Certified Ethical Hacker (CEH) flashcards

EC-COUNCIL · Certified Ethical Hacker (CEH) (312-50)

By Spock

Log in to rate

This is the first of a few flash card sets I used when studying CEH. This is one of the exams where knowing the definition is absolutely critical as if you're spending time trying to remember something, you're going to end up running out of time on the exam.

Certification Summary

The EC-Council Certified Ethical Hacker 312-50 exam is for people working as penetration testers or security auditors. You take this exam to show you can manually test a school network for gaps before a real attacker finds them.

Reconnaissance, system hacking, network perimeter, and web application hacking account for seventy-four percent of your score. The other questions cover mobile, IoT, cloud, and cryptography. You will spend your time picking the right Nmap scan flag or Burp Suite configuration to bypass a specific security control.

Study

Card 1 of 136

Log in to mark cards as mastered and track progress.

The Imposter Hunt

The Imposter Hunt (Unlocked!)

Prove your knowledge to unlock this challenge.

Test your knowledge and spot the fake definitions.

0% / 75% mastery
0%

Mastery

0 of 136 cards mastered

All cards (136)

Scroll to review fronts and backs

Card 1

Front

OWASP Top 10

Back

Common web app security risks, updated periodically

Card 2

Front

A01:2021 Broken Access Control

Back

Users acting outside intended permissions

Card 3

Front

A02:2021 Cryptographic Failures

Back

Sensitive data exposed due to weak crypto

Card 4

Front

A03:2021 Injection

Back

Untrusted data sent to interpreter; SQL, NoSQL, OS

Card 5

Front

A04:2021 Insecure Design

Back

Missing security controls by design; threat modeling issue

Card 6

Front

A05:2021 Security Misconfiguration

Back

Default configs, open ports, verbose errors

Card 7

Front

A06:2021 Vulnerable Components

Back

Using libraries, frameworks with known issues

Card 8

Front

A07:2021 Identification, Auth Failures

Back

Weak passwords, session management, MFA bypass

Card 9

Front

A08:2021 Software, Data Integrity Failures

Back

Updates, critical data without integrity checks

Card 10

Front

A09:2021 Security Logging, Monitoring Failures

Back

Insufficient logging, alerting on security events

Card 11

Front

A10:2021 Server-Side Request Forgery (SSRF)

Back

Server fetches malicious URL, internal systems exposed

Card 12

Front

Reconnaissance purpose

Back

Information gathering before attack

Card 13

Front

Passive vs. Active Reconnaissance

Back

Passive: no direct interaction

Card 14

Front

Open Source Intelligence (OSINT)

