Field manual9 domains312-50
CEH study guide: 20 modules, 9 domains, one order to study them
This CEH study guide maps the 20 modules of the v13 course onto the nine domains of EC-Council's blueprint v5.0, shows what each domain is worth, and gives you one order to work through them: the biggest domain first, the three 5% domains last.
- Exam
- 312-50
- Domains
- 9
- Modules
- 20
- Technique files
- 15
Blueprint v5.0 shares by domain
Shares from blueprint v5.0 (effective April 2024), the blueprint EC-Council still links for the current exam. Read the bars before any module: they decide where your weeks go.
How 20 modules fit into nine domains
EC-Council's CEH v13 course runs to 20 modules, and blueprint v5.0 groups them into nine domains, from Information Security and Ethical Hacking Overview (Module 1) to Cryptography (Module 20). Per that blueprint, each module accounts for six or seven questions of the 125-question exam. Modules are near-equal; domains range from 5% to 24%.
That changes what a heavy domain is. Network and Perimeter Hacking tops the chart because it holds five modules. Four domains are a single module each: the overview, wireless, cloud and cryptography. Module files on this site follow that grain, and each one's kicker names its domain. Module 12 has no file of its own; its defensive side is covered by the IDS vs IPS vs firewall technique file.
On versions: the course is CEH v13, while the blueprint carries its own number, v5.0, and is dated April 2024. EC-Council still links it from the CEH certification page (checked Oct 11, 2026). The CEH v13 page untangles the numbering.
All 20 modules and what each one tests
| Module | Domain and share | What the module covers |
|---|---|---|
| 01 Introduction to ethical hacking | Overview, 6% | Hacker classes, the five phases, Cyber Kill Chain vs MITRE ATT&CK, control types, and which law or standard (PCI DSS, HIPAA, SOX, GDPR) applies to which data |
| 02 Footprinting and reconnaissance | Recon, 17% | Passive vs active collection, search-engine, Whois and DNS sources, OSINT, and how an organization shrinks what it exposes |
| 03 Scanning networks | Recon, 17% | Host discovery, port-scan types and what each response means, OS fingerprinting, and what filtering does to results |
| 04 Enumeration | Recon, 17% | Which service (NetBIOS, SNMP, LDAP, NTP, NFS, SMTP, DNS) gives away what, and the countermeasure for each |
| 05 Vulnerability analysis | System hacking, 15% | Assessment types, CVSS scoring, CVE and NVD, and the vulnerability-management life cycle |
| 06 System hacking | System hacking, 15% | Password attack categories, privilege escalation, persistence, steganography, and how covering tracks is detected |
| 07 Malware threats | System hacking, 15% | Virus vs worm vs trojan, ransomware, fileless malware, the APT life cycle, static vs dynamic analysis |
| 08 Sniffing | Network and perimeter, 24% | MAC, DHCP and ARP attacks, DNS poisoning, and the switch features that stop each one |
| 09 Social engineering | Network and perimeter, 24% | Phishing variants by channel, pretexting, insider threats, impersonation, and people-and-process defenses |
| 10 Denial of service | Network and perimeter, 24% | Volumetric vs protocol vs application-layer attacks, botnets, and the mitigation each class needs |
| 11 Session hijacking | Network and perimeter, 24% | Application-level vs network-level hijacking, how session IDs leak, and the defenses that close each path |
| 12 Evading IDS, firewalls and honeypots | Network and perimeter, 24% | IDS vs IPS vs firewall types, signature vs anomaly detection, honeypots, and the countermeasures that keep detection working. No module file; start from IDS vs IPS vs firewall. |
| 13 Hacking web servers | Web apps, 14% | Server-level attacks such as cache poisoning and DNS hijacking, misconfiguration, and patch management |
| 14 Hacking web applications | Web apps, 14% | OWASP Top 10 (the course names the 2021 edition; 2025 is current), XSS, CSRF, SSRF, access control, APIs and webhooks |
