CEH v13 Study Material, Books and Exam Voucher: What to Use Now That v12 Is Retired
The course is intended to provide a general understanding of ethical hacking; Internet security; web application security; penetration testing; and computer forensics. It should be considered a prerequisite for those who want to pursue CEH v12 certification, CEH v12 Study Material, Books, Exam Prepartion and Discounted Voucher or other related cyber security training
Quick answer: CEH v12 is retired; the current exam is CEH v13, branded CEH v13 AI. The best study material is EC-Council's official courseware and iLabs, a lab of your own for hands-on practice, and original practice questions. Avoid exam dumps. Study the 20 modules, then sit the 125-question multiple-choice exam (312-50), and add CEH Practical if you want a hands-on credential.
Key takeaways
- CEH v10, v11 and v12 are retired. Study material that says v12 will be out of date for the current exam.
- The theory exam is 312-50 (125 multiple-choice questions, 4 hours). CEH Practical is a separate hands-on exam.
- Official courseware and labs are the authoritative source. Third-party books help only if they match the current version.
- Dumps are unreliable, can be outdated and risk your certification. Original practice questions and your own lab are safer and teach more.
- Buy vouchers only from EC-Council or an authorised training partner, and ask for the current price in writing.
Is CEH v12 study material still useful?
Partly. The current exam is CEH v13, branded CEH v13 AI, and CEH v10, v11 and v12 are retired. The core ideas (reconnaissance, scanning, enumeration, attacks and defences) carry over, and the module structure is similar, but tools, attack examples and AI-related content change between versions. Use v12 material only as background and always check it against the current syllabus on the EC-Council CEH page.
What does the CEH v13 exam cover?
CEH is organised into 20 modules. Grouped by purpose, they look like this:
| Block | Modules |
|---|---|
| Foundations and information gathering | Introduction to ethical hacking; footprinting and reconnaissance; scanning networks; enumeration; vulnerability analysis |
| Attacking systems | System hacking; malware threats; sniffing; social engineering; denial of service; session hijacking |
| Evasion and perimeter | Evading IDS, firewalls and honeypots; hacking web servers |
| Applications and wireless | Hacking web applications; SQL injection; hacking wireless networks; hacking mobile platforms |
| Newer technology and crypto | IoT and OT hacking; cloud computing; cryptography |
The exam asks what an attack is, how it works, which tool or technique fits, and how to detect or prevent it. For every attack you study, learn the defence too. That is the point of the credential.
How do the CEH exam and CEH Practical differ?
| Feature | CEH (theory) | CEH Practical |
|---|---|---|
| Exam code | 312-50 | Separate hands-on exam |
| Format | 125 multiple-choice questions | Practical challenges in a live lab |
| Time | 4 hours | Several hours; check EC-Council for current length |
| Tests | Knowledge and concepts | Doing the work on live targets |
| Combined credential | CEH Master is awarded when you pass both | |
Confirm all figures with EC-Council before booking, because formats and policies change. Our course pages cover each route: CEH v13 AI, CEH v13 AI Practical and CEH v13 AI Master.
What study material should you actually use?
- Official courseware and labs. EC-Council's materials match the exam blueprint. If you train with an authorised centre, the courseware and lab access usually come with the course.
- Primary references. Read the Nmap reference guide for scanning, and the OWASP Top 10 for web topics. Both are free and better than most summaries.
- Your own lab. Build a small isolated network with a Kali Linux VM and deliberately vulnerable targets such as DVWA or Metasploitable. Practise only on machines you own or are authorised to test.
- Original practice questions. They show gaps in knowledge. Write your own from each module's objectives or use a trainer-made set, and always read the explanation, not just the answer.
- Third-party books. A good study guide helps for revision, but check the edition covers the current version and the 20 modules before you buy. Treat any book as secondary to official material.
Why should you avoid CEH dumps?
- They go out of date quickly, and many are simply wrong.
- They breach the exam agreement. Using or sharing leaked questions can lead to a ban or revocation by the certifying body.
- They do not build the skill. Interviews for security roles test whether you can explain how a scan or an injection works.
Memorising answers is the slowest way to learn this material. A lab and a clear understanding are quicker and last longer.
What is a realistic 10-week study plan?
- Week 1: Networking basics: TCP/IP, ports, DNS, HTTP, subnetting. Module 1.
- Week 2: Footprinting, reconnaissance and scanning. Practise Nmap on your lab.
- Week 3: Enumeration and vulnerability analysis. Learn how CVSS scores work.
- Week 4: System hacking, malware threats and sniffing, with a Wireshark capture of your own traffic.
- Week 5: Social engineering, denial of service and session hijacking, focusing on detection and defence.
- Week 6: Evasion, web servers, web application attacks and SQL injection against DVWA.
- Week 7: Wireless, mobile, IoT and OT.
- Week 8: Cloud computing and cryptography.
- Week 9: Revision with original practice questions. Note the topics you miss and revisit them.
- Week 10: Two timed full-length practice runs, then book the exam.
Adjust to your background. If your networking is weak, spend longer on weeks 1 and 2, because everything builds on them.
Legal and ethical ground rules for practice
Only test systems you own or have written permission to test. In India, unauthorised access to computers is an offence under the Information Technology Act, 2000. Keep your lab on an isolated network, use deliberately vulnerable machines, and never point scanners or attack tools at a real site "just to see". Ethical hacking means written authorisation and a defined scope.
How do you buy a CEH exam voucher?
Vouchers are sold by EC-Council and by authorised training partners. Ask the WebAsha team what is included in a course bundle, the current price, and the retake terms. Ask for these in writing. Avoid unknown sellers offering deep discounts. Vouchers can be invalid, used, or refused at the exam centre, and you will not get your money back from a stranger. See also our note on exam vouchers with training, but check the version, since that page covers CEH v12.
Next steps
List the 20 modules, mark each as strong, weak or unseen, and start with the weak ones. For a guided path with labs, see our CEH v13 AI course. For exam-day strategy read how to pass CEH in the first attempt, and for a candidate's account of the full route see one candidate's CEH Master account (written for v12).
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0