Career Employer

Your FREE CEH Flashcards 2026 – 200+ Cards

Realistic, CEH exam-style flashcards across all 9 official domains — flip, match, type, and quiz yourself.

How well do you know them?

To find us again, just search “Career Employer CEH”

By

Click Study Flashcards above to open the flashcard hub — hundreds of CEH cards you can flip, match, type, or quiz yourself on. Every card is drawn from the nine official CEH v13 domains, so you study exactly what the exam tests.[2] Pair them with our free practice test and study guide.

CEH Flashcard Study Modes

Flip mode is the straight study pass, front to back, at your own speed. Match is the timed game where you pair terms with definitions. Type shows you a definition and asks you to produce the term, so a front like KRACK has to come back spelled correctly. Quiz turns the same cards into multiple choice for mixed recall.

Free CEH flashcards from Career Employer — active recall for the EC-Council Certified Ethical Hacker exam

Why Flashcards Work for CEH

Network & Perimeter Hacking is the largest block at 45 cards and the heaviest part of the exam at 24%, so it drills detection gear and traffic-level attacks together. Cards like IDS, IPS, and tcpdump sit alongside DNSSEC, while Botnet and DDoS cover volumetric attacks and social engineering fronts such as Whaling and Vishing round out the human side.

Reconnaissance Techniques brings 32 cards for 17% of the exam and leans on footprinting tools and port recall, with fronts like Nmap, Shodan, and Maltego next to OSINT, NTP port, and NFS port. System Hacking & Malware adds 35 cards covering malware taxonomy, vulnerability scoring, and credential defense, including CVE, CVSS, and Rootkit, plus Salting and APT.

Web Application Hacking holds 25 cards for 14% and focuses on injection and access-control flaws: CSRF, SSRF, and IDOR appear beside Stored XSS, Blind SQLi, and tooling like Burp Suite and WAF. Mobile, IoT & OT Hacking contributes 17 cards for 10%, mixing device policy terms such as MDM, BYOD, and COPE with industrial fronts like ICS / SCADA and Purdue model.

The remaining domains are smaller in weight but dense in vocabulary. Information Security & Ethical Hacking Overview runs 35 cards on foundational and regulatory terms, including Risk, Threat, and Asset alongside GDPR, HIPAA, and PCI-DSS. Wireless Network Hacking has 14 cards for 5%, covering WEP, WPA3, and Evil twin. Cloud Computing adds 14 cards for 5% with IaaS, CASB, and Public S3 bucket. Cryptography closes with 24 cards for 5%, drilling AES, RSA, PKI, and hash fronts like MD5 and SHA-256.

CEH is dense with terminology — attack types, malware families, hacking tools, default ports, cryptography, and frameworks like MITRE ATT&CK.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.

CEH Flashcards by Domain

The cards are organized by the nine official CEH v13 domains. Drill the highest-weighted ones first — Network & Perimeter Hacking and Reconnaissance alone are 41% of the exam:[2]

CEH flashcards by domain and weight
DomainExam weight
Network & Perimeter Hacking24%
Reconnaissance Techniques17%
System Hacking Phases & Attack Techniques15%
Web Application Hacking14%
Mobile, IoT & OT Hacking10%
Information Security & Overview6%
Wireless Network Hacking5%
Cloud Computing5%
Cryptography5%

How to Get the Most Out of These Flashcards

  • Start at the perimeter. Network & Perimeter Hacking carries 45 cards and 24% of the exam, so run it in Flip first until IDS, IPS, and DNSSEC come back instantly.
  • Type-drill the lookalikes. Terms that blur under pressure, such as CSRF against SSRF or Whaling against Vishing, belong in Type, where producing the exact term proves you actually separated them.
  • Use Match for the short fronts. Port and acronym cards like NTP port, NFS port, and IaaS pair quickly, and the timer exposes which ones you are guessing rather than knowing.
  • Move to the practice test when Quiz stops surprising you. Once the multiple choice across all 241 cards feels routine, shift to scenario wording and use the study guide to close gaps.
  • Rotate two domains a session. Pair a heavy one like Reconnaissance Techniques with a lighter one like Cryptography, then Quiz across the whole deck so older cards keep resurfacing.

