Ravindra BagaleCourses & study guides

48. CEH v13 Exam Modules Map and Practice Questions

48.1 How to Use This Map – Ethics and Exam Mindset

Pehle trust, mag map, mag MCQ. Exam module = topic basket – not a shopping list for illegal tools on live networks. Samjla ka?

Master map (CEH v13 → this book → one Blue control):

Mod CEH v13 exam module Book chapters (read these) One Blue control to remember
01 Introduction to Ethical Hacking ch17, ch18, ch34, ch35 Written authorisation + scope before any scan
02 Footprinting and Reconnaissance ch19, ch36 (Amass/WhatWeb) Limit public exposure; monitor unusual DNS / OSINT hits
03 Scanning Networks ch01–ch03, ch19 (Nmap) Security group / firewall least privilege; alert on mass SYN
04 Enumeration ch37, ch38 (AD awareness) Disable unneeded shares/services; tight LDAP/SMB logging
05 Vulnerability Analysis ch20 Patch cadence + prioritise internet-facing CVEs
06 System Hacking ch22, ch23, ch26 MFA, strong auth, least privilege, patch, EDR awareness
07 Malware Threats ch39, ch28 (forensics awareness) App allow-listing mindset; backups; do not pay blindly
08 Sniffing ch24 Prefer HTTPS/TLS; avoid cleartext on shared segments
09 Social Engineering ch27 MFA + user reporting + SPF/DKIM/DMARC
10 Denial-of-Service ch40 Rate limits, capacity plan, cloud/DDoS protection pattern
11 Session Hijacking ch41 HttpOnly/Secure cookies; HTTPS; short session lifetime
12 Evading IDS, Firewalls, and Honeypots ch42, ch32 Layered detect; tune IDS; isolate honeypots
13 Hacking Web Servers ch07, ch08, ch21 Patch web server; harden config; least-open ports
14 Hacking Web Applications ch21, ch29 OWASP fixes: authZ, encoding, CSP, input allow-lists
15 SQL Injection ch10, ch11, ch29 Prepared statements / parameterised queries always
16 Hacking Wireless Networks ch25 WPA2/WPA3, strong passphrase, guest isolation
17 Hacking Mobile Platforms ch44 Screen lock, app sources, MDM/update hygiene
18 IoT and OT Hacking ch43 Change defaults; segment OT from IT; patch when possible
19 Cloud Computing ch04–ch16 foundation, ch30 IAM least privilege; S3 BPA; CloudTrail/GuardDuty mindset
20 Cryptography ch33 TLS 1.2+, modern hashes (bcrypt/Argon2), key hygiene

Exam mindset (classroom rules):

  1. Authorisation first – every scenario in your head starts with "Do I own this / have paper?"
  2. Phase order matters – recon before scan before enum before exploit awareness.
  3. Answer in control language – what Blue detects / stops, not payload recipes.
  4. OWN lab proof beats memorised tool flags you never typed.
  5. India context: IT Act awareness (ch34) – exam overseas ≠ ignore local law.
Red team (attacker) does Blue team (defender) detects / stops
Treats CEH badge as permission to scan random IPs Scope document; host-only lab; refuses illegal asks
Memorizes tool names with zero Blue story Maps each module to a detection or fix in OWN lab

Ravindra Bagale's Tip

Students "CEH module list rattlo = hacker" samajtat. Nako. Interview / exam madhe phase + tool purpose + Blue control teen parts. Payload dump = red flag for good employers. Lakshat theva.

Lab

Print or copy the master map table into your notebook. Tick modules you already practised on host-only 192.168.56.x. Circle three weak modules – those get 30 minutes each this week with Sahyadri / Raja-Rani OWN VMs only.