48. CEH v13 Exam Modules Map and Practice Questions
48.8 Quick Revision Table – Module → Book Chapter → Blue Control
Thodkyaat – ek page revision. Exam night / interview morning. Chala!
| Mod | Exam module (short) | Revise chapters | Blue control (one-liner) | OWN lab tick |
|---|---|---|---|---|
| 01 | Intro ethical hacking | ch17, ch18, ch34, ch35 | Written scope + IT Act awareness | Ethics sticky note |
| 02 | Footprinting | ch19, ch36 | Shrink OSINT surface; monitor DNS noise | Amass passive on domain you own |
| 03 | Scanning | ch01–03, ch19 | SG/firewall; alert mass SYN | Nmap .20 only |
| 04 | Enumeration | ch37, ch38 | Close unused shares; log directory binds | Enum notes without exploit |
| 05 | Vuln analysis | ch20 | Patch by exposure | Scanner → ticket → re-scan |
| 06 | System hacking | ch22, ch23, ch26 | MFA, keys, least privilege, patch | Hardened SSH lab |
| 07 | Malware | ch39, ch28 | Backups + least privilege + IR | No prod detonation |
| 08 | Sniffing | ch24 | TLS; no telnet/FTP | Wireshark lab HTTPS proof |
| 09 | Social engineering | ch27 | MFA + report + DMARC | Consented sim only |
| 10 | DoS | ch40 | Rate limit / DDoS pattern / playbook | Never flood third parties |
| 11 | Session hijack | ch41 | HTTPS + cookie flags | Cookie flags on .50 |
| 12 | IDS/FW/honeypot | ch42, ch32 | Layered detect; isolate honeypot | fail2ban/firewalld lab |
| 13 | Web servers | ch07, ch08, ch21 | Patch + harden httpd/nginx | sudo service reload |
| 14 | Web apps | ch21, ch29 | OWASP fixes + authZ | DVWA/Juice fix loop |
| 15 | SQLi | ch10, ch11, ch29 | Prepared statements | Concat → PDO proof |
| 16 | Wireless | ch25 | WPA2/WPA3 + guest isolation | OWN AP only |
| 17 | Mobile | ch44 | Lock + updates + MDM mindset | Emulator hygiene |
| 18 | IoT/OT | ch43 | Defaults changed + segment OT | Camera inventory fiction |
| 19 | Cloud | ch04–16, ch30 | IAM + S3 BPA + CloudTrail | Free Tier checklist |
| 20 | Cryptography | ch33 | TLS 1.2+; bcrypt/Argon2 | Hash vs encrypt drill |
| Red team (attacker) does | Blue team (defender) detects / stops |
|---|---|
| Revises only tool flags, zero Blue column | Revises module + chapter + Blue one-liner + lab tick |
| Skips Modules 01/09/19 as "soft" | Treats ethics, phishing, cloud misconfig as high-score areas |
Ravindra Bagale's Tip
Print the revision table – but fill in the blank "OWN lab tick" column yourself. A blank tick = a weak module. Don't just rattle off exam modules – tick = typed in lab. Got it?
Ravindra Bagale's Tip – मराठी
Revision table print करा – पण रिकामा "OWN lab tick" column स्वतः भरा. Blank tick = weak module. Exam modules फक्त पटापट सांगू नका – tick = typed in lab. समजले का?
Ravindra Bagale's Tip – हिंदी
Revision table print करो – पर खाली "OWN lab tick" column खुद भरो. Blank tick = weak module. Exam modules सिर्फ़ फटाफट मत गिनाओ – tick = typed in lab. समझ आया?
Lab
With Zoya: quiz each other random module numbers for 15 minutes. Answer format mandatory: (1) module name, (2) book chapter, (3) one Blue control, (4) one OWN lab proof sentence.