48. CEH v13 Exam Modules Map and Practice Questions
48.3 Modules 06–10 Map (System Hacking through DoS)
Modules 06–10 = access, malware awareness, sniff, people, availability. Ghabru naka – defensive framing.
Module 06 – System Hacking
Book: ch22 (Password Attacks), ch23 (Exploitation with Metasploit – OWN lab), ch26 (Privilege Escalation).
Focus: credential weakness, post-access awareness, privilege paths on OWN Metasploitable – paired with hardening.
Blue: MFA, password policy, patch, remove risky SUID/sudo misconfig, EDR/log review.
Module 07 – Malware Threats
Book: ch39 (Malware Threats), ch28 (Digital Forensics awareness).
Focus: families at concept level (virus/worm/trojan/ransomware ideas); delivery themes; no payload building.
Blue: backups offline-ish, least privilege, mail/web filtering, IR playbook, do not run mystery samples on prod.
Module 08 – Sniffing
Book: ch24 (Traffic Sniffing and Analysis).
Focus: why cleartext on a shared segment is dangerous; Wireshark for defence and lab learning.
Blue: TLS everywhere practical; avoid FTP/telnet; network segmentation; detect promiscuous oddities in lab study.
Module 09 – Social Engineering
Book: ch27 (Social Engineering Awareness).
Focus: phishing / pretext themes; consented simulation only; 1930 / cybercrime.gov.in awareness for India.
Blue: MFA, report button culture, DMARC chain, verify payment-change calls.
Module 10 – Denial-of-Service
Book: ch40 (DoS and DDoS – Availability Attacks).
Focus: availability pillar; volumetric vs application-layer ideas; never run flood tools at third parties.
Blue: rate limits, autoscaling/capacity, upstream DDoS service pattern, playbooks.
| Red team (attacker) does | Blue team (defender) detects / stops |
|---|---|
Password spray / weak SSH on OWN .20 only |
fail2ban-style blocks; key auth; alert on 4625-style failures |
| Cleartext sniff demo on host-only lab bridge | Force HTTPS; kill telnet/FTP in hardening checklist |
| Phish kit against classmates "for fun" | Consented sim only; MFA; report path; never real victims |
Ravindra Bagale's Tip
Module 06 madhe students Metasploit screenshots portfolio madhe "production hack" mhantat. Career death. Caption: OWN lab / fictional Sahyadri. Exam pan ethics language expect karto. Lakshat theva.
Lab
Raja-Rani OWN Amazon Linux: sudo yum update -y habit; ensure SSH keys; sudo service sshd status (or sshd name on your image). From Kali, confirm password auth is off if you hardened it. Document Module 06 Blue controls in four bullets.