
CEH Certified Ethical Hacker v13 Study Guide
Description
Alles über E-Books | Antworten auf Fragen rund um E-Books, Kopierschutz und Dateiformate finden Sie in unserem Info- & Hilfebereich.
Master ethical hacking with the definitive ethical hacking study guide, fully updated with chapter review questions and practice tests
As cyber threats evolve and data breaches make headlines, organizations everywhere are prioritizing information security like never before. The Certified Ethical Hacker Version 13 (CEH v13) stands out as the gold standard amongst a growing set of accreditation options - a credential that opens doors and accelerates careers in this critical field.
The CEH Certified Ethical Hacker v13 Study Guide delivers everything you need to obtain this prestigious certification. This enhanced edition combines clear, step-by-step instruction with flexible pacing that adapts to your learning style. The content has been expanded and updated, integrating additional chapter reviews and online practice tests into one comprehensive resource that delivers exceptional value.
Dive deep into the tactics and techniques that matter most, including reconnaissance and network scanning, advanced intrusion detection. Denial-of-Service attacks, buffer overflow exploits, wireless vulnerabilities, mobile security threats, and emerging Internet of Things risks. Each topic systematically builds your expertise while preparing you for the real-world challenges you'll face in a wide variety of information security roles.
You'll find:
- Challenging chapter review questions and critical Exam Essentials that spotlight must-know concepts, translate theory into practical skills, and identify knowledge gaps
- Content that aligns with Department of Defense 8570 Directive requirements for Information Assurance positions, helping you secure government and contractor roles
- Complimentary access to the Sybex online learning platform that features additional practice exams, digital flashcards, and a comprehensive glossary
Upgrade your cybersecurity knowledge and launch your ethical hacking career with the CEH Certified Ethical Hacker v13 Study Guide today.
More details
Other editions
Additional editions

Person
ABOUT THE AUTHOR
WILLIAM PANEK is a 5-time Microsoft MVP Winner who specializes in Windows and Windows Server. He has consulted with and trained personnel working for the United States Secret Service, United States Air Force, and the United States Army. He creates useful training videos to help readers prepare for Microsoft certification exams.
Content
Introduction xix
Assessment Test xxvii
Answers to Assessment Test xxxii
Chapter 1 Ethical Hacking 1
Chapter 2 Networking Foundations 15
Chapter 3 Security Foundations 59
Chapter 4 Footprinting and Reconnaissance 103
Chapter 5 Scanning Networks 163
Chapter 6 Enumeration 233
Chapter 7 System Hacking 279
Chapter 8 Malware 343
Chapter 9 Sniffing 399
Chapter 10 Social Engineering 441
Chapter 11 Wireless Security 479
Chapter 12 Attack and Defense 521
Chapter 13 Cryptography 561
Chapter 14 Security Architecture and Design 597
Chapter 15 Cloud Computing and the Internet of Things 629
Index 681
Introduction
You're thinking about becoming a Certified Ethical Hacker (CEH). No matter what variation of security testing you are performing-ethical hacking, penetration testing, red teaming, or application assessment-the skills and knowledge necessary to achieve this certification are in demand. Even the idea of security testing and ethical hacking is evolving as businesses and organizations begin to have a better understanding of the adversaries they are facing. It's no longer the so-called script kiddies that businesses felt they were fending off for so long. Today's adversary is organized, well funded, and determined. This means testing requires different tactics.
Depending on who you are listening to, 80-90 percent of attacks today use social engineering. The old technique of looking for technical vulnerabilities in network services is simply not how attackers are getting into networks. Networks that are focused on applying a defense-in-depth approach, hardening the outside, may end up being susceptible to attacks from the inside, which is what happens when desktop systems are compromised. The skills needed to identify vulnerabilities and recommend remediations are evolving, along with the tactics and techniques used by attackers.
This book is written to help you understand the breadth of content you will need to know to obtain the CEH certification. You will find a lot of concepts to provide you with a foundation that can be applied to the skills required for the certification. While you can read this book cover to cover, for a substantial chunk of the subjects getting hands-on experience is essential. The concepts are often demonstrated through the use of tools. Following along with these demonstrations and using the tools yourself will help you understand the tools and how to use them. Many of the demonstrations are done in Kali Linux, though many of the tools have Windows analogs if you are more comfortable there.
We can't get through this without talking about ethics, and you will find it mentioned in several places throughout the book. This is serious, and not only because it's a huge part of the basis for the certification. It's also essential for protecting yourself and the people you are working for. The short version is do not do anything that would cause damage to systems or your employer. There is much more to it than that, which you'll read more about in Chapter 1, "Ethical Hacking," as a starting point. It's necessary to start wrapping your head around the ethics involved in this exam and profession. You will have to sign an agreement as part of achieving your certification.
At the end of each chapter, you will find a set of questions. This will help you to demonstrate to yourself that you understand the content. Most of the questions are multiple choice, which is the question format used for the CEH exam. These questions, along with the hands-on experience you take advantage of, will be good preparation for taking the exam.
What Is a CEH?
The purpose of the Certified Ethical Hacker exam is to validate that those holding the certification understand the broad range of subject matter that is required for someone to be an effective ethical hacker. The reality is that most days, if you are paying attention to the news, you will see a news story about a company that has been compromised and had data stolen, a government that has been attacked, or even enormous denial-of-service attacks, making it difficult for users to gain access to business resources.