Back

Publicly available information gathering

Card 15

Front

Google Dorking

Back

Advanced search operators for specific data

Card 16

Front

Shodan

Back

Search engine for internet-connected devices

Card 17

Front

Censys

Back

Internet-wide scan data and search engine

Card 18

Front

WHOIS lookup

Back

Domain registration information

Card 19

Front

DNS enumeration

Back

Mapping DNS records for a domain

Card 20

Front

Zone transfer

Back

Requesting full DNS zone data; often restricted

Card 21

Front

Email harvesting

Back

Collecting email addresses for phishing

Card 22

Front

Social media reconnaissance

Back

Gathering info from public profiles

Card 23

Front

Physical reconnaissance

Back

On-site observation, dumpster diving

Card 24

Front

Footprinting tools

Back

Maltego, Nmap, Recon-ng

Card 25

Front

Maltego

Back

Graphical link analysis tool for OSINT

Card 26

Front

Robots.txt file

Back

Directs web crawlers; can reveal hidden paths

Card 27

Front

Metadata analysis

Back

Info in documents, images; author, creation date

Card 28

Front

Wayback Machine

Back

Archives past versions of websites

Card 29

Front

Netcraft

Back

Website uptime, OS, web server info

Card 30

Front

Traceroute

Back

Maps network path to target; router hops

Card 31

Front

Ping sweep

Back

Identify active hosts on a network segment

Card 32

Front

Port scanning

Back

Identify open ports, running services

Card 33

Front

Nmap

Back

Network scanner, port discovery, OS detection

Card 34

Front

Service version detection

Back

Identifies software and version on open ports

Card 35

Front

Vulnerability scanning

Back

Identifies known weaknesses in systems, applications

Card 36

Front

Cisco IOS reconnaissance

Back

SNMP, telnet, SSH for device info

Card 37

Front

SNMP enumeration

Back

Gather network device info from MIBs

Card 38

Front

System Hacking Phases

Back

Gaining access, escalating, maintaining, covering tracks

Card 39

Front

Password cracking attacks

Back

Brute force, dictionary, hybrid, rainbow table

Card 40

Front

Brute force attack

Back

Try all possible combinations until match

Card 41

Front

Dictionary attack

Back

Uses list of common words, phrases

Card 42

Front

Rainbow table attack

Back

Precomputed hashes to find plaintext passwords

Card 43

Front

Password spraying attack

Back

Single common password against many accounts

Card 44

Front

Kerberoasting attack

Back

Extracting service account hashes from AD

Card 45

Front

Pass-the-Hash attack

Back

Reusing NTLM hash without knowing plaintext password

Card 46

Front

NTLM vs. Kerberos authentication

Back

NTLM: challenge-response

Card 47

Front

Privilege escalation

Back

Gaining higher access levels on a system

Card 48

Front

Vertical privilege escalation

Back

Low user to administrator

Card 49

Front

Horizontal privilege escalation

Back

User A to User B, same level

Card 50

Front

Kernel exploits

Back

Vulnerabilities in OS kernel for root access

Card 51

Front

Misconfigured services

Back

Running with excessive permissions; path to escalation

Card 52

Front

Weak service permissions

Back

Allows modification of service executables

Card 53

Front

Unquoted service paths

Back

Windows search order vulnerability; executable hijack

Card 54

Front

DLL hijacking

Back

Loading malicious DLL instead of legitimate one

Card 55

Front

Scheduled tasks exploitation

Back

Modifying or creating tasks for persistence/escalation

Card 56

Front

Sticky Keys backdoor

Back

Replacing accessibility tool with cmd.exe

Card 57

Front

Golden Ticket attack

Back

Forged Kerberos Ticket Granting Ticket (TGT)

Card 58

Front

Silver Ticket attack

Back

Forged Kerberos Ticket Granting Service (TGS)

Card 59

Front

Rootkit types

Back

User-mode, kernel-mode, firmware, hypervisor

Card 60

Front

Covering tracks

Back

Clearing logs, altering timestamps, steganography

Card 61

Front

Network sniffing

Back

Capturing data packets from network traffic

Card 62

Front

Promiscuous mode

Back

Network interface sees all traffic, not just its own

Card 63

Front

Active sniffing

Back

Injecting traffic to force responses, e.g., ARP poisoning

Card 64

Front

Passive sniffing

Back

Just listening to traffic without interaction

Card 65

Front

ARP poisoning

Back

Associating attacker MAC with victim IP, MITM

Card 66

Front

MAC flooding

Back

Overwhelming switch CAM table; forces broadcast mode

Card 67

Front

DHCP starvation

Back

Exhausting IP addresses in DHCP pool; DoS

Card 68

Front

DNS poisoning

Back

Injecting malicious DNS records into resolver cache

Card 69

Front

Tunneling protocols

Back

Encapsulating one protocol within another, often for evasion

Card 70

Front

VPN vs. IPsec

Back

VPN: concept

Card 71

Front

Firewall evasion techniques

Back

Fragmentation, tunneling, port forwarding, ICMP tunneling

Card 72

Front

IDS evasion techniques

Back

Encryption, obfuscation, polymorphic code, atomicity

Card 73

Front

Honeypots

Back

Decoy systems to attract attackers, gather info

Card 74

Front

Port scanning

Back

Identifying open ports and services on a host

Card 75

Front

SYN scan (half-open)

Back

Sends SYN, checks SYN-ACK, doesn't complete handshake

Card 76

Front

FIN scan

Back

Sends FIN packet; closed ports reply RST, open don't

Card 77

Front

Xmas scan

Back

Sends FIN, URG, PSH; closed ports reply RST

Card 78

Front

Null scan

Back

Sends packet with no flags set; closed ports reply RST

Card 79

Front

Idle scan (zombie scan)

Back

Uses IP ID sequence of idle host to scan target

Card 80

Front

SQL injection

Back

Manipulating database queries via input fields

Card 81

Front

Error-based SQLi

Back

Triggering database errors to reveal information

Card 82

Front

Union-based SQLi

Back

Using UNION SELECT to combine query results

Card 83

Front

Blind SQLi

Back

Inferring data based on true/false responses or time delays

Card 84

Front

Time-based blind SQLi

Back

Using delays to deduce information, no direct output

Card 85

Front

Boolean-based blind SQLi

Back

Observing true/false application responses

Card 86

Front

Out-of-band SQLi

Back

Attacker receives data via a separate channel, DNS/HTTP

Card 87

Front

Cross-Site Scripting (XSS)

