Click Study Flashcards above to open the flashcard hub — hundreds of CEH cards you can flip, match, type, or quiz yourself on. Every card is drawn from the nine official CEH v13 domains, so you study exactly what the exam tests.[2] Pair them with our free practice test and study guide.
CEH Flashcard Study Modes
Flip mode is the straight study pass, front to back, at your own speed. Match is the timed game where you pair terms with definitions. Type shows you a definition and asks you to produce the term, so a front like KRACK has to come back spelled correctly. Quiz turns the same cards into multiple choice for mixed recall.

Why Flashcards Work for CEH
Network & Perimeter Hacking is the largest block at 45 cards and the heaviest part of the exam at 24%, so it drills detection gear and traffic-level attacks together. Cards like IDS, IPS, and tcpdump sit alongside DNSSEC, while Botnet and DDoS cover volumetric attacks and social engineering fronts such as Whaling and Vishing round out the human side.
Reconnaissance Techniques brings 32 cards for 17% of the exam and leans on footprinting tools and port recall, with fronts like Nmap, Shodan, and Maltego next to OSINT, NTP port, and NFS port. System Hacking & Malware adds 35 cards covering malware taxonomy, vulnerability scoring, and credential defense, including CVE, CVSS, and Rootkit, plus Salting and APT.
Web Application Hacking holds 25 cards for 14% and focuses on injection and access-control flaws: CSRF, SSRF, and IDOR appear beside Stored XSS, Blind SQLi, and tooling like Burp Suite and WAF. Mobile, IoT & OT Hacking contributes 17 cards for 10%, mixing device policy terms such as MDM, BYOD, and COPE with industrial fronts like ICS / SCADA and Purdue model.
The remaining domains are smaller in weight but dense in vocabulary. Information Security & Ethical Hacking Overview runs 35 cards on foundational and regulatory terms, including Risk, Threat, and Asset alongside GDPR, HIPAA, and PCI-DSS. Wireless Network Hacking has 14 cards for 5%, covering WEP, WPA3, and Evil twin. Cloud Computing adds 14 cards for 5% with IaaS, CASB, and Public S3 bucket. Cryptography closes with 24 cards for 5%, drilling AES, RSA, PKI, and hash fronts like MD5 and SHA-256.
CEH is dense with terminology — attack types, malware families, hacking tools, default ports, cryptography, and frameworks like MITRE ATT&CK.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
CEH Flashcards by Domain
The cards are organized by the nine official CEH v13 domains. Drill the highest-weighted ones first — Network & Perimeter Hacking and Reconnaissance alone are 41% of the exam:[2]
| Domain | Exam weight |
|---|---|
| Network & Perimeter Hacking | 24% |
| Reconnaissance Techniques | 17% |
| System Hacking Phases & Attack Techniques | 15% |
| Web Application Hacking | 14% |
| Mobile, IoT & OT Hacking | 10% |
| Information Security & Overview | 6% |
| Wireless Network Hacking | 5% |
| Cloud Computing | 5% |
| Cryptography | 5% |
How to Get the Most Out of These Flashcards
- Start at the perimeter. Network & Perimeter Hacking carries 45 cards and 24% of the exam, so run it in Flip first until IDS, IPS, and DNSSEC come back instantly.
- Type-drill the lookalikes. Terms that blur under pressure, such as CSRF against SSRF or Whaling against Vishing, belong in Type, where producing the exact term proves you actually separated them.
- Use Match for the short fronts. Port and acronym cards like NTP port, NFS port, and IaaS pair quickly, and the timer exposes which ones you are guessing rather than knowing.
- Move to the practice test when Quiz stops surprising you. Once the multiple choice across all 241 cards feels routine, shift to scenario wording and use the study guide to close gaps.
- Rotate two domains a session. Pair a heavy one like Reconnaissance Techniques with a lighter one like Cryptography, then Quiz across the whole deck so older cards keep resurfacing.
