Free knowledge base

EC-Council Certified Ethical Hacker (CEH) v12 — key terms, tricks & tips

Everything from the course in one searchable place: 526 entries. Use it to review before a practice test or look up a word you forgot.

526 results · showing first 300, refine your search

Key term

Proctored Exam

An exam supervised to ensure fairness and prevent cheating.

Getting Started: Your CEH v12 Journey

Key term

Scaled Scoring

Exam scoring where question difficulty influences passing score.

Getting Started: Your CEH v12 Journey

Key term

Domain Weighting

Percentage indicating the importance of an exam topic area.

Getting Started: Your CEH v12 Journey

Key term

CEH Practical

A separate, hands-on exam for applying ethical hacking skills.

Getting Started: Your CEH v12 Journey

Key term

CEH Master

Designation for passing both CEH multiple-choice and practical exams.

Getting Started: Your CEH v12 Journey

Key term

Blueprint

Official document detailing exam topics and objectives.

Getting Started: Your CEH v12 Journey

Key term

312-50

The official exam code for the CEH v12 multiple-choice exam.

Getting Started: Your CEH v12 Journey

Memory trick

CEH v12 Exam Structure & Objectives

To remember the exam details: '1-2-5 questions, 4 hours to strive, 60 to 85 to stay alive!'

Getting Started: Your CEH v12 Journey

Exam tip

CEH v12 Exam Structure & Objectives

The CEH v12 exam has 125 multiple-choice questions and a 4-hour time limit. The passing score is variable, typically between 60-85%. Memorize the top three weighted domains: Footprinting and Reconnaissance (21%), Scanning Networks (16%), and Enumeration (10%).

Getting Started: Your CEH v12 Journey

Common mistake

CEH v12 Exam Structure & Objectives

Underestimating the importance of lower-weighted domains; while less frequent, questions from these domains still count.

Getting Started: Your CEH v12 Journey

Common mistake

CEH v12 Exam Structure & Objectives

Not practicing hands-on skills, even if not immediately taking the CEH Practical; practical application solidifies theoretical knowledge.

Getting Started: Your CEH v12 Journey

Common mistake

CEH v12 Exam Structure & Objectives

Focusing solely on memorization without understanding the underlying concepts and why certain tools or techniques are used.

Getting Started: Your CEH v12 Journey

Key term

Virtualization

Running multiple OS on one physical machine.

Getting Started: Your CEH v12 Journey

Key term

Hypervisor

Software managing virtual machines and resources.

Getting Started: Your CEH v12 Journey

Key term

Virtual Machine (VM)

A software-based, emulated computer system.

Getting Started: Your CEH v12 Journey

Key term

Host OS

The operating system running on the physical hardware.

Getting Started: Your CEH v12 Journey

Key term

Guest OS

An operating system running inside a VM.

Getting Started: Your CEH v12 Journey

Key term

Kali Linux

A Linux distribution for penetration testing.

Getting Started: Your CEH v12 Journey

Key term

Snapshot

A saved state of a VM at a specific point in time.

Getting Started: Your CEH v12 Journey

Memory trick

Setting Up Your Ethical Hacking Lab Environment

To remember lab components: 'H.H.A.T.' – Host, Hypervisor, Attacker, Target. You need a HAT to hack!

Getting Started: Your CEH v12 Journey

Exam tip

Setting Up Your Ethical Hacking Lab Environment

EC-Council emphasizes practical skills. Expect questions on identifying appropriate tools (e.g., Kali Linux for attacking, Metasploitable for target) and the benefits of virtualization (e.g., isolation, snapshots) for lab setups.

Getting Started: Your CEH v12 Journey

Common mistake

Setting Up Your Ethical Hacking Lab Environment

Not allocating enough RAM or CPU to virtual machines, leading to slow performance.

Getting Started: Your CEH v12 Journey

Common mistake

Setting Up Your Ethical Hacking Lab Environment

Connecting lab VMs directly to the internet, risking exposure or legal issues.

Getting Started: Your CEH v12 Journey

Common mistake

Setting Up Your Ethical Hacking Lab Environment

Forgetting to take snapshots before performing potentially destructive tests.

Getting Started: Your CEH v12 Journey

Key term

Threat

A potential danger that could exploit a vulnerability.

Foundations of Information Security & Hacking

Key term

Vulnerability

A weakness in a system that can be exploited.

Foundations of Information Security & Hacking

Key term

Attack Vector

The path or means by which an attacker gains access.

Foundations of Information Security & Hacking

Key term

Hacking

Unauthorized access to or manipulation of systems.

Foundations of Information Security & Hacking

Key term

Ethical Hacking

Hacking with permission to identify vulnerabilities.

Foundations of Information Security & Hacking

Key term

Reconnaissance

Initial phase of gathering information about a target.

Foundations of Information Security & Hacking

Key term

Social Engineering

Manipulating people to divulge info or perform actions.

Foundations of Information Security & Hacking

Key term

Malware

Malicious software designed to disrupt, damage, or gain access.

Foundations of Information Security & Hacking

Memory trick

InfoSec Threats, Attack Vectors & Hacking Concepts

To remember the hacking phases: 'R S G M C' - Really Smart Guys Make Coffee (Reconnaissance, Scanning, Gaining Access, Maintaining Access, Covering Tracks).

Foundations of Information Security & Hacking

Exam tip

InfoSec Threats, Attack Vectors & Hacking Concepts

The CEH exam frequently asks about the phases of ethical hacking and the CIA triad. Memorize the order of the hacking phases and understand what each phase entails. For the CIA triad, remember Confidentiality, Integrity, and Availability and what each component protects.

Foundations of Information Security & Hacking

Common mistake

InfoSec Threats, Attack Vectors & Hacking Concepts

Confusing a threat with a vulnerability; a threat is the 'who or what' (e.g., hacker), a vulnerability is the 'weakness' (e.g., unpatched software).

Foundations of Information Security & Hacking

Common mistake

InfoSec Threats, Attack Vectors & Hacking Concepts

Underestimating the human element in security; social engineering is a highly effective attack vector.

Foundations of Information Security & Hacking

Common mistake

InfoSec Threats, Attack Vectors & Hacking Concepts

Not understanding the distinct actions performed in each phase of the hacking methodology.

