Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Free Practice Test

Free CEH Practice Test 2026 (v13 · 312-50)

Check your readiness for the EC-Council Certified Ethical Hacker (CEH v13) 312-50 exam with 50 scenario questions built from the official 20 modules, each with an instant explanation. Free to take, timed with a 90-minute limit set to the pace of the real exam, and yours to retake as often as you want.

25 or 50 Questions 90-Minute Timer 7 v13 · 312-50 Domains Every Answer Explained New Sample Each Retake

New to CEH? Learn more about the certification →

Start Your Free Practice Test

Enter your details, then choose a 25-question Quick Test or the full 50-question, 90-minute practice test.

First Name
Last Name
Phone
About This Test

Free CEH Practice Test (312-50 v13)

This free EC-Council Certified Ethical Hacker (CEH v13) practice test checks your readiness for the 312-50 knowledge exam with 50 scenario questions built from the official 20 modules, each with an explanation for every answer choice. It is built by Training Camp, an EC-Council Accredited Training Center. New to the exam? Learn what the CEH certification is, or see the accelerated CEH Boot Camp.

What's on the EC-Council Certified Ethical Hacker (CEH v13) exam?

The CEH v13 knowledge exam (312-50) has 125 multiple-choice questions and a 4-hour time limit, delivered through Pearson VUE or EC-Council's exam portal. The certification is organized into 20 modules and, in v13, adds AI-driven techniques woven through the attack lifecycle.

EC-Council does not publish fixed domain percentage weights for v13, so the topic areas in this practice test are our own groupings built from the official 20 modules, from ethical hacking fundamentals and reconnaissance through system hacking, network attacks, web application attacks, wireless and IoT, and cloud and cryptography.

How to use this practice test

Every question is an original, scenario-style item that frames you as a penetration tester working under a signed engagement, a security analyst, or an exam candidate identifying the right tool, phase, countermeasure or indicator. The test runs 50 questions on a 90-minute timer, and after each answer you get an explanation for the correct choice and for every distractor, so a wrong answer becomes a learning moment.

Take it timed to build exam stamina, review the per-topic breakdown at the end, and retake it as often as you want. Treat it as a readiness check that points you toward the modules to study, not as a substitute for full preparation.

Domains Covered · v13 · 312-50

Ethical Hacking FundamentalsModule 1

Hacking phases, attacker types, scope and authorization.

Reconnaissance, Scanning and EnumerationModules 2-5

Footprinting, OSINT, port scanning and service enumeration.

System Hacking and MalwareModules 6-7

Gaining access, privilege escalation, persistence and malware types.

Network Attacks and EvasionModules 8-12

Sniffing, social engineering, DoS, session hijacking and IDS evasion.

Web Application AttacksModules 13-15

Web server flaws, web application attacks and SQL injection.

Wireless, Mobile, IoT and OTModules 16-18

Wireless attacks, mobile platform risks, and IoT and OT security.

Cloud and CryptographyModules 19-20

Cloud security models and applied cryptography concepts.

Try Before You Start

Sample CEH Practice Questions

Four questions from the bank, one per domain, with the reasoning behind every answer. The full test has 50.

Question 1 Ethical Hacking Fundamentals

A penetration tester has a signed engagement and has finished gathering open-source intelligence and scanning the target range. They now begin exploiting a validated vulnerability to obtain a foothold on a host. Which phase of the ethical hacking lifecycle does this activity BEST represent?

  1. Reconnaissance
  2. Scanning
  3. Gaining access Correct
  4. Clearing tracks
Why this is the best answer

Correct. Gaining access is the phase where the tester exploits a validated weakness to obtain a foothold or elevate privileges on a target. It follows reconnaissance and scanning.

Question 2 Reconnaissance, Scanning and Enumeration

During the footprinting phase, an analyst wants to learn about a target organization's employees, technologies and subdomains without sending any traffic to the organization's own systems. Which approach BEST fits this requirement?

  1. Passive reconnaissance using public records, search engines and social media Correct
  2. A full TCP connect scan of the target's public IP range
  3. Banner grabbing against the target's web and mail servers
  4. A DNS zone transfer request to the target's name server
Why this is the best answer

Correct. Passive reconnaissance gathers intelligence from third-party and public sources such as search engines, social media and registries without interacting with the target's systems, so it leaves no trace on them.

Question 3 System Hacking and Malware

A tester recovers a database of unsalted password hashes during an authorized assessment. To speed up recovery, they use a precomputed table that maps hash values back to their plaintext inputs rather than hashing each guess in real time. Which technique is this?

  1. Dictionary attack
  2. Brute-force attack
  3. Rainbow table attack Correct
  4. Password spraying
Why this is the best answer

Correct. A rainbow table is a precomputed structure that reverses unsalted hashes to plaintext far faster than hashing guesses in real time. Adding a unique salt to each password defeats it.

Question 4 Network Attacks and Evasion

On a switched LAN during an authorized test, an analyst sends forged replies that associate the default gateway's IP address with their own MAC address, causing other hosts to send their traffic through the analyst's machine. Which attack is being performed?

  1. DNS cache poisoning
  2. MAC flooding
  3. ARP spoofing Correct
  4. Smurf attack
Why this is the best answer

Correct. ARP spoofing sends forged ARP replies that map a legitimate IP, such as the gateway, to the attacker's MAC, redirecting traffic through the attacker for a man-in-the-middle position. Dynamic ARP inspection is a countermeasure.

Every one of the 50 questions works this way: an explanation for the right answer and for the one you picked, so a wrong answer teaches you something. Questions last reviewed against the current EC-Council Certified Ethical Hacker (CEH v13) objectives.

CEH Practice Test

Frequently Asked Questions

Quick answers about the test, the EC-Council Certified Ethical Hacker (CEH v13) exam, and how to prepare.

Is this CEH practice test free?

Yes. Training Camp's CEH practice test is free to take. You get 50 original scenario questions built from the EC-Council Certified Ethical Hacker (CEH v13) modules, with a written explanation for every answer choice.

How does this practice test work?

It is 50 multiple-choice questions drawn from the 20 CEH v13 modules, with an instant explanation after each answer and a 90-minute timer that is set to the pace of the real exam. You can retake it as often as you want. It is a readiness check, not a substitute for full preparation.

How many questions are on the real CEH exam?

The CEH v13 knowledge exam (312-50) has 125 multiple-choice questions and a 4-hour time limit. It is delivered through Pearson VUE or EC-Council's exam portal.

What score do I need to pass the CEH exam?

EC-Council does not publish a fixed passing score for the CEH exam. The cut score varies between 60% and 85% depending on the difficulty of the exam form you receive.

What topics does the CEH v13 exam cover?

CEH v13 covers 20 modules, and v13 adds AI-driven techniques across the attack lifecycle. EC-Council does not publish domain percentage weights, so the topic groupings in this test, such as reconnaissance, system hacking, network attacks, web application attacks, wireless and IoT, and cloud and cryptography, are ours, built from those modules.

Is the CEH exam hard, and are there prerequisites?

CEH is an intermediate certification. EC-Council expects familiarity with networking, operating systems and security fundamentals, and either official training or documented information security work experience. Practicing with scenario questions is one of the most effective ways to prepare.

How should I prepare for the CEH exam?

Combine hands-on lab practice with structured study across all 20 modules. Beyond practice questions, consider the accelerated CEH Boot Camp, which includes an exam voucher and a free retake option.