Certified Ethical Hacker (CEH) v12

Master offensive security and ethical hacking with the industry-leading CEH v12 certification. Learn penetration testing, vulnerability assessment, and security tools used by professionals worldwide.

8 Weeks Study Duration
200+ Practice Questions
75 Flashcards
3 Hands-on Labs

Certification Overview

The Certified Ethical Hacker (CEH) v12 is a globally recognized certification that validates your skills in ethical hacking and penetration testing. Offered by EC-Council, CEH covers the latest attack vectors and defensive strategies.

Exam Code 312-50 (CEH v12)
Duration 4 hours
Questions 125 multiple choice
Passing Score 60-85% (varies)
Cost $1,199 (exam only)
Validity 3 years (with ECE credits)
Format Multiple choice + Practical (optional)
Prerequisites 2 years security experience OR training

8-Week Study Roadmap

1

Week 1: Foundations & Reconnaissance

  • Information Security Fundamentals: CIA triad, security policies, laws and regulations (GDPR, HIPAA, PCI DSS)
  • Ethical Hacking Methodology: 5 phases, types of hackers, penetration testing concepts
  • Footprinting and Reconnaissance: Passive vs active reconnaissance, OSINT techniques, Google dorking
  • Tools Practice: Shodan, Censys, theHarvester, Maltego, WHOIS, nslookup, dig
  • Study Resources: CEH official courseware Chapter 1-2, complete 40 practice questions
  • Lab Work: Set up Kali Linux VM, perform passive reconnaissance on public targets
2

Week 2: Scanning & Enumeration

  • Network Scanning: TCP/UDP scanning, SYN/ACK scans, port states, scan evasion techniques
  • Nmap Mastery: Scan types (-sS, -sT, -sU, -sN), timing templates, NSE scripts
  • Enumeration Techniques: SMB, SNMP, LDAP, NetBIOS enumeration, banner grabbing
  • Vulnerability Scanning: Nessus, OpenVAS, authenticated vs unauthenticated scanning
  • Tools Practice: Nmap, Zenmap, hping3, NetBIOS Enumerator, SNMPwalk
  • Lab Work: Scan Metasploitable VM, enumerate services, identify vulnerabilities
3

Week 3: System Hacking & Exploitation

  • Password Cracking: Rainbow tables, brute force, dictionary attacks, John the Ripper, Hashcat
  • Exploitation Techniques: Buffer overflow, return-oriented programming, shellcode injection
  • Metasploit Framework: Architecture, modules, payloads, Meterpreter, post-exploitation
  • Privilege Escalation: Vertical and horizontal escalation, kernel exploits, misconfigurations
  • Credential Theft: Mimikatz, Pass-the-Hash, Pass-the-Ticket, Golden Ticket attacks
  • Lab Work: Exploit vulnerable services, gain shells, escalate privileges, harvest credentials
4

Week 4: Web Application Security

  • OWASP Top 10: Injection, broken access control, cryptographic failures, XSS, CSRF, XXE, SSRF
  • SQL Injection: Error-based, union-based, blind (boolean/time-based), SQLMap automation
  • Cross-Site Scripting: Reflected, stored, DOM-based XSS, filter bypass techniques
  • Web Application Testing: Burp Suite Professional, ZAP proxy, cookie manipulation
  • Advanced Attacks: Insecure deserialization, directory traversal, command injection, CSRF
  • Lab Work: Complete Web Application Penetration Testing project on DVWA/WebGoat
5

Week 5: Wireless & Network Attacks

  • Wireless Security: WEP/WPA/WPA2/WPA3, 4-way handshake, wireless encryption protocols
  • Wireless Attacks: Deauthentication, handshake capture, Evil Twin, rogue APs, WPS attacks
  • Aircrack-ng Suite: Airmon-ng, airodump-ng, aireplay-ng, aircrack-ng, password cracking
  • Network Attacks: ARP spoofing, MAC flooding, VLAN hopping, STP attacks, DHCP starvation
  • Sniffing: Wireshark, tcpdump, packet analysis, MITM attacks, SSL stripping
  • Lab Work: Complete Wireless Security Assessment project, capture and crack handshakes
6

