Home Features Reviews Pricing Vendors Contact Blog Sign in
EC-Council

Certified Ethical Hacker v13

Certified Ethical Hacker (CEH) is a globally recognized certification provided by the EC-Council (International Council of E-Commerce Consultants) that validates an individual's ability to identify vulnerabilities in computer systems by simulating the tactics, techniques, and procedures of malicious hackers—legally and ethically.

Exam code

CEHv13

Duration

240 min

Questions

125

Official Prerequisites

  • Basic networking knowledge including TCP/IP, DNS, and routing.
  • Familiarity with Windows and Linux operating systems and command-line usage.
  • Understanding of core security concepts: confidentiality, integrity, availability, authentication, and encryption.
  • At least two years of experience in information security or a related IT role.
  • Recommended completion of EC-Council official training or self-study of the CEH v13 curriculum.
Certified Ethical Hacker v13

Targeted Professions

Ethical Hacker Penetration Tester Security Analyst Information Security Consultant Red Team Operator

Domain blueprint

ExamBoot simulation engine is synchronized with official exam outline. Our adaptive question banks prioritize your reaching your objectives quickly..

Overview of ethical hacking concepts, attack methodologies, legal and compliance considerations, and the roles and responsibilities of an ethical hacker.
Techniques and tools for information gathering about targets, including passive and active reconnaissance, OSINT, and footprinting methodologies to map attack surfaces.
Methods for discovering live hosts, open ports and services, and network topology using scanning tools and techniques to identify potential entry points.
Active probing to obtain detailed information about network resources and services—usernames, machine names, shares, and banners—to support vulnerability identification.
Processes and tools to identify, validate and prioritize vulnerabilities in systems and applications, including vulnerability assessment methodologies and reporting.

Domain 5

Vulnerability Analysis

5%
Processes and tools to identify, validate and prioritize vulnerabilities in systems and applications, including vulnerability assessment methodologies and reporting.

Domain 6

System Hacking

6%
Techniques for gaining and maintaining access on target systems, including password attacks, privilege escalation, persistence mechanisms, and post-exploitation activities.

Domain 7

Malware Threats

5%
Understanding malware types, delivery mechanisms, analysis basics, and countermeasures used to detect, analyze and mitigate malicious software.

Domain 8

Sniffing

5%
Packet-capture and analysis techniques for intercepting and inspecting network traffic to discover sensitive data, session information and network weaknesses.

Domain 9

Social Engineering

4%
Human-centric attack methods including phishing, pretexting and other manipulation techniques, along with mitigation strategies and awareness best practices.

Domain 10

Denial-of-Service

6%
Techniques and tools used to conduct DoS/DDoS attacks, amplification methods, and defenses to detect, mitigate and respond to service disruption attacks.

Domain 11

Session Hijacking

4%
Attacks targeting active sessions and authentication mechanisms, including session prediction, fixation and cookie-based hijacking, plus prevention controls.

Domain 12

Evading IDS, Firewalls and Honeypots

6%
Methods to bypass or neutralize intrusion detection/prevention systems, firewalls and deception technologies through obfuscation, tunneling and traffic manipulation.

Domain 13

Hacking Web Servers

6%
Attacks and hardening techniques specific to web server platforms, including server misconfigurations, exploitation of server-side vulnerabilities and mitigation practices.

Domain 14

Hacking Web Applications

6%
Assessment of web application vulnerabilities and attacks (e.g., XSS, CSRF, insecure deserialization), secure coding considerations and application-layer defenses.

Domain 15

SQL Injection

5%
Techniques for exploiting database-driven applications via SQL injection and related database attacks, plus detection, prevention and remediation strategies.

Domain 16

Hacking Wireless Networks

5%
Attacks against wireless protocols and infrastructure, including Wi‑Fi discovery, cracking, exploitation of weak encryption and defenses for wireless security.

Domain 17

Hacking Mobile Platforms

4%
Security threats and attack techniques targeting mobile operating systems and applications, including app analysis, reverse engineering and platform-specific controls.

Domain 18

IoT and OT Hacking

4%
Security considerations and attack methods for Internet of Things and Operational Technology environments, including device discovery, protocol exploitation and mitigation.

Domain 19

Cloud Computing

5%
Cloud-specific threats, attack vectors and assessment techniques across IaaS, PaaS and SaaS models, plus cloud security controls and best practices.

Domain 20

Cryptography

6%
Fundamentals of cryptographic systems, encryption algorithms, hashing, PKI, and practical use and misuse of cryptography in securing communications and data.

Study Tip

Focus on hands-on practice with CEH v13 labs, memorize tools/commands, take timed practice exams, and review exploit methodologies and mitigation strategies.

Blog

Latest from the ExamBoot Blog

Latest news, hands-on guides, and learner success stories from the ExamBoot blog

Docker Certified Associate – Preparation & methodology

Docker Certified Associate – Preparation & methodology

Preparing for the Docker Certified Associate (DCA) exam is an achievable goal with the right plan, focused practice, and high-quality mock exams.

From Zero to Certified: How to Study Smarter, Not Longer

From Zero to Certified: How to Study Smarter, Not Longer

Studying smarter isn’t about shortcuts. It’s about understanding how learning actually works

Why You Keep Failing Practice Tests — And How to Fix It

Why You Keep Failing Practice Tests — And How to Fix It

Failing a practice test stings. Not because it’s just a score…