EC-Council CEH v13 312-50: What the Current Blueprint Covers

The master plan labels this exam 312-50v13, while EC-Council’s official certification exam prefix remains 312-50. The current course generation is CEH v13 / CEH powered by AI, and the live knowledge exam remains a four-hour, 125-question multiple-choice examination. EC-Council’s official CEH Exam Blueprint v5.0 organizes the knowledge exam into nine weighted domains rather than the 20 training modules used in the course.

The current v13 course adds AI-assisted ethical-hacking workflows, current cloud/container/serverless coverage, and hands-on labs, but the knowledge exam is still centered on ethical-hacking concepts, reconnaissance, exploitation lifecycle, network/web/wireless/mobile/cloud attack concepts, countermeasures, and cryptography. The passing cut score is not one fixed percentage; EC-Council uses form-specific cut scores.

Domain 1: Information Security and Ethical Hacking Overview is 6%

This domain covers information-security concepts, hacking methodologies and frameworks, ethical-hacking concepts, controls, and relevant laws and standards. Candidates should understand authorization, scope, professional boundaries, and the difference between legitimate security testing and unauthorized activity.

An introduction to the CEH certification is useful for placing the exam inside a defensive and authorized testing context rather than treating it as an exploitation contest.

Domain 2: Reconnaissance Techniques is 17%

The blueprint groups footprinting/reconnaissance, network scanning, and enumeration. Topics include search engines, web services, social networks, DNS/WHOIS, email/website footprinting, host discovery, port/service discovery, OS fingerprinting, NetBIOS/SNMP/LDAP/NTP/NFS/SMTP/DNS and other enumeration techniques.

Countermeasures matter alongside data collection. CEH wants candidates to recognize both how information is gathered and how organizations can reduce unnecessary exposure.

Domain 3: System Hacking Phases and Attack Techniques is 15%

This domain covers vulnerability analysis, system hacking, password attacks, vulnerability exploitation, privilege escalation, persistence, application execution, hiding/clearing evidence, malware concepts, APTs, Trojans, viruses/worms, fileless malware, analysis, and countermeasures.

The ethical-hacking lifecycle is conceptual: identify weakness, gain authorized access in a lab or approved scope, understand post-compromise risk, and report remediation. Production systems should never be tested outside written authorization.

Domain 4: Network and Perimeter Hacking is 24%

This is the heaviest domain. It includes sniffing, MAC/DHCP/ARP/spoofing/DNS attacks, social engineering, insider threats, identity theft, denial-of-service, botnets, session hijacking, and evasion of IDS/IPS/firewalls/NAC/honeypots.

The large weight explains why traffic behavior, trust boundaries, user manipulation, perimeter controls, and detection/evasion concepts deserve substantial study time.

Domain 5: Web Application Hacking is 14%

The blueprint covers web-server attacks, web-application threats and methodology, client-side controls, authentication/authorization/session weaknesses, input/injection attacks, logic flaws, shared environments, database connectivity, web services/APIs/webhooks/web shells, SQL injection, evasion, and countermeasures.

Advanced ethical-hacking concepts are most useful when paired with OWASP-style defensive reasoning: understand why the weakness exists and what control would prevent or detect it.

Domain 6: Wireless Network Hacking is 5%

Wireless concepts, encryption, threats, assessment methodology, common tools, Bluetooth risks, countermeasures, and wireless-security tools make up this smaller but distinct domain.

The candidate should understand differences among wireless technologies and protections, while keeping practical testing confined to owned or explicitly authorized lab networks.

Domain 7: Mobile Platform, IoT and OT Hacking is 10%

The mobile section covers attack vectors, Android/iOS concepts, mobile-device management, security guidelines and tools. IoT/OT covers device/industrial concepts, attacks, assessment methodology, and countermeasures.

These environments can have stronger safety, availability, privacy, or physical-process consequences than conventional IT. Defensive judgment matters as much as attack vocabulary.

Domain 8: Cloud Computing is 5%

Cloud concepts, containers, serverless, cloud threats, cloud hacking concepts, and cloud-security controls are in scope. Candidates should understand how shared responsibility, identity, storage exposure, APIs, and cloud-native workloads change the attack surface.

The v13 course’s cloud coverage reflects how modern ethical-hacking engagements increasingly include SaaS, public-cloud, container, and serverless components.

Domain 9: Cryptography is 5%

The final domain includes cryptographic concepts, symmetric/asymmetric algorithms, tools, PKI, email/disk encryption, cryptanalysis, and countermeasures. The exam tests why cryptographic controls work, where they fail, and how implementation or key-management weaknesses can undermine them.

Cryptography should be learned as a protection system for confidentiality, integrity, authentication, and trust—not simply as a list of algorithm names.

CEH v13 maps course modules into the nine exam domains

The v13 course still uses 20 modules from Introduction to Ethical Hacking through Cryptography, with AI integrated into the learning/lab experience. The exam blueprint consolidates those modules into nine domains with 6/17/15/24/14/5/10/5/5 weighting.