Foundations of Information Security & Hacking

Key term

Information Security Controls

Safeguards to protect confidentiality, integrity, and availability of assets.

Foundations of Information Security & Hacking

Key term

Administrative Controls

Policies, procedures, and guidelines for managing security.

Foundations of Information Security & Hacking

Key term

Technical Controls

Hardware or software mechanisms enforcing security policies.

Foundations of Information Security & Hacking

Key term

Physical Controls

Measures to protect physical access to systems and assets.

Foundations of Information Security & Hacking

Key term

Preventative Controls

Controls designed to stop an incident from occurring.

Foundations of Information Security & Hacking

Key term

Detective Controls

Controls designed to identify and alert about an incident.

Foundations of Information Security & Hacking

Key term

Corrective Controls

Controls designed to minimize impact and restore systems after an incident.

Foundations of Information Security & Hacking

Memory trick

Ethical Hacking Principles & InfoSec Controls

To remember the control types, think 'APT': **A**dministrative (policies), **P**hysical (locks), **T**echnical (firewalls).

Foundations of Information Security & Hacking

Exam tip

Ethical Hacking Principles & InfoSec Controls

The CEH exam frequently tests the classification of controls. Memorize the definitions and examples for administrative, technical, and physical controls, and their functions (preventative, detective, corrective). Look for keywords describing policies, software, or physical barriers.

Foundations of Information Security & Hacking

Common mistake

Ethical Hacking Principles & InfoSec Controls

Confusing the type of control (e.g., administrative vs. technical) with its function (e.g., preventative vs. detective).

Foundations of Information Security & Hacking

Common mistake

Ethical Hacking Principles & InfoSec Controls

Assuming ethical hacking is just about finding vulnerabilities; it also includes reporting and remediation guidance.

Foundations of Information Security & Hacking

Common mistake

Ethical Hacking Principles & InfoSec Controls

Underestimating the importance of administrative controls; technology alone cannot solve all security problems.

Foundations of Information Security & Hacking

Key term

GDPR

General Data Protection Regulation; EU law on data protection and privacy.

Foundations of Information Security & Hacking

Key term

CCPA

California Consumer Privacy Act; US law on consumer data rights.

Foundations of Information Security & Hacking

Key term

HIPAA

Health Insurance Portability and Accountability Act; US law protecting health data.

Foundations of Information Security & Hacking

Key term

CFAA

Computer Fraud and Abuse Act; US law prohibiting unauthorized computer access.

Foundations of Information Security & Hacking

Key term

Authorization

Explicit, documented permission to perform an action.

Foundations of Information Security & Hacking

Key term

Code of Ethics

Principles guiding professional conduct and decision-making.

Foundations of Information Security & Hacking

Memory trick

Legal & Ethical Aspects: Laws and Standards

To remember key laws: 'G-C-H-C' - GDPR, CCPA, HIPAA, CFAA. Think of it as 'Good Cyber Hygiene Counts!'

Foundations of Information Security & Hacking

Exam tip

Legal & Ethical Aspects: Laws and Standards

The CEH exam frequently tests your understanding of the legal implications of hacking. Look for keywords like 'authorization,' 'consent,' 'scope,' and 'reporting' in questions related to penetration testing. Memorize that unauthorized access, even without malicious intent, is illegal.

Foundations of Information Security & Hacking

Common mistake

Legal & Ethical Aspects: Laws and Standards

Assuming good intentions justify unauthorized access.

Foundations of Information Security & Hacking

Common mistake

Legal & Ethical Aspects: Laws and Standards

Failing to obtain explicit, written authorization before any security assessment.

Foundations of Information Security & Hacking

Common mistake

Legal & Ethical Aspects: Laws and Standards

Not understanding the scope of an engagement and exceeding it.

Foundations of Information Security & Hacking

Key term

Cyber Kill Chain

A framework outlining the seven phases of a typical cyberattack.

Foundations of Information Security & Hacking

Key term

MITRE ATT&CK

A knowledge base of adversary tactics and techniques based on real-world observations.

Foundations of Information Security & Hacking

Key term

Attack Methodology

A structured approach or framework describing how cyberattacks are conducted.

Foundations of Information Security & Hacking

Key term

Weaponization

The process of combining an exploit with a payload for delivery.

Foundations of Information Security & Hacking

Key term

Command and Control (C2)

The communication channel between an attacker and a compromised system.

Foundations of Information Security & Hacking

Key term

Unified Kill Chain

A comprehensive framework integrating multiple attack models.

Foundations of Information Security & Hacking

Memory trick

Common Attack Methodologies

Remember the Cyber Kill Chain with 'R W D E I C A': Really Wicked Dragons Eat Icy Cold Apples!

Foundations of Information Security & Hacking

Exam tip

Common Attack Methodologies

The CEH exam frequently tests knowledge of the Cyber Kill Chain phases and their order. Be prepared to identify what happens in each phase and recognize common attack vectors associated with them, especially 'Delivery' and 'Exploitation'.

Foundations of Information Security & Hacking

Common mistake

Common Attack Methodologies

Confusing the linear nature of the Cyber Kill Chain with the more granular, matrix-based MITRE ATT&CK framework.

Foundations of Information Security & Hacking

Common mistake

Common Attack Methodologies

Underestimating the importance of 'Reconnaissance' – often seen as passive, but critical for an attacker's success.

Foundations of Information Security & Hacking

Common mistake

Common Attack Methodologies

Failing to understand that a single attack can involve multiple attack vectors and techniques across different phases.

Foundations of Information Security & Hacking

Key term

Footprinting

Gathering information about a target before an attack or assessment.

Mastering Footprinting Techniques

Key term

Passive Footprinting

Collecting information without direct interaction with the target system.

Mastering Footprinting Techniques

Key term

Active Footprinting

Collecting information through direct interaction with the target system.

Mastering Footprinting Techniques

Key term

OSINT

Open-Source Intelligence; information gathered from publicly available sources.

Mastering Footprinting Techniques

Key term

Attack Surface

The sum of all possible points where an unauthorized user can try to enter or extract data.

Mastering Footprinting Techniques

Key term

WHOIS

A public database containing registration details for domain names and IP addresses.

