CEH v13 Study Plan: A 10-Week Schedule Across All 20 Modules
A module-by-module CEH v13 study plan covering the exam format, the tools you must know by name, lab practice, the optional Practical exam, and how to handle the tool-trivia question style.
Know What You Are Preparing For
The CEH knowledge exam is 125 multiple-choice questions in four hours, with a cut score that varies by form, typically between 60 and 85 percent. There is also an optional CEH Practical, a six-hour hands-on assessment of 20 challenges; passing both earns CEH Master.
The most important thing to understand about the CEH: it rewards breadth and tool recognition, not depth. You will be asked which tool performs a given function, what a specific flag does, and which phase of an engagement an activity belongs to. This shapes how you should study. Going deep on one exploitation technique is less useful than knowing all twenty modules at a working level.
Time commitment: 10 weeks at 10 to 12 hours per week suits someone with basic networking and Linux familiarity. Add three to four weeks if you are new to command-line Linux.
Weeks 1 to 2: Foundations and Reconnaissance
Module 1, Introduction to Ethical Hacking. The five phases (reconnaissance, scanning, gaining access, maintaining access, covering tracks), the CIA triad, the cyber kill chain, MITRE ATT&CK, threat categories, and the legal and engagement concepts: scope, rules of engagement, and authorization. Exam questions frequently ask which phase an activity belongs to, so be exact.
Module 2, Footprinting and Reconnaissance. Passive versus active. WHOIS, DNS interrogation, Google dorking operators, Shodan, theHarvester, Recon-ng, Maltego, and email and social media gathering. Learn the dork operators (`site:`, `filetype:`, `inurl:`, `intitle:`, `cache:`) because they appear verbatim.
Module 3, Scanning Networks. Nmap in depth: this is the highest-yield tool on the exam. Know `-sS`, `-sT`, `-sU`, `-sN`, `-sF`, `-sX`, `-sA`, `-sV`, `-O`, `-A`, `-Pn`, `-T0` through `-T5`, and what each scan type returns for open, closed, and filtered ports. Also hping3, and the TCP three-way handshake and flag behaviour.
Module 4, Enumeration. NetBIOS, SNMP (and the default community strings), LDAP, NTP, SMTP, DNS zone transfers, and SMB enumeration. Tools: enum4linux, snmp-check, ldapsearch, `nmap` NSE scripts.
Practice: build a lab with Kali plus Metasploitable 2 and a Windows VM. Run every nmap scan type against it and compare the output. Log what you see.
Weeks 3 to 4: Vulnerabilities, System Hacking and Malware
Module 5, Vulnerability Analysis. Assessment types and lifecycle, CVSS scoring components, CVE and CWE, and scanners: Nessus, OpenVAS, Qualys, Nikto. Know the difference between a vulnerability scan and a penetration test, and what a credentialed scan adds.
Module 6, System Hacking. Password attacks (dictionary, brute force, rule-based, rainbow tables, and why salting defeats them), Windows authentication and LM versus NTLM versus Kerberos, pass-the-hash, privilege escalation, Metasploit and Meterpreter basics, keyloggers, rootkits, steganography, and clearing logs. Tools: Hashcat, John the Ripper, Mimikatz, Responder.
Module 7, Malware Threats. Virus, worm, trojan, ransomware, fileless malware, APT structure, and static versus dynamic analysis. Know the analysis tool names.
Practice: capture and crack hashes in your lab. Run a Meterpreter session end to end and enumerate the host from it.
Weeks 5 to 6: Traffic, Social Engineering and Denial of Service
Module 8, Sniffing. ARP poisoning, MAC flooding, DHCP starvation, port mirroring, and defences (DAI, port security). Wireshark filters matter: practise `http`, `tcp.port==80`, `ip.addr==`, and `tcp.flags.syn==1`. Tools: Wireshark, tcpdump, Ettercap, Bettercap, macof.
Module 9, Social Engineering. Phishing, vishing, pretexting, tailgating, dumpster diving, shoulder surfing, insider threats, and the Social Engineering Toolkit. Learn the terminology distinctions precisely.
Module 10, Denial of Service. Volumetric, protocol and application layer attacks, SYN flood, Slowloris, amplification and reflection (DNS, NTP, memcached), botnets, and mitigation (rate limiting, blackholing, sinkholing, scrubbing).
