CEH v13 Exam: All 20 Modules Explained (With Weights)
Every CEH v13 module explained with its exam weight, the tools tested and the questions to expect - from footprinting to cryptography.
CEH modules · 9 min read · updated 2026-09-06
The CEH curriculum is a complete attacker lifecycle. Understanding how the 20 modules chain together - and where the exam weights sit - makes revision dramatically more efficient.
The reconnaissance and analysis block (modules 1-5, ~43%)
Introduction (7%), footprinting (9%), scanning (10%), enumeration (8%) and vulnerability analysis (9%) form the information-gathering half. Expect Nmap flag questions, passive/active classification, port-tool-data matching and CVSS scoring.
Master one flagship tool per module: theHarvester, nmap, enum4linux and a vulnerability scanner. The exam tests tool selection as often as theory.
The exploitation block (modules 6-15, ~48%)
System hacking (12%) is the single heaviest module: password attacks, privilege escalation, persistence and covering tracks. Malware (10%), sniffing (6%), social engineering (6%), DoS (5%), session hijacking (4%), IDS evasion (4%), web servers (4%), web apps (4%) and SQL injection (4%) follow.
This is where scenario questions live: given a payload, name the attack; given an attack, pick the countermeasure. Practise by attack chain, not by flashcards alone.
The specialist block (modules 16-20, ~14%)
Wireless (3%), mobile (2%), IoT/OT (2%), cloud (1%) and cryptography (4%) are lighter but cheap points - each has a compact, repeatable pattern: WEP/WPA cracking sequences, MDM controls, Shodan discovery, shared responsibility, and algorithm/attack matching.
Cryptography deserves full attention despite the 4%: algorithm families, PKI flow and attack names (padding oracle, downgrade, collision) appear on every form.
Frequently asked questions
- What changed in CEH v13?
- EC-Council wove AI throughout: AI-assisted reconnaissance, AI-generated phishing, defensive AI tooling and responsible use of large language models during engagements. Expect a few AI-flavoured questions.
- Which modules should I study first?
- Follow the numbering - it mirrors the attacker lifecycle, so each module assumes the previous one. Modules 3, 6 and 15 (scanning, system hacking, SQL injection) deserve the deepest practice.
- Is the CEH Practical included?
- No - the practical is a separate 24-hour certification. The 312-50 exam is entirely multiple choice, which is why scenario practice matters so much.
Keep reading for CEH
PassYour is an independent study aid and is not affiliated with, endorsed by or sponsored by ISC2, CompTIA or Microsoft.
