Pair with: research/ for deep dives · 99-cheatsheet.md for last-mile review
| Decision |
Recommendation |
| Should I take CEH? |
Yes if you want HR-friendly + DoD-approved + balanced theory+practical. If you only want pure offensive credibility, take OSCP instead. |
| Which version? |
CEH v13 (current as of Aug 2026). It adds AI/LLM attack surface, cloud-native, and updated MITRE ATT&CK alignment. |
| Eligibility path |
ANSI self-study path if you have 2+ years of verifiable infosec work experience and an employer reference. Otherwise official training. |
| Cost (Singapore) |
~S$2,200 sticker; with SkillsFuture SSG funding: S$75–S$317 effective. |
| Study time |
8–10 weeks part-time (≈ 8–12 hours/week). |
| Best hands-on combo |
TryHackMe (CEH-aligned paths) + PortSwigger Web Security Academy (free) + HTB Academy (CPTS) for credibility. |
| Exam booking |
Pearson VUE or ECC test center, ID = passport, reschedule ≥ 48h before. |
| Pass threshold |
~70% (CEH uses a statistical cut score, not fixed %). |
| Week |
Focus |
Resources |
Output |
| 0 |
Setup |
Install Kali VM, create THM + PortSwigger accounts, register EC-Council candidate account |
Lab ready |
| 1 |
Domain 1+2 — Threats & Defense |
research/02-domain-1-2-threats-defense.md · THM “Intro to Cyber Security” path · MITRE ATT&CK 101 |
Flashcards for 7 Kill Chain phases + 14 ATT&CK tactics |
| 2 |
Domain 3.A — Recon & Scanning |
research/03-domain-3a-reconnaissance.md · Nmap Reference Guide · THM “Nmap” room · TryHackMe “Mr. Robot CTF” |
Nmap muscle memory · Cheat sheet of -s* flags |
| 3 |
Domain 3.B — System/Network Attacks |
research/04-domain-3b-system-network-attacks.md · THM “Attacktive Directory” + “Post-Exploitation Basics” · HTB Academy “Bug Bounty Hunter” intro |
Exploit one box, document the 5-phase CEH methodology in your own words |
| 4 |
Domain 3.C — Web/SQL/Wireless/Mobile/IoT/Cloud/Crypto |
research/05-domain-3c-app-crypto-cloud.md · PortSwigger Web Security Academy (all Apprentice labs, especially SQLi, XSS, access control, SSRF) · THM “SQL Injection” + “Wireless” rooms |
Complete the PortSwigger Apprentice tier (~30 labs) |
| 5 |
Domain 3.C continued — Cloud + IoT/OT |
Same doc · TryHackMe “Cloud Fundamentals” + “Containers” + “Kubernetes” rooms · Dragos “PIPEDREAM” white paper |
Understand the shared responsibility model + Purdue model |
| 6 |
Domain 4 — Procedures & Legal |
research/06-domain-4-procedures-legal.md · Read PTES standard end-to-end · Review SG PDPA + CMCA |
Write a 2-page sample pen-test report on the box from Week 3 |
| 7 |
Tools deep-dive + mock exam |
research/07-tools-labs-and-practice-plan.md · Boson CEH practice exam (or EC-Council official practice test) · HTB 2 boxes (TJ Null list) |
Score ≥ 80% on practice test. If < 75%, schedule exam 2 weeks out and remediate. |
| 8 |
Review + exam |
99-cheatsheet.md end-to-end · Re-do your weakest domain · Schedule exam at Pearson VUE |
Take exam |
Optional Week 9–10: buffer for any domain < 80% on practice test. Specifically: if you keep missing crypto, add 1hr/day on research/05 § Cryptography.