CEH Flashcards FAQ

Hundreds of free CEH flashcards, organized across all nine official CEH v13 domains — from Reconnaissance and System Hacking to Web Application Hacking, Wireless, Cloud, and Cryptography. They're free with no account required.

CEH flashcard bank

All 241 cards, by topic

A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.

Information Security & Ethical Hacking Overview (35)

CIA triad
Show answer

Confidentiality, Integrity, Availability — the three core goals of information security.

Confidentiality
Show answer

Ensuring only authorized people can access data; enforced by encryption and access control.

Integrity
Show answer

Ensuring data is accurate and unaltered; enforced by hashing and digital signatures.

Availability
Show answer

Ensuring authorized users can access data and systems when needed; enforced by redundancy and backups.

Non-repudiation
Show answer

Assurance that someone cannot deny an action; provided by digital signatures and logging.

Vulnerability
Show answer

A weakness or flaw in a system that could be exploited by a threat.

Threat
Show answer

A potential danger — an attacker or malware — that could exploit a vulnerability.

Exploit
Show answer

The code or technique that actively takes advantage of a vulnerability.

Risk
Show answer

The likelihood a threat exploits a vulnerability combined with the impact if it does.

Asset
Show answer

Anything of value worth protecting — data, a server, a service, or a reputation.

Five phases of hacking
Show answer

Reconnaissance, Scanning, Gaining Access, Maintaining Access, Clearing Tracks.

Reconnaissance (phase 1)
Show answer

Gathering information about the target before attacking.

Gaining Access (phase 3)
Show answer

Exploiting a weakness to get into a system, then escalating privileges.

Maintaining Access (phase 4)
Show answer

Keeping the foothold with backdoors, rootkits, or new accounts.

Clearing Tracks (phase 5)
Show answer

Covering the trail — clearing logs, hiding files, disabling auditing.

White hat
Show answer

An authorized, ethical hacker who tests systems with permission to improve security.

Black hat
Show answer

A malicious attacker who breaks into systems without authorization for harm or gain.

Gray hat
Show answer

A hacker who probes systems without permission but without clear malicious intent.

Script kiddie
Show answer

An unskilled attacker who uses tools and exploits written by others.

Hacktivist
Show answer

An attacker motivated by a political or social cause.

Defense in depth
Show answer

Layering multiple independent controls so one failure doesn't expose the asset.

Cyber Kill Chain
Show answer

Lockheed Martin's 7 stages: recon, weaponization, delivery, exploitation, installation, C2, actions on objectives.

MITRE ATT&CK
Show answer

A knowledge base of real-world adversary tactics and techniques across the attack lifecycle.

Black-box testing
Show answer

A pentest where the tester has no prior knowledge of the target (external attacker view).

White-box testing
Show answer

A pentest where the tester has full knowledge (architecture, source, credentials).

Gray-box testing
Show answer

A pentest with partial knowledge, such as a standard user account.

Rules of engagement
Show answer

The agreed scope, methods, timing, and limits of an authorized engagement.

Vulnerability scan vs pentest
Show answer

A scan only identifies weaknesses; a penetration test actually exploits them.

Authorization
Show answer

Written permission and defined scope — the only thing separating a CEH from a criminal.

PCI-DSS
Show answer

Payment Card Industry Data Security Standard — protects cardholder data.

HIPAA
Show answer

U.S. law protecting the privacy and security of health information.

GDPR
Show answer

EU regulation governing personal-data privacy and protection.

ISO/IEC 27001
Show answer

International standard for an information security management system (ISMS).

AAA
Show answer

Authentication, Authorization, Accounting.

Bug bounty
Show answer

A program that pays outside researchers for responsibly disclosed vulnerabilities.

Reconnaissance Techniques (32)

Footprinting
Show answer

Systematically gathering information to profile a target's network, people, and tech.

