Skip to content
CompTIA Security+ and PenTest+

Security+ vs CEH: which is better for a beginner?

Security+ vs CEH for beginners: what each exam tests, eligibility, format and which job it suits, with a fair verdict and where CCNA fits instead.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 7 min read

For most complete beginners, CompTIA Security+ is the better first certification: it has no eligibility hurdle, covers the broad foundations every security job uses, and maps directly to entry-level defensive roles. CEH (Certified Ethical Hacker, from EC-Council) makes more sense as a second step for someone who already has some IT or security experience and knows they want offensive work, or whose target employers specifically ask for it.

That’s the short answer. The rest of this post explains why, fairly, because both certifications have real strengths and both have critics.

Security+ and CEH at a glance

CompTIA Security+ EC-Council CEH
Current version SY0-701 (a new version is expected; see below) CEH, currently branded “CEH AI” (v13)
Focus Broad security foundations, mostly defensive Offensive techniques and attacker methodology
Eligibility None required (CompTIA recommends prior networking knowledge) Official EC-Council training, or two years' information security experience via an eligibility application
Core exam Up to 90 questions, 90 minutes, multiple choice and performance-based 125 multiple-choice questions, 4 hours
Practical exam Performance-based questions within the main exam Separate, optional CEH Practical: 6 hours, 20 challenges in a cyber range
Pass mark 750 on a 100–900 scale Varies by question bank (EC-Council quotes 60% to 85%)
Typical first job it supports SOC analyst, security administrator, IT roles with security duties Junior penetration tester, vulnerability assessment, red-team-adjacent roles

Sources: CompTIA Security+ and EC-Council CEH. Prices change and vary by country, so check each official page for current fees rather than trusting a figure in a blog post.

What does Security+ actually test?

Security+ SY0-701 is built around five domains:

Domain Weighting
General Security Concepts 12%
Threats, Vulnerabilities & Mitigations 22%
Security Architecture 18%
Security Operations 28%
Security Program Management & Oversight 20%

A timing note: CompTIA says the next version of Security+ is expected to launch on or around 17 November 2026. SY0-701 is still available, and CompTIA hasn’t confirmed its retirement date, so check CompTIA’s Security+ page for the current exam version before you book.

Notice that Security Operations is the biggest slice. Security+ wants you to understand how an organisation runs security day to day: hardening, identity and access management, vulnerability management, monitoring, incident response, and the governance that sits above it. Attacks appear, but mainly so you can recognise and mitigate them.

The exam includes performance-based questions, small simulations where you configure or analyse something rather than pick from four options. That makes it more than a vocabulary test, though it’s still not a full hands-on lab exam.

Our Security+ SY0-701 study guide breaks each domain into a study plan.

What does CEH actually test?

CEH is organised around the attacker’s process: reconnaissance and footprinting, scanning and enumeration, vulnerability analysis, system hacking, malware, sniffing, social engineering, denial of service, session hijacking, web application and wireless attacks, mobile, IoT and cloud, and cryptography. EC-Council describes the current programme as 20 modules, and the latest version adds AI-assisted techniques throughout.

There are two exams:

  • The CEH knowledge exam (125 multiple-choice questions, 4 hours) earns the CEH certification.
  • The CEH Practical (6 hours, 20 challenges in EC-Council’s cyber range) is optional. Pass both and you hold CEH Master.

This distinction matters in any fair comparison. The most common criticism of CEH is that the knowledge exam is multiple choice, so it proves you know about hacking tools rather than that you can use them. That’s a fair point about the knowledge exam alone. The Practical exists precisely to address it, and if you go the CEH route, the Practical is the half that says the most about your skills.

Can a beginner even sit CEH?

This is where the two differ most for a newcomer. EC-Council’s eligibility process gives two routes:

  1. Complete official EC-Council training (through an accredited training centre, EC-Council’s own online learning, or an approved academic institution). You’re then eligible to attempt the exam.
  2. Apply with at least two years' information security work experience. EC-Council verifies this with the referees you list, and there is a non-refundable application fee.

For a true beginner with no security experience, that usually means route 1: official training. Security+ has no equivalent requirement. You can study however you like and book the exam.

Neither route is a problem in itself, but it changes the total cost and timeline, so factor it in.

Which one do employers ask for?