CEH Flashcards FAQ
Hundreds of free CEH flashcards, organized across all nine official CEH v13 domains — from Reconnaissance and System Hacking to Web Application Hacking, Wireless, Cloud, and Cryptography. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions. CEH is heavy on tools, ports, attack types, and terminology, which is exactly what flashcards drill best.
All nine CEH v13 domains: Information Security & Overview, Reconnaissance (footprinting, scanning, enumeration), System Hacking & Malware, Network & Perimeter Hacking (sniffing, social engineering, DoS, session hijacking, evasion), Web Application Hacking, Wireless, Mobile/IoT/OT, Cloud, and Cryptography.
Lead with the highest-weighted domains — Network & Perimeter Hacking (24%), Reconnaissance (17%), System Hacking (15%), and Web Application Hacking (14%), which together are 70% of the exam. Mix the modes: flip to learn, type to test recall, match for speed, and quiz to check yourself before a full practice test.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to EC-Council's current CEH v13 (Exam Blueprint v5.0), covering all nine scored domains in their official proportions, including the expanded cloud and AI-driven content.
CEH flashcard bank
All 241 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Information Security & Ethical Hacking Overview (35)
- CIA triad
Show answerHide answer
Confidentiality, Integrity, Availability — the three core goals of information security.
- Confidentiality
Show answerHide answer
Ensuring only authorized people can access data; enforced by encryption and access control.
- Integrity
Show answerHide answer
Ensuring data is accurate and unaltered; enforced by hashing and digital signatures.
- Availability
Show answerHide answer
Ensuring authorized users can access data and systems when needed; enforced by redundancy and backups.
- Non-repudiation
Show answerHide answer
Assurance that someone cannot deny an action; provided by digital signatures and logging.
- Vulnerability
Show answerHide answer
A weakness or flaw in a system that could be exploited by a threat.
- Threat
Show answerHide answer
A potential danger — an attacker or malware — that could exploit a vulnerability.
- Exploit
Show answerHide answer
The code or technique that actively takes advantage of a vulnerability.
- Risk
Show answerHide answer
The likelihood a threat exploits a vulnerability combined with the impact if it does.
- Asset
Show answerHide answer
Anything of value worth protecting — data, a server, a service, or a reputation.
- Five phases of hacking
Show answerHide answer
Reconnaissance, Scanning, Gaining Access, Maintaining Access, Clearing Tracks.
- Reconnaissance (phase 1)
Show answerHide answer
Gathering information about the target before attacking.
- Gaining Access (phase 3)
Show answerHide answer
Exploiting a weakness to get into a system, then escalating privileges.
- Maintaining Access (phase 4)
Show answerHide answer
Keeping the foothold with backdoors, rootkits, or new accounts.
- Clearing Tracks (phase 5)
Show answerHide answer
Covering the trail — clearing logs, hiding files, disabling auditing.
- White hat
Show answerHide answer
An authorized, ethical hacker who tests systems with permission to improve security.
- Black hat
Show answerHide answer
A malicious attacker who breaks into systems without authorization for harm or gain.
- Gray hat
Show answerHide answer
A hacker who probes systems without permission but without clear malicious intent.
- Script kiddie
Show answerHide answer
An unskilled attacker who uses tools and exploits written by others.
- Hacktivist
Show answerHide answer
An attacker motivated by a political or social cause.
- Defense in depth
Show answerHide answer
Layering multiple independent controls so one failure doesn't expose the asset.
- Cyber Kill Chain
Show answerHide answer
Lockheed Martin's 7 stages: recon, weaponization, delivery, exploitation, installation, C2, actions on objectives.
- MITRE ATT&CK
Show answerHide answer
A knowledge base of real-world adversary tactics and techniques across the attack lifecycle.
- Black-box testing
Show answerHide answer
A pentest where the tester has no prior knowledge of the target (external attacker view).
- White-box testing
Show answerHide answer
A pentest where the tester has full knowledge (architecture, source, credentials).
