CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingA phase-by-phase CEH study plan: sequencing the v13 domains, choosing resources, using practice tests properly and knowing when you're ready to book.

Preparing for the Certified Ethical Hacker (CEH) exam is a coverage problem. The 312-50 knowledge exam asks 125 multiple-choice questions in 4 hours across the whole attack lifecycle — reconnaissance through cryptography — and EC-Council's cut score is a moving band between 60% and 85%, not a fixed mark you can aim to scrape. So an effective plan has one job: get you genuinely competent in every domain, including the ones your day job never touches, and prove it under timed conditions before you spend a voucher.
This guide gives you that plan: a four-phase structure, a prioritised domain sequence, a resource shortlist, and a practice-test method that measures readiness instead of flattering it. Background questions — eligibility routes, exact costs, the Practical exam, renewal — are the territory of the CEH certification guide for beginners, and if you're still deciding whether the exam's demands suit you at all, read how hard the CEH exam is before investing study weeks here.
Your eligibility route (official EC-Council training, or the $100 application with two years' infosec experience) decides whether courseware is handed to you or chosen by you. Either way, verify that everything you study is aligned to CEH v13 — the current version as of 2026, which integrates AI-driven techniques such as AI-assisted OSINT, vulnerability assessment and malware analysis into the standard exam. v12 was retired for new candidates when v13 launched in late 2024, and older-version materials leave gaps precisely where the exam is newest.
EC-Council publishes no official preparation-hours figure, and any fixed number you read is someone else's circumstances. Build your timeline backwards from coverage instead: count the domains, subtract the ones you already work in daily, and allocate study blocks to what remains, with extra weight on the areas furthest from your experience. A network administrator and a SOC analyst can follow the same plan below with completely different week counts and both be right.
CEH assumes fluency in TCP/IP, common ports and protocols, and Windows and Linux administration basics. If reading a port-scan output or navigating a Linux shell is not routine for you, schedule a foundations phase before touching CEH-specific material — skipping it is the most expensive shortcut in this exam, because every scenario question will tax you twice.
Start by finding out where you actually stand, not where you assume you stand.
The output of Phase 1 is a personal gap map. Everything after this is just executing it.
Work through your tiers in order. A sequence that works well for most candidates, because each block builds vocabulary the next one uses:
Weave the v13 AI-related techniques into their host domains as you meet them rather than treating "AI" as a separate cram topic — that's how the exam itself presents them.
For each domain, follow the same loop: read or watch the material, make your own one-page summary (tools, flags, ports, countermeasures — the exact details CEH questions name), then answer a small block of topic-specific questions to confirm the domain moved from "read" to "usable". If a domain's question block goes badly, loop once more before moving on; unresolved weak domains compound.
CEH's knowledge exam is multiple-choice, but candidates who have run the tools remember them at a different depth than candidates who have only read about them. You don't need a penetration-testing lab of OSCP grade — for contrast, preparing for OSCP is almost entirely lab work — but you should:
The goal is modest and specific: when a question quotes a tool's flag or output, you recognise it from your own terminal rather than from a flashcard. If the hands-on side of security is what draws you, note one sentence of signposting: the six-hour CEH Practical and the CEH Master designation exist beyond the knowledge exam, and the beginner's CEH guide explains where they fit.
This phase decides whether you book the exam or book more study time.
Use practice questions to test understanding of the exam objectives — never to memorise answers. A memorised bank fails you the moment the real exam rephrases a concept, and reasoning through unfamiliar questions is precisely the skill the 312-50 rewards.
You need surprisingly few resources, chosen deliberately:
Signals a resource deserves your money: it states v13 alignment, it organises content by the official domains, and its practice questions explain why answers are right. Signals to walk away: promises of "real exam questions", pass guarantees, or version-unspecified material.
Run this gate honestly. Book the exam when all of the following are true:
If the gate says yes, schedule while everything is fresh — a long gap between readiness and exam day quietly erodes the breadth you built. If it says no, it will also tell you exactly which domains to loop back to, which is the plan working as designed.
Spend the last two weeks consolidating rather than expanding: one timed mock at the start of the fortnight to set the agenda, targeted revision of whatever it flags, a lighter second mock a few days out, then domain summaries and rest. Confirm your logistics early — remote proctoring via the ECC Exam Portal has different set-up requirements from a Pearson VUE test centre, and exam-day technical stress is the one variable this plan can't revise away. Walk in knowing your preparation already answered the only question that matters: not "will I pass?", but "is there any domain where I'd be surprised by a question?" If you've followed the four phases, the answer is no — and once the certificate arrives, the CEH career path guide covers what it opens next.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading