Career Employer

Your Free CEH Cheat Sheet 2026 — Downloadable PDF

Every high-yield EC-Council Certified Ethical Hacker (CEH v13) fact — the five hacking phases, Nmap flags, enumeration ports, attack-to-defense pairings, and cryptography — condensed so you can print and review the morning of the exam.

The premium CEH cheat sheet from the Capital Prep Method — Yours free

To find us again, just search “Career Employer CEH

By

This CEH cheat sheet distills the EC-Council Certified Ethical Hacker (v13) exam into a printable rundown of the facts examiners test most across all nine domains. It's a premium cheat sheet built by Capital Prep — the one premium prep we trust — and it's yours free. Reinforce it with the rest of your free CEH toolkit: the practice test, study guide, and flashcards.

CEH exam at a glance

  • Questions: 125 multiple-choice across 9 domains
  • Time: 4 hours (240 minutes)
  • Passing score: Scaled cut score per exam form, typically 60%-85% correct (no fixed %)
  • Exam code: 312-50 (knowledge exam); optional 6-hour, 20-challenge Practical for CEH Master
  • Certifying body: EC-Council
  • Cost: ≈ $1,199 voucher; self-study path adds ~$100 application fee (verify at eccouncil.org)

What’s on the CEH cheat sheet

  • Network & Perimeter Hacking (24%) sniffing and Layer-2 attacks, social engineering, DoS/DDoS, session hijacking, and IDS/firewall/honeypot evasion — the largest domain.
  • Reconnaissance Techniques (17%) passive vs. active footprinting, Nmap scan flags, and the enumeration port map (SMB, SNMP, LDAP, SMTP, DNS).
  • System Hacking & Malware (15%) the five phases, password attacks (pass-the-hash, Kerberoasting), privilege escalation, and the malware families.
  • Web Application Hacking (14%) the OWASP Top 10, SQL injection and its parameterized-query fix, XSS, CSRF, and directory traversal.
  • Mobile/IoT/OT, Wireless, Cloud & Cryptography (5-10% each) WEP/WPA2/WPA3 tiers, shared-responsibility model, and symmetric vs. asymmetric encryption, hashing, and PKI.

How to use it in your final week

  • Front-load Network & Perimeter Hacking (24%) plus Reconnaissance (17%) — together with System Hacking and Web App Hacking they make up about 70% of your score, so give the sheet's top block the most passes.
  • Drill the pairings the exam loves: each Layer-2 attack to its switch defense (ARP poisoning → Dynamic ARP Inspection, MAC flooding → port security, DHCP starvation → DHCP snooping) and each enumeration port to its protocol (161 SNMP, 389 LDAP, 445 SMB, 53 DNS).
  • Recite the five phases and the Nmap scan flags cold — Reconnaissance → Scanning → Gaining Access → Maintaining Access → Clearing Tracks, and -sS half-open vs -sT connect vs -sU UDP.
  • Read the sheet the morning of the exam, then pair each pass with a short timed practice set (roughly 1.9 minutes per question) so your four-hour pacing feels routine.

The cheat sheet is your review layer — your CEH practice test drives the exam-readiness ring at the top of this page. Download it, review, then take a full practice exam (or drill with the study guide and flashcards) to see where you stand.

CEH cheat sheet FAQ

Yes — the CEH cheat sheet downloads as a PDF with no sign-up and no account. It sits alongside Career Employer's free CEH practice test, study guide, and flashcards, so your whole prep stack costs nothing.

References

  1. 1.EC-Council. “Certified Ethical Hacker (CEH) — Program Overview.” eccouncil.org.
  2. 2.EC-Council. “CEH Exam Blueprint v5.0.” cert.eccouncil.org.
  3. 3.The MITRE Corporation. “MITRE ATT&CK — Enterprise Matrix.” attack.mitre.org.
  4. 4.OWASP Foundation. “OWASP Top 10 Web Application Security Risks.” owasp.org.
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.