Mastering Footprinting Techniques

Memory trick

Footprinting Concepts & Passive Information Gathering

P.A.S.S.I.V.E. = Publicly Available Sources Systematically Searched for Information Via Everything.

Mastering Footprinting Techniques

Exam tip

Footprinting Concepts & Passive Information Gathering

The CEH exam frequently tests the distinction between passive and active reconnaissance. Remember that 'passive' means no direct contact with the target, leaving no logs or traces on their systems. Keywords like 'publicly available,' 'OSINT,' 'search engines,' and 'social media' usually point to passive methods.

Mastering Footprinting Techniques

Common mistake

Footprinting Concepts & Passive Information Gathering

Confusing passive and active footprinting: Passive means no direct interaction, active means direct interaction.

Mastering Footprinting Techniques

Common mistake

Footprinting Concepts & Passive Information Gathering

Underestimating the amount of information available publicly: Many organizations leak more than they realize.

Mastering Footprinting Techniques

Common mistake

Footprinting Concepts & Passive Information Gathering

Skipping footprinting: This critical first step saves time and increases effectiveness in later phases.

Mastering Footprinting Techniques

Key term

DNS Reconnaissance

Gathering information from a target's Domain Name System.

Mastering Footprinting Techniques

Key term

Nmap

A powerful network scanner for host discovery and port scanning.

Mastering Footprinting Techniques

Key term

Port Scanning

Identifying open ports on a network host.

Mastering Footprinting Techniques

Key term

Service Enumeration

Determining specific services and their versions running on ports.

Mastering Footprinting Techniques

Key term

Vulnerability Scanner

Tool to identify known security weaknesses in systems.

Mastering Footprinting Techniques

Key term

Web Crawler

Automated program to browse and index web content.

Mastering Footprinting Techniques

Memory trick

Footprinting Tools & Active Reconnaissance

Nmap Needs More Ports! (Nmap for Network Mapping, identifying open Ports).

Mastering Footprinting Techniques

Exam tip

Footprinting Tools & Active Reconnaissance

The CEH exam frequently tests the functionality and common uses of specific tools. Memorize that Nmap is for network scanning, nslookup/dig for DNS, and Nessus/OpenVAS for vulnerability scanning.

Mastering Footprinting Techniques

Common mistake

Footprinting Tools & Active Reconnaissance

Confusing active reconnaissance with passive reconnaissance; active involves direct interaction.

Mastering Footprinting Techniques

Common mistake

Footprinting Tools & Active Reconnaissance

Using aggressive scanning techniques without proper authorization, which can be illegal or trigger alerts.

Mastering Footprinting Techniques

Common mistake

Footprinting Tools & Active Reconnaissance

Failing to document findings from active scans, making it difficult to analyze and report vulnerabilities.

Mastering Footprinting Techniques

Key term

Digital Footprint

The trail of data left by online activities.

Mastering Footprinting Techniques

Key term

WHOIS Privacy

Service to hide domain registrant's personal info.

Mastering Footprinting Techniques

Key term

Zone Transfer

DNS process to replicate domain information.

Mastering Footprinting Techniques

Key term

Metadata

Data about data, often hidden in files.

Mastering Footprinting Techniques

Key term

OSINT Defense

Proactive management of publicly available info.

Mastering Footprinting Techniques

Key term

Information Leakage

Unintended disclosure of sensitive data.

Mastering Footprinting Techniques

Memory trick

Footprinting Countermeasures & OSINT Defenses

To protect your FOOTPRINT, remember P.R.I.V.A.C.Y.: Protect WHOIS, Restrict DNS, Inspect Metadata, Vet Public Info, Audit Regularly, Control Social Media, Yield Less Data.

Mastering Footprinting Techniques

Exam tip

Footprinting Countermeasures & OSINT Defenses

The CEH exam often asks about specific countermeasures for common footprinting techniques. Memorize that disabling DNS zone transfers, using WHOIS privacy, and reviewing public documents for metadata are key defenses. Look for questions about 'preventing information disclosure' or 'reducing attack surface'.

Mastering Footprinting Techniques

Common mistake

Footprinting Countermeasures & OSINT Defenses

Forgetting to check metadata in publicly shared documents (e.g., PDFs, images).

Mastering Footprinting Techniques

Common mistake

Footprinting Countermeasures & OSINT Defenses

Underestimating the amount of information employees share on personal social media.

Mastering Footprinting Techniques

Common mistake

Footprinting Countermeasures & OSINT Defenses

Believing that obscurity alone is a strong security measure; active defense is needed.

Mastering Footprinting Techniques

Key term

Geospatial Intelligence (GEOINT)

Analysis of satellite imagery and geographic data for physical reconnaissance.

Mastering Footprinting Techniques

Key term

Public Records

Government-maintained documents available for public inspection, e.g., business filings.

Mastering Footprinting Techniques

Key term

Supply Chain Footprinting

Gathering intelligence on a target's vendors and partners to find indirect attack vectors.

Mastering Footprinting Techniques

Key term

Metadata Extraction

Retrieving hidden information from files (e.g., images, documents) that reveals details.

Mastering Footprinting Techniques

Key term

Professional Networks

Platforms like LinkedIn used to map organizational structures and individual roles.

Mastering Footprinting Techniques

Key term

Dark Web Monitoring

Searching illicit online forums for mentions of a target or leaked credentials.

Mastering Footprinting Techniques

Key term

Rules of Engagement (ROE)

A formal document outlining the scope, limits, and authorization for a penetration test.

Mastering Footprinting Techniques

Key term

OSINT Fusion

Combining diverse open-source intelligence sources to form a complete picture.

Mastering Footprinting Techniques

Memory trick

Advanced Footprinting Scenarios & Case Studies

Remember 'P.O.S.T. G.A.P.' for advanced footprinting: Public Records, OSINT, Supply Chain, Technical, Geospatial, Authorization, Privacy.

Mastering Footprinting Techniques

Exam tip

Advanced Footprinting Scenarios & Case Studies

The CEH exam often presents scenario-based questions where you must select the most appropriate footprinting technique for a given situation. Pay close attention to keywords like 'physical security,' 'personnel information,' or 'third-party risk' to guide your answer.

