Certified Ethical Hacker (CEH) Exam Preparation

A two-day intensive across the CEH attack lifecycle, written for defenders who need to understand offence properly. The value of this material is not that it turns anyone into a penetration tester in two days. It is that a security team which has walked the attack chain from reconnaissance through to covering tracks stops guessing about which controls actually matter, and starts reading its own telemetry the way an attacker would.

The programme follows the CEH domain structure and pairs each offensive technique with the detection and countermeasure that answers it, which is also how the exam frames its questions. The recent revision of the certification adds AI-assisted offensive tooling throughout, and that is covered here rather than treated as a novelty. This is exam preparation rather than accredited delivery, and it is not a licensed EC-Council course: participants pursuing certification arrange the exam and any eligibility requirements separately. All practical work is done against a lab environment, and the legal boundary under Malaysian law, including the Computer Crimes Act 1997, is covered on day one and taken seriously.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

Day 1, 9:00 AM - 9:15 AM

Welcome and Exam Orientation

Exam format, domain coverage, and how CEH questions are framed. Setting the two-day plan.

02

Day 1, 9:15 AM - 10:15 AM

Ethical Hacking Fundamentals and the Legal Boundary

Information security fundamentals, the cyber kill chain and the MITRE ATT&CK framework. Hacker classes and the attack lifecycle. Where authorised testing begins and ends: scope, rules of engagement, written authorisation and the get-out-of-jail letter. Malaysian legal context including the Computer Crimes Act 1997, and how PDPA obligations constrain what a tester may collect and retain. Why an unauthorised scan of a third party is a criminal matter regardless of intent.

03

Day 1, 10:15 AM - 10:30 AM

Break

04

Day 1, 10:30 AM - 12:00 PM

Reconnaissance and Footprinting

Passive and active reconnaissance. OSINT: search engines, web services, social networking, WHOIS, DNS and network footprinting. Email and website footprinting. Automated OSINT tooling and, in the current revision, AI-assisted collection and summarisation of a target's public surface. Countermeasures, and the practical exercise of footprinting the participants' own organisation to see what an attacker already has for free. This exercise is usually the moment the room goes quiet.

05

Day 1, 12:00 PM - 1:00 PM

Scanning and Enumeration

Host discovery, port and service scanning, scan techniques and evasion. OS fingerprinting. Enumeration across NetBIOS, SNMP, LDAP, NTP, SMTP, DNS and SMB. Reading scan output critically rather than trusting it. Detection: what each scan type looks like in your own logs, which is the half most offensive courses skip.

06

Day 1, 1:00 PM - 2:00 PM

Lunch

07

Day 1, 2:00 PM - 3:15 PM

Vulnerability Analysis and System Hacking

Vulnerability classification, assessment types and tooling, and interpreting a scanner report against real exploitability. System hacking: gaining access through password attacks, cracking and credential theft. Privilege escalation. Maintaining access, persistence mechanisms and rootkits. Clearing tracks and log tampering, together with the anti-forensic indicators that expose it.

08

Day 1, 3:15 PM - 3:30 PM

Break

09

Day 1, 3:30 PM - 5:00 PM

Malware, Sniffing and Social Engineering

Malware families: trojans, viruses, worms, fileless malware and APT behaviour. Static and dynamic malware analysis at an introductory level. Sniffing techniques including MAC and DHCP attacks, ARP poisoning, spoofing and DNS poisoning, plus the countermeasures. Social engineering techniques, insider threats, impersonation and identity theft, and how AI-generated voice and video have changed the credibility of a pretext.

10

Day 2, 9:00 AM - 9:15 AM

Day 1 Review

11

Day 2, 9:15 AM - 10:30 AM

Denial of Service, Session Hijacking and Evasion

Denial of service and distributed denial of service techniques, botnets, and detection and mitigation. Session hijacking at the application and network level. Evading intrusion detection, firewalls and honeypots, and what a defender should conclude from evidence of evasion in their own environment.

12

Day 2, 10:30 AM - 10:45 AM

Break

13

Day 2, 10:45 AM - 12:30 PM

Web Server, Web Application and Database Attacks

Web server attacks and hardening. The web application attack surface and the OWASP Top 10 in practice: injection, broken access control, authentication failures, misconfiguration and vulnerable components. SQL injection types, detection and evasion. API and webhook attacks. Countermeasures including input validation, parameterised queries and web application firewalls, with attention to what a WAF does not solve.

14

Day 2, 12:30 PM - 1:30 PM

Lunch

15

Day 2, 1:30 PM - 3:00 PM

Wireless, Mobile, IoT, OT and Cloud

Wireless encryption, attacks and Bluetooth. Mobile platform attack vectors, mobile device management and application security. IoT and operational technology attacks, with reference to the ICS and SCADA exposure that matters to Malaysian manufacturing and utilities. Cloud computing threats: container and serverless security, misconfiguration, identity abuse and the shared responsibility line that attackers rely on being misunderstood.

16

Day 2, 3:00 PM - 3:15 PM

Break

17

Day 2, 3:15 PM - 4:15 PM

Cryptography and AI in Offensive Security

Cryptographic algorithms, public key infrastructure, disk and email encryption, cryptanalysis and cryptographic attacks. How AI tooling is now used across the attack lifecycle for reconnaissance, payload generation, phishing content and evasion, and what that changes for a defender's detection assumptions.

18

Day 2, 4:15 PM - 4:45 PM

Timed Practice Assessment

A timed practice set under exam conditions, scored and reviewed by domain.

19

Day 2, 4:45 PM - 5:00 PM

Exam Strategy, Study Plan and Close

Certification eligibility, booking, and a personalised study plan before the attempt.

Key Outcomes

  • Describe the attack lifecycle and map techniques onto MITRE ATT&CK
  • Set a lawful scope for authorised testing under Malaysian law, including the Computer Crimes Act 1997
  • Perform reconnaissance, scanning and enumeration against an authorised target and read the output critically
  • Explain system, malware, sniffing and social engineering techniques together with their countermeasures
  • Cover web application, wireless, mobile, IoT, OT and cloud attack surfaces to CEH depth
  • Recognise how AI-assisted tooling changes both offensive technique and defensive detection
  • Sit the CEH exam with a scored diagnostic and a personalised study plan behind you

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Advanced. Suitable for security analysts, penetration testers, system and network administrators and incident responders. Solid networking and operating system knowledge is assumed, at Security+ level or equivalent working experience.

Duration   2 Days (16 Hours)  |  9:00 AM to 5:00 PM daily

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   A timed practice assessment scored by domain plus lab exercises throughout. The certification exam and any eligibility requirements are arranged separately with the certification body.

Certificate   Orbix Certificate of Completion issued to all participants upon full attendance. This is a training certificate, not the CEH credential. CEH is awarded by the certification body only on passing its exam, which is booked and paid for separately.

EnquiriesContact us to register or discuss scheduling

Frequently Asked Questions

Yes. Certified Ethical Hacker (CEH) Exam Preparation is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

Certified Ethical Hacker (CEH) Exam Preparation runs for 2 days (16 hours) | 9:00 AM to 5:00 PM daily. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Orbix Certificate of Completion issued to all participants upon full attendance. This is a training certificate, not the CEH credential. CEH is awarded by the certification body only on passing its exam, which is booked and paid for separately. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Advanced. Suitable for security analysts, penetration testers, system and network administrators and incident responders. Solid networking and operating system knowledge is assumed, at Security+ level or equivalent working experience. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.