Passive reconnaissance
Show answer

Gathering info with no direct contact — OSINT, WHOIS, DNS, Shodan, social media.

Active reconnaissance
Show answer

Interacting with the target directly — ping sweeps, port scans, banner grabbing.

OSINT
Show answer

Open-Source Intelligence — information gathered from publicly available sources.

Google dorking
Show answer

Using search operators (site:, inurl:, intitle:, filetype:) to find exposed information.

Shodan
Show answer

A search engine that indexes Internet-connected devices and their open services.

WHOIS
Show answer

A query returning domain/IP registration details (registrar, contacts, name servers).

DNS enumeration
Show answer

Querying DNS records (A, MX, NS, TXT); a zone transfer can dump the whole zone.

DNS zone transfer (AXFR)
Show answer

Copying an entire DNS zone; if misconfigured, it leaks all records to an attacker.

theHarvester
Show answer

A tool that gathers emails, subdomains, and hosts from public sources.

Maltego
Show answer

An OSINT tool that maps relationships between people, domains, and infrastructure.

Nmap
Show answer

The standard network scanner for host discovery, port scanning, and OS/version detection.

TCP three-way handshake
Show answer

SYN → SYN/ACK → ACK — how a TCP connection is established.

TCP connect scan (-sT)
Show answer

Completes the full handshake — reliable but easily logged.

SYN / half-open scan (-sS)
Show answer

Sends SYN, never finishes the handshake — stealthier; the default for root.

NULL / FIN / Xmas scans
Show answer

Send unusual TCP flag combinations to slip past simple filters.

UDP scan (-sU)
Show answer

Probes connectionless services like DNS, SNMP, and DHCP.

Banner grabbing
Show answer

Reading a service's response to identify its software and version.

OS fingerprinting (-O)
Show answer

Identifying the target operating system from network behavior.

Ping sweep
Show answer

Sending ICMP echo requests to a range to find live hosts.

Enumeration
Show answer

Actively extracting users, shares, services, and config after scanning.

NetBIOS / SMB ports
Show answer

137–139 and 445 — enumerate Windows shares, users, and system names.

SNMP port
Show answer

161 — default community strings ('public'/'private') can leak device config.

LDAP port
Show answer

389 — enumerate directory objects: users, groups, and OUs.

SMTP enumeration
Show answer

Port 25 — VRFY/EXPN/RCPT TO can reveal valid email accounts.

NTP port
Show answer

123 — can reveal hosts and times that sync to a server.

NFS port
Show answer

2049 — network file shares that may be exported insecurely.

SNMP community strings
Show answer

Shared 'passwords' for SNMP; defaults 'public' (read) and 'private' (write) are classic findings.

Scanning countermeasure
Show answer

Reduce exposed ports and services — you can't attack a closed port.

netcat
Show answer

A versatile tool to read/write network connections; banner grabbing and simple backdoors.

Wayback / archived pages
Show answer

Old site versions revealing structure or data the target later removed.

Email footprinting
Show answer

Tracking email headers and read-receipts to map infrastructure and behavior.

System Hacking & Malware (35)

Vulnerability assessment
Show answer

A systematic review that identifies, classifies, and prioritizes weaknesses.

CVSS
Show answer

Common Vulnerability Scoring System — a 0–10 score rating a vulnerability's severity.

CVE
Show answer

Common Vulnerabilities and Exposures — a public catalog of IDs for known vulnerabilities.

False positive
Show answer

A finding flagged as a vulnerability that isn't actually exploitable.

Password cracking
Show answer

Recovering passwords from hashes via dictionary, brute-force, hybrid, or rainbow tables.

Dictionary attack
Show answer

Tries a wordlist of likely passwords against a hash or login.

Brute-force attack
Show answer

Tries every possible combination until the password is found.

Hybrid attack
Show answer

Combines a dictionary with appended numbers/symbols (e.g., Password123!).

Rainbow table
Show answer

A precomputed table of hashes used to reverse unsalted password hashes quickly.