Back

Injecting client-side scripts into web pages

Card 88

Front

Reflected XSS

Back

Script returned immediately in response, not stored

Card 89

Front

Stored XSS

Back

Malicious script saved on server, served to all users

Card 90

Front

DOM-based XSS

Back

Vulnerability in client-side code modifying DOM

Card 91

Front

CSRF (Cross-Site Request Forgery)

Back

Tricking user's browser into executing unwanted actions

Card 92

Front

Session hijacking

Back

Stealing or predicting a valid session ID

Card 93

Front

Session fixation

Back

Attacker forces a known session ID onto a victim

Card 94

Front

Broken authentication

Back

Weaknesses in login, session management, password handling

Card 95

Front

Insecure Direct Object References

Back

Accessing resources directly without proper authorization

Card 96

Front

Security misconfiguration

Back

Default credentials, unpatched systems, open ports

Card 97

Front

XML External Entity (XXE)

Back

Processing untrusted XML input, accessing local files

Card 98

Front

Server-Side Request Forgery (SSRF)

Back

Server makes requests to internal/external resources

Card 99

Front

File upload vulnerabilities

Back

Uploading malicious files, e.g., web shells

Card 100

Front

Command injection

Back

Executing OS commands via application input

Card 101

Front

Directory traversal

Back

Accessing files outside intended directory using '..'

Card 102

Front

WEP cracking

Back

Exploiting weak IVs to recover key

Card 103

Front

WPA/WPA2-PSK cracking

Back

Capturing 4-way handshake, offline brute force

Card 104

Front

Evil Twin attack

Back

Rogue AP mimics legitimate one, intercepts traffic

Card 105

Front

Deauthentication attack

Back

Forcing clients off network to capture handshake

Card 106

Front

Aircrack-ng suite

Back

Tools for wireless network auditing, cracking

Card 107

Front

WPS Pixie Dust attack

Back

Offline brute force on WPS PIN, vulnerable routers

Card 108

Front

Reaver

Back

Tool for WPS brute force attacks

Card 109

Front

Jamming wireless signals

Back

Denial of service, flooding channel with noise

Card 110

Front

Android debugging bridge (ADB)

Back

Interface for device control, file transfer, shell access

Card 111

Front

iOS jailbreaking

Back

Removing vendor restrictions, allows unsigned code

Card 112

Front

Rooting Android

Back

Gaining superuser access, bypasses OS security

Card 113

Front

Mobile app reverse engineering

Back

Analyzing compiled code, understanding logic, finding flaws

Card 114

Front

OWASP Mobile Top 10

Back

Common mobile app vulnerabilities, risk categories

Card 115

Front

Side-loading apps

Back

Installing apps outside official stores, bypassing checks

Card 116

Front

Insecure data storage (mobile)

Back

Sensitive data saved unencrypted on device

Card 117

Front

Broken cryptography (mobile)

Back

Weak algorithms or improper crypto implementations

Card 118

Front

Mobile device management (MDM)

Back

Centralized policy enforcement, security controls for devices

Card 119

Front

IoT device firmware analysis

Back

Extracting, examining firmware for vulnerabilities

Card 120

Front

Shodan search engine

Back

Finds internet-connected devices, services, ports

Card 121

Front

Cloud computing benefits

Back

Scalability, cost savings, accessibility, resource pooling

Card 122

Front

Cloud deployment models

Back

Public, private, hybrid, community

Card 123

Front

Cloud service models

Back

IaaS, PaaS, SaaS

Card 124

Front

IaaS

Back

Infrastructure as a Service

Card 125

Front

PaaS

Back

Platform as a Service

Card 126

Front

SaaS

Back

Software as a Service

Card 127

Front

Shared responsibility model

Back

Vendor secures the cloud, customer secures in the cloud

Card 128

Front

Cloud security risks

Back

Data breaches, misconfigurations, account hijacking, insecure APIs

Card 129

Front

Symmetric encryption

Back

Shared secret key

Card 130

Front

Asymmetric encryption

Back

Public/private key pair

Card 131

Front

RSA algorithm

Back

Asymmetric

Card 132

Front

Hashing function

Back

One-way transformation

Card 133

Front

Digital signature

Back

Sender's private key

Card 134

Front

AES block size

Back

Fixed 128-bit block length

Card 135

Front

Birthday attack

Back

Exploits collision probability in hash functions

Card 136

Front

Perfect forward secrecy

Back

Ephemeral keys