- Gray-box testing
Show answerHide answer
A pentest with partial knowledge, such as a standard user account.
- Rules of engagement
Show answerHide answer
The agreed scope, methods, timing, and limits of an authorized engagement.
- Vulnerability scan vs pentest
Show answerHide answer
A scan only identifies weaknesses; a penetration test actually exploits them.
- Authorization
Show answerHide answer
Written permission and defined scope — the only thing separating a CEH from a criminal.
- PCI-DSS
Show answerHide answer
Payment Card Industry Data Security Standard — protects cardholder data.
- HIPAA
Show answerHide answer
U.S. law protecting the privacy and security of health information.
- GDPR
Show answerHide answer
EU regulation governing personal-data privacy and protection.
- ISO/IEC 27001
Show answerHide answer
International standard for an information security management system (ISMS).
- AAA
Show answerHide answer
Authentication, Authorization, Accounting.
- Bug bounty
Show answerHide answer
A program that pays outside researchers for responsibly disclosed vulnerabilities.
Reconnaissance Techniques (32)
- Footprinting
Show answerHide answer
Systematically gathering information to profile a target's network, people, and tech.
- Passive reconnaissance
Show answerHide answer
Gathering info with no direct contact — OSINT, WHOIS, DNS, Shodan, social media.
- Active reconnaissance
Show answerHide answer
Interacting with the target directly — ping sweeps, port scans, banner grabbing.
- OSINT
Show answerHide answer
Open-Source Intelligence — information gathered from publicly available sources.
- Google dorking
Show answerHide answer
Using search operators (site:, inurl:, intitle:, filetype:) to find exposed information.
- Shodan
Show answerHide answer
A search engine that indexes Internet-connected devices and their open services.
- WHOIS
Show answerHide answer
A query returning domain/IP registration details (registrar, contacts, name servers).
- DNS enumeration
Show answerHide answer
Querying DNS records (A, MX, NS, TXT); a zone transfer can dump the whole zone.
- DNS zone transfer (AXFR)
Show answerHide answer
Copying an entire DNS zone; if misconfigured, it leaks all records to an attacker.
- theHarvester
Show answerHide answer
A tool that gathers emails, subdomains, and hosts from public sources.
- Maltego
Show answerHide answer
An OSINT tool that maps relationships between people, domains, and infrastructure.
- Nmap
Show answerHide answer
The standard network scanner for host discovery, port scanning, and OS/version detection.
- TCP three-way handshake
Show answerHide answer
SYN → SYN/ACK → ACK — how a TCP connection is established.
- TCP connect scan (-sT)
Show answerHide answer
Completes the full handshake — reliable but easily logged.
- SYN / half-open scan (-sS)
Show answerHide answer
Sends SYN, never finishes the handshake — stealthier; the default for root.
- NULL / FIN / Xmas scans
Show answerHide answer
Send unusual TCP flag combinations to slip past simple filters.
- UDP scan (-sU)
Show answerHide answer
Probes connectionless services like DNS, SNMP, and DHCP.
- Banner grabbing
Show answerHide answer
Reading a service's response to identify its software and version.
- OS fingerprinting (-O)
Show answerHide answer
Identifying the target operating system from network behavior.
- Ping sweep
Show answerHide answer
Sending ICMP echo requests to a range to find live hosts.
- Enumeration
Show answerHide answer
Actively extracting users, shares, services, and config after scanning.
- NetBIOS / SMB ports
Show answerHide answer
137–139 and 445 — enumerate Windows shares, users, and system names.
- SNMP port
Show answerHide answer
161 — default community strings ('public'/'private') can leak device config.
- LDAP port
Show answerHide answer
389 — enumerate directory objects: users, groups, and OUs.
- SMTP enumeration
Show answerHide answer
Port 25 — VRFY/EXPN/RCPT TO can reveal valid email accounts.
- NTP port
Show answerHide answer
123 — can reveal hosts and times that sync to a server.
- NFS port
Show answerHide answer
2049 — network file shares that may be exported insecurely.
