🇺🇸 Certified Ethical Hacker (CEH) · flashcards
Certified Ethical Hacker (CEH) Introduction to Ethical Hacking and Reconnaissance Flashcards
51 question-and-answer cards covering Introduction to Ethical Hacking and Reconnaissance as it is examined in Certified Ethical Hacker (CEH). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.
24 sample cards from the Introduction to Ethical Hacking and Reconnaissance deck
Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.
What U.S. law primarily criminalizes unauthorized access to computer systems?
The Computer Fraud and Abuse Act (CFAA), 18 U.S.C. 1030, criminalizes unauthorized access and exceeding authorized access to protected computers.
What does GDPR regulate and what is the maximum fine?
The EU General Data Protection Regulation (GDPR) governs personal data protection/privacy of EU residents; maximum fines are up to 20 million euros or 4% of annual global turnover, whichever is higher.
What is the difference between Black Box, White Box, and Gray Box penetration testing?
Black Box: tester has no prior knowledge of the target; White Box: tester has full knowledge (source code, architecture); Gray Box: tester has partial/limited knowledge.
What are the main phases of the penetration testing process?
Pre-engagement (scoping/agreement), Reconnaissance/Information Gathering, Scanning/Enumeration, Vulnerability Analysis, Exploitation/Gaining Access, Post-Exploitation, and Reporting.
Why is a 'Rules of Engagement' (RoE) document essential before a penetration test?
The RoE legally defines scope, targets, allowed techniques, timing, and limitations, providing authorization that protects the tester and prevents unauthorized/out-of-scope actions.
What is footprinting and what are its two main types?
Footprinting is the first step of gathering information about a target's network/systems; its two types are passive (no direct contact, OSINT) and active (direct interaction with the target).
What does OSINT stand for and what does it involve?
Open Source Intelligence (OSINT) involves collecting information from publicly available sources such as websites, social media, search engines, public records, and metadata.
List four key objectives of footprinting for an attacker.
Collect network information (IP ranges, domains), system information (OS, services), organizational information (employees, structure), and identify the attack surface/security posture.
What is Google Dorking (Google Hacking)?
Using advanced Google search operators to find sensitive information, exposed files, login pages, or vulnerabilities indexed by search engines (queries are cataloged in the Google Hacking Database / GHDB).
What does the Google operator 'site:' do, and give an example combined with 'filetype:'.
'site:' restricts results to a specific domain. Example: 'site:example.com filetype:pdf' returns only PDF files indexed on example.com.
What does the Google 'inurl:' operator do?
It restricts results to pages whose URL contains the specified term, e.g., 'inurl:admin' to find admin pages.
How can the Wayback Machine (archive.org) aid web footprinting?
It stores historical snapshots of websites, letting an attacker view old pages, removed content, prior structures, and exposed information no longer on the live site.
What is a WHOIS lookup used for in footprinting?
WHOIS queries domain registration databases to reveal registrant details, contact info, registrar, name servers, and domain creation/expiry dates.
What information can DNS footprinting reveal, and which tool retrieves DNS records?
It reveals host names, IP addresses, mail servers, and network structure via DNS records; tools include nslookup, dig, and host.
Match these DNS record types to their function: A, MX, NS, CNAME, PTR, SOA.
A = maps hostname to IPv4; MX = mail exchange server; NS = authoritative name server; CNAME = alias to another name; PTR = reverse lookup (IP to name); SOA = Start of Authority (zone admin info).
What is a DNS zone transfer (AXFR) and why is it a security concern?
A zone transfer replicates a full DNS zone database between servers; if misconfigured to allow anyone, an attacker can obtain a complete list of hosts/records, mapping the entire network.
What does the traceroute/tracert utility reveal during network footprinting?
It maps the path packets take to a target, revealing intermediate hops/routers, network topology, and the geographic/logical route, aiding network mapping.
What is email footprinting and what does an email header reveal?
Email footprinting analyzes email headers to extract sender IP, mail servers, routing path, timestamps, and originating geolocation; email tracking tools can also confirm if/when a message was read.
How is social media used in footprinting?
Attackers mine platforms like LinkedIn, Facebook, and X for employee names, roles, technologies used, locations, relationships, and personal details to enable social engineering or password guessing.
What is people search / personnel footprinting?
Using people-search engines and public records to gather personal data (phone, address, email, employer) about individuals for social engineering or targeting.
What does the Maltego tool do in reconnaissance?
Maltego is an OSINT and link-analysis tool that visually maps relationships between people, domains, infrastructure, and organizations gathered from many data sources.
What information does the Shodan search engine provide to a footprinter?
Shodan indexes Internet-connected devices and reveals open ports, running services, banners, IoT devices, webcams, and exposed systems by IP/service.
What is theHarvester used for?
theHarvester is an OSINT tool that gathers emails, subdomains, hosts, employee names, and open ports/banners from public sources and search engines.
List four key countermeasures against footprinting.
Restrict information published publicly (web/social media), enforce privacy on WHOIS and disable DNS zone transfers to untrusted hosts, configure web servers to avoid info leakage, and train employees on social engineering and OSINT awