This CEH cheat sheet distills the EC-Council Certified Ethical Hacker (v13) exam into a printable rundown of the facts examiners test most across all nine domains. It's a premium cheat sheet built by Capital Prep — the one premium prep we trust — and it's yours free. Reinforce it with the rest of your free CEH toolkit: the practice test, study guide, and flashcards.
CEH exam at a glance
- Questions: 125 multiple-choice across 9 domains
- Time: 4 hours (240 minutes)
- Passing score: Scaled cut score per exam form, typically 60%-85% correct (no fixed %)
- Exam code: 312-50 (knowledge exam); optional 6-hour, 20-challenge Practical for CEH Master
- Certifying body: EC-Council
- Cost: ≈ $1,199 voucher; self-study path adds ~$100 application fee (verify at eccouncil.org)
What’s on the CEH cheat sheet
- Network & Perimeter Hacking (24%) — sniffing and Layer-2 attacks, social engineering, DoS/DDoS, session hijacking, and IDS/firewall/honeypot evasion — the largest domain.
- Reconnaissance Techniques (17%) — passive vs. active footprinting, Nmap scan flags, and the enumeration port map (SMB, SNMP, LDAP, SMTP, DNS).
- System Hacking & Malware (15%) — the five phases, password attacks (pass-the-hash, Kerberoasting), privilege escalation, and the malware families.
- Web Application Hacking (14%) — the OWASP Top 10, SQL injection and its parameterized-query fix, XSS, CSRF, and directory traversal.
- Mobile/IoT/OT, Wireless, Cloud & Cryptography (5-10% each) — WEP/WPA2/WPA3 tiers, shared-responsibility model, and symmetric vs. asymmetric encryption, hashing, and PKI.
How to use it in your final week
- Front-load Network & Perimeter Hacking (24%) plus Reconnaissance (17%) — together with System Hacking and Web App Hacking they make up about 70% of your score, so give the sheet's top block the most passes.
- Drill the pairings the exam loves: each Layer-2 attack to its switch defense (ARP poisoning → Dynamic ARP Inspection, MAC flooding → port security, DHCP starvation → DHCP snooping) and each enumeration port to its protocol (161 SNMP, 389 LDAP, 445 SMB, 53 DNS).
- Recite the five phases and the Nmap scan flags cold — Reconnaissance → Scanning → Gaining Access → Maintaining Access → Clearing Tracks, and -sS half-open vs -sT connect vs -sU UDP.
- Read the sheet the morning of the exam, then pair each pass with a short timed practice set (roughly 1.9 minutes per question) so your four-hour pacing feels routine.
The cheat sheet is your review layer — your CEH practice test drives the exam-readiness ring at the top of this page. Download it, review, then take a full practice exam (or drill with the study guide and flashcards) to see where you stand.
CEH cheat sheet FAQ
Yes — the CEH cheat sheet downloads as a PDF with no sign-up and no account. It sits alongside Career Employer's free CEH practice test, study guide, and flashcards, so your whole prep stack costs nothing.
It condenses the high-yield facts EC-Council tests across all nine CEH v13 domains: the five hacking phases, the Nmap scan flags, enumeration ports, Layer-2 attacks and their switch defenses, the malware families, the OWASP Top 10 and SQL injection, Wi-Fi encryption tiers, cloud shared responsibility, and core cryptography. Everything is grouped by domain weight so you review the heaviest content first.
No — the sheet is a fast recall and final-week cram layer, not a replacement for reading the modules and drilling questions. The CEH spans 125 items across nine domains in four hours, so use the sheet to lock in terminology and the practice test to build readiness under the clock.
It's built from the current EC-Council CEH v13 program and Exam Blueprint v5.0, so the domains, weights, and exam code (312-50) match what you'll sit today. Prices and policies shift, so confirm the latest details at eccouncil.org before you register.
Click the download button or the preview card at the top of this page and the PDF opens instantly. Bookmark the page so it's one tap away in the days before your exam.
References
- 1.EC-Council. “Certified Ethical Hacker (CEH) — Program Overview.” eccouncil.org. ↑
- 2.EC-Council. “CEH Exam Blueprint v5.0.” cert.eccouncil.org. ↑
- 3.The MITRE Corporation. “MITRE ATT&CK — Enterprise Matrix.” attack.mitre.org. ↑
- 4.OWASP Foundation. “OWASP Top 10 Web Application Security Risks.” owasp.org. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
