Skip to content
ScopefileGet the app

Field manual9 domains312-50

CEH study guide: 20 modules, 9 domains, one order to study them

This CEH study guide maps the 20 modules of the v13 course onto the nine domains of EC-Council's blueprint v5.0, shows what each domain is worth, and gives you one order to work through them: the biggest domain first, the three 5% domains last.

Exam
312-50
Domains
9
Modules
20
Technique files
15

Blueprint v5.0 shares by domain

Shares from blueprint v5.0 (effective April 2024), the blueprint EC-Council still links for the current exam. Read the bars before any module: they decide where your weeks go.

Domain weights and module question counts from EC-Council's CEH Exam Blueprint v5.0 (effective April 2024; checked Oct 11, 2026). Weights sum to 101% because of rounding.

How 20 modules fit into nine domains

EC-Council's CEH v13 course runs to 20 modules, and blueprint v5.0 groups them into nine domains, from Information Security and Ethical Hacking Overview (Module 1) to Cryptography (Module 20). Per that blueprint, each module accounts for six or seven questions of the 125-question exam. Modules are near-equal; domains range from 5% to 24%.

That changes what a heavy domain is. Network and Perimeter Hacking tops the chart because it holds five modules. Four domains are a single module each: the overview, wireless, cloud and cryptography. Module files on this site follow that grain, and each one's kicker names its domain. Module 12 has no file of its own; its defensive side is covered by the IDS vs IPS vs firewall technique file.

On versions: the course is CEH v13, while the blueprint carries its own number, v5.0, and is dated April 2024. EC-Council still links it from the CEH certification page (checked Oct 11, 2026). The CEH v13 page untangles the numbering.

All 20 modules and what each one tests

Modules in course order, with their blueprint domain
ModuleDomain and shareWhat the module covers
01 Introduction to ethical hackingOverview, 6%Hacker classes, the five phases, Cyber Kill Chain vs MITRE ATT&CK, control types, and which law or standard (PCI DSS, HIPAA, SOX, GDPR) applies to which data
02 Footprinting and reconnaissanceRecon, 17%Passive vs active collection, search-engine, Whois and DNS sources, OSINT, and how an organization shrinks what it exposes
03 Scanning networksRecon, 17%Host discovery, port-scan types and what each response means, OS fingerprinting, and what filtering does to results
04 EnumerationRecon, 17%Which service (NetBIOS, SNMP, LDAP, NTP, NFS, SMTP, DNS) gives away what, and the countermeasure for each
05 Vulnerability analysisSystem hacking, 15%Assessment types, CVSS scoring, CVE and NVD, and the vulnerability-management life cycle
06 System hackingSystem hacking, 15%Password attack categories, privilege escalation, persistence, steganography, and how covering tracks is detected
07 Malware threatsSystem hacking, 15%Virus vs worm vs trojan, ransomware, fileless malware, the APT life cycle, static vs dynamic analysis
08 SniffingNetwork and perimeter, 24%MAC, DHCP and ARP attacks, DNS poisoning, and the switch features that stop each one
09 Social engineeringNetwork and perimeter, 24%Phishing variants by channel, pretexting, insider threats, impersonation, and people-and-process defenses
10 Denial of serviceNetwork and perimeter, 24%Volumetric vs protocol vs application-layer attacks, botnets, and the mitigation each class needs
11 Session hijackingNetwork and perimeter, 24%Application-level vs network-level hijacking, how session IDs leak, and the defenses that close each path
12 Evading IDS, firewalls and honeypotsNetwork and perimeter, 24%IDS vs IPS vs firewall types, signature vs anomaly detection, honeypots, and the countermeasures that keep detection working. No module file; start from IDS vs IPS vs firewall.
13 Hacking web serversWeb apps, 14%Server-level attacks such as cache poisoning and DNS hijacking, misconfiguration, and patch management
14 Hacking web applicationsWeb apps, 14%OWASP Top 10 (the course names the 2021 edition; 2025 is current), XSS, CSRF, SSRF, access control, APIs and webhooks
15 SQL injectionWeb apps, 14%In-band, blind and out-of-band types, the signs in logs, and why parameterized queries are the fix
16 Hacking wireless networksWireless, 5%WEP through WPA3, rogue access points, Bluetooth attack terms, and wireless defenses
17 Hacking mobile platformsMobile, IoT, OT, 10%Rooting vs jailbreaking, OWASP Mobile Top 10 (2024), SMiShing, and mobile device management
18 IoT and OT hackingMobile, IoT, OT, 10%IoT architecture and OWASP IoT Top 10, ICS and SCADA parts, and why availability and safety lead in OT
19 Cloud computingCloud, 5%IaaS, PaaS and SaaS with the shared-responsibility split, containers, serverless, and cloud threats
20 CryptographyCrypto, 5%Symmetric vs asymmetric vs hashing, PKI, email and disk encryption, and cryptanalysis attack types

Module names follow EC-Council's CEH v13 course outline; domains and shares follow blueprint v5.0. The OWASP edition is on owasp.org. All checked Oct 11, 2026.

One order to study them

  1. Skim the overview first, in one evening

    Module 1 is only 6%, but hacker classes, the five phases and the control types come back in every later module. Read the introduction to ethical hacking once now; the laws and frameworks can wait for the last week.
  2. Network and perimeter, 24%

    Five modules, the biggest block on the exam, from sniffing to session hijacking plus Module 12 on IDS, firewalls and honeypots. If ports and TCP flags are new to you, read scanning networks first; this domain assumes them.
  3. Reconnaissance, 17%

    Footprinting, scanning and enumeration. The common thread is which activity touches the target and which service exposes what, so the enumeration file pays back its time.
  4. System hacking, 15%

    Vulnerability analysis, system hacking and malware. Learn the categories and the defense matched to each; the long tool lists in course material are the part to skim.
  5. Web applications, 14%

    Web servers, web apps and SQL injection. Name the OWASP edition every time you study a list: the course still cites 2021.
  6. Mobile, IoT and OT, 10%

    Two modules. The OT half rests on one idea: in a plant, availability and safety come before confidentiality.
  7. The 5% trio last: wireless, cloud, cryptography

    Recall-heavy and compact. Cram them in the final weeks next to a mock, then let them go after the exam. The CEH study plan turns this order into a 4-, 8- or 12-week calendar from your exam date.

Every domain, topic and technique file

Module files plus the technique files that split confusable pairs, grouped by domain.

Exam facts

Format, cut score, cost and retakes, each with its source and the date it was checked.

Getting certified

Eligibility routes, renewal, pay data and how CEH sits among other certifications.

Compare certs and prep tools

CEH set against other certifications, plus CEH prep resources compared on what can be checked: edition, version and price.

Questions about the syllabus

Is this the CEH v13 syllabus?

Yes. The module list is the CEH v13 course outline on EC-Council's CEH page, and the domains and weights come from blueprint v5.0, which EC-Council links as the CEH blueprint. Both were checked on Oct 11, 2026.

How long is EC-Council's own CEH course?

EC-Council structures its instructor-led CEH training as a five-day boot camp, with the exam typically at the end of day five (EC-Council, checked Oct 11, 2026). That is a course format. Self-study time depends on how much networking and security groundwork you bring.

Where do I practice once a module is done?

On the CEH practice test, filtered to that module's domain, or in the drill set at the bottom of each module file. Every option there carries a note.

Sources