| 15 SQL injection | Web apps, 14% | In-band, blind and out-of-band types, the signs in logs, and why parameterized queries are the fix |
| 16 Hacking wireless networks | Wireless, 5% | WEP through WPA3, rogue access points, Bluetooth attack terms, and wireless defenses |
| 17 Hacking mobile platforms | Mobile, IoT, OT, 10% | Rooting vs jailbreaking, OWASP Mobile Top 10 (2024), SMiShing, and mobile device management |
| 18 IoT and OT hacking | Mobile, IoT, OT, 10% | IoT architecture and OWASP IoT Top 10, ICS and SCADA parts, and why availability and safety lead in OT |
| 19 Cloud computing | Cloud, 5% | IaaS, PaaS and SaaS with the shared-responsibility split, containers, serverless, and cloud threats |
| 20 Cryptography | Crypto, 5% | Symmetric vs asymmetric vs hashing, PKI, email and disk encryption, and cryptanalysis attack types |
Module names follow EC-Council's CEH v13 course outline; domains and shares follow blueprint v5.0. The OWASP edition is on owasp.org. All checked Oct 11, 2026.
One order to study them
Skim the overview first, in one evening
Module 1 is only 6%, but hacker classes, the five phases and the control types come back in every later module. Read the introduction to ethical hacking once now; the laws and frameworks can wait for the last week.Network and perimeter, 24%
Five modules, the biggest block on the exam, from sniffing to session hijacking plus Module 12 on IDS, firewalls and honeypots. If ports and TCP flags are new to you, read scanning networks first; this domain assumes them.Reconnaissance, 17%
Footprinting, scanning and enumeration. The common thread is which activity touches the target and which service exposes what, so the enumeration file pays back its time.System hacking, 15%
Vulnerability analysis, system hacking and malware. Learn the categories and the defense matched to each; the long tool lists in course material are the part to skim.Web applications, 14%
Web servers, web apps and SQL injection. Name the OWASP edition every time you study a list: the course still cites 2021.Mobile, IoT and OT, 10%
Two modules. The OT half rests on one idea: in a plant, availability and safety come before confidentiality.The 5% trio last: wireless, cloud, cryptography
Recall-heavy and compact. Cram them in the final weeks next to a mock, then let them go after the exam. The CEH study plan turns this order into a 4-, 8- or 12-week calendar from your exam date.
Every domain, topic and technique file
Module files plus the technique files that split confusable pairs, grouped by domain.
D2Reconnaissance Techniques 17%
D3System Hacking Phases and Attack Techniques 15%
D4Network and Perimeter Hacking 24%
- Sniffing
- Social engineering
- Denial of service
- Session hijacking
- Evading IDS, Firewalls, and Honeypots (Module 12, no separate page)
D5Web Application Hacking 14%
D7Mobile Platform, IoT, and OT Hacking 10%
D8Cloud Computing 5%
Exam facts
Format, cut score, cost and retakes, each with its source and the date it was checked.
Getting certified
Eligibility routes, renewal, pay data and how CEH sits among other certifications.
Compare certs and prep tools
CEH set against other certifications, plus CEH prep resources compared on what can be checked: edition, version and price.
Questions about the syllabus
Is this the CEH v13 syllabus?
Yes. The module list is the CEH v13 course outline on EC-Council's CEH page, and the domains and weights come from blueprint v5.0, which EC-Council links as the CEH blueprint. Both were checked on Oct 11, 2026.
How long is EC-Council's own CEH course?
EC-Council structures its instructor-led CEH training as a five-day boot camp, with the exam typically at the end of day five (EC-Council, checked Oct 11, 2026). That is a course format. Self-study time depends on how much networking and security groundwork you bring.
Where do I practice once a module is done?
On the CEH practice test, filtered to that module's domain, or in the drill set at the bottom of each module file. Every option there carries a note.