The honest answer: it depends on your market and the role, and the only reliable way to know is to look. Before you spend money on either, do this:

  1. Search a job board for 20 roles you would realistically apply for in the next year.
  2. Note every certification mentioned, and whether it’s “required” or “desirable”.
  3. Count.

As a rough pattern, Security+ tends to be listed for SOC, security administration and general security roles, while CEH appears more in penetration testing and vulnerability assessment adverts, and sometimes in government or contractor work. Treat that as a starting hypothesis: your 20 adverts beat it, and they beat any statistic you’ll find online.

One more point: certifications get you past filters; they don’t do the interview for you. Hiring managers for testing roles will ask you to explain an attack. Hiring managers for SOC roles will hand you a log and ask what happened.

Security+ vs CEH: which job are you aiming at?

Use this as a decision table.

If you… Start with
Have no IT background and want your first security role Security+ (consider Network+ first, see below)
Want a SOC analyst or blue-team role Security+
Work in IT already and want to move into security generally Security+
Have a couple of years in security and want to move into offensive work CEH (aim for the Practical too) or CompTIA PenTest+
See CEH named as required in the specific adverts you’re targeting CEH, ideally after Security+
Want a GRC or compliance role Security+ plus framework study (ISO 27001, NIST CSF)

If offensive security is your goal, compare CEH with CompTIA PenTest+ (PT0-003) as well. Both target penetration testing; they differ in style, eligibility and cost. Our guide on how to become a penetration tester from scratch puts certifications in the context of the practical skills you’ll need regardless.

The case for Security+

  • No barrier to entry. You can start studying today with free and low-cost resources.
  • Broad foundations. Networking concepts, identity, cryptography, governance and operations are used in every security role, including penetration testing.
  • Vendor-neutral and widely recognised. It’s often the baseline certification in job adverts for entry-level roles.
  • A sensible base for later certifications, including CySA+ for analysts and PenTest+ for testers.

The fair criticism: Security+ is wide rather than deep. It won’t teach you to run a penetration test or investigate a complex intrusion. It tells an employer you have the foundations to be trained.

The case for CEH

  • Offensive vocabulary and methodology. It gives structure to how attacks unfold, which helps defenders too.
  • Recognition in some sectors. Some employers and contracts name it specifically.
  • The Practical adds real evidence of hands-on ability when you take it.
  • Structured training included, if you take the official training route, which some learners prefer to self-study.

The fair criticism: the knowledge exam on its own is multiple choice, the eligibility rules push beginners towards paid official training, and many practitioners prefer exams that are entirely hands-on. Taking the Practical answers most of this.

What about Security+ vs CCNA?

People often weigh these against each other too, but they cover different ground. Cisco’s CCNA (exam 200-301) is a networking certification: routing, switching, IP addressing, wireless and network automation, with a Cisco flavour. Security+ is a security certification that assumes some networking knowledge.

If your weak spot is networking, a networking certification before Security+ is sensible. Many people choose CompTIA Network+ (N10-009) instead of CCNA because it’s vendor-neutral; CCNA is the stronger choice if you’re aiming at network engineering or employers that run Cisco kit. See our comparison of Security+ vs Network+ for that decision.

A sensible order for most beginners

Illustrative example, not a real student: someone with no IT background who wants to end up in penetration testing.

  1. Months 1–3: networking and Linux fundamentals; optional Network+.
  2. Months 4–6: Security+ SY0-701, plus a home lab where they practise what each domain describes.
  3. Months 7–12: an entry-level SOC or IT role if possible, while practising web and network attacks in their own lab.
  4. Year two: an offensive certification (CEH with the Practical, or PenTest+) once they understand what they’re attacking.

Only test systems you own or have written permission to test, including while studying for either exam.

Questions

Is CEH harder than Security+?

They're hard in different ways. CEH covers more attack techniques in more depth, and the Practical is a long hands-on exam. Security+ covers broader ground, including governance and operations, and includes performance-based questions. Most beginners find Security+ the more natural first step.

Can I take CEH without experience?

Yes, through EC-Council's official training route. Without official training, you need two years' information security experience and an approved eligibility application.

Do I need Security+ before CEH?

It isn't required, but the foundations it covers make CEH material much easier to understand.

Will either certification get me a job?

No certification guarantees a job. Each one improves your chances of passing CV filters; your projects, lab work and interview performance do the rest.