CEH v13 AI – STUDY GUIDE, PRACTICAL EXERCISES, AND TRAINING PLAN: 3 MONTHS THEORY - 6 MONTHS PRACTICE

CEH v13 AI – HƯỚNG DẪN HỌC TẬP, THỰC HÀNH VÀ KẾ HOẠCH ĐÀO TẠO 03 THÁNG LÝ THUYẾT - 6 THÁNG THỰC HÀNH

STUDY GUIDE AND TRAINING PLAN

CERTIFIED ETHICAL HACKER – CEH v13 AI

Theoretical study time: 03 months & Practical training for 6 months combined on ECCOUNCIL CyberQ LAB CEH v13.

Students need to update their progress to their instructor via the class group.

1. Purpose of this document

This document specifies the study methodology and training progress for students participating in the Certified Ethical Hacker – CEH v13 AI program at Security365.

Students must carefully read the instructions before starting and maintain the correct study sequence throughout the program.

CEH v13 AI is a program with a broad scope of knowledge, including system security, networks, Web applications, Malware, Wireless, Mobile, IoT/OT, Cloud, Cryptography, and many other Ethical Hacking techniques.

Therefore, students should not approach the course by sequentially watching all videos before starting practical exercises.

The program at Security365 is organized according to the principle of:

Building foundational knowledge → Learning official content → Reinforcing knowledge → Practicing → Reviewing and assessing.

Throughout the 03 months, students must study both theory and practice simultaneously according to the guided progress.


2. Program learning resources

CEH v13 AI students at Security365 utilize various learning resource groups. Each group has a specific purpose and should be used appropriately.

2.1. Vietnamese theoretical materials

Security365 provides a set of Vietnamese materials based on CEH fundamental topics.

The purpose of these materials is to help students:

  • Form an overall understanding before in-depth study.

  • Become familiar with important concepts and terminology.

  • Understand the context of each group of techniques.

  • Conveniently look up and review during the learning process.

This is the learning resource that students should approach first for each topic.

Students do not need to memorize the material during the first reading. The requirement for this step is to form a knowledge framework so that subsequent lectures can be approached more systematically.


2.2. Vietnamese theoretical Audio

Audio content is developed corresponding to many topics in the program.

Audio serves to:

  • Reinforce content already read.

  • Help students become familiar with specialized terminology.

  • Support repeated review.

  • Utilize time outside of official study hours.

Students can listen to Audio on their computer or phone.

Audio is a supplementary learning resource and does not replace official lectures or practical exercises.


2.3. Vietnamese video lectures

Security365 provides Vietnamese videos corresponding to many CEH topics such as:

  • Ethical Hacking.

  • Footprinting and Reconnaissance.

  • Scanning.

  • Enumeration.

  • System Hacking.

  • Trojan and Backdoor.

  • Virus and Worm.

  • Sniffing.

  • Social Engineering.

  • Denial-of-Service.

  • Session Hijacking.

  • Web Server Security.

  • Web Application Security.

  • SQL Injection.

  • Wireless Security.

  • IDS, Firewall and Honeypot.

  • Buffer Overflow.

  • Cryptography.

  • Penetration Testing.

Vietnamese videos help students systematize their knowledge after reading the materials and facilitate easier access to English lectures.


3. Official CEH v13 AI lectures

This is the main and mandatory learning resource of the program.

Students need to log in to the LMS Security365 system with their assigned account to study the official CEH v13 AI lectures.

The lectures are presented in English with subtitles.

Directly studying the official content has important objectives:

  • Ensuring students access the correct CEH v13 AI program.

  • Familiarizing themselves with English specialized terminology.

  • Understanding how EC-Council presents concepts, techniques, and tools.

  • Preparing for practical exercises.

  • Building a foundation for the CEH certification exam later.

Vietnamese materials are not to be used as a substitute for this section.


4. CEH v13 lectures in Vietnamese on Telegram

In parallel with the official lectures, Security365 will provide students with Vietnamese theoretical lectures built on 100% of the official CEH v13 content.

These lectures are provided through the course's Telegram study group.