Full version in research/08-career-market-and-comparison.md. Summary:
| Cert |
Cost (USD) |
Format |
Theory/Practical |
Best for |
CEH match |
| CEH v13 |
$1,199 (voucher); S$2,200 SG |
4h MCQ |
70/30 |
HR recognition, DoD 8140, mid-career breadth |
— |
| OSCP |
$1,749 + PEN-200 course |
24h practical |
10/90 |
Pure offensive credibility, technical HR |
Different |
| CompTIA PenTest+ |
$404 |
165min MCQ + perf-based |
60/40 |
Mid-level federal resume builders |
Adjacent |
| PNPT (TCM) |
$399 |
5-day practical + report |
20/80 |
Cheapest practical credibility |
Better ROI/practical |
| HTB CPTS |
$210 |
Practical exam |
5/95 |
Cheapest hands-on cert, no-name recognition |
Best $/credibility |
| BSCP |
$99 (free training) |
4h practical web |
5/95 |
Web app specialists |
Different niche |
| GPEN (SANS) |
$8,000+ |
3h MCQ + 1 day lab |
60/40 |
Enterprise/government, SANS alumni |
Comparable, more $ |
| eCPPT (INE) |
$499 |
7-day practical |
20/80 |
Network pen-test focus |
Cheaper, similar ROI |
- Choose CEH if: HR/recruiter screen | DoD 8140 needed | resume padding | government role
- Choose OSCP if: pentest job | red team | “can I actually break it” matters | no exam budget concern
- Choose PNPT if: $400 budget | want hands-on | TCM-aligned study
- Choose HTB CPTS if: $210 budget | hands-on only | don’t care about HR
- Choose BSCP if: web app pentester | $99 budget
- Choose PenTest+ if: federal resume | need CompTIA badge
| Item |
Status / Action |
| CEH recognized in SG? |
Yes — by CSA (Cyber Security Agency), IMDA, and most enterprise employers (DBS, OCBC, GovTech, Singtel). |
| SkillsFuture funding |
Course is on SSG’s list. CEH-via-ATC training gets up to 70% subsidy for citizens/PRs. Effective cost drops to S$75–S$317 for eligible candidates. |
| Voucher alone (no training)? |
Not SkillsFuture-subsidised. Must pay ~S$2,200 out-of-pocket. |
| Where to sit exam |
Pearson VUE centres: Bugis Junction, International Plaza, Tampines, Jurong East. ECC exam centre: limited. |
| ID required |
Passport (NRIC not accepted for international ID requirement). |
| Salary uplift |
PayScale SG reports ~S$75K median base for CEH holders; senior pentesters reach S$120K–S$180K+ with OSCP. |
| Common SG employers |
GovTech, CSA, DSO, Singtel, DBS, OCBC, UOB, ST Engineering, NUS/SMU internal security, ByteDance SG, Google SG (some). |
| LinkedIn SG CEH tag |
Add “EC-Council Certified Ethical Hacker (CEH)” to your Skills section. |
- Treating CEH as theory-only. The exam has scenario-based questions. If you only memorised, you’ll fail scenario questions. Do hands-on.
- Ignoring Domain 4 (legal/procedures). ~12% of the exam. Most candidates underprep this. Easy points.
- Skipping PortSwigger. Web attacks are 15–20% of the exam. PortSwigger Apprentice labs are free and the fastest way to internalise SQLi/XSS/SSRF.
- Reading outdated study guides. Many third-party books still predate v12. Use only the v12/v13-aligned material from EC-Council or recent (2024–2026) third-party.
- Booking exam before practice test. Take Boson or EC-Council official practice test first. Score ≥ 80% before booking.
- Not doing MITRE ATT&CK hands-on. The exam tests phases, not just definitions. Open ATT&CK Navigator, pick a real attack (e.g., APT29), and follow it.
| Line item |
Estimate |
| Exam voucher (EC-Council, no training) |
S$2,200 |
| Or: official training (5-day bootcamp) |
+S$3,500–S$6,500 |
| SkillsFuture subsidy (training path only) |
−S$1,200 to −S$2,300 |
| Net out-of-pocket (training path with subsidy) |
S$75–S$317 |
| Net out-of-pocket (ANSI self-study, no subsidy) |
S$2,200 |
| TryHackMe 1-month premium |
S$20 (optional) |
| HTB Academy 6-month |
S$120 (optional) |
| PortSwigger Web Security Academy |
Free |
| Boson CEH practice exam |
S$120 (optional) |
| Total realistic budget (ANSI path) |
S$2,200–S$2,460 |
| Total realistic budget (training path, subsidised) |
S$500–S$1,800 |
- Update LinkedIn with the cert, “EC-Council CEH” badge, and a 1-line project about a lab you completed.
- Submit ECE credits to start the 3-year recert cycle.
- Stack your next cert. Common path: CEH → HTB CPTS → OSCP → OSWE (web specialist) or CRTP (Active Directory).
- Consider the practical (CEH Practical) for the “Master” badge — adds ~S$700 to the cost, gives you a real pen-test report deliverable.
- Join the community: EC-Council forum, r/CEH, TCM Discord, HackTheBox Discord, Intigriti (bug bounty).
Schedule it the day you hit 80%+ on the practice test. Don’t let preparation drift.