Salting
Show answer

Adding unique random data before hashing so identical passwords differ; defeats rainbow tables.

Pass-the-hash
Show answer

Authenticating with a captured NTLM hash without cracking the plaintext password.

Kerberoasting
Show answer

Requesting service tickets and cracking them offline to recover service-account passwords.

Privilege escalation
Show answer

Gaining higher access than granted — vertical (to admin) or horizontal (to another user).

Vertical privilege escalation
Show answer

Moving from a low-privilege account to administrator or root.

Horizontal privilege escalation
Show answer

Moving sideways to another user's account at the same level.

DLL hijacking
Show answer

Tricking a program into loading a malicious library to run attacker code.

SUID exploitation
Show answer

Abusing a Linux root-owned binary with the setuid bit to gain root.

Rootkit
Show answer

Malware that hides deep in the system (often the kernel) for stealthy privileged access.

User-mode vs kernel-mode rootkit
Show answer

User-mode hooks normal programs; kernel-mode runs with the highest privilege and is harder to detect.

Keylogger
Show answer

Software or hardware that records keystrokes to capture passwords and input.

Spyware
Show answer

Malware that secretly collects information about a user or system.

Steganography
Show answer

Hiding data inside other data (e.g., within an image) to conceal its existence.

Clearing logs
Show answer

Deleting or altering log entries to cover the attacker's tracks.

Malware
Show answer

Malicious software — viruses, worms, trojans, ransomware, spyware, rootkits, fileless.

Virus
Show answer

Malware that attaches to a host file and needs user action to run and spread.

Worm
Show answer

Self-propagating malware that spreads across networks with no user action.

Trojan
Show answer

Malware disguised as legitimate software that opens a hidden backdoor when run.

Ransomware
Show answer

Malware that encrypts a victim's data and demands payment for the decryption key.

Double extortion
Show answer

Ransomware that also steals data and threatens to leak it if no ransom is paid.

Fileless malware
Show answer

Malware that runs in memory using legitimate tools to evade disk-based detection.

APT
Show answer

Advanced Persistent Threat — a skilled, well-resourced adversary keeping long-term stealthy access.

Logic bomb
Show answer

Malicious code that executes when a specific condition (date/event) is met.

Static malware analysis
Show answer

Inspecting malware without running it (strings, hashes, headers).

Dynamic malware analysis
Show answer

Running malware in a sandbox to observe its behavior.

Backdoor
Show answer

A hidden method of bypassing authentication to regain access to a system.

Network & Perimeter Hacking (45)

Sniffing
Show answer

Capturing and inspecting network traffic, often to harvest credentials or data.

Promiscuous mode
Show answer

A NIC mode that captures all traffic on a segment, not just frames addressed to it.

Active vs passive sniffing
Show answer

Passive works on hubs; active (ARP poisoning) is needed on switched networks.

Wireshark
Show answer

A packet analyzer used to capture and inspect network traffic in detail.

tcpdump
Show answer

A command-line packet capture tool for Unix/Linux.

ARP poisoning
Show answer

Sending forged ARP replies to redirect LAN traffic through the attacker (on-path).

ARP poisoning defense
Show answer

Dynamic ARP Inspection (DAI), static ARP entries, and encryption.

MAC flooding
Show answer

Overflowing a switch's CAM table so it fails open and broadcasts like a hub.

MAC flooding defense
Show answer

Port security — limit the number of MAC addresses per port.

DHCP starvation
Show answer

Exhausting the DHCP pool, then offering an attacker-controlled gateway/DNS.

DHCP snooping
Show answer

A switch feature that blocks rogue DHCP servers and starvation attacks.

DNS poisoning
Show answer

Injecting false DNS records so victims resolve a name to an attacker's host.

DNSSEC
Show answer

Adds cryptographic signatures to DNS to prevent record forgery.

On-path attack
Show answer

Secretly relaying or altering traffic between two parties (formerly man-in-the-middle).

MAC spoofing
Show answer

Changing a device's MAC address to impersonate another or bypass filters.