Module 11, Session Hijacking. Session fixation, session prediction, cross-site request forgery, on-path attacks, TCP sequence prediction, and the defences (secure and HttpOnly cookies, token regeneration).
Module 12, Evading IDS, Firewalls and Honeypots. Signature versus anomaly detection, fragmentation, encoding, tunnelling, decoy scanning, Snort rule anatomy, and honeypot categories.
Weeks 7 to 8: Web, Wireless and Mobile
Module 13, Hacking Web Servers. Server misconfiguration, directory traversal, webserver footprinting, and patch management. Tools: Nikto, dirb, gobuster.
Module 14, Hacking Web Applications. Map this onto the OWASP Top 10. Injection, broken authentication, XSS (reflected, stored, DOM), insecure deserialization, SSRF, file inclusion, and API weaknesses. Tools: Burp Suite, OWASP ZAP, sqlmap, wpscan.
Module 15, SQL Injection. In-band (union and error based), inferential (boolean and time based blind), and out-of-band. Know sqlmap's common flags, and the defences: parameterized queries first, input validation and least privilege second.
Module 16, Hacking Wireless Networks. WEP, WPA, WPA2, WPA3 and their weaknesses, the four-way handshake, evil twin, deauthentication, KRACK, and the Aircrack-ng suite workflow.
Module 17, Hacking Mobile Platforms. Android and iOS architecture, rooting and jailbreaking, the OWASP Mobile Top 10, mobile device management, and app repackaging.
Practice: work through a deliberately vulnerable web app (DVWA, Juice Shop, or WebGoat) and exploit each OWASP category by hand before using automated tools.
Week 9: IoT, OT, Cloud and Cryptography
Module 18, IoT and OT Hacking. IoT architecture and protocols (MQTT, CoAP, Zigbee, BLE), the OWASP IoT Top 10, and on the OT side: ICS and SCADA components, the Purdue model, Modbus and DNP3 weaknesses, and why availability and safety outrank confidentiality in industrial environments.
Module 19, Cloud Computing. Service and deployment models, the shared responsibility model, container and Kubernetes concerns, serverless, misconfigured storage buckets, metadata service abuse, and cloud-specific attack tooling.
Module 20, Cryptography. Symmetric and asymmetric algorithms by name (AES, DES, 3DES, RC4, Blowfish, RSA, ECC, Diffie-Hellman), hashing (MD5, SHA family), HMAC, PKI and certificate structure, disk and email encryption, and attacks (birthday, collision, downgrade). You need names, key sizes, and use cases more than internals.
Week 10: Consolidation
Days 1 to 2. Build a tool-to-function table covering every tool named in all 20 modules. This single artifact answers a large share of exam questions. Add the port list and the nmap flag list.
Day 3. Full-length timed practice exam. Score by module.
Day 4. Review misses only. Rebuild the weakest two modules.
Day 5. Second full-length timed exam. Target 85 percent, which gives comfortable margin over any form's cut score.
Days 6 to 7. Light review. Sleep. Do not cram new material.
If You Are Also Taking CEH Practical
Add three to four weeks of pure lab time after the knowledge exam. The Practical rewards speed and fluency: you need to enumerate, exploit, and extract answers under time pressure without looking up syntax. Repetition against Metasploitable, DVWA, and a small Active Directory lab is the preparation that works.
The Trap to Avoid
CEH punishes candidates who study only concepts and skip tool names, and equally punishes those who go deep on two modules and skim eighteen. Keep your coverage even, and treat the tool-to-function table as a graded deliverable.
Drill the Question Style
Because so many CEH items are recognition questions, high-volume practice with explanations is unusually effective here. CyberCertPrep covers all 20 CEH v13 modules with exam-style questions, tool-focused items, and per-module analytics, so you can find the modules where your recall is thin while there is still time to fix them.
Sources & References
Daniel Agrici
CEH, Security+, PenTest+
Daniel is the founder of CyberCertPrep. With a background in penetration testing and security consulting, he has passed 8 cybersecurity certifications and writes about exam strategies and career development.
Ready to start practicing?
72+ certifications. 126,000+ questions. 20 free per cert.