- SNMP community strings
Show answerHide answer
Shared 'passwords' for SNMP; defaults 'public' (read) and 'private' (write) are classic findings.
- Scanning countermeasure
Show answerHide answer
Reduce exposed ports and services — you can't attack a closed port.
- netcat
Show answerHide answer
A versatile tool to read/write network connections; banner grabbing and simple backdoors.
- Wayback / archived pages
Show answerHide answer
Old site versions revealing structure or data the target later removed.
- Email footprinting
Show answerHide answer
Tracking email headers and read-receipts to map infrastructure and behavior.
System Hacking & Malware (35)
- Vulnerability assessment
Show answerHide answer
A systematic review that identifies, classifies, and prioritizes weaknesses.
- CVSS
Show answerHide answer
Common Vulnerability Scoring System — a 0–10 score rating a vulnerability's severity.
- CVE
Show answerHide answer
Common Vulnerabilities and Exposures — a public catalog of IDs for known vulnerabilities.
- False positive
Show answerHide answer
A finding flagged as a vulnerability that isn't actually exploitable.
- Password cracking
Show answerHide answer
Recovering passwords from hashes via dictionary, brute-force, hybrid, or rainbow tables.
- Dictionary attack
Show answerHide answer
Tries a wordlist of likely passwords against a hash or login.
- Brute-force attack
Show answerHide answer
Tries every possible combination until the password is found.
- Hybrid attack
Show answerHide answer
Combines a dictionary with appended numbers/symbols (e.g., Password123!).
- Rainbow table
Show answerHide answer
A precomputed table of hashes used to reverse unsalted password hashes quickly.
- Salting
Show answerHide answer
Adding unique random data before hashing so identical passwords differ; defeats rainbow tables.
- Pass-the-hash
Show answerHide answer
Authenticating with a captured NTLM hash without cracking the plaintext password.
- Kerberoasting
Show answerHide answer
Requesting service tickets and cracking them offline to recover service-account passwords.
- Privilege escalation
Show answerHide answer
Gaining higher access than granted — vertical (to admin) or horizontal (to another user).
- Vertical privilege escalation
Show answerHide answer
Moving from a low-privilege account to administrator or root.
- Horizontal privilege escalation
Show answerHide answer
Moving sideways to another user's account at the same level.
- DLL hijacking
Show answerHide answer
Tricking a program into loading a malicious library to run attacker code.
- SUID exploitation
Show answerHide answer
Abusing a Linux root-owned binary with the setuid bit to gain root.
- Rootkit
Show answerHide answer
Malware that hides deep in the system (often the kernel) for stealthy privileged access.
- User-mode vs kernel-mode rootkit
Show answerHide answer
User-mode hooks normal programs; kernel-mode runs with the highest privilege and is harder to detect.
- Keylogger
Show answerHide answer
Software or hardware that records keystrokes to capture passwords and input.
- Spyware
Show answerHide answer
Malware that secretly collects information about a user or system.
- Steganography
Show answerHide answer
Hiding data inside other data (e.g., within an image) to conceal its existence.
- Clearing logs
Show answerHide answer
Deleting or altering log entries to cover the attacker's tracks.
- Malware
Show answerHide answer
Malicious software — viruses, worms, trojans, ransomware, spyware, rootkits, fileless.
- Virus
Show answerHide answer
Malware that attaches to a host file and needs user action to run and spread.
- Worm
Show answerHide answer
Self-propagating malware that spreads across networks with no user action.
- Trojan
Show answerHide answer
Malware disguised as legitimate software that opens a hidden backdoor when run.
- Ransomware
Show answerHide answer
Malware that encrypts a victim's data and demands payment for the decryption key.
- Double extortion
Show answerHide answer
Ransomware that also steals data and threatens to leak it if no ransom is paid.
- Fileless malware
Show answerHide answer
Malware that runs in memory using legitimate tools to evade disk-based detection.
