CEH v13 Certified Ethical Hacker: Full Preparation Guide
EC-Council's flagship offensive security cert, now with AI-augmented hacking labs. 20 modules, 60-day plan, and the honest verdict on whether CEH is still worth it vs OSCP.
CEH v13 dropped in late 2024 with a major update: AI-augmented labs, more emphasis on cloud attacks, and a full IoT/OT module. It's still EC-Council's most recognized cert and still the one HR filters use for penetration tester roles in Bangladesh, UAE, and KSA banks. It's not as respected as OSCP among practitioners - but it's a lot easier to pass and often opens doors first.
§CEH v13 vs previous versions
- Added: AI hacking module, extended cloud attack coverage, IoT/OT chapter
- Removed: some legacy Windows XP-era exploits, older wireless tools
- 20 modules total, 125 questions, 4 hours, 70% pass mark
- New: optional CEH Master which adds a 6-hour practical exam
§The 20 modules at a glance
| Module | Focus |
|---|---|
| 1. Intro to Ethical Hacking | Threat landscape, methodology |
| 2. Footprinting & Recon | OSINT, WHOIS, DNS enum |
| 3. Scanning Networks | Nmap, service detection |
| 4. Enumeration | SMB, LDAP, SNMP enum |
| 5. Vulnerability Analysis | CVSS, Nessus, OpenVAS |
| 6. System Hacking | Password attacks, privilege escalation |
| 7. Malware Threats | Trojans, viruses, worms |
| 8. Sniffing | ARP poisoning, MITM |
| 9. Social Engineering | Phishing, pretexting |
| 10. Denial-of-Service | DoS/DDoS techniques |
| 11. Session Hijacking | Token attacks, replay |
| 12. Evading IDS/Firewalls | AV evasion, tunneling |
| 13. Web Server Hacking | Server-level attacks |
| 14. Web App Hacking | OWASP Top 10 |
| 15. SQL Injection | Manual + tools |
| 16. Wireless Hacking | WPA2/WPA3, evil twin |
| 17. Mobile Hacking | Android, iOS |
| 18. IoT & OT Hacking | New in v13 |
| 19. Cloud Computing | AWS/Azure/GCP attacks |
| 20. Cryptography | Attacks, PKI, ransomware |
§The 60-day plan
- Weeks 1–2: Modules 1–5 - recon, scanning, enumeration foundations. Nmap and Nessus daily.
- Weeks 3–4: Modules 6–10 - system hacking, malware, DoS. Set up a home lab with Kali + intentionally vulnerable VMs.
- Weeks 5–6: Modules 11–15 - web attacks, SQL injection. Do 20 DVWA/Juice Shop scenarios.
- Weeks 7–8: Modules 16–20 - wireless, mobile, IoT, cloud, cryptography. Broad review + 4 full practice exams.
§Home lab that beats iLabs
EC-Council's iLabs are usable but slow and cost extra. A better free lab:
- VirtualBox or VMware Workstation Player (free for personal use)
- Kali Linux VM (attacker)
- Metasploitable 2 and 3 (Linux vulnerable targets)
- OWASP Broken Web Apps VM (web target)
- DVWA + Juice Shop containers
- Wazuh or Security Onion for the blue-team view - bonus
§CEH vs OSCP - the honest comparison
| Aspect | CEH v13 | OSCP |
|---|---|---|
| Format | MCQ + optional practical | 24hr practical + report |
| Difficulty | Moderate | Hard |
| Time to prep | 2–3 months | 6–9 months |
| Cost | USD 950–1200 | USD 1699+ |
| HR recognition | High | Medium (but growing) |
| Practitioner respect | Medium | Very high |
| Best for | First offensive cert, HR filters | Real pentest career |
"CEH is the door-opener; OSCP is the door-kicker. If you're building a pentest career, take CEH first for the résumé line, then commit to OSCP for the skills. Skip neither."
§Salary landscape
| Location | CEH + 1 yr | CEH + OSCP + 3 yrs |
|---|---|---|
| Dhaka, Bangladesh | BDT 70k–120k/mo | BDT 180k–350k/mo |
| Dubai, UAE | AED 14k–20k/mo | AED 30k–48k/mo |
| Riyadh, KSA | SAR 15k–22k/mo | SAR 32k–52k/mo |
| Remote pentest gigs | USD 3k–5k/mo | USD 8k–14k/mo |
§Resources
- EC-Council iLabs - official, expensive, sometimes bundled
- TryHackMe 'Offensive Pentesting' path - best cheap alternative
- HackTheBox Academy CPTS content - closer to real exam feel
- 'CEH v13 Cheat Sheet' community docs - google for a recent one
- Boson practice tests for CEH - closest to real exam questions
§FAQ
How much does CEH cost?
USD 1199 with training or USD 950 exam-only if you meet the 2-year experience waiver. iLabs subscription is extra.
Do I need to take EC-Council's training?
No, but you either take the training OR prove 2 years of infosec experience with a waiver application (USD 100 fee).
Is CEH worth it if I already have OSCP?
Only if a job posting specifically requires it. Otherwise skip - OSCP outweighs CEH among practitioners.
How long is CEH valid?
3 years. Renew via 120 EC-Council CPE credits.
Certified practitioner and lead curriculum architect at KNScert. Writes about cert strategy, exam tactics, and the real-world skills employers actually pay for.
Stop reading. Start passing.
Verified Q&A, hands-on simulators, and expert workbooks - updated monthly to match the live exam.
Discussion(0)
More from the Journal
Palo AltoPalo Alto PCNSA Study Guide 2026: Pass on Your First Attempt
An honest, lab-tested PCNSA roadmap for 2026 - exam blueprint, real prep timeline, salary impact, and the mistakes that fail most first-timers.
CompTIAIs CySA+ Worth It in 2026? Salary, Jobs & Full Breakdown
A no-fluff look at CySA+ pay bands, hiring demand, and how it stacks up against Security+ and CASP+.
DevOpsSplunk vs Datadog: Side-by-Side Comparison for 2026
Logs, metrics, pricing, certification paths - which observability stack wins for your team in 2026.
Explore certification practice material
Get verified practice questions and exam dumps with a 100% pass guarantee.