Mastering Footprinting Techniques

Common mistake

Advanced Footprinting Scenarios & Case Studies

Failing to document all gathered information, leading to missed connections or redundant efforts.

Mastering Footprinting Techniques

Common mistake

Advanced Footprinting Scenarios & Case Studies

Crossing legal or ethical boundaries by attempting unauthorized access or social engineering without explicit permission.

Mastering Footprinting Techniques

Common mistake

Advanced Footprinting Scenarios & Case Studies

Over-relying on a single source of information without cross-referencing or validating data from multiple sources.

Mastering Footprinting Techniques

Key term

Network Scanning

Process of identifying active devices, open ports, and services on a network.

Network Scanning & Enumeration

Key term

TCP SYN Scan

Half-open scan that doesn't complete the TCP handshake; stealthy.

Network Scanning & Enumeration

Key term

TCP Connect Scan

Completes the full TCP three-way handshake; less stealthy but reliable.

Network Scanning & Enumeration

Key term

UDP Scan

Sends UDP packets to determine the state of UDP ports.

Network Scanning & Enumeration

Key term

Port State

Indicates whether a port is open, closed, or filtered.

Network Scanning & Enumeration

Key term

Filtered Port

A port blocked by a firewall or other network device.

Network Scanning & Enumeration

Memory trick

Network Scanning Concepts & Port Scanning Techniques

Think of port states like a traffic light: Green is 'Open' (go ahead, connect!), Red is 'Closed' (stop, nothing there), and Yellow is 'Filtered' (caution, something is blocking the way!).

Network Scanning & Enumeration

Exam tip

Network Scanning Concepts & Port Scanning Techniques

Memorize the characteristics of TCP SYN scan (stealthy, half-open, common for ethical hackers) and TCP Connect scan (full connect, reliable, noisy). The exam often asks to differentiate these or identify which is less likely to be logged by a target.

Network Scanning & Enumeration

Common mistake

Network Scanning Concepts & Port Scanning Techniques

Confusing TCP SYN scan with TCP Connect scan: SYN is 'half-open' and stealthier; Connect is 'full-open' and noisier.

Network Scanning & Enumeration

Common mistake

Network Scanning Concepts & Port Scanning Techniques

Ignoring UDP scans: While often less reliable, UDP services (like DNS, SNMP) are common attack vectors and must be scanned.

Network Scanning & Enumeration

Common mistake

Network Scanning Concepts & Port Scanning Techniques

Misinterpreting 'Filtered' port state: This doesn't mean the port is necessarily closed, just that a firewall is preventing you from knowing its true state.

Network Scanning & Enumeration

Key term

Hping3

Command-line tool for crafting and sending custom TCP/IP packets.

Network Scanning & Enumeration

Key term

Unicornscan

Fast, asynchronous TCP/UDP port scanner for large networks.

Network Scanning & Enumeration

Key term

Nessus

Commercial vulnerability scanner detecting misconfigurations and weaknesses.

Network Scanning & Enumeration

Key term

OpenVAS

Open-source vulnerability assessment system, similar to Nessus.

Network Scanning & Enumeration

Key term

IP Fragmentation

Breaking large packets into smaller ones to evade IDS/IPS detection.

Network Scanning & Enumeration

Key term

Decoy IP

Using spoofed IP addresses to hide the true source of a scan.

Network Scanning & Enumeration

Key term

Proxy Chain

Routing network traffic through multiple proxy servers for anonymity.

Network Scanning & Enumeration

Key term

Tor

The Onion Router, an anonymizing network for internet traffic.

Network Scanning & Enumeration

Memory trick

Advanced Scanning Tools & Evasion

To remember evasion techniques: 'F-D-P-T': Fragmentation, Decoys, Proxies, Time delays. Think of 'Fighting Drones, Protecting Targets'.

Network Scanning & Enumeration

Exam tip

Advanced Scanning Tools & Evasion

The CEH exam often tests knowledge of specific tool names and their primary functions. Memorize the key capabilities of Hping3, Unicornscan, Nessus, and OpenVAS. Be prepared to identify evasion techniques like IP fragmentation and decoy IPs.

Network Scanning & Enumeration

Common mistake

Advanced Scanning Tools & Evasion

Underestimating the importance of slow/randomized scanning; many IDS/IPS systems are tuned to detect rapid, sequential scans.

Network Scanning & Enumeration

Common mistake

Advanced Scanning Tools & Evasion

Assuming all proxies provide complete anonymity; some proxies log traffic or are easily traceable.

Network Scanning & Enumeration

Common mistake

Advanced Scanning Tools & Evasion

Not testing evasion techniques against the actual target's security controls, leading to false assumptions about effectiveness.

Network Scanning & Enumeration

Key term

Firewall

Network security system controlling traffic.

Network Scanning & Enumeration

Key term

IDS (Intrusion Detection System)

Monitors network traffic for suspicious activity.

Network Scanning & Enumeration

Key term

IPS (Intrusion Prevention System)

Detects and actively blocks malicious traffic.

Network Scanning & Enumeration

Key term

Fragmentation

Splitting packets to evade detection.

Network Scanning & Enumeration

Key term

Decoy Scanning

Using spoofed source IPs to hide scanner.

Network Scanning & Enumeration

Key term

Slow Scan

Sending probes at very low rates to evade.

Network Scanning & Enumeration

Key term

Deep Packet Inspection (DPI)

Examines data part of packets for content.

Network Scanning & Enumeration

Memory trick

Network Scanning Countermeasures & IDS/IPS Bypass

F.I.D.S. (Firewall, IDS, Decoy, Slow scan) – Remember these four key defenses and evasions for network scanning.

Network Scanning & Enumeration

Exam tip

Network Scanning Countermeasures & IDS/IPS Bypass

Memorize the core difference between IDS (detection) and IPS (prevention/blocking). For the exam, understand that fragmentation, decoy, and slow scans are primary IDS/IPS evasion techniques. Keywords like 'alerting' vs. 'blocking' are key.

Network Scanning & Enumeration

Common mistake

Network Scanning Countermeasures & IDS/IPS Bypass

Assuming a firewall alone is sufficient protection against all scanning techniques.

