48. CEH v13 Exam Modules Map and Practice Questions
48.5 Modules 16–20 Map (Wireless through Cryptography)
Last five – wireless, mobile, IoT/OT, cloud, crypto. Modern CEH weight. Aata map complete kara.
Module 16 – Hacking Wireless Networks
Book: ch25 (Wireless Security).
Focus: weak Wi-Fi hygiene; evil-twin awareness; never crack neighbour APs.
Blue: WPA2/WPA3-Enterprise where needed, strong PSK, guest VLAN, disable WPS if risky, monitor rogue APs in org process.
Module 17 – Hacking Mobile Platforms
Book: ch44 (Mobile Device Security – Android, iPhone, Bluetooth and Wi-Fi).
Focus: sideload risk, outdated OS, insecure apps, Bluetooth pairing hygiene – emulator/OWN device.
Blue: screen lock + biometrics, official app stores, MDM for shops, patch cadence, least app permissions.
Module 18 – IoT and OT Hacking
Book: ch43 (IoT and OT Security – Cameras, Smart Devices, Plant Networks).
Focus: default passwords on cameras; flat IT/OT networks as risk; safety note for plants.
Blue: change defaults, segment OT, inventory devices, vendor patch when available, no direct internet for PLC ideas.
Module 19 – Cloud Computing
Book: ch04–ch16 (EC2, S3, RDS, live project foundation), ch30 (Cloud and AWS Security).
Focus: shared responsibility, IAM keys, public S3, SG 0.0.0.0/0, IMDSv2 mindset.
Blue: S3 Block Public Access, IAM least privilege, CloudTrail on, GuardDuty awareness, no long-lived keys in code.
Module 20 – Cryptography
Book: ch33 (Cryptography Basics).
Focus: symmetric vs asymmetric ideas, hashing vs encryption, TLS role, why MD5/SHA1 password storage fails.
Blue: TLS 1.2/1.3, bcrypt/Argon2 for passwords, protect keys, prefer AES-GCM class authenticated encryption in modern stacks.
| Red team (attacker) does | Blue team (defender) detects / stops |
|---|---|
| Tests neighbour Wi-Fi "because CEH module 16" | Only OWN AP / lab router you control; WPA3/WPA2 strong |
| Leaves S3 public for "demo" on shared account | BPA + bucket policy review + CloudTrail |
| Stores lab passwords with MD5 "because notes" | bcrypt/Argon2; never MD5 for passwords |
Ravindra Bagale's Tip
In Modules 19–20, students mix things up: "encryption = hashing". That's an exam trap. Encryption is reversible with a key; a hash is one-way, for password verification. For cloud, keep a clear one-liner on shared responsibility. This is very important!
Ravindra Bagale's Tip – मराठी
Module 19–20 मध्ये students mix करतात: "encryption = hashing". Exam trap. Encryption key ने reversible; hash one-way, password verify साठी. Cloud मध्ये shared responsibility ची एक line clear ठेवा. हे खूप important आहे!
Ravindra Bagale's Tip – हिंदी
Module 19–20 में students mix कर देते हैं: "encryption = hashing". Exam trap. Encryption key से reversible; hash one-way, password verify के लिए. Cloud में shared responsibility की एक line clear रखो. यह बहुत important है!
Lab
On OWN Free Tier: confirm S3 Block Public Access is On for a practice bucket; rotate any practice IAM access key you pasted in a file; enable CloudTrail in the account if not already (lab). Tick Module 19 Blue row in your map.