Content will be updated according to the training progress, instead of being provided entirely from the start.

This method aims to ensure students:

  • Focus on the content they are currently studying.

  • Are not overwhelmed by a large volume of materials.

  • Have Vietnamese materials corresponding to each stage.

  • Can cross-reference between Vietnamese lectures and official lectures.

  • Follow the general curriculum of the program.

For example, when the program is studying Footprinting and Reconnaissance, content related to OSINT, Footprinting, WHOIS, DNS, Website Reconnaissance, and information gathering methods will be updated accordingly.

When moving on to Scanning Networks, students continue to receive content related to Host Discovery, Port Scanning, Service Detection, OS Detection, and appropriate tools.

The Telegram group is therefore an official component of the training system, not just a place for information exchange.

Students need to regularly monitor the updated content in the group.


5. CEH v13 iLAB practical section

CEH is an Ethical Hacking training program. Therefore, completing the theory does not mean completing a topic.

After the theoretical part, students must complete the CEH v13 iLAB exercises and assigned practical content.

The objectives of the practical section are to help students:

  • Directly use the introduced tools.

  • Understand the function of each tool.

  • Observe and analyze results.

  • Understand the relationship between theory and practical operations.

  • Develop skills instead of just memorizing concepts.

For example, when studying Network Scanning, students not only need to know that Nmap is a network scanning tool.

Students need to actually perform scanning operations, identify Hosts, Ports, Services, Operating Systems, and analyze the returned results.

Similarly, for Web Application, SQL Injection, Sniffing, Wireless Hacking, or System Hacking, the practical part must be conducted in parallel with the corresponding theoretical content.


6. Mandatory study sequence for each topic

To maintain consistency throughout the course, students should follow this sequence for each Module.

Phase 1 – Building the knowledge framework

Step 1. Skim Vietnamese materials

Before watching the lecture, students should read the corresponding Vietnamese materials.

The initial reading time can be about 15–30 minutes depending on the topic.

At this stage, memorizing details is not required.

Students need to identify:

  • What the topic being studied is about.

  • What the attacker's objective is.

  • Key concepts.

  • Key techniques.

  • Commonly mentioned tools.

  • Basic prevention measures.

After this step, students should have an overview of the content to be learned.


Phase 2 – Familiarization and knowledge reinforcement in Vietnamese

Step 2. Listen to the corresponding Audio

After reading the materials, students listen to the Audio for the topic.

The goal is to reinforce the concepts just introduced and increase familiarity with terminology.

Step 3. Watch the Vietnamese Video

Next, students watch the corresponding Vietnamese Video.

At this stage, focus on the relationship between:

Concept – Technique – Tool – Risk – Prevention Measure.

Students are not required to memorize the names of all tools appearing during the first learning attempt.

It is more important to understand when and for what purpose a tool is used.


7. Studying official lectures in parallel

After having foundational knowledge, students begin or continue studying the official CEH v13 AI lectures in English with subtitles.

This section should be done in parallel with the Vietnamese videos and Vietnamese lectures on Telegram.

Students should pay special attention to English terminology.

For example:

  • Footprinting

  • Reconnaissance

  • Scanning

  • Enumeration

  • Vulnerability Analysis

  • Privilege Escalation

  • Session Hijacking

  • SQL Injection

  • Defense Evasion

  • Cryptography

During the learning process, students need to understand the content in Vietnamese but at the same time must recognize and use specialized terminology in English.

This is a necessary requirement for both the CEH learning process and the certification exam later.


8. Standard sequence of a Module

For each Module, students follow the sequence:

1. Read Vietnamese materials to form the knowledge framework.

2. Listen to the corresponding Audio.

3. Watch the Vietnamese Video.

4. Study the official CEH v13 AI lectures on LMS.

5. Study the Vietnamese CEH v13 content updated on Telegram.

6. Complete the corresponding CEH v13 iLAB exercises.

7. Re-watch or re-listen to sections not fully grasped.

8. Summarize key terminology, tools, and techniques of the Module.

Only after completing this cycle should students move on to the next Module.