Network Scanning & Enumeration

Common mistake

Network Scanning Countermeasures & IDS/IPS Bypass

Ignoring IDS/IPS alerts, leading to undetected reconnaissance.

Network Scanning & Enumeration

Common mistake

Network Scanning Countermeasures & IDS/IPS Bypass

Not understanding the difference between signature-based and anomaly-based detection.

Network Scanning & Enumeration

Common mistake

Network Scanning Countermeasures & IDS/IPS Bypass

Failing to update and tune IDS/IPS rules, making them ineffective against new threats.

Network Scanning & Enumeration

Key term

Enumeration

Process of extracting detailed information about a target system or network.

Network Scanning & Enumeration

Key term

NetBIOS

Protocol used for naming, discovery, and session services on small networks.

Network Scanning & Enumeration

Key term

SMB

Server Message Block, a network file sharing protocol often abused for enumeration.

Network Scanning & Enumeration

Key term

LDAP

Lightweight Directory Access Protocol, used to query and modify directory services.

Network Scanning & Enumeration

Key term

SNMP

Simple Network Management Protocol, used for managing network devices.

Network Scanning & Enumeration

Key term

Community String

A password used to authenticate to an SNMP device, often 'public' or 'private' by default.

Network Scanning & Enumeration

Key term

Banner Grabbing

Technique to retrieve information about a service by connecting to it and examining its response.

Network Scanning & Enumeration

Memory trick

Enumeration Concepts, Tools & Countermeasures

Remember 'E.N.U.M.E.R.A.T.E.' for key protocols: **E**very **N**etwork **U**ses **M**any **E**numerated **R**esources **A**nd **T**ools **E**asily.

Network Scanning & Enumeration

Exam tip

Enumeration Concepts, Tools & Countermeasures

The CEH exam frequently tests knowledge of common enumeration protocols (SMB, SNMP, LDAP, DNS, SMTP) and their associated tools (e.g., Enum4linux, snmpwalk, ldapsearch). Be prepared to identify which protocol is used for what type of information gathering.

Network Scanning & Enumeration

Common mistake

Enumeration Concepts, Tools & Countermeasures

Failing to disable unnecessary services, leaving open enumeration vectors.

Network Scanning & Enumeration

Common mistake

Enumeration Concepts, Tools & Countermeasures

Using default or weak community strings for SNMP, exposing device details.

Network Scanning & Enumeration

Common mistake

Enumeration Concepts, Tools & Countermeasures

Not implementing rate limiting, allowing attackers to brute-force enumeration attempts.

Network Scanning & Enumeration

Key term

Exploit

Software or data that takes advantage of a vulnerability.

Vulnerability Analysis & System Exploitation

Key term

False Positive

A scan result indicating a vulnerability that isn't actually present.

Vulnerability Analysis & System Exploitation

Key term

CVSS

Common Vulnerability Scoring System, for severity ranking.

Vulnerability Analysis & System Exploitation

Key term

Remediation

The process of fixing or mitigating identified vulnerabilities.

Vulnerability Analysis & System Exploitation

Key term

OWASP Top 10

List of the most critical web application security risks.

Vulnerability Analysis & System Exploitation

Memory trick

Vulnerability Analysis Concepts & Assessment Tools

To remember the assessment cycle: 'P-S-A-R-R-R' – 'Please Scan All Reports, Remediate, Re-verify.'

Vulnerability Analysis & System Exploitation

Exam tip

Vulnerability Analysis Concepts & Assessment Tools

The CEH exam frequently tests on the phases of a vulnerability assessment life cycle and the common tools used. Remember the sequence: Planning, Scanning, Analysis, Reporting, Remediation, Re-assessment. Also, be familiar with the primary function of tools like Nessus, OpenVAS, and Nmap.

Vulnerability Analysis & System Exploitation

Common mistake

Vulnerability Analysis Concepts & Assessment Tools

Ignoring false positives: Always verify findings to avoid wasting time on non-existent issues.

Vulnerability Analysis & System Exploitation

Common mistake

Vulnerability Analysis Concepts & Assessment Tools

Not prioritizing vulnerabilities: Focus on high-risk items first, don't try to fix everything at once.

Vulnerability Analysis & System Exploitation

Common mistake

Vulnerability Analysis Concepts & Assessment Tools

Forgetting re-assessment: Always re-scan after remediation to confirm fixes and avoid regressions.

Vulnerability Analysis & System Exploitation

Key term

Phishing

Fraudulent emails to trick recipients into revealing info.

Vulnerability Analysis & System Exploitation

Key term

Vulnerability Exploitation

Leveraging weaknesses in systems or software to gain access.

Vulnerability Analysis & System Exploitation

Key term

Credential Stuffing

Using leaked username/password pairs from other breaches.

Vulnerability Analysis & System Exploitation

Key term

Supply Chain Attack

Compromising a trusted vendor to attack their customers.

Vulnerability Analysis & System Exploitation

Key term

Initial Access Broker

Cybercriminal selling initial access to compromised networks.

Vulnerability Analysis & System Exploitation

Key term

Zero-Day Exploit

Exploit for a vulnerability unknown to the vendor.

Vulnerability Analysis & System Exploitation

Memory trick

Initial Access: System Hacking Techniques

Remember 'SPAM' for common initial access: Social engineering, Physical access, Application/System exploits, Malware.

Vulnerability Analysis & System Exploitation

Exam tip

Initial Access: System Hacking Techniques

The CEH exam often tests knowledge of common initial access vectors and the difference between active and passive reconnaissance. Memorize specific social engineering techniques and the role of unpatched systems.

Vulnerability Analysis & System Exploitation

Common mistake

Initial Access: System Hacking Techniques

Underestimating the effectiveness of social engineering techniques.

Vulnerability Analysis & System Exploitation

Common mistake

Initial Access: System Hacking Techniques

Neglecting physical security as a potential initial access vector.

Vulnerability Analysis & System Exploitation

Common mistake

Initial Access: System Hacking Techniques

Failing to conduct thorough reconnaissance before attempting technical exploits.

Vulnerability Analysis & System Exploitation

Key term

Persistence

Techniques to maintain access to a system after reboots or disconnections.