Social engineering
Show answer

Manipulating people into divulging info or actions that compromise security.

Phishing
Show answer

A fraudulent email that tricks the victim into revealing credentials or running malware.

Spear phishing
Show answer

Phishing targeted at a specific individual or organization.

Whaling
Show answer

Phishing that targets high-value executives.

Vishing
Show answer

Voice phishing — a social-engineering attack over a phone call.

Smishing
Show answer

SMS phishing — a social-engineering attack by text message.

Pretexting
Show answer

Inventing a believable scenario to extract information from a target.

Tailgating / piggybacking
Show answer

Following an authorized person through a secure door without credentials.

Impersonation
Show answer

Posing as IT, a vendor, or an executive to gain trust and access.

Business email compromise
Show answer

Impersonating a trusted executive or vendor to authorize fraudulent payments.

Insider threat
Show answer

An employee/contractor misusing authorized access to harm the organization.

Social engineering defense
Show answer

Recurring security-awareness training plus phishing simulations.

Denial-of-service (DoS)
Show answer

Overwhelming a system so legitimate users can't access it.

DDoS
Show answer

A distributed DoS launched from many compromised machines (a botnet) at once.

Botnet
Show answer

A network of malware-infected 'zombie' hosts controlled by an attacker.

SYN flood
Show answer

A protocol DoS that exhausts server state with half-open TCP connections.

Volumetric attack
Show answer

A DoS that saturates the target's bandwidth (UDP/ICMP floods, amplification).

Application-layer DoS
Show answer

Low-volume valid-looking requests that exhaust app resources (e.g., Slowloris).

SYN cookies
Show answer

A defense that lets a server handle SYN floods without allocating state.

Session hijacking
Show answer

Taking over an authenticated session by stealing or predicting the session ID.

Session fixation
Show answer

Planting a known session ID before the victim logs in, then reusing it.

HttpOnly cookie flag
Show answer

Prevents JavaScript from reading a cookie — blunts cookie theft via XSS.

Secure cookie flag
Show answer

Ensures a cookie is only sent over HTTPS.

IDS
Show answer

Intrusion Detection System — detects and alerts on suspicious traffic (passive).

IPS
Show answer

Intrusion Prevention System — detects and blocks suspicious traffic inline (active).

Stateful firewall
Show answer

A firewall that tracks connection state to allow only valid return traffic.

Honeypot
Show answer

A decoy system that lures attackers away from real assets and records them.

Honeynet
Show answer

A network of honeypots that mimics a real environment.

IDS evasion
Show answer

Fragmentation, encoding, and tunneling to break the signature an IDS looks for.

Firewalking
Show answer

Probing which ports/services a firewall permits by manipulating TTLs.

Web Application Hacking (25)

OWASP Top 10
Show answer

The list of the most critical web application security risks.

Web server attack
Show answer

Targeting server software/config — traversal, defaults, unpatched CVEs.

Directory traversal
Show answer

Using ../ to access files outside the intended web root.

SQL injection
Show answer

Inserting malicious SQL into input so the database runs unintended commands.

SQLi primary fix
Show answer

Parameterized queries (prepared statements) plus input validation.

In-band SQLi
Show answer

SQL injection where results come back in the same channel (union/error-based).

Blind SQLi
Show answer

Inferring data via true/false (boolean) or response timing (time-based).

' OR '1'='1
Show answer

A classic SQLi payload that makes a WHERE clause always true to bypass login.

Cross-site scripting (XSS)
Show answer

Injecting script into a trusted site that runs in another user's browser.

Stored XSS
Show answer

Malicious script persisted on the server and served to many users.

Reflected XSS
Show answer

Malicious script echoed back from a request and run immediately.

DOM-based XSS
Show answer

XSS executed entirely in the browser via the page's own JavaScript.

XSS primary fix
Show answer

Output encoding plus a Content Security Policy (CSP).

CSRF
Show answer

Forcing an authenticated user's browser to send an unwanted request to a trusted site.

CSRF defense
Show answer

Anti-CSRF tokens and SameSite cookies.