The v13 training course still follows a 20-module structure, which is more granular than the nine-domain exam blueprint. Modules 1–4 move from introduction through reconnaissance, scanning, and enumeration; Modules 5–7 cover vulnerability analysis, system hacking, and malware; Modules 8–12 cover sniffing, social engineering, DoS, session hijacking, and evasion; Modules 13–15 focus on web servers, web applications, and SQL injection.

Modules 16–20 cover wireless, mobile, IoT/OT, cloud, and cryptography. This alignment explains why a course syllabus can look much longer than the exam-domain list without being a different exam. The blueprint simply aggregates several modules into broader assessment domains.

The current blueprint’s 24% Network and Perimeter Hacking domain deserves the largest study block. It combines traffic interception concepts, human manipulation, availability attacks, session abuse, and defensive-control evasion. Candidates who over-focus on web hacking because it feels familiar can underprepare for the heaviest scored area.

The 17% Reconnaissance domain also deserves substantial time because it spans passive and active information gathering plus enumeration. Ethical hackers should know how public records, DNS, websites, metadata, exposed services, and protocol information can reveal attack surface—and how defenders can reduce or monitor that exposure.

System Hacking’s 15% weight includes vulnerability analysis, access, privilege, persistence, and malware concepts. The exam can therefore move from identifying a vulnerability to asking what an attacker might accomplish afterward or what defensive control would limit post-compromise activity.

Web Application Hacking at 14% extends beyond SQL injection. The official blueprint includes authentication, authorization, access controls, session management, client-side controls, logic flaws, database connectivity, web services, APIs, webhooks, and web shells. Candidates should understand categories of weakness and countermeasure, not one injection technique.

The Mobile/IoT/OT domain at 10% is broader than its single percentage suggests. Mobile security involves app/device attack vectors and management, while IoT/OT adds constrained devices, industrial protocols, operational availability, physical consequences, and lifecycle weaknesses. The security context changes even when some attack concepts are familiar.

Wireless, Cloud, and Cryptography are each 5%, but together they represent 15% of the exam. Ignoring smaller domains can therefore cost as much as ignoring System Hacking. Weighted preparation should keep them concise but complete.

CEH v13’s AI emphasis is primarily a learning and workflow enhancement layered across the ethical-hacking methodology. EC-Council promotes AI-assisted reconnaissance, vulnerability research, automation, reporting, and defensive analysis, as well as material about AI-system risks. Candidates should still validate AI-generated claims and tools inside authorized environments.

EC-Council’s five ethical-hacking phases—reconnaissance, scanning, gaining access, maintaining access, and covering tracks—are useful for organizing attacker behavior. A professional assessment, however, also includes preparation, authorization, evidence, reporting, remediation guidance, and retesting. The certification context remains defensive and ethical.

The knowledge exam and CEH Practical are different assessments. Passing the knowledge exam awards the CEH credential; the optional six-hour practical with 20 challenges is used with CEH to earn CEH Master. The blog series here focuses on the knowledge-exam scope unless practical-lab context helps explain an objective.

EC-Council’s current candidate materials list the credential as valid for three-year periods under its continuing-education program. That lifecycle matters because ethical-hacking tools and attack methods change quickly; certification knowledge must be maintained after the exam rather than treated as permanent.

Eligibility also has more than one path. Candidates completing authorized EC-Council training can become eligible through that route, while experience-based candidates who skip official training may need to follow EC-Council’s application process. Final registration details should always be checked on the current vendor page.

The blueprint itself is intentionally tool-neutral at the objective level. It may mention categories of tools, but the exam’s durable knowledge is methodology: what information the tool reveals, what evidence means, what countermeasure applies, and what ethical boundary governs use. Tool names can change faster than the security concept.

For current-scope study, separate three documents mentally: the CEH v13 course modules explain the training journey, the CEH Exam Blueprint v5.0 defines knowledge-exam weighting and objectives, and the CEH candidate/exam page defines current logistics and credential rules. Mixing those sources can create confusion about module count versus exam-domain count.

The official blueprint’s nine domains can also be read as a progression from information gathering toward impact and defense. Domains 1–3 establish methodology, reconnaissance and system compromise concepts; Domains 4–7 broaden the attack surface across network, web, wireless and device/industrial contexts; Domains 8–9 extend the same reasoning into cloud and cryptography.

The current v13 curriculum’s large lab count should not lead candidates to assume the knowledge exam is a practical cyber-range assessment. The knowledge exam remains multiple choice. Practical lab experience is valuable because it makes terminology and countermeasures real, while the optional CEH Practical is a separate hands-on assessment.

For final scope control, use the official CEH Exam Blueprint v5.0 for domain weights and the current CEH v13 course page for module/lab context. Avoid older v12 or v11 course outlines when they conflict with current AI-integrated material, but retain timeless fundamentals such as reconnaissance, web security, network defense and cryptography where they remain in the blueprint.

An ethical-hacking preparation plan should therefore use the official blueprint for exam weighting and the current v13 modules/labs for practical context. The goal is authorized security assessment and countermeasure understanding, not unsanctioned exploitation.