Vulnerability Analysis & System Exploitation

Key term

Backdoor

A hidden method to bypass normal authentication for remote access.

Vulnerability Analysis & System Exploitation

Key term

Remote Access Trojan (RAT)

Malware providing comprehensive remote control over a compromised system.

Vulnerability Analysis & System Exploitation

Key term

Web Shell

A script uploaded to a web server for remote command execution via a browser.

Vulnerability Analysis & System Exploitation

Key term

Rootkit

A stealthy set of tools designed to hide its presence and maintain privileged access.

Vulnerability Analysis & System Exploitation

Key term

Cron Job

A Linux/macOS utility for scheduling commands to run periodically.

Vulnerability Analysis & System Exploitation

Key term

Registry Run Keys

Windows registry entries that automatically launch programs at startup.

Vulnerability Analysis & System Exploitation

Memory trick

Maintaining Access: Persistence & Backdoors

To 'Persist' in 'Backdoor' access, remember: 'RATS' (Remote Access Trojans) 'HIDE' (Hardware, IDS bypass, Drivers, Executables) in 'WEBS' (Web shells, Windows Services, Bootkits, Scheduled tasks).

Vulnerability Analysis & System Exploitation

Exam tip

Maintaining Access: Persistence & Backdoors

The CEH exam frequently asks about specific Windows Registry keys used for persistence (e.g., HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). Memorize these common paths. Also, know the difference between a RAT and a web shell.

Vulnerability Analysis & System Exploitation

Common mistake

Maintaining Access: Persistence & Backdoors

Forgetting to establish persistence, leading to loss of access after a system reboot.

Vulnerability Analysis & System Exploitation

Common mistake

Maintaining Access: Persistence & Backdoors

Relying on only one persistence mechanism, which can be easily detected and removed.

Vulnerability Analysis & System Exploitation

Common mistake

Maintaining Access: Persistence & Backdoors

Not properly cleaning up persistence mechanisms after a penetration test is complete, leaving a real vulnerability.

Vulnerability Analysis & System Exploitation

Key term

Privilege Escalation

Gaining higher access than initially granted on a system.

Vulnerability Analysis & System Exploitation

Key term

Vertical Escalation

Moving from lower to higher privilege levels (e.g., user to admin).

Vulnerability Analysis & System Exploitation

Key term

Horizontal Escalation

Accessing another user's account with similar privileges.

Vulnerability Analysis & System Exploitation

Key term

SUID Bit

Special permission on Linux that runs an executable with the owner's permissions.

Vulnerability Analysis & System Exploitation

Key term

Unquoted Service Path

Windows vulnerability where spaces in service paths can lead to arbitrary code execution.

Vulnerability Analysis & System Exploitation

Key term

Mimikatz

Windows tool to extract plaintext passwords, hash, PIN code, and kerberos tickets from memory.

Vulnerability Analysis & System Exploitation

Key term

Log Clearing

Deleting or modifying system logs to remove traces of malicious activity.

Vulnerability Analysis & System Exploitation

Key term

Least Privilege

Security principle granting minimum necessary permissions to users/processes.

Vulnerability Analysis & System Exploitation

Memory trick

Post-Exploitation: Privilege Escalation & Clearing Logs

P.E.A.C.E. - **P**rivileges **E**levated, **A**nonymity **C**overed, **E**vidence Erased. Remember the goal of post-exploitation!

Vulnerability Analysis & System Exploitation

Exam tip

Post-Exploitation: Privilege Escalation & Clearing Logs

Memorize common Windows privilege escalation techniques like unquoted service paths and Mimikatz, and Linux techniques like SUID/SGID binaries and kernel exploits. The exam often presents scenarios where you must identify the appropriate escalation method.

Vulnerability Analysis & System Exploitation

Common mistake

Post-Exploitation: Privilege Escalation & Clearing Logs

Forgetting to check for kernel exploits specific to the target's OS version.

Vulnerability Analysis & System Exploitation

Common mistake

Post-Exploitation: Privilege Escalation & Clearing Logs

Not thoroughly enumerating the system for all possible privilege escalation vectors.

Vulnerability Analysis & System Exploitation

Common mistake

Post-Exploitation: Privilege Escalation & Clearing Logs

Failing to clear relevant logs across all affected systems, leaving forensic evidence.

Vulnerability Analysis & System Exploitation

Key term

Web Server

Software that delivers web content to clients via HTTP/S.

Web Server & Application Attacks

Key term

HTTP/HTTPS

Protocols for transferring web data; HTTPS is secure.

Web Server & Application Attacks

Key term

Apache HTTP Server

Popular open-source web server software.

Web Server & Application Attacks

Key term

Nginx

High-performance web server, often used as a reverse proxy.

Web Server & Application Attacks

Key term

Microsoft IIS

Microsoft's proprietary web server for Windows.

Web Server & Application Attacks

Key term

WAF

Web Application Firewall; filters HTTP traffic for attacks.

Web Server & Application Attacks

Key term

Directory Traversal

Attack accessing files outside the web root.

Web Server & Application Attacks

Key term

DoS/DDoS

Attacks overwhelming a server to make it unavailable.

Web Server & Application Attacks

Memory trick

Web Server Concepts, Attacks & Countermeasures

To secure your Web Server, remember 'P-C-L-A-W': Patching, Configuration, Logging, Auditing, WAF.

Web Server & Application Attacks

Exam tip

Web Server Concepts, Attacks & Countermeasures

The CEH exam frequently tests knowledge of common web server software (Apache, Nginx, IIS) and their default ports (HTTP 80, HTTPS 443). Be prepared to identify common attack types like DoS, directory traversal, and misconfiguration, and their corresponding countermeasures.

Web Server & Application Attacks

Common mistake

Web Server Concepts, Attacks & Countermeasures

Forgetting to disable default accounts or unnecessary services.

Web Server & Application Attacks

Common mistake

Web Server Concepts, Attacks & Countermeasures

Not regularly updating web server software and underlying OS.

Web Server & Application Attacks

Common mistake

Web Server Concepts, Attacks & Countermeasures

Relying solely on network firewalls without a WAF for web application protection.

Web Server & Application Attacks

Key term

Web Application

Client-server software accessed via a web browser.

