Skip to content

CEH Master Strategy - 8-Week Study Plan + Decision Matrix

CEH Master Strategy — 8-Week Study Plan + Decision Matrix

Section titled “CEH Master Strategy — 8-Week Study Plan + Decision Matrix”

Pair with: research/ for deep dives · 99-cheatsheet.md for last-mile review


Decision Recommendation
Should I take CEH? Yes if you want HR-friendly + DoD-approved + balanced theory+practical. If you only want pure offensive credibility, take OSCP instead.
Which version? CEH v13 (current as of Aug 2026). It adds AI/LLM attack surface, cloud-native, and updated MITRE ATT&CK alignment.
Eligibility path ANSI self-study path if you have 2+ years of verifiable infosec work experience and an employer reference. Otherwise official training.
Cost (Singapore) ~S$2,200 sticker; with SkillsFuture SSG funding: S$75–S$317 effective.
Study time 8–10 weeks part-time (≈ 8–12 hours/week).
Best hands-on combo TryHackMe (CEH-aligned paths) + PortSwigger Web Security Academy (free) + HTB Academy (CPTS) for credibility.
Exam booking Pearson VUE or ECC test center, ID = passport, reschedule ≥ 48h before.
Pass threshold ~70% (CEH uses a statistical cut score, not fixed %).

Week Focus Resources Output
0 Setup Install Kali VM, create THM + PortSwigger accounts, register EC-Council candidate account Lab ready
1 Domain 1+2 — Threats & Defense research/02-domain-1-2-threats-defense.md · THM “Intro to Cyber Security” path · MITRE ATT&CK 101 Flashcards for 7 Kill Chain phases + 14 ATT&CK tactics
2 Domain 3.A — Recon & Scanning research/03-domain-3a-reconnaissance.md · Nmap Reference Guide · THM “Nmap” room · TryHackMe “Mr. Robot CTF” Nmap muscle memory · Cheat sheet of -s* flags
3 Domain 3.B — System/Network Attacks research/04-domain-3b-system-network-attacks.md · THM “Attacktive Directory” + “Post-Exploitation Basics” · HTB Academy “Bug Bounty Hunter” intro Exploit one box, document the 5-phase CEH methodology in your own words
4 Domain 3.C — Web/SQL/Wireless/Mobile/IoT/Cloud/Crypto research/05-domain-3c-app-crypto-cloud.md · PortSwigger Web Security Academy (all Apprentice labs, especially SQLi, XSS, access control, SSRF) · THM “SQL Injection” + “Wireless” rooms Complete the PortSwigger Apprentice tier (~30 labs)
5 Domain 3.C continued — Cloud + IoT/OT Same doc · TryHackMe “Cloud Fundamentals” + “Containers” + “Kubernetes” rooms · Dragos “PIPEDREAM” white paper Understand the shared responsibility model + Purdue model
6 Domain 4 — Procedures & Legal research/06-domain-4-procedures-legal.md · Read PTES standard end-to-end · Review SG PDPA + CMCA Write a 2-page sample pen-test report on the box from Week 3
7 Tools deep-dive + mock exam research/07-tools-labs-and-practice-plan.md · Boson CEH practice exam (or EC-Council official practice test) · HTB 2 boxes (TJ Null list) Score ≥ 80% on practice test. If < 75%, schedule exam 2 weeks out and remediate.
8 Review + exam 99-cheatsheet.md end-to-end · Re-do your weakest domain · Schedule exam at Pearson VUE Take exam

Optional Week 9–10: buffer for any domain < 80% on practice test. Specifically: if you keep missing crypto, add 1hr/day on research/05 § Cryptography.


Full version in research/08-career-market-and-comparison.md. Summary:

Cert Cost (USD) Format Theory/Practical Best for CEH match
CEH v13 $1,199 (voucher); S$2,200 SG 4h MCQ 70/30 HR recognition, DoD 8140, mid-career breadth
OSCP $1,749 + PEN-200 course 24h practical 10/90 Pure offensive credibility, technical HR Different
CompTIA PenTest+ $404 165min MCQ + perf-based 60/40 Mid-level federal resume builders Adjacent
PNPT (TCM) $399 5-day practical + report 20/80 Cheapest practical credibility Better ROI/practical
HTB CPTS $210 Practical exam 5/95 Cheapest hands-on cert, no-name recognition Best $/credibility
BSCP $99 (free training) 4h practical web 5/95 Web app specialists Different niche
GPEN (SANS) $8,000+ 3h MCQ + 1 day lab 60/40 Enterprise/government, SANS alumni Comparable, more $
eCPPT (INE) $499 7-day practical 20/80 Network pen-test focus Cheaper, similar ROI
  • Choose CEH if: HR/recruiter screen | DoD 8140 needed | resume padding | government role
  • Choose OSCP if: pentest job | red team | “can I actually break it” matters | no exam budget concern
  • Choose PNPT if: $400 budget | want hands-on | TCM-aligned study
  • Choose HTB CPTS if: $210 budget | hands-on only | don’t care about HR
  • Choose BSCP if: web app pentester | $99 budget
  • Choose PenTest+ if: federal resume | need CompTIA badge