- APT
Show answerHide answer
Advanced Persistent Threat — a skilled, well-resourced adversary keeping long-term stealthy access.
- Logic bomb
Show answerHide answer
Malicious code that executes when a specific condition (date/event) is met.
- Static malware analysis
Show answerHide answer
Inspecting malware without running it (strings, hashes, headers).
- Dynamic malware analysis
Show answerHide answer
Running malware in a sandbox to observe its behavior.
- Backdoor
Show answerHide answer
A hidden method of bypassing authentication to regain access to a system.
Network & Perimeter Hacking (45)
- Sniffing
Show answerHide answer
Capturing and inspecting network traffic, often to harvest credentials or data.
- Promiscuous mode
Show answerHide answer
A NIC mode that captures all traffic on a segment, not just frames addressed to it.
- Active vs passive sniffing
Show answerHide answer
Passive works on hubs; active (ARP poisoning) is needed on switched networks.
- Wireshark
Show answerHide answer
A packet analyzer used to capture and inspect network traffic in detail.
- tcpdump
Show answerHide answer
A command-line packet capture tool for Unix/Linux.
- ARP poisoning
Show answerHide answer
Sending forged ARP replies to redirect LAN traffic through the attacker (on-path).
- ARP poisoning defense
Show answerHide answer
Dynamic ARP Inspection (DAI), static ARP entries, and encryption.
- MAC flooding
Show answerHide answer
Overflowing a switch's CAM table so it fails open and broadcasts like a hub.
- MAC flooding defense
Show answerHide answer
Port security — limit the number of MAC addresses per port.
- DHCP starvation
Show answerHide answer
Exhausting the DHCP pool, then offering an attacker-controlled gateway/DNS.
- DHCP snooping
Show answerHide answer
A switch feature that blocks rogue DHCP servers and starvation attacks.
- DNS poisoning
Show answerHide answer
Injecting false DNS records so victims resolve a name to an attacker's host.
- DNSSEC
Show answerHide answer
Adds cryptographic signatures to DNS to prevent record forgery.
- On-path attack
Show answerHide answer
Secretly relaying or altering traffic between two parties (formerly man-in-the-middle).
- MAC spoofing
Show answerHide answer
Changing a device's MAC address to impersonate another or bypass filters.
- Social engineering
Show answerHide answer
Manipulating people into divulging info or actions that compromise security.
- Phishing
Show answerHide answer
A fraudulent email that tricks the victim into revealing credentials or running malware.
- Spear phishing
Show answerHide answer
Phishing targeted at a specific individual or organization.
- Whaling
Show answerHide answer
Phishing that targets high-value executives.
- Vishing
Show answerHide answer
Voice phishing — a social-engineering attack over a phone call.
- Smishing
Show answerHide answer
SMS phishing — a social-engineering attack by text message.
- Pretexting
Show answerHide answer
Inventing a believable scenario to extract information from a target.
- Tailgating / piggybacking
Show answerHide answer
Following an authorized person through a secure door without credentials.
- Impersonation
Show answerHide answer
Posing as IT, a vendor, or an executive to gain trust and access.
- Business email compromise
Show answerHide answer
Impersonating a trusted executive or vendor to authorize fraudulent payments.
- Insider threat
Show answerHide answer
An employee/contractor misusing authorized access to harm the organization.
- Social engineering defense
Show answerHide answer
Recurring security-awareness training plus phishing simulations.
- Denial-of-service (DoS)
Show answerHide answer
Overwhelming a system so legitimate users can't access it.
- DDoS
Show answerHide answer
A distributed DoS launched from many compromised machines (a botnet) at once.
- Botnet
Show answerHide answer
A network of malware-infected 'zombie' hosts controlled by an attacker.
- SYN flood
Show answerHide answer
A protocol DoS that exhausts server state with half-open TCP connections.
- Volumetric attack
Show answerHide answer
A DoS that saturates the target's bandwidth (UDP/ICMP floods, amplification).
