Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-COUNCIL

EC-Council Ethical Hacking Essentials

EHEEthical Hacking Essentials

The EC-Council Ethical Hacking Essentials (EHE) certification is your entry point into the world of ethical hacking and penetration testing. This beginner-friendly program requires no prior IT or cybersecurity experience, yet it delivers hands-on skills through 47 guided labs and real-world CTF challenges. You'll learn to think like an attacker, understand the full hacking lifecycle, and validate your abilities with a globally recognized credential that sets you on the path to advanced certifications like CEH.

1527 practice questions · Updated 2026-07-30

8Domains
36Objectives
234Concepts
1527Questions

EHE Curriculum

Every domain, objective, and concept the EHE exam measures.

  1. Information Security Fundamentals
  2. Threats and Vulnerabilities
  3. Defense in Depth
  4. Security Controls
  5. Risk Management Basics
  6. Security Policies and Procedures
  7. Ethical Hacking Overview
  1. Threat definition
  2. Threat sources
  3. Threat types
  4. Vulnerability definition
  5. Vulnerability categories
  6. Relationship between threats and vulnerabilities

Cryptography concepts

7 concepts · 39 questions
  1. Cryptography Fundamentals
  2. Symmetric Encryption
  3. Asymmetric Encryption
  4. Hash Functions
  5. Digital Signatures
  6. Key Management
  7. Cryptographic Attacks
  1. Information Security Laws
  2. Regulatory Compliance
  3. Standards and Frameworks
  4. Legal and Ethical Implications

Hacking concepts and hacker classes

4 concepts · 37 questions
  1. Definition of hacking
  2. Hacker classes
  3. Hacker skill levels
  4. Ethical hacking principles
  1. Ethical hacking scope
  2. Ethical hacking methodologies
  3. Ethical hacking frameworks

  1. Malware Definition
  2. Malware Types
  3. Malware Attack Vectors
  4. Malware Lifecycle
  5. Malware Obfuscation Techniques
  6. Malware Indicators of Compromise
  1. Malware propagation vectors
  2. Malware propagation techniques
  3. Indicators of malware infection
  4. Network indicators of malware
  5. Behavioral indicators of malware

Malware countermeasures

12 concepts · 58 questions
  1. Malware countermeasures overview
  2. Antivirus and anti-malware software
  3. Host-based intrusion prevention
  4. Network-based intrusion prevention
  5. Firewalls and malware filtering
  6. Patch management and vulnerability mitigation
  7. User awareness and training
  8. Least privilege and access control
  9. Application whitelisting
  10. Email and web security gateways
  11. Endpoint detection and response (EDR)
  12. Incident response and recovery planning

Password cracking techniques

10 concepts · 42 questions
  1. Password cracking fundamentals
  2. Password storage mechanisms
  3. Password cracking techniques overview
  4. Brute force attacks
  5. Dictionary attacks
  6. Hybrid attacks
  7. Rainbow table attacks
  8. Rule-based attacks
  9. Password cracking tools
  10. Countermeasures against password cracking

Password cracking countermeasures

7 concepts · 44 questions
  1. Password Cracking Countermeasures Overview
  2. Strong Password Policies
  3. Password Storage Best Practices
  4. Multi-Factor Authentication (MFA)
  5. Account Lockout and Rate Limiting
  6. Password Managers and User Education
  7. Monitoring and Auditing

  1. Reconnaissance Fundamentals
  2. Footprinting Concepts
  3. OSINT Sources and Tools
  4. Passive Reconnaissance Techniques
  5. Active Reconnaissance Techniques
  6. Information Collection Methods
  7. Footprinting Steps
  8. OSINT Analysis and Application

Scanning and enumeration methodologies

6 concepts · 38 questions
  1. Scanning Fundamentals
  2. Scanning Techniques
  3. Scanning Tools
  4. Enumeration Fundamentals
  5. Enumeration Techniques
  6. Enumeration Tools

Vulnerability scanning and assessment

6 concepts · 45 questions
  1. Vulnerability Scanning Fundamentals
  2. Vulnerability Assessment Process
  3. Types of Vulnerability Scans
  4. Vulnerability Scanning Tools
  5. Interpreting Scan Results
  6. Remediation and Reporting
  1. Gaining Access
  2. Maintaining Access
  3. Covering Tracks

Countermeasures across hacking phases

6 concepts · 39 questions
  1. Identify countermeasures for each hacking phase
  2. Apply countermeasures to reconnaissance
  3. Apply countermeasures to scanning and enumeration
  4. Apply countermeasures to gaining access
  5. Apply countermeasures to maintaining access
  6. Apply countermeasures to covering tracks

  1. Definition of social engineering
  2. Social engineering attack cycle
  3. Human psychology exploitation
  4. Social engineering techniques
  5. Impact of social engineering

Insider threats and identity theft

7 concepts · 39 questions
  1. Insider threat definition
  2. Insider threat indicators
  3. Insider threat mitigation strategies
  4. Identity theft definition
  5. Identity theft impact
  6. Identity theft prevention
  7. Identity theft response