Item Status / Action
CEH recognized in SG? Yes — by CSA (Cyber Security Agency), IMDA, and most enterprise employers (DBS, OCBC, GovTech, Singtel).
SkillsFuture funding Course is on SSG’s list. CEH-via-ATC training gets up to 70% subsidy for citizens/PRs. Effective cost drops to S$75–S$317 for eligible candidates.
Voucher alone (no training)? Not SkillsFuture-subsidised. Must pay ~S$2,200 out-of-pocket.
Where to sit exam Pearson VUE centres: Bugis Junction, International Plaza, Tampines, Jurong East. ECC exam centre: limited.
ID required Passport (NRIC not accepted for international ID requirement).
Salary uplift PayScale SG reports ~S$75K median base for CEH holders; senior pentesters reach S$120K–S$180K+ with OSCP.
Common SG employers GovTech, CSA, DSO, Singtel, DBS, OCBC, UOB, ST Engineering, NUS/SMU internal security, ByteDance SG, Google SG (some).
LinkedIn SG CEH tag Add “EC-Council Certified Ethical Hacker (CEH)” to your Skills section.

  1. Treating CEH as theory-only. The exam has scenario-based questions. If you only memorised, you’ll fail scenario questions. Do hands-on.
  2. Ignoring Domain 4 (legal/procedures). ~12% of the exam. Most candidates underprep this. Easy points.
  3. Skipping PortSwigger. Web attacks are 15–20% of the exam. PortSwigger Apprentice labs are free and the fastest way to internalise SQLi/XSS/SSRF.
  4. Reading outdated study guides. Many third-party books still predate v12. Use only the v12/v13-aligned material from EC-Council or recent (2024–2026) third-party.
  5. Booking exam before practice test. Take Boson or EC-Council official practice test first. Score ≥ 80% before booking.
  6. Not doing MITRE ATT&CK hands-on. The exam tests phases, not just definitions. Open ATT&CK Navigator, pick a real attack (e.g., APT29), and follow it.

Time / Cost Summary (SG Resident, ANSI Path)

Section titled “Time / Cost Summary (SG Resident, ANSI Path)”
Line item Estimate
Exam voucher (EC-Council, no training) S$2,200
Or: official training (5-day bootcamp) +S$3,500–S$6,500
SkillsFuture subsidy (training path only) −S$1,200 to −S$2,300
Net out-of-pocket (training path with subsidy) S$75–S$317
Net out-of-pocket (ANSI self-study, no subsidy) S$2,200
TryHackMe 1-month premium S$20 (optional)
HTB Academy 6-month S$120 (optional)
PortSwigger Web Security Academy Free
Boson CEH practice exam S$120 (optional)
Total realistic budget (ANSI path) S$2,200–S$2,460
Total realistic budget (training path, subsidised) S$500–S$1,800

  1. Update LinkedIn with the cert, “EC-Council CEH” badge, and a 1-line project about a lab you completed.
  2. Submit ECE credits to start the 3-year recert cycle.
  3. Stack your next cert. Common path: CEH → HTB CPTSOSCPOSWE (web specialist) or CRTP (Active Directory).
  4. Consider the practical (CEH Practical) for the “Master” badge — adds ~S$700 to the cost, gives you a real pen-test report deliverable.
  5. Join the community: EC-Council forum, r/CEH, TCM Discord, HackTheBox Discord, Intigriti (bug bounty).

Pre-Flight Checklist Before Booking the Exam

Section titled “Pre-Flight Checklist Before Booking the Exam”
  • Eligibility application approved (if ANSI path)
  • Pearson VUE account created
  • Passport valid for ≥ 6 months past exam date
  • Practice test score ≥ 80% (Boson or official)
  • Reviewed 99-cheatsheet.md once in the last 7 days
  • Booked ≥ 5 business days ahead (some centres fully booked on Saturdays)
  • Read research/01-exam-logistics.md § Exam Day rules

Schedule it the day you hit 80%+ on the practice test. Don’t let preparation drift.