- Application-layer DoS
Show answerHide answer
Low-volume valid-looking requests that exhaust app resources (e.g., Slowloris).
- SYN cookies
Show answerHide answer
A defense that lets a server handle SYN floods without allocating state.
- Session hijacking
Show answerHide answer
Taking over an authenticated session by stealing or predicting the session ID.
- Session fixation
Show answerHide answer
Planting a known session ID before the victim logs in, then reusing it.
- HttpOnly cookie flag
Show answerHide answer
Prevents JavaScript from reading a cookie — blunts cookie theft via XSS.
- Secure cookie flag
Show answerHide answer
Ensures a cookie is only sent over HTTPS.
- IDS
Show answerHide answer
Intrusion Detection System — detects and alerts on suspicious traffic (passive).
- IPS
Show answerHide answer
Intrusion Prevention System — detects and blocks suspicious traffic inline (active).
- Stateful firewall
Show answerHide answer
A firewall that tracks connection state to allow only valid return traffic.
- Honeypot
Show answerHide answer
A decoy system that lures attackers away from real assets and records them.
- Honeynet
Show answerHide answer
A network of honeypots that mimics a real environment.
- IDS evasion
Show answerHide answer
Fragmentation, encoding, and tunneling to break the signature an IDS looks for.
- Firewalking
Show answerHide answer
Probing which ports/services a firewall permits by manipulating TTLs.
Web Application Hacking (25)
- OWASP Top 10
Show answerHide answer
The list of the most critical web application security risks.
- Web server attack
Show answerHide answer
Targeting server software/config — traversal, defaults, unpatched CVEs.
- Directory traversal
Show answerHide answer
Using ../ to access files outside the intended web root.
- SQL injection
Show answerHide answer
Inserting malicious SQL into input so the database runs unintended commands.
- SQLi primary fix
Show answerHide answer
Parameterized queries (prepared statements) plus input validation.
- In-band SQLi
Show answerHide answer
SQL injection where results come back in the same channel (union/error-based).
- Blind SQLi
Show answerHide answer
Inferring data via true/false (boolean) or response timing (time-based).
- ' OR '1'='1
Show answerHide answer
A classic SQLi payload that makes a WHERE clause always true to bypass login.
- Cross-site scripting (XSS)
Show answerHide answer
Injecting script into a trusted site that runs in another user's browser.
- Stored XSS
Show answerHide answer
Malicious script persisted on the server and served to many users.
- Reflected XSS
Show answerHide answer
Malicious script echoed back from a request and run immediately.
- DOM-based XSS
Show answerHide answer
XSS executed entirely in the browser via the page's own JavaScript.
- XSS primary fix
Show answerHide answer
Output encoding plus a Content Security Policy (CSP).
- CSRF
Show answerHide answer
Forcing an authenticated user's browser to send an unwanted request to a trusted site.
- CSRF defense
Show answerHide answer
Anti-CSRF tokens and SameSite cookies.
- Command injection
Show answerHide answer
Running OS commands through unvalidated input.
- LFI / RFI
Show answerHide answer
Local/Remote File Inclusion — loading attacker-chosen files via input.
- SSRF
Show answerHide answer
Server-Side Request Forgery — making the server request attacker-chosen URLs.
- Broken access control
Show answerHide answer
Failing to enforce what authenticated users may do — a top OWASP risk.
- IDOR
Show answerHide answer
Insecure Direct Object Reference — accessing others' data by changing an ID.
- Input validation
Show answerHide answer
Treating all user input as untrusted and checking it server-side.
- WAF
Show answerHide answer
Web Application Firewall — filters layer-7 attacks like injection and XSS.
- Burp Suite
Show answerHide answer
A proxy/toolkit for intercepting and testing web application requests.
- Web cache poisoning
Show answerHide answer
Tricking a cache into storing and serving a malicious response.
- Clickjacking
Show answerHide answer
Tricking a user into clicking a hidden element via a transparent overlay/iframe.