Command injection
Show answer

Running OS commands through unvalidated input.

LFI / RFI
Show answer

Local/Remote File Inclusion — loading attacker-chosen files via input.

SSRF
Show answer

Server-Side Request Forgery — making the server request attacker-chosen URLs.

Broken access control
Show answer

Failing to enforce what authenticated users may do — a top OWASP risk.

IDOR
Show answer

Insecure Direct Object Reference — accessing others' data by changing an ID.

Input validation
Show answer

Treating all user input as untrusted and checking it server-side.

WAF
Show answer

Web Application Firewall — filters layer-7 attacks like injection and XSS.

Burp Suite
Show answer

A proxy/toolkit for intercepting and testing web application requests.

Web cache poisoning
Show answer

Tricking a cache into storing and serving a malicious response.

Clickjacking
Show answer

Tricking a user into clicking a hidden element via a transparent overlay/iframe.

Wireless Network Hacking (14)

WEP
Show answer

Obsolete Wi-Fi encryption using RC4 with a weak, reused IV — completely broken.

WPA2
Show answer

Wi-Fi security using AES-CCMP; weak pre-shared keys are crackable offline.

WPA3
Show answer

Current Wi-Fi standard; SAE (Dragonfly) resists offline password cracking.

Four-way handshake
Show answer

The WPA2 key exchange; capturing it enables an offline dictionary attack.

Aircrack-ng
Show answer

A suite for capturing handshakes and cracking WEP/WPA keys.

Evil twin
Show answer

A rogue access point impersonating a legitimate SSID to capture traffic/credentials.

Rogue access point
Show answer

An unauthorized AP attached to a network, creating a backdoor.

Deauthentication attack
Show answer

Forging deauth frames to knock clients off so they reconnect (often to an evil twin).

WPS attack
Show answer

Brute-forcing the 8-digit Wi-Fi Protected Setup PIN to recover the passphrase.

Bluejacking
Show answer

Sending unsolicited messages to a Bluetooth device.

Bluesnarfing
Show answer

Stealing data from a Bluetooth device without permission.

Bluebugging
Show answer

Taking control of a Bluetooth device to make calls or read data.

KRACK
Show answer

Key Reinstallation Attack against the WPA2 four-way handshake.

Wardriving
Show answer

Searching for Wi-Fi networks while moving, to map and target them.

Mobile, IoT & OT Hacking (17)

OWASP Mobile Top 10
Show answer

The list of the most critical mobile application security risks.

Rooting / jailbreaking
Show answer

Removing an OS's built-in restrictions — also removes security protections.

App repackaging
Show answer

Adding malware to a legitimate app and redistributing it.

Insecure data storage
Show answer

Storing sensitive data (tokens, credentials) unprotected on a device.

MDM
Show answer

Mobile Device Management — enforces policy, encryption, and remote wipe.

BYOD
Show answer

Bring Your Own Device — employees use personal devices for work.

COPE
Show answer

Corporate-Owned, Personally Enabled device model.

Overlay attack
Show answer

Malware that draws a fake screen over a real app to steal input.

IoT
Show answer

Internet of Things — networked physical devices, often with weak defaults.

OWASP IoT Top 10
Show answer

Leading IoT risks: weak passwords, insecure services, no update mechanism.

Weak default credentials
Show answer

Hard-coded/default passwords on IoT devices that are rarely changed.

OT
Show answer

Operational Technology — systems that monitor and control physical processes.

ICS / SCADA
Show answer

Industrial Control Systems / Supervisory Control and Data Acquisition.

AIC priority (OT)
Show answer

OT flips the CIA triad to Availability → Integrity → Confidentiality (safety first).

Zigbee / BLE
Show answer

Short-range IoT protocols that expand the wireless attack surface.

IoT segmentation
Show answer

Isolating IoT/OT devices on separate networks as a key defense.

Purdue model
Show answer

A reference architecture for segmenting ICS/OT network zones.

Cloud Computing (14)

Shared responsibility model
Show answer

Provider secures the cloud; customer secures data, identities, and config.

