Certified Ethical Hacker (CEH) flashcards
EC-COUNCIL · Certified Ethical Hacker (CEH) (312-50)
This is the first of a few flash card sets I used when studying CEH. This is one of the exams where knowing the definition is absolutely critical as if you're spending time trying to remember something, you're going to end up running out of time on the exam.
Certification Summary
The EC-Council Certified Ethical Hacker 312-50 exam is for people working as penetration testers or security auditors. You take this exam to show you can manually test a school network for gaps before a real attacker finds them.
Reconnaissance, system hacking, network perimeter, and web application hacking account for seventy-four percent of your score. The other questions cover mobile, IoT, cloud, and cryptography. You will spend your time picking the right Nmap scan flag or Burp Suite configuration to bypass a specific security control.
You have mastered every card in this deck.
Pass complete.
Log in to mark cards as mastered and track progress.
The Imposter Hunt
The Imposter Hunt (Unlocked!)
Prove your knowledge to unlock this challenge.
Test your knowledge and spot the fake definitions.
Log in and master this deck to unlock.
All cards (136)
Scroll to review fronts and backs
Card 1
Front
OWASP Top 10
Back
Common web app security risks, updated periodically
Card 2
Front
A01:2021 Broken Access Control
Back
Users acting outside intended permissions
Card 3
Front
A02:2021 Cryptographic Failures
Back
Sensitive data exposed due to weak crypto
Card 4
Front
A03:2021 Injection
Back
Untrusted data sent to interpreter; SQL, NoSQL, OS
Card 5
Front
A04:2021 Insecure Design
Back
Missing security controls by design; threat modeling issue
Card 6
Front
A05:2021 Security Misconfiguration
Back
Default configs, open ports, verbose errors
Card 7
Front
A06:2021 Vulnerable Components
Back
Using libraries, frameworks with known issues
Card 8
Front
A07:2021 Identification, Auth Failures
Back
Weak passwords, session management, MFA bypass
Card 9
Front
A08:2021 Software, Data Integrity Failures
Back
Updates, critical data without integrity checks
Card 10
Front
A09:2021 Security Logging, Monitoring Failures
Back
Insufficient logging, alerting on security events
Card 11
Front
A10:2021 Server-Side Request Forgery (SSRF)
Back
Server fetches malicious URL, internal systems exposed
Card 12
Front
Reconnaissance purpose
Back
Information gathering before attack
Card 13
Front
Passive vs. Active Reconnaissance
Back
Passive: no direct interaction
Card 14
Front
Open Source Intelligence (OSINT)
Back
Publicly available information gathering
Card 15
Front
Google Dorking
Back
Advanced search operators for specific data
Card 16
Front
Shodan
Back
Search engine for internet-connected devices
Card 17
Front
Censys
Back
Internet-wide scan data and search engine
Card 18
Front
WHOIS lookup
Back
Domain registration information
Card 19
Front
DNS enumeration
Back
Mapping DNS records for a domain
Card 20
Front
Zone transfer
Back
Requesting full DNS zone data; often restricted
Card 21
Front
Email harvesting
Back
Collecting email addresses for phishing
Card 22
Front
Social media reconnaissance
Back
Gathering info from public profiles
Card 23
Front
Physical reconnaissance
Back
On-site observation, dumpster diving
Card 24
Front
Footprinting tools
Back
Maltego, Nmap, Recon-ng
Card 25
Front
Maltego
Back
Graphical link analysis tool for OSINT
Card 26
Front
Robots.txt file
Back
Directs web crawlers; can reveal hidden paths
Card 27
Front
Metadata analysis
Back
Info in documents, images; author, creation date
Card 28
Front
Wayback Machine
Back
Archives past versions of websites
Card 29
Front
Netcraft
Back
Website uptime, OS, web server info
Card 30
Front
Traceroute
Back
Maps network path to target; router hops
Card 31
Front
Ping sweep
Back
Identify active hosts on a network segment
Card 32
Front
Port scanning
Back
Identify open ports, running services
Card 33
Front
Nmap
Back
Network scanner, port discovery, OS detection
Card 34
Front
Service version detection
Back
Identifies software and version on open ports
Card 35
Front
Vulnerability scanning
Back
Identifies known weaknesses in systems, applications
Card 36
Front
Cisco IOS reconnaissance
Back