Social engineering countermeasures

8 concepts · 55 questions
  1. Social engineering countermeasures overview
  2. Security policies and procedures
  3. User awareness and training
  4. Technical controls
  5. Physical security measures
  6. Incident reporting and response
  7. Monitoring and auditing
  8. Verification and authentication procedures

Packet sniffing concepts

5 concepts · 40 questions
  1. Definition of packet sniffing
  2. Types of packet sniffing
  3. Sniffing techniques
  4. Sniffing tools
  5. Countermeasures against sniffing

DoS and DDoS attack methods

17 concepts · 63 questions
  1. DoS attack definition
  2. DDoS attack definition
  3. Volumetric attacks
  4. Protocol attacks
  5. Application-layer attacks
  6. SYN flood attack
  7. UDP flood attack
  8. ICMP flood attack
  9. Ping of Death
  10. Smurf attack
  11. HTTP flood attack
  12. Slowloris attack
  13. DNS amplification attack
  14. NTP amplification attack
  15. Botnet role in DDoS
  16. DDoS mitigation techniques
  17. DoS/DDoS countermeasures

Session hijacking techniques

8 concepts · 34 questions
  1. Session hijacking definition
  2. Session hijacking process
  3. Session ID prediction
  4. Session fixation
  5. Cross-site scripting (XSS) for session hijacking
  6. Session side-jacking
  7. Man-in-the-browser attack
  8. Countermeasures against session hijacking
  1. Network attack detection techniques
  2. Network attack countermeasures
  3. Monitoring and analysis of network traffic
  4. Incident response and remediation

Web server attacks

4 concepts · 44 questions
  1. Web server attack surface
  2. Common web server vulnerabilities
  3. Web server attack techniques
  4. Web server attack countermeasures
  1. Web Application Attack Surface
  2. Injection Attacks
  3. Cross-Site Scripting (XSS)
  4. Cross-Site Request Forgery (CSRF)
  5. Session Hijacking and Fixation
  6. Authentication and Authorization Flaws
  7. File Upload Vulnerabilities
  8. XML External Entity (XXE) Attacks
  9. Server-Side Request Forgery (SSRF)
  10. Web Application Exploitation Tools
  11. Countermeasures and Secure Coding Practices
  1. SQL Injection Fundamentals
  2. Types of SQL Injection
  3. SQL Injection Attack Techniques
  4. Impact of SQL Injection
  5. SQL Injection Detection
  6. SQL Injection Prevention
  7. SQL Injection Mitigation in Web Applications

  1. Wireless Network Fundamentals
  2. Wireless Encryption and Authentication
  3. Wireless Attack Types
  4. Wireless Attack Tools
  5. Wireless Security Countermeasures
  1. Bluetooth Attack Vectors
  2. Bluetooth Security Weaknesses
  3. Bluetooth Attack Countermeasures
  4. Wireless Network Threats
  5. Wireless Encryption Protocols
  6. Wireless Security Best Practices
  1. Mobile attack vectors
  2. Mobile vulnerabilities
  3. Mobile malware types
  4. Mobile device management risks
  5. Mobile app security risks
  6. Mobile network threats
  7. Mobile OS security features
  8. Mobile device physical security
  1. MDM Fundamentals
  2. MDM Features and Capabilities
  3. MDM Deployment Models
  4. BYOD Policies
  5. BYOD Security Risks
  6. Containerization and Separation
  7. Mobile Threat Defense (MTD)
  8. Compliance and Legal Considerations

IoT and OT attacks and countermeasures

8 concepts · 54 questions
  1. IoT Attack Surface
  2. Common IoT Vulnerabilities
  3. IoT Attack Types
  4. IoT Security Countermeasures
  5. OT Attack Surface
  6. Common OT Vulnerabilities
  7. OT Attack Types
  8. OT Security Countermeasures

  1. Cloud Computing Fundamentals
  2. Cloud Service Models
  3. Cloud Deployment Models
  4. Containerization Concepts
  5. Container Security
  6. Container Orchestration

Cloud computing threats and attacks

4 concepts · 39 questions
  1. Cloud Threat Landscape
  2. Cloud Attack Vectors
  3. Cloud Security Risks
  4. Mitigation Strategies

Cloud attack countermeasures

8 concepts · 42 questions
  1. Cloud Attack Countermeasures Overview
  2. Identity and Access Management (IAM) Countermeasures
  3. Data Protection Countermeasures
  4. Network Security Countermeasures
  5. Application Security Countermeasures
  6. Monitoring and Logging Countermeasures
  7. Incident Response and Recovery Countermeasures
  8. Compliance and Governance Countermeasures
  1. Types of penetration testing
  2. Phases of penetration testing
  3. Approaches to penetration testing
  1. Penetration Testing Guidelines
  2. Penetration Testing Recommendations
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for EHE, so none is invented.