← All Certified Ethical Hacker Flashcard Decks

Mixed Deck — All Certified Ethical Hacker Topics Flashcards

100 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All Certified Ethical Hacker Topics flashcards as text
  1. After compromising one host, a tester uses it to attack deeper internal systems. What is this called?

    Answer: Pivoting

    Pivoting uses a compromised host as a stepping stone to reach other internal systems.

  2. Which Google search operator is used to search for specific file types hosted on a target website?

    Answer: filetype:

    The 'filetype:' Google dork operator restricts results to specific file extensions (e.g., PDF, XLS, DOC) which may expose sensitive documents.

  3. A polymorphic virus evades antivirus primarily by doing what on each infection?

    Answer: Changing its decryption routine/code signature

    Polymorphic viruses mutate their code or decryption routine each time to alter their signature.

  4. What distinguishes an IPS from an IDS?

    Answer: An IPS can actively block or drop malicious traffic

    An IPS is inline and can actively block or drop malicious traffic, while an IDS only detects and alerts.

  5. You work as a Security Analyst for a retail organization. In securing the company's network, you set up a firewall and an IDS. However, hackers are able to attack the network. After investigating, you discover that your IDS is not configured properly and therefore is unable to trigger alarms when needed. What type of alert is the IDS giving?

    Answer: False Negative

    A false negative occurs when a security system, such as an Intrusion Detection System (IDS), fails to detect an actual attack or malicious activity. In this scenario, hackers successfully attacked the network, but the misconfigured IDS did not trigger an alarm, allowing the breach to go unnoticed. This is a critical failure as it means a real threat was missed, compromising the network's security.

  6. An attacker enumerates valid usernames by observing different error messages. This is a flaw in:

    Answer: Username enumeration / verbose feedback

    Distinct responses for valid vs invalid users leak account existence (username enumeration).

  7. What is the key size used by the AES algorithm in its strongest standard configuration?

    Answer: 256 bits

    AES supports 128, 192, and 256-bit keys, with 256-bit being the strongest.

  8. Which protocol does a ping sweep typically use to identify live hosts?

    Answer: ICMP echo request

    A ping sweep sends ICMP echo requests across a range to find responsive hosts.

  9. Which of these is an example of active reconnaissance?

    Answer: Performing a port scan against the target

    Port scanning directly interacts with the target, making it active reconnaissance.

  10. A web shell uploaded through an unrestricted file upload allows an attacker to:

    Answer: Execute commands on the server

    A web shell provides remote command execution on the compromised server.

  11. What is a 'zero-day vulnerability'?

    Answer: A previously unknown vulnerability with no available patch

    A zero-day vulnerability is a security flaw that is unknown to the vendor and has no available patch, making it particularly dangerous and valuable to attackers.

  12. Why must an ethical hacker document every action and finding during an engagement?

    Answer: For reproducibility, reporting, and legal accountability

    Thorough documentation supports reproducible results, clear reporting, and legal accountability.

  13. Which tool is commonly used to bind a Trojan to a legitimate executable so it runs alongside the original program?

    Answer: Wrapper (binder)

    A wrapper or binder joins a Trojan to a legitimate executable so both run together.

  14. An attacker sets up a rogue AP with the same SSID as a legitimate corporate network to lure clients. What is this called?

    Answer: Evil twin

    An evil twin mimics a legitimate AP's SSID to trick users into connecting through the attacker.

  15. In a man-in-the-middle attack on key exchange, what does the attacker do?

    Answer: Intercepts and relays communication while impersonating both parties

    The attacker secretly relays and possibly alters messages between two parties who think they communicate directly.

  16. Which algorithm is an example of asymmetric (public-key) cryptography?

    Answer: RSA

    RSA is a widely used asymmetric algorithm based on factoring large prime numbers.

  17. Which of the following is the most important step for the ethical hacker to perform during the pre-assessment?

    Answer: Obtain written permission to hack

    The most crucial step for an ethical hacker is to obtain explicit, written permission from the target organization before commencing any hacking activities. Without written authorization, any penetration testing or security assessment, even if intended for good, could be considered illegal and lead to severe legal consequences. This step ensures the legality, ethical conduct, and clear scope of the engagement.

  18. What ethical principle requires that a tester stop and notify the client immediately upon discovering an active breach by a real attacker?

    Answer: Duty to report critical findings promptly

    Ethical hackers must promptly report critical findings such as evidence of an active compromise.

  19. Which phase would include using tools like Maltego to map relationships between people, domains, and infrastructure?

    Answer: Reconnaissance

    Maltego is an OSINT tool used during reconnaissance to map relationships among entities.

  20. What is the purpose of privilege escalation after gaining initial access?

    Answer: Gain higher-level permissions

    Privilege escalation elevates an attacker's access from a low-privilege account to admin/root.