Wireless Network Hacking (14)
- WEP
Show answerHide answer
Obsolete Wi-Fi encryption using RC4 with a weak, reused IV — completely broken.
- WPA2
Show answerHide answer
Wi-Fi security using AES-CCMP; weak pre-shared keys are crackable offline.
- WPA3
Show answerHide answer
Current Wi-Fi standard; SAE (Dragonfly) resists offline password cracking.
- Four-way handshake
Show answerHide answer
The WPA2 key exchange; capturing it enables an offline dictionary attack.
- Aircrack-ng
Show answerHide answer
A suite for capturing handshakes and cracking WEP/WPA keys.
- Evil twin
Show answerHide answer
A rogue access point impersonating a legitimate SSID to capture traffic/credentials.
- Rogue access point
Show answerHide answer
An unauthorized AP attached to a network, creating a backdoor.
- Deauthentication attack
Show answerHide answer
Forging deauth frames to knock clients off so they reconnect (often to an evil twin).
- WPS attack
Show answerHide answer
Brute-forcing the 8-digit Wi-Fi Protected Setup PIN to recover the passphrase.
- Bluejacking
Show answerHide answer
Sending unsolicited messages to a Bluetooth device.
- Bluesnarfing
Show answerHide answer
Stealing data from a Bluetooth device without permission.
- Bluebugging
Show answerHide answer
Taking control of a Bluetooth device to make calls or read data.
- KRACK
Show answerHide answer
Key Reinstallation Attack against the WPA2 four-way handshake.
- Wardriving
Show answerHide answer
Searching for Wi-Fi networks while moving, to map and target them.
Mobile, IoT & OT Hacking (17)
- OWASP Mobile Top 10
Show answerHide answer
The list of the most critical mobile application security risks.
- Rooting / jailbreaking
Show answerHide answer
Removing an OS's built-in restrictions — also removes security protections.
- App repackaging
Show answerHide answer
Adding malware to a legitimate app and redistributing it.
- Insecure data storage
Show answerHide answer
Storing sensitive data (tokens, credentials) unprotected on a device.
- MDM
Show answerHide answer
Mobile Device Management — enforces policy, encryption, and remote wipe.
- BYOD
Show answerHide answer
Bring Your Own Device — employees use personal devices for work.
- COPE
Show answerHide answer
Corporate-Owned, Personally Enabled device model.
- Overlay attack
Show answerHide answer
Malware that draws a fake screen over a real app to steal input.
- IoT
Show answerHide answer
Internet of Things — networked physical devices, often with weak defaults.
- OWASP IoT Top 10
Show answerHide answer
Leading IoT risks: weak passwords, insecure services, no update mechanism.
- Weak default credentials
Show answerHide answer
Hard-coded/default passwords on IoT devices that are rarely changed.
- OT
Show answerHide answer
Operational Technology — systems that monitor and control physical processes.
- ICS / SCADA
Show answerHide answer
Industrial Control Systems / Supervisory Control and Data Acquisition.
- AIC priority (OT)
Show answerHide answer
OT flips the CIA triad to Availability → Integrity → Confidentiality (safety first).
- Zigbee / BLE
Show answerHide answer
Short-range IoT protocols that expand the wireless attack surface.
- IoT segmentation
Show answerHide answer
Isolating IoT/OT devices on separate networks as a key defense.
- Purdue model
Show answerHide answer
A reference architecture for segmenting ICS/OT network zones.
Cloud Computing (14)
- Shared responsibility model
Show answerHide answer
Provider secures the cloud; customer secures data, identities, and config.
- IaaS
Show answerHide answer
Infrastructure as a Service — customer manages OS, apps, and data (the most).
- PaaS
Show answerHide answer
Platform as a Service — provider manages the runtime; customer manages apps/data.
- SaaS
Show answerHide answer
Software as a Service — provider manages almost everything (customer: data/access).
- Cloud misconfiguration
Show answerHide answer
The leading cause of cloud breaches — e.g., a public storage bucket.