SNMP, telnet, SSH for device info
Card 37
Front
SNMP enumeration
Back
Gather network device info from MIBs
Card 38
Front
System Hacking Phases
Back
Gaining access, escalating, maintaining, covering tracks
Card 39
Front
Password cracking attacks
Back
Brute force, dictionary, hybrid, rainbow table
Card 40
Front
Brute force attack
Back
Try all possible combinations until match
Card 41
Front
Dictionary attack
Back
Uses list of common words, phrases
Card 42
Front
Rainbow table attack
Back
Precomputed hashes to find plaintext passwords
Card 43
Front
Password spraying attack
Back
Single common password against many accounts
Card 44
Front
Kerberoasting attack
Back
Extracting service account hashes from AD
Card 45
Front
Pass-the-Hash attack
Back
Reusing NTLM hash without knowing plaintext password
Card 46
Front
NTLM vs. Kerberos authentication
Back
NTLM: challenge-response
Card 47
Front
Privilege escalation
Back
Gaining higher access levels on a system
Card 48
Front
Vertical privilege escalation
Back
Low user to administrator
Card 49
Front
Horizontal privilege escalation
Back
User A to User B, same level
Card 50
Front
Kernel exploits
Back
Vulnerabilities in OS kernel for root access
Card 51
Front
Misconfigured services
Back
Running with excessive permissions; path to escalation
Card 52
Front
Weak service permissions
Back
Allows modification of service executables
Card 53
Front
Unquoted service paths
Back
Windows search order vulnerability; executable hijack
Card 54
Front
DLL hijacking
Back
Loading malicious DLL instead of legitimate one
Card 55
Front
Scheduled tasks exploitation
Back
Modifying or creating tasks for persistence/escalation
Card 56
Front
Sticky Keys backdoor
Back
Replacing accessibility tool with cmd.exe
Card 57
Front
Golden Ticket attack
Back
Forged Kerberos Ticket Granting Ticket (TGT)
Card 58
Front
Silver Ticket attack
Back
Forged Kerberos Ticket Granting Service (TGS)
Card 59
Front
Rootkit types
Back
User-mode, kernel-mode, firmware, hypervisor
Card 60
Front
Covering tracks
Back
Clearing logs, altering timestamps, steganography
Card 61
Front
Network sniffing
Back
Capturing data packets from network traffic
Card 62
Front
Promiscuous mode
Back
Network interface sees all traffic, not just its own
Card 63
Front
Active sniffing
Back
Injecting traffic to force responses, e.g., ARP poisoning
Card 64
Front
Passive sniffing
Back
Just listening to traffic without interaction
Card 65
Front
ARP poisoning
Back
Associating attacker MAC with victim IP, MITM
Card 66
Front
MAC flooding
Back
Overwhelming switch CAM table; forces broadcast mode
Card 67
Front
DHCP starvation
Back
Exhausting IP addresses in DHCP pool; DoS
Card 68
Front
DNS poisoning
Back
Injecting malicious DNS records into resolver cache
Card 69
Front
Tunneling protocols
Back
Encapsulating one protocol within another, often for evasion
Card 70
Front
VPN vs. IPsec
Back
VPN: concept
Card 71
Front
Firewall evasion techniques
Back
Fragmentation, tunneling, port forwarding, ICMP tunneling
Card 72
Front
IDS evasion techniques
Back
Encryption, obfuscation, polymorphic code, atomicity
Card 73
Front
Honeypots
Back
Decoy systems to attract attackers, gather info
Card 74
Front
Port scanning
Back
Identifying open ports and services on a host
Card 75
Front
SYN scan (half-open)
Back
Sends SYN, checks SYN-ACK, doesn't complete handshake
Card 76
Front
FIN scan
Back
Sends FIN packet; closed ports reply RST, open don't
Card 77
Front
Xmas scan
Back
Sends FIN, URG, PSH; closed ports reply RST
Card 78
Front
Null scan
Back
Sends packet with no flags set; closed ports reply RST
Card 79
Front
Idle scan (zombie scan)
Back
Uses IP ID sequence of idle host to scan target
Card 80
Front
SQL injection
Back
Manipulating database queries via input fields
Card 81
Front
Error-based SQLi
Back
Triggering database errors to reveal information
Card 82
Front
Union-based SQLi
Back
Using UNION SELECT to combine query results
Card 83
Front
Blind SQLi
Back
Inferring data based on true/false responses or time delays
Card 84
Front
Time-based blind SQLi
Back
Using delays to deduce information, no direct output
Card 85
Front
Boolean-based blind SQLi
Back
Observing true/false application responses
Card 86
Front
Out-of-band SQLi
Back
Attacker receives data via a separate channel, DNS/HTTP