In cases where a Module has a large volume of content, theoretical and practical study may extend over multiple sessions.


9. Content of the 20 official CEH v13 AI Modules

Module 01 – Introduction to Ethical Hacking

Foundations of Ethical Hacking, Information Security, types of hackers, attack phases, methods, and mindset of an Ethical Hacker.

Module 02 – Footprinting and Reconnaissance

OSINT, Footprinting, Reconnaissance, gathering information about organizations, domains, DNS, websites, personnel, and target infrastructure.

Module 03 – Scanning Networks

Host Discovery, Port Scanning, Service Detection, OS Detection, and Network Scanning methods.

Module 04 – Enumeration

Enumeration on SMB, NetBIOS, SNMP, LDAP, DNS, SMTP, and network services.

Module 05 – Vulnerability Analysis

Vulnerability Assessment, CVE, CVSS, Vulnerability Scanner, analysis and evaluation of vulnerabilities.

Module 06 – System Hacking

Password Attack, Exploitation, Privilege Escalation, Maintaining Access, and Covering Tracks.

Module 07 – Malware Threats

Virus, Worm, Trojan, Backdoor, Ransomware, Rootkit, Spyware, and various Malware groups.

Module 08 – Sniffing

Packet Sniffing, ARP Poisoning, Man-in-the-Middle, and network traffic analysis.

Module 09 – Social Engineering

Phishing, Spear Phishing, Vishing, Smishing, Impersonation, and forms of Social Engineering.

Module 10 – Denial-of-Service

DoS, DDoS, Botnet, Flooding, and detection/mitigation methods.

Module 11 – Session Hijacking

Session Token, Cookie, TCP Session Hijacking, and Web Session Hijacking.

Module 12 – Evading IDS, Firewalls, and Honeypots

IDS/IPS, Firewall, Honeypot, and Defense Evasion techniques.

Module 13 – Hacking Web Servers

Web Server Enumeration, Vulnerability, Misconfiguration, and Web Server Security.

Module 14 – Hacking Web Applications

Web Application Architecture, Authentication, Authorization, and types of Web application vulnerabilities.

Module 15 – SQL Injection

SQL Injection techniques, exploitation, detection, and prevention methods.

Module 16 – Hacking Wireless Networks

Wireless Architecture, Wi-Fi Security, WEP, WPA/WPA2/WPA3, and wireless network attack techniques.

Module 17 – Hacking Mobile Platforms

Android, iOS, Mobile Application Security, and threats to mobile devices.

Module 18 – IoT and OT Hacking

IoT Security, Operational Technology, ICS/SCADA, and threats to IoT/OT systems.

Module 19 – Cloud Computing

Cloud Architecture, IaaS, PaaS, SaaS, Cloud Security, and risks in the Cloud environment.

Module 20 – Cryptography

Encryption, Hashing, Symmetric and Asymmetric Cryptography, Digital Signature, PKI, and SSL/TLS.


10. 3-month training plan

The program is organized over approximately 12 weeks.

FIRST MONTH

Building Ethical Hacking Foundations

Week 1

  • Module 01 – Introduction to Ethical Hacking

  • Module 02 – Footprinting and Reconnaissance

Objective: understand the overall structure of an Ethical Hacking process and methods for gathering target information.

Week 2

  • Module 03 – Scanning Networks

  • Module 04 – Enumeration

Objective: understand the transition from Reconnaissance to actively identifying Hosts, Ports, Services, and technical system information.

Week 3

  • Module 05 – Vulnerability Analysis

  • Module 06 – System Hacking

Objective: understand the relationship between vulnerability detection and system exploitation.

Practical exercises should be intensified from this stage.

Week 4

  • Module 07 – Malware Threats

  • Complete remaining Labs from the first month.

  • Review Modules 01–07.

Requirements at the end of the first month

Students must understand the relationship:

Reconnaissance → Scanning → Enumeration → Vulnerability Analysis → Exploitation.