The CEH is a certification that recognizes the importance of identifying security issues to get them remediated. This is one way companies can protect themselves against attacks-by getting there before the attackers do. It requires someone who knows how to follow techniques that attackers would normally use. Just running scans using automated tools is insufficient because as good as security scanners may be, they will identify false positives-cases where the scanner indicates an issue that isn't really an issue. Additionally, they will miss a lot of vulnerabilities-false negatives-for a variety of reasons, including the fact that the vulnerability or attack may not be known.
Because companies need to understand where they are vulnerable to attack, they need people who are able to identify those vulnerabilities, which can be very complex. Scanners are a good start, but being able to find holes in complex networks can take the creative intelligence that humans offer. This is why we need ethical hackers. These are people who can take extensive knowledge of a broad range of technical subjects and use it to identify vulnerabilities that can be exploited.
The important part of that two-word phrase, by the way, is "ethical." Companies have protections in place because they have resources they don't want stolen or damaged. When they bring in someone who is looking for vulnerabilities to exploit, they want to be certain that nothing will be stolen or damaged. They also must be certain that anything that may be seen or reviewed isn't shared with anyone else. This is especially true when it comes to any vulnerabilities that have been identified.
The CEH exam, then, has a dual purpose. It not only tests deeply technical knowledge but also binds anyone who is a certification holder to a code of conduct. Not only will you be expected to know the content and expectations of that code of conduct, but you will be expected to live by that code. When companies hire or contract people who have their CEH certification, they can be assured they have brought on someone with discretion who can keep their secrets and provide them with professional service in order to help improve their security posture and keep their important resources protected.
The Subject Matter
If you were to take the CEH v13 training, you would have to go through the following modules:
- Introduction to Ethical Hacking
- Footprinting and Reconnaissance
- Scanning Networks
- Enumeration
- Vulnerability Analysis
- System Hacking
- Malware Threats
- Sniffing
- Social Engineering
- Denial of Service
- Session Hijacking
- Evading IDSs, Firewalls, and Honeypots
- Hacking Web Servers
- Hacking Web Applications
- SQL Injection
- Hacking Wireless Networks
- Hacking Mobile Platforms
- IoT and OT Hacking
- Cloud Computing
- Cryptography
As you can see, the range of subjects is broad. Beyond knowing the concepts associated with these topics, you will be expected to know about various tools that may be used to perform the actions associated with the concepts you are learning. You will need to know tools like nmap for port scanning, for example. You may be required to know proxy-based web application attack tools. For wireless network attacks, you may have to know about the aircrack-ng suite of tools. For every module listed, potentially dozens of tools may be used.
The subject matter of the CEH exam is very technical. This is not a field in which you can get by with theoretical knowledge. You must have had experience with the methods and tools that are covered within the subject matter for the CEH exam. What you may also have noticed here is that the modules all fall within the different stages mentioned earlier. Although you may not necessarily be asked for a specific methodology, you will find that the contents of the exam do generally follow the methodology that the EC-Council believes to be a standard approach.
About the Exam
The CEH exam has much the same parameters as other professional certification exams. You will take a computerized, proctored exam. You will have 4 hours to complete 125 questions. That means you will have, on average, roughly 2 minutes per question. The questions are all multiple choice. The exam can be taken through the ECC Exam Center or at a Pearson VUE center. For details about VUE, please visit https://home.pearsonvue.com/eccouncil.
Should you want to take your certification even further, you could go after the CEH Practical exam. For this exam you must perform an actual penetration test and write a report at the end of it. This demonstrates that in addition to knowing the body of material covered by the exam, you can put that knowledge to use in a practical way. You will be expected to know how to compromise systems and identify vulnerabilities.
To pass the exam, you will have to correctly answer a certain number of questions, though the actual number will vary. The passing grade varies depending on the difficulty of the questions asked. The harder the questions that are asked out of the complete pool of questions, the fewer questions you need to get right to pass the exam. If you get easier questions, you will need to get more of the questions right to pass. There are some sources of information that will tell you that you must get 70 percent of the questions right, and that may be okay for general guidance and preparation as a rough low-end marker. However, keep in mind that when you sit down to take the actual test at the testing center, the passing grade will vary. The score you will need to achieve will range from 60 to 85 percent.
The good news is that you will know whether you passed before you leave the testing center. You will get your score when you finish the exam, and you will also be given a piece of paper indicating the details of your grade. You will receive feedback associated with the various scoring areas and...
System requirements
File format: ePUB
Copy protection: Adobe-DRM (Digital Rights Management)
System requirements:
- Computer (Windows; MacOS X; Linux): Install the free reader Adobe Digital Editions prior to download (see eBook Help).
- Tablet/smartphone (Android; iOS): Install the free app Adobe Digital Editions or the app PocketBook before downloading (see eBook Help).
- E-reader: Bookeen, Kobo, Pocketbook, Sony, Tolino and many more (not Kindle).
The file format ePub works well for novels and non-fiction books – i.e., „flowing” text without complex layout. On an e-reader or smartphone, line and page breaks automatically adjust to fit the small displays.
This eBook uses Adobe-DRM, a „hard” copy protection. If the necessary requirements are not met, unfortunately you will not be able to open the eBook. You will therefore need to prepare your reading hardware before downloading.
Please note: We strongly recommend that you authorise using your personal Adobe ID after installation of any reading software.
For more information, see our ebook Help page.