Week 6: Malware, Social Engineering & DoS

  • Malware Types: Viruses, worms, trojans, ransomware, rootkits, RATs, APTs
  • Malware Analysis: Static vs dynamic analysis, sandboxing, Cuckoo, IDA Pro
  • Social Engineering: Phishing, pretexting, vishing, whaling, baiting, tailgating
  • Social Engineering Tools: SET (Social Engineering Toolkit), GoPhish, email spoofing
  • Denial of Service: SYN flood, UDP flood, ICMP flood, application layer DDoS, amplification
  • Lab Work: Create phishing campaigns (ethical), analyze malware samples in sandbox
7

Week 7: Cloud, Mobile & IoT Security

  • Cloud Security: Shared responsibility, IaaS/PaaS/SaaS security, misconfigurations, container security
  • Cloud Attacks: S3 bucket enumeration, metadata exploitation, container escape, serverless attacks
  • Mobile Security: Android/iOS architecture, app analysis, reverse engineering, insecure storage
  • Mobile Attacks: App repackaging, SSL pinning bypass, runtime manipulation, Frida framework
  • IoT/OT Security: MQTT, CoAP, firmware analysis, Shodan for IoT, default credentials
  • Lab Work: Analyze mobile apps with MobSF, enumerate cloud resources, test IoT devices
8

Week 8: Cryptography, IDS/IPS & Review

  • Cryptography Fundamentals: Symmetric (AES, DES, 3DES), asymmetric (RSA, ECC, DSA), hashing
  • PKI & Certificates: Digital certificates, CAs, certificate pinning, SSL/TLS, perfect forward secrecy
  • Cryptographic Attacks: Rainbow tables, collision attacks, side-channel, birthday attacks
  • IDS/IPS: Signature vs anomaly detection, Snort rules, evasion techniques
  • Frameworks: MITRE ATT&CK, Cyber Kill Chain, OWASP, NIST CSF
  • Final Review: Complete all 200 practice questions, review flashcards, take mock exams

Career Paths After CEH

Penetration Tester / Ethical Hacker

Conduct authorized security assessments, identify vulnerabilities, exploit systems, and provide remediation guidance.

💰 $75,000 - $120,000 / year

Next Certifications: OSCP, GPEN, LPT (Master)

Security Analyst / SOC Analyst

Monitor security events, analyze threats, respond to incidents, and improve security posture.

💰 $65,000 - $100,000 / year

Next Certifications: Security+, CySA+, GCIH

Vulnerability Analyst / Researcher

Discover zero-days, analyze security vulnerabilities, contribute to CVE database, work on bug bounty programs.

💰 $80,000 - $140,000 / year

Next Certifications: GWAPT, OSWE, OSCE

Red Team Operator

Simulate advanced persistent threats, test detection capabilities, perform adversary emulation, assess organizational defenses.

💰 $95,000 - $160,000+ / year

Next Certifications: OSCP, OSCE, CRTO, PNPT

Senior Security Consultant

Lead security assessments, develop security strategies, advise C-level executives, design security architectures.

💰 $110,000 - $180,000+ / year

Next Certifications: CISSP, CISM, CCSP

Exam Day Strategy

Time Management

You have 4 hours for 125 questions (1.9 min/question). Flag difficult questions and return to them later.

Read Carefully

CEH questions can be tricky. Read each question twice, identify keywords like "BEST," "MOST," "FIRST."

Know Your Tools

Memorize tool names, purposes, and command syntax. Nmap, Metasploit, Burp Suite, Wireshark, and Aircrack-ng are essential.

Understand Methodologies

Know the phases of ethical hacking, Cyber Kill Chain, MITRE ATT&CK framework, and penetration testing steps.

Port Numbers

Memorize common ports: FTP (21), SSH (22), HTTP (80), HTTPS (443), SMB (445), RDP (3389), SNMP (161).

Ethics & Laws

Understand legal aspects, obtain proper authorization, rules of engagement, and responsible disclosure.

CVSS Scoring

Understand vulnerability severity ratings, CVSS scoring (0-10), and prioritization based on exploitability and impact.

Eliminate Wrong Answers

Use process of elimination. Often 2-3 answers are obviously wrong, choose between remaining options.

Practice Resources

Additional Learning Resources