- Public S3 bucket
Show answerHide answer
An object-storage bucket left readable to anyone — a classic cloud finding.
- IAM key compromise
Show answerHide answer
Stolen long-lived API keys let an attacker abuse cloud resources.
- Cryptojacking
Show answerHide answer
Using stolen cloud resources to mine cryptocurrency.
- Container
Show answerHide answer
Packages an app with its dependencies, sharing the host OS kernel (e.g., Docker).
- Container escape
Show answerHide answer
Breaking out of a container's isolation to reach the host or other containers.
- Kubernetes secrets
Show answerHide answer
Sensitive values (passwords, keys) used by pods — must be protected.
- Serverless
Show answerHide answer
Running functions without managing servers; risks include over-permissioned roles.
- Least privilege (cloud)
Show answerHide answer
Granting IAM roles only the minimum permissions needed.
- CASB
Show answerHide answer
Cloud Access Security Broker — enforces policy between users and cloud services.
Cryptography (24)
- Symmetric encryption
Show answerHide answer
One shared secret key encrypts and decrypts; fast (AES, DES/3DES).
- Asymmetric encryption
Show answerHide answer
A public/private key pair; encrypt with one key, decrypt with the other (RSA, ECC).
- Hashing
Show answerHide answer
A one-way function producing a fixed-length digest (SHA-256); not reversible.
- AES
Show answerHide answer
The current symmetric block-cipher standard (Rijndael); 128/192/256-bit keys.
- RSA
Show answerHide answer
An asymmetric algorithm whose security rests on factoring large numbers.
- ECC
Show answerHide answer
Elliptic Curve Cryptography — strong asymmetric security with smaller keys.
- Diffie-Hellman
Show answerHide answer
A key-exchange algorithm that derives a shared secret over an insecure channel.
- MD5
Show answerHide answer
A broken hash function — practical collisions make it unsafe for integrity.
- SHA-1
Show answerHide answer
A broken hash function — collision attacks exist; replaced by SHA-256/SHA-3.
- SHA-256
Show answerHide answer
A secure hash producing a 256-bit digest, widely used for integrity.
- Digital signature
Show answerHide answer
A hash signed with the sender's private key; proves integrity and authenticity.
- Encrypt vs sign keys
Show answerHide answer
Encrypt FOR someone with their public key; SIGN with your own private key.
- PKI
Show answerHide answer
Public Key Infrastructure — CAs, policies, and keys that issue digital certificates.
- X.509 certificate
Show answerHide answer
A file binding a public key to a verified identity, signed by a CA.
- Certificate Authority
Show answerHide answer
A trusted entity that issues and signs digital certificates.
- CRL / OCSP
Show answerHide answer
Certificate Revocation List / Online Certificate Status Protocol — revocation checks.
- TLS handshake
Show answerHide answer
Uses asymmetric crypto to exchange a fast symmetric session key (hybrid).
- Birthday attack
Show answerHide answer
Exploits collision math to find two inputs with the same hash faster than brute force.
- ECB mode weakness
Show answerHide answer
Encrypting identical blocks identically leaks patterns — avoid ECB.
- Key escrow
Show answerHide answer
Storing copies of cryptographic keys with a trusted third party for recovery.
- PGP / GPG
Show answerHide answer
Tools for email encryption and signing using public-key cryptography.
- Disk encryption
Show answerHide answer
Protecting data at rest by encrypting the whole drive (e.g., BitLocker).
- Salting (crypto)
Show answerHide answer
Unique random data added before hashing so equal passwords differ.
- Collision
Show answerHide answer
When two different inputs produce the same hash — a flaw in MD5/SHA-1.
References
- 1.EC-Council. “Certified Ethical Hacker (CEH) — Program Overview.” eccouncil.org. ↑
- 2.EC-Council. “CEH Exam Blueprint v5.0.” cert.eccouncil.org. ↑
- 3.The MITRE Corporation. “MITRE ATT&CK — Enterprise Matrix.” attack.mitre.org. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