Web Server & Application Attacks

Key term

Injection Flaw

Untrusted data sent to an interpreter, executing unintended commands.

Web Server & Application Attacks

Key term

SQL Injection (SQLi)

Malicious SQL queries injected to control a database.

Web Server & Application Attacks

Key term

Cross-Site Scripting (XSS)

Malicious client-side scripts injected into web pages.

Web Server & Application Attacks

Key term

Broken Authentication

Vulnerabilities allowing attackers to assume user identities.

Web Server & Application Attacks

Key term

Session Management

How an application handles user sessions; prone to hijacking.

Web Server & Application Attacks

Memory trick

Web Application Concepts & Common Vulnerabilities

For common web app attacks, remember 'I BAXS': Injection, Broken Authentication, XSS, Session Management.

Web Server & Application Attacks

Exam tip

Web Application Concepts & Common Vulnerabilities

The CEH exam frequently tests on the OWASP Top 10. Memorize the top 3-5 categories and be able to provide a brief description and an example attack for each. Pay close attention to Injection, Broken Authentication, and XSS.

Web Server & Application Attacks

Common mistake

Web Application Concepts & Common Vulnerabilities

Confusing server-side and client-side vulnerabilities; XSS is client-side, SQLi is server-side.

Web Server & Application Attacks

Common mistake

Web Application Concepts & Common Vulnerabilities

Underestimating the impact of seemingly minor vulnerabilities; they can often be chained for major exploits.

Web Server & Application Attacks

Common mistake

Web Application Concepts & Common Vulnerabilities

Forgetting that input validation is critical on both the client and server sides, but server-side validation is the ultimate defense.

Web Server & Application Attacks

Key term

Web Proxy

An intermediary that intercepts and modifies HTTP/S traffic between a browser and server.

Web Server & Application Attacks

Key term

Burp Suite

A popular integrated platform for web application security testing, including a proxy.

Web Server & Application Attacks

Key term

OWASP ZAP

An open-source web application security scanner and proxy, maintained by OWASP.

Web Server & Application Attacks

Key term

Fuzzing

Sending malformed or unexpected inputs to find vulnerabilities and crashes.

Web Server & Application Attacks

Key term

SQLMap

An open-source penetration testing tool that automates SQL injection detection and exploitation.

Web Server & Application Attacks

Key term

XSSer

A tool designed for detecting, exploiting, and bypassing XSS vulnerabilities.

Web Server & Application Attacks

Key term

Automated Scanner

Software that crawls web apps to automatically find common vulnerabilities.

Web Server & Application Attacks

Memory trick

Web Application Attack Tools & Exploitation

To remember key web app tools: 'P.A.F.S.' - Proxies, Automated scanners, Fuzzers, Specialized tools. Each has a distinct role!

Web Server & Application Attacks

Exam tip

Web Application Attack Tools & Exploitation

The CEH exam frequently tests knowledge of specific tools like Burp Suite, OWASP ZAP, and SQLMap. Memorize their primary functions and what types of attacks they facilitate. Pay attention to their capabilities in interception, scanning, and exploitation.

Web Server & Application Attacks

Common mistake

Web Application Attack Tools & Exploitation

Relying solely on automated scanners without manual verification, leading to false positives or missed complex flaws.

Web Server & Application Attacks

Common mistake

Web Application Attack Tools & Exploitation

Not understanding how to properly configure a web proxy, resulting in missed traffic or incorrect interception.

Web Server & Application Attacks

Common mistake

Web Application Attack Tools & Exploitation

Using a tool without understanding the underlying vulnerability it targets, making it difficult to interpret results or adapt to defenses.

Web Server & Application Attacks

Key term

SSRF

Server-Side Request Forgery; server makes requests on attacker's behalf.

Web Server & Application Attacks

Key term

API

Application Programming Interface; set of rules for software interaction.

Web Server & Application Attacks

Key term

BOLA

Broken Object-Level Authorization; accessing unauthorized resources by ID.

Web Server & Application Attacks

Key term

BFLA

Broken Function-Level Authorization; accessing unauthorized administrative functions.

Web Server & Application Attacks

Key term

IDOR

Insecure Direct Object Reference; direct access to objects without authorization.

Web Server & Application Attacks

Key term

MFA

Multi-Factor Authentication; requires multiple verification methods.

Web Server & Application Attacks

Memory trick

Advanced Web App Attacks & Defensive Strategies

To remember API attack types, think 'BAM! Excessive Data Massages'. BOLA, BFLA, Excessive Data Exposure, Mass Assignment.

Web Server & Application Attacks

Exam tip

Advanced Web App Attacks & Defensive Strategies

The CEH exam frequently tests on the *impact* of advanced attacks like SSRF and API vulnerabilities. Know that SSRF can lead to internal network reconnaissance and data exfiltration, and API flaws often result in unauthorized data access or privilege escalation. Memorize the OWASP API Security Top 10 categories.

Web Server & Application Attacks

Common mistake

Advanced Web App Attacks & Defensive Strategies

Confusing SSRF with CSRF (Cross-Site Request Forgery). SSRF involves the server making requests; CSRF involves the user's browser making requests.

Web Server & Application Attacks

Common mistake

Advanced Web App Attacks & Defensive Strategies

Underestimating the impact of seemingly minor API flaws. Small authorization gaps can lead to massive data breaches.

Web Server & Application Attacks

Common mistake

Advanced Web App Attacks & Defensive Strategies

Relying solely on network firewalls for web application security. Web application attacks operate at a higher layer and require WAFs and application-level controls.

Web Server & Application Attacks

Key term

Access Point (AP)

A device that creates a wireless local area network (WLAN).

Wireless Network Hacking

Key term

SSID

Service Set Identifier; the name of a wireless network.

Wireless Network Hacking

Key term

WEP

Wired Equivalent Privacy; an outdated and insecure Wi-Fi encryption standard.

Wireless Network Hacking

Key term

WPA2

Wi-Fi Protected Access II; a strong Wi-Fi encryption standard using AES-CCMP.

Wireless Network Hacking

Key term

WPA3

Wi-Fi Protected Access III; the latest and most secure Wi-Fi encryption standard.

Wireless Network Hacking

Key term

AES

Advanced Encryption Standard; a symmetric block cipher used in WPA2 and WPA3.