IaaS
Show answer

Infrastructure as a Service — customer manages OS, apps, and data (the most).

PaaS
Show answer

Platform as a Service — provider manages the runtime; customer manages apps/data.

SaaS
Show answer

Software as a Service — provider manages almost everything (customer: data/access).

Cloud misconfiguration
Show answer

The leading cause of cloud breaches — e.g., a public storage bucket.

Public S3 bucket
Show answer

An object-storage bucket left readable to anyone — a classic cloud finding.

IAM key compromise
Show answer

Stolen long-lived API keys let an attacker abuse cloud resources.

Cryptojacking
Show answer

Using stolen cloud resources to mine cryptocurrency.

Container
Show answer

Packages an app with its dependencies, sharing the host OS kernel (e.g., Docker).

Container escape
Show answer

Breaking out of a container's isolation to reach the host or other containers.

Kubernetes secrets
Show answer

Sensitive values (passwords, keys) used by pods — must be protected.

Serverless
Show answer

Running functions without managing servers; risks include over-permissioned roles.

Least privilege (cloud)
Show answer

Granting IAM roles only the minimum permissions needed.

CASB
Show answer

Cloud Access Security Broker — enforces policy between users and cloud services.

Cryptography (24)

Symmetric encryption
Show answer

One shared secret key encrypts and decrypts; fast (AES, DES/3DES).

Asymmetric encryption
Show answer

A public/private key pair; encrypt with one key, decrypt with the other (RSA, ECC).

Hashing
Show answer

A one-way function producing a fixed-length digest (SHA-256); not reversible.

AES
Show answer

The current symmetric block-cipher standard (Rijndael); 128/192/256-bit keys.

RSA
Show answer

An asymmetric algorithm whose security rests on factoring large numbers.

ECC
Show answer

Elliptic Curve Cryptography — strong asymmetric security with smaller keys.

Diffie-Hellman
Show answer

A key-exchange algorithm that derives a shared secret over an insecure channel.

MD5
Show answer

A broken hash function — practical collisions make it unsafe for integrity.

SHA-1
Show answer

A broken hash function — collision attacks exist; replaced by SHA-256/SHA-3.

SHA-256
Show answer

A secure hash producing a 256-bit digest, widely used for integrity.

Digital signature
Show answer

A hash signed with the sender's private key; proves integrity and authenticity.

Encrypt vs sign keys
Show answer

Encrypt FOR someone with their public key; SIGN with your own private key.

PKI
Show answer

Public Key Infrastructure — CAs, policies, and keys that issue digital certificates.

X.509 certificate
Show answer

A file binding a public key to a verified identity, signed by a CA.

Certificate Authority
Show answer

A trusted entity that issues and signs digital certificates.

CRL / OCSP
Show answer

Certificate Revocation List / Online Certificate Status Protocol — revocation checks.

TLS handshake
Show answer

Uses asymmetric crypto to exchange a fast symmetric session key (hybrid).

Birthday attack
Show answer

Exploits collision math to find two inputs with the same hash faster than brute force.

ECB mode weakness
Show answer

Encrypting identical blocks identically leaks patterns — avoid ECB.

Key escrow
Show answer

Storing copies of cryptographic keys with a trusted third party for recovery.

PGP / GPG
Show answer

Tools for email encryption and signing using public-key cryptography.

Disk encryption
Show answer

Protecting data at rest by encrypting the whole drive (e.g., BitLocker).

Salting (crypto)
Show answer

Unique random data added before hashing so equal passwords differ.

Collision
Show answer

When two different inputs produce the same hash — a flaw in MD5/SHA-1.

References

  1. 1.EC-Council. “Certified Ethical Hacker (CEH) — Program Overview.” eccouncil.org. ↑
  2. 2.EC-Council. “CEH Exam Blueprint v5.0.” cert.eccouncil.org. ↑
  3. 3.The MITRE Corporation. “MITRE ATT&CK — Enterprise Matrix.” attack.mitre.org. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.