🇺🇸 Certified Ethical Hacker (CEH) · flashcards
Certified Ethical Hacker (CEH) Cloud Computing, Cryptography, and Social Engineering Flashcards
50 question-and-answer cards covering Cloud Computing, Cryptography, and Social Engineering as it is examined in Certified Ethical Hacker (CEH). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.
24 sample cards from the Cloud Computing, Cryptography, and Social Engineering deck
Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.
What advantage does Elliptic Curve Cryptography (ECC) offer over RSA?
ECC provides equivalent security with much smaller key sizes, making it faster and more efficient (e.g., a 256-bit ECC key ≈ a 3072-bit RSA key).
What is a cryptographic hash function and name two common examples.
A one-way function that produces a fixed-size digest from arbitrary input, used for integrity. Examples: SHA-256 and MD5.
Why is MD5 considered cryptographically broken?
MD5 (128-bit) is vulnerable to collision attacks, where two different inputs produce the same hash, so it cannot be trusted for integrity or signatures.
What is an HMAC?
A Hash-based Message Authentication Code that combines a cryptographic hash with a secret key to provide both data integrity and authentication.
What is the difference between encryption and hashing?
Encryption is reversible (with a key) and protects confidentiality; hashing is one-way (irreversible) and protects integrity.
What is a digital signature and what does it provide?
A value created by hashing a message and encrypting the hash with the sender's private key; it provides integrity, authentication, and non-repudiation.
In a digital signature, which key signs and which key verifies?
The sender's private key signs (encrypts the hash); the sender's public key verifies (decrypts the hash).
What is a Public Key Infrastructure (PKI)?
A framework of hardware, software, policies, and procedures to create, manage, distribute, store, and revoke digital certificates and public keys.
What is the role of a Certificate Authority (CA) in PKI?
A trusted entity that issues, signs, and vouches for the authenticity of digital certificates binding a public key to an identity.
What is an X.509 digital certificate?
The standard format for a digital certificate containing the subject's identity, public key, validity period, issuer, and CA's digital signature.
What is a Certificate Revocation List (CRL) and its real-time alternative?
A CRL is a list of revoked certificates published by the CA; the real-time alternative is OCSP (Online Certificate Status Protocol).
What is the function of a Registration Authority (RA) in PKI?
It verifies and authenticates the identity of certificate requesters before the CA issues a certificate; it does not issue certificates itself.
What is a known-plaintext attack in cryptanalysis?
An attack where the analyst has access to both the plaintext and its corresponding ciphertext and uses them to deduce the key or algorithm.
What is a chosen-plaintext attack?
An attack where the attacker can choose arbitrary plaintexts to be encrypted and observe the resulting ciphertexts to derive the key.
What is a birthday attack and what does it target?
A brute-force attack based on the birthday paradox that targets hash functions to find two inputs producing the same hash (a collision).
What is a rainbow table attack and the best defense against it?
An attack using precomputed tables of hashes to reverse password hashes; the best defense is adding a unique random salt to each password before hashing.
What is a meet-in-the-middle attack?
A cryptanalytic attack against multiple-encryption schemes (like 2DES) that reduces brute-force effort by encrypting from one end and decrypting from the other to find matching intermediate values.
Define social engineering in the context of information security.
The art of manipulating people through deception to divulge confidential information or perform actions that compromise security, exploiting human trust rather than technical flaws.
What are the typical four phases of a social engineering attack?
Research (information gathering/reconnaissance), Developing a relationship/hook, Exploitation (extracting information or access), and Execution/Exit.
What is phishing, and how do spear phishing and whaling differ from it?
Phishing is fraudulent mass email to steal data; spear phishing targets a specific individual/organization, and whaling targets high-profile executives (the 'big fish').
What are pretexting, baiting, and quid pro quo social engineering techniques?
Pretexting uses a fabricated scenario to gain trust; baiting lures victims with something enticing (e.g., a malware USB); quid pro quo offers a service/benefit in exchange for information.
What are tailgating and piggybacking in physical social engineering?
Tailgating is following an authorized person through a secure door without their consent; piggybacking is the same but with the authorized person's knowing consent/help.
What is an insider threat and what are its main categories?
A security risk originating from within the organization (employees, contractors). Categories: malicious insider, negligent/careless insider, and compromised insider (whose credentials are stolen).
What is identity theft and how is it used in social engineering attacks?
Identity theft is stealing someone's personal/identifying information to impersonate them; attackers use it for fraud, to gain trust, or to bypass authentication and access systems.
What this deck covers
The Cloud Computing, Cryptography, and Social Engineering deck follows the Certified Ethical Hacker (CEH) Cloud Computing, Cryptography, and Social Engineering syllabus — 3 chapters and 12 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 16.7 cards per chapter.
Answers are written to be recallable, not just readable — averaging about 151 characters, which is long enough to carry the reasoning and short enough to say out loud.
A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.
Cloud Computing, Cryptography, and Social Engineering flashcards FAQ
How many Cloud Computing, Cryptography, and Social Engineering flashcards are in this Certified Ethical Hacker (CEH) deck?
50 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.
Are these Certified Ethical Hacker (CEH) flashcards free?
Yes. The preview here is free to read with no signup, and the full 50-card deck is free inside the Examius app.
What do the Cloud Computing, Cryptography, and Social Engineering cards cover?
They follow the Certified Ethical Hacker (CEH) Cloud Computing, Cryptography, and Social Engineering syllabus — 3 chapters and 12 topics — so the questions track what is actually examinable.
How should I use these flashcards?
Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.