Wireless Network Hacking

Key term

SAE

Simultaneous Authentication of Equals; key exchange in WPA3-Personal for forward secrecy.

Wireless Network Hacking

Memory trick

Wireless Concepts & Encryption Standards

Wireless standards: 'WEP Was Poor, WPA Was Alright, WPA2 Was Great, WPA3 is Awesome!' (Remember the security progression)

Wireless Network Hacking

Exam tip

Wireless Concepts & Encryption Standards

The CEH exam frequently tests the differences between WEP, WPA, WPA2, and WPA3. Memorize the primary encryption algorithms (RC4, TKIP, AES-CCMP, AES-SAE) associated with each and their key vulnerabilities. Pay close attention to WPA2-Personal vs. WPA2-Enterprise and the new features of WPA3 like SAE and Enhanced Open.

Wireless Network Hacking

Common mistake

Wireless Concepts & Encryption Standards

Confusing the encryption algorithms used by each standard (e.g., thinking WPA2 uses TKIP by default).

Wireless Network Hacking

Common mistake

Wireless Concepts & Encryption Standards

Believing that hiding an SSID provides significant security against discovery.

Wireless Network Hacking

Common mistake

Wireless Concepts & Encryption Standards

Underestimating the severity of WEP vulnerabilities; it's not just 'weak,' it's broken.

Wireless Network Hacking

Key term

Deauthentication Attack

Forces clients off a wireless network to capture handshakes.

Wireless Network Hacking

Key term

Evil Twin Attack

A rogue access point impersonating a legitimate one to intercept traffic.

Wireless Network Hacking

Key term

Aircrack-ng

A suite of tools for wireless packet capturing, injection, and key cracking.

Wireless Network Hacking

Key term

Bettercap

A powerful, modular framework for performing MITM attacks and network reconnaissance.

Wireless Network Hacking

Key term

Kismet

A passive wireless network detector, sniffer, and intrusion detection system.

Wireless Network Hacking

Key term

4-way Handshake

The process by which a client and AP establish a secure connection using WPA/WPA2.

Wireless Network Hacking

Key term

Rogue Access Point

An unauthorized AP installed on a network, often for malicious purposes.

Wireless Network Hacking

Memory trick

Wireless Attacks & Exploitation Tools

Think 'A-C-K' for Aircrack-ng components: Airodump (capture), Aireplay (inject/attack), Aircrack (crack).

Wireless Network Hacking

Exam tip

Wireless Attacks & Exploitation Tools

The CEH exam frequently tests on the specific functions of tools like Aircrack-ng, Bettercap, and Kismet. Memorize which tool performs what action (e.g., 'aircrack-ng for cracking WPA/WPA2 keys'). Be able to distinguish between passive (Kismet) and active (aireplay-ng) attack methods.

Wireless Network Hacking

Common mistake

Wireless Attacks & Exploitation Tools

Confusing the purpose of different tools within the Aircrack-ng suite (e.g., airodump-ng vs. aireplay-ng).

Wireless Network Hacking

Common mistake

Wireless Attacks & Exploitation Tools

Underestimating the importance of a strong passphrase even with WPA2/WPA3, as offline cracking is still possible.

Wireless Network Hacking

Common mistake

Wireless Attacks & Exploitation Tools

Failing to understand the legal and ethical implications of performing wireless attacks without explicit authorization.

Wireless Network Hacking

Key term

802.1X

Port-based network access control for authentication.

Wireless Network Hacking

Key term

RADIUS

Centralized authentication, authorization, and accounting protocol.

Wireless Network Hacking

Key term

Rogue AP

Unauthorized access point connected to a network.

Wireless Network Hacking

Key term

WIDS/WIPS

Wireless Intrusion Detection/Prevention System.

Wireless Network Hacking

Key term

SSID Broadcasting

Visibility of a Wi-Fi network's name to nearby devices.

Wireless Network Hacking

Key term

MAC Filtering

Restricting network access based on MAC addresses.

Wireless Network Hacking

Memory trick

Wireless Attack Countermeasures & Security Best Practices

WIFI SECURE: WPA3, Isolation, Firmware updates, Internal audits, Strong passwords, Encryption, Rogue AP detection, Employee training.

Wireless Network Hacking

Exam tip

Wireless Attack Countermeasures & Security Best Practices

The CEH exam frequently tests knowledge of WPA2/WPA3 differences and the importance of 802.1X for enterprise security. Memorize that WEP and WPA are considered insecure and should not be used.

Wireless Network Hacking

Common mistake

Wireless Attack Countermeasures & Security Best Practices

Relying solely on MAC address filtering for security, as MAC addresses can be easily spoofed.

Wireless Network Hacking

Common mistake

Wireless Attack Countermeasures & Security Best Practices

Using default administrative credentials on access points, making them easy targets for attackers.

Wireless Network Hacking

Common mistake

Wireless Attack Countermeasures & Security Best Practices

Neglecting to update access point firmware, leaving known vulnerabilities unpatched.

Wireless Network Hacking

Key term

WPA/WPA2-PSK

Wi-Fi Protected Access with Pre-Shared Key, a common wireless encryption method.

Wireless Network Hacking

Key term

Evil Twin

A type of rogue AP that mimics a legitimate Wi-Fi network's SSID to trick users.

Wireless Network Hacking

Key term

WPS (Wi-Fi Protected Setup)

A feature for easy device connection, often vulnerable to PIN brute-force attacks.

Wireless Network Hacking

Key term

Client Isolation

A security feature preventing wireless clients from directly communicating with each other.

Wireless Network Hacking

Memory trick

Practical Wireless Hacking Scenarios

To remember common wireless attacks: 'We Really Don't Want Cyber-attacks!' (WPS, Rogue AP, Deauth, WPA Cracking, Client-side).

Wireless Network Hacking

Exam tip

Practical Wireless Hacking Scenarios

The CEH exam frequently tests your understanding of practical attack methodologies. Be prepared to identify the tools used for specific attacks (e.g., Aircrack-ng for WPA cracking, Reaver for WPS), and the steps involved in each scenario. Focus on the 'why' behind each attack type and its impact.

Wireless Network Hacking