Card 87
Front
Cross-Site Scripting (XSS)
Back
Injecting client-side scripts into web pages
Card 88
Front
Reflected XSS
Back
Script returned immediately in response, not stored
Card 89
Front
Stored XSS
Back
Malicious script saved on server, served to all users
Card 90
Front
DOM-based XSS
Back
Vulnerability in client-side code modifying DOM
Card 91
Front
CSRF (Cross-Site Request Forgery)
Back
Tricking user's browser into executing unwanted actions
Card 92
Front
Session hijacking
Back
Stealing or predicting a valid session ID
Card 93
Front
Session fixation
Back
Attacker forces a known session ID onto a victim
Card 94
Front
Broken authentication
Back
Weaknesses in login, session management, password handling
Card 95
Front
Insecure Direct Object References
Back
Accessing resources directly without proper authorization
Card 96
Front
Security misconfiguration
Back
Default credentials, unpatched systems, open ports
Card 97
Front
XML External Entity (XXE)
Back
Processing untrusted XML input, accessing local files
Card 98
Front
Server-Side Request Forgery (SSRF)
Back
Server makes requests to internal/external resources
Card 99
Front
File upload vulnerabilities
Back
Uploading malicious files, e.g., web shells
Card 100
Front
Command injection
Back
Executing OS commands via application input
Card 101
Front
Directory traversal
Back
Accessing files outside intended directory using '..'
Card 102
Front
WEP cracking
Back
Exploiting weak IVs to recover key
Card 103
Front
WPA/WPA2-PSK cracking
Back
Capturing 4-way handshake, offline brute force
Card 104
Front
Evil Twin attack
Back
Rogue AP mimics legitimate one, intercepts traffic
Card 105
Front
Deauthentication attack
Back
Forcing clients off network to capture handshake
Card 106
Front
Aircrack-ng suite
Back
Tools for wireless network auditing, cracking
Card 107
Front
WPS Pixie Dust attack
Back
Offline brute force on WPS PIN, vulnerable routers
Card 108
Front
Reaver
Back
Tool for WPS brute force attacks
Card 109
Front
Jamming wireless signals
Back
Denial of service, flooding channel with noise
Card 110
Front
Android debugging bridge (ADB)
Back
Interface for device control, file transfer, shell access
Card 111
Front
iOS jailbreaking
Back
Removing vendor restrictions, allows unsigned code
Card 112
Front
Rooting Android
Back
Gaining superuser access, bypasses OS security
Card 113
Front
Mobile app reverse engineering
Back
Analyzing compiled code, understanding logic, finding flaws
Card 114
Front
OWASP Mobile Top 10
Back
Common mobile app vulnerabilities, risk categories
Card 115
Front
Side-loading apps
Back
Installing apps outside official stores, bypassing checks
Card 116
Front
Insecure data storage (mobile)
Back
Sensitive data saved unencrypted on device
Card 117
Front
Broken cryptography (mobile)
Back
Weak algorithms or improper crypto implementations
Card 118
Front
Mobile device management (MDM)
Back
Centralized policy enforcement, security controls for devices
Card 119
Front
IoT device firmware analysis
Back
Extracting, examining firmware for vulnerabilities
Card 120
Front
Shodan search engine
Back
Finds internet-connected devices, services, ports
Card 121
Front
Cloud computing benefits
Back
Scalability, cost savings, accessibility, resource pooling
Card 122
Front
Cloud deployment models
Back
Public, private, hybrid, community
Card 123
Front
Cloud service models
Back
IaaS, PaaS, SaaS
Card 124
Front
IaaS
Back
Infrastructure as a Service
Card 125
Front
PaaS
Back
Platform as a Service
Card 126
Front
SaaS
Back
Software as a Service
Card 127
Front
Shared responsibility model
Back
Vendor secures the cloud, customer secures in the cloud
Card 128
Front
Cloud security risks
Back
Data breaches, misconfigurations, account hijacking, insecure APIs
Card 129
Front
Symmetric encryption
Back
Shared secret key
Card 130
Front
Asymmetric encryption
Back
Public/private key pair
Card 131
Front
RSA algorithm
Back
Asymmetric
Card 132
Front
Hashing function
Back
One-way transformation
Card 133
Front
Digital signature
Back
Sender's private key
Card 134
Front
AES block size
Back
Fixed 128-bit block length
Card 135
Front
Birthday attack
Back
Exploits collision probability in hash functions
Card 136
Front
Perfect forward secrecy
Back
Ephemeral keys