of weaknesses. Expect tool names, scan types and what a given result tells you.
Attacking systems and people. System hacking, malware threats, sniffing, social engineering, denial of service, session hijacking, and evading IDS, firewalls and honeypots. These modules cover gaining and keeping access, privilege escalation, malware families and how they behave, capturing and manipulating traffic, manipulating people rather than machines, overwhelming a service, taking over an established session, and slipping past the controls meant to catch you.
Web targets. Hacking web servers, hacking web applications and SQL injection. Server misconfiguration, application flaws and injection attacks, with questions that often show you a request, a payload or an error and ask what is happening or what comes next.
Wireless, mobile, IoT, OT and cloud. Hacking wireless networks, hacking mobile platforms, IoT and OT hacking, and cloud computing. This is where much of the newer v13 material lives, including attacks on connected devices, industrial systems and cloud services.
Cryptography. Ciphers, hashing, public key infrastructure and the attacks against them. It is one module out of 20, but it is the one candidates from a non mathematical background most often leave until too late.
Why people fail it
The first reason is breadth. Twenty modules means you need to know something about everything, from social engineering and cryptography to cloud security, IoT hacking and the AI powered techniques added in this version. Most candidates who fail do not collapse on one topic. They lose a few marks in each of the modules they decided were less important, and those small losses add up.
The second reason is the pass mark. It shifts between 60% and 85% depending on the difficulty of the question pool you are given, so you will not know your cut score until after you finish. That makes it unsafe to aim for the minimum. If your practice scores are hovering around the lower end of that range, you are not ready.
The third is the cost of getting it wrong. EC-Council does not offer free retakes or partial credit, so a near miss is a full fail and another voucher. Candidates who treat the first attempt as a trial run tend to pay for that decision.
Finally, CEH asks about tools and techniques in a specific way. Plenty of working testers know how to do something in practice but hesitate when a question asks which option, flag or phase a textbook would name. Reading the question in EC-Council’s terms, not your own habits, matters.
A study plan that fits the exam
Seven weeks, arranged by module groups because there are no published weights. The aim is even coverage, with no module skipped.
- Week 1: foundations and reconnaissance. Introduction to ethical hacking, footprinting and reconnaissance, scanning networks. At the end of the week, try the free CEH v13 practice questions to see how EC-Council phrases tool and technique questions.
- Week 2: enumeration, vulnerability analysis and system hacking. Work through the matching questions in the 312-50v13 practice question pack and read every explanation, including why the wrong options are wrong.
- Week 3: malware, sniffing and social engineering. Learn how each malware type behaves and how traffic capture and manipulation attacks work.
- Week 4: denial of service, session hijacking and evasion. Focus on how IDS, firewalls and honeypots detect activity and how attackers avoid them.
- Week 5: web servers, web applications and SQL injection. Practise reading requests and payloads until you can identify the attack from the evidence.
- Week 6: wireless, mobile, IoT and OT, cloud and cryptography. A heavy week of newer material. Give cryptography its own two days.
- Week 7: timed runs. Use the questions only PDF for full sittings of 125 questions in 4 hours, score yourself by module, and spend the last days on the modules that came out lowest.
On exam day
You sit CEH v13 at an EC-Council Exam Centre or through Pearson VUE. Whichever route you book, read the confirmation carefully for identification and check in requirements, confirm the location and start time, and plan to arrive early so the admission process does not eat into your nerves.
The exam is 125 questions in 4 hours, which is generous for multiple choice. Use the time to read each question fully, because many hinge on a single word such as first, best or most likely. Do not try to work out whether you are over the line while you are sitting it: your form’s pass mark is not shown to you in advance. Answer every question and review flagged items at the end.
Frequently asked questions
What is the passing score for CEH v13?
It is not a single number. The pass mark ranges from 60 to 85% depending on the exam form you receive, which reflects the difficulty of your particular question pool. Prepare to score comfortably above the top of your practice range rather than aiming at a figure.
What happens if I fail? Can I retake it?
You can, but there are no free retakes and no partial credit, so each new attempt needs a new voucher. EC-Council publishes its retake policy, including any waiting period between attempts, on its website, so check it before you book. The practice pack is refunded if you fail, but the voucher is not.
Is the practice question pack enough on its own?
No. It is 1,049 practice questions with an explanation for every answer and every wrong option, and it is very good at showing you EC-Council’s phrasing and exposing modules you have neglected. It is not a course, and it will not teach you the tools the way hands on lab time does. Use it alongside your study material and a lab, not instead of them.
When you want to test yourself across all 20 modules, get the 1,049 question CEH v13 pack for US$39, pass or your money back.