11. SECOND MONTH

Network Security and Web Security

Week 5

  • Module 08 – Sniffing

  • Module 09 – Social Engineering

Week 6

  • Module 10 – Denial-of-Service

  • Module 11 – Session Hijacking

Week 7

  • Module 12 – Evading IDS, Firewalls, and Honeypots

  • Module 13 – Hacking Web Servers

Week 8

  • Module 14 – Hacking Web Applications

  • Module 15 – SQL Injection

Modules 13, 14, and 15 require students to dedicate significant time to practical exercises.

It is especially important to clearly distinguish between:

Web Server Security

and

Web Application Security.

At the same time, students must understand the role of SQL Injection in the process of Web application security testing.

Requirements at the end of the second month

Students must understand the relationship:

Network Attack → Session Attack → Defense Evasion → Web Server → Web Application → Database.


12. THIRD MONTH

Wireless, Mobile, IoT/OT, Cloud and Cryptography

Week 9

  • Module 16 – Hacking Wireless Networks

  • Practice Wireless Security according to assigned content.

Week 10

  • Module 17 – Hacking Mobile Platforms

  • Module 18 – IoT and OT Hacking

Week 11

  • Module 19 – Cloud Computing

  • Module 20 – Cryptography

Week 12 – Comprehensive Review

The final week is used for:

  • Completing any missing Lab assignments.

  • Reviewing Modules that have not met requirements.

  • Systematizing specialized terminology.

  • Consolidating learned tools.

  • Reviewing attack and defense techniques.

  • Answering practice questions.

  • Taking a Mock Exam.

  • Assessing readiness before moving to the exam preparation phase.


13. Requirements for students during the course

Students need to proactively manage their progress and avoid leaving Modules pending for extended periods.

For each topic, students must meet at least the following four requirements:

1. Understand the concept

Be able to explain what the technique being studied is and its purpose.

2. Understand the technique's position in the attack process

Be able to identify whether the technique belongs to the Reconnaissance, Scanning, Enumeration, Exploitation, Post-Exploitation, or Defense phase.

3. Identify key tools

Know what task the tool is used for, instead of just memorizing the tool's name.

4. Ability to practice

For content with Labs, students must independently perform and analyze the results.


14. Self-assessment method after each Module

After completing a Module, students should be able to answer the following questions:

1. What is the objective of the recently learned technique?

2. What information or conditions does an attacker need before executing it?

3. What are the main tools used?

4. What do the tool's results indicate?

5. How does this technique relate to the previous and subsequent Modules?

6. How can this technique be detected?

7. How can it be prevented or mitigated?

If students cannot answer these questions, they should review the content before moving on to the next topic.


15. Program training principles

The CEH v13 AI program at Security365 is not organized according to the method:

Watch all videos → memorize questions → take the exam.

The training objective is to establish a complete cycle:

Foundational knowledge

→ Official CEH content

→ Explanation and reinforcement in Vietnamese

→ Practice

→ Result analysis

→ Review

→ Assessment

→ Preparation for certification exam

Where:

Vietnamese materials help build the knowledge framework.

Audio supports content reinforcement and repetition.

Vietnamese videos help systematize knowledge.

Official CEH v13 AI lectures are the primary learning resource.

Vietnamese lectures on Telegram closely follow CEH v13 content and are updated according to training progress.

CEH v13 iLAB is the practical component of the program.

Practice Tests and Mock Exams are used during the assessment and exam preparation phase.


16. Expected outcomes after 03 months

Upon successful completion of the plan, students are expected to achieve three main outcomes.

Regarding knowledge

Understand the structure and main content of 20 CEH v13 AI Modules.

Regarding skills

Be able to perform and explain important practical exercises within the program's scope.

Regarding mindset

Understand the entire cycle:

Reconnaissance → Scanning → Enumeration → Vulnerability Analysis → Exploitation → Post-Exploitation → Detection & Countermeasures.

This is the foundation for students to move on to the phase of comprehensive review, Mock Exam practice, and preparation for the Certified Ethical Hacker certification exam.

Security365 requires students to consider this plan as their official learning roadmap for the first 03 months and proactively adhere to the schedule to achieve the best results from the CEH v13 AI program.