Start Your Free Practice Test
Enter your details, then choose a 25-question Quick Test or the full 50-question, 90-minute practice test.
Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Check your readiness for the EC-Council Certified Ethical Hacker (CEH v13) 312-50 exam with 50 scenario questions built from the official 20 modules, each with an instant explanation. Free to take, timed with a 90-minute limit set to the pace of the real exam, and yours to retake as often as you want.
New to CEH? Learn more about the certification →
Enter your details, then choose a 25-question Quick Test or the full 50-question, 90-minute practice test.
This free EC-Council Certified Ethical Hacker (CEH v13) practice test checks your readiness for the 312-50 knowledge exam with 50 scenario questions built from the official 20 modules, each with an explanation for every answer choice. It is built by Training Camp, an EC-Council Accredited Training Center. New to the exam? Learn what the CEH certification is, or see the accelerated CEH Boot Camp.
The CEH v13 knowledge exam (312-50) has 125 multiple-choice questions and a 4-hour time limit, delivered through Pearson VUE or EC-Council's exam portal. The certification is organized into 20 modules and, in v13, adds AI-driven techniques woven through the attack lifecycle.
EC-Council does not publish fixed domain percentage weights for v13, so the topic areas in this practice test are our own groupings built from the official 20 modules, from ethical hacking fundamentals and reconnaissance through system hacking, network attacks, web application attacks, wireless and IoT, and cloud and cryptography.
Every question is an original, scenario-style item that frames you as a penetration tester working under a signed engagement, a security analyst, or an exam candidate identifying the right tool, phase, countermeasure or indicator. The test runs 50 questions on a 90-minute timer, and after each answer you get an explanation for the correct choice and for every distractor, so a wrong answer becomes a learning moment.
Take it timed to build exam stamina, review the per-topic breakdown at the end, and retake it as often as you want. Treat it as a readiness check that points you toward the modules to study, not as a substitute for full preparation.
Domains Covered · v13 · 312-50
Hacking phases, attacker types, scope and authorization.
Footprinting, OSINT, port scanning and service enumeration.
Gaining access, privilege escalation, persistence and malware types.
Sniffing, social engineering, DoS, session hijacking and IDS evasion.
Web server flaws, web application attacks and SQL injection.
Wireless attacks, mobile platform risks, and IoT and OT security.
Cloud security models and applied cryptography concepts.
Four questions from the bank, one per domain, with the reasoning behind every answer. The full test has 50.
A penetration tester has a signed engagement and has finished gathering open-source intelligence and scanning the target range. They now begin exploiting a validated vulnerability to obtain a foothold on a host. Which phase of the ethical hacking lifecycle does this activity BEST represent?
Correct. Gaining access is the phase where the tester exploits a validated weakness to obtain a foothold or elevate privileges on a target. It follows reconnaissance and scanning.
During the footprinting phase, an analyst wants to learn about a target organization's employees, technologies and subdomains without sending any traffic to the organization's own systems. Which approach BEST fits this requirement?
Correct. Passive reconnaissance gathers intelligence from third-party and public sources such as search engines, social media and registries without interacting with the target's systems, so it leaves no trace on them.
A tester recovers a database of unsalted password hashes during an authorized assessment. To speed up recovery, they use a precomputed table that maps hash values back to their plaintext inputs rather than hashing each guess in real time. Which technique is this?
Correct. A rainbow table is a precomputed structure that reverses unsalted hashes to plaintext far faster than hashing guesses in real time. Adding a unique salt to each password defeats it.
On a switched LAN during an authorized test, an analyst sends forged replies that associate the default gateway's IP address with their own MAC address, causing other hosts to send their traffic through the analyst's machine. Which attack is being performed?
Correct. ARP spoofing sends forged ARP replies that map a legitimate IP, such as the gateway, to the attacker's MAC, redirecting traffic through the attacker for a man-in-the-middle position. Dynamic ARP inspection is a countermeasure.
Every one of the 50 questions works this way: an explanation for the right answer and for the one you picked, so a wrong answer teaches you something. Questions last reviewed against the current EC-Council Certified Ethical Hacker (CEH v13) objectives.
Quick answers about the test, the EC-Council Certified Ethical Hacker (CEH v13) exam, and how to prepare.
Yes. Training Camp's CEH practice test is free to take. You get 50 original scenario questions built from the EC-Council Certified Ethical Hacker (CEH v13) modules, with a written explanation for every answer choice.
It is 50 multiple-choice questions drawn from the 20 CEH v13 modules, with an instant explanation after each answer and a 90-minute timer that is set to the pace of the real exam. You can retake it as often as you want. It is a readiness check, not a substitute for full preparation.
The CEH v13 knowledge exam (312-50) has 125 multiple-choice questions and a 4-hour time limit. It is delivered through Pearson VUE or EC-Council's exam portal.
EC-Council does not publish a fixed passing score for the CEH exam. The cut score varies between 60% and 85% depending on the difficulty of the exam form you receive.
CEH v13 covers 20 modules, and v13 adds AI-driven techniques across the attack lifecycle. EC-Council does not publish domain percentage weights, so the topic groupings in this test, such as reconnaissance, system hacking, network attacks, web application attacks, wireless and IoT, and cloud and cryptography, are ours, built from those modules.
CEH is an intermediate certification. EC-Council expects familiarity with networking, operating systems and security fundamentals, and either official training or documented information security work experience. Practicing with scenario questions is one of the most effective ways to prepare.
Combine hands-on lab practice with structured study across all 20 modules. Beyond practice questions, consider the accelerated CEH Boot Camp, which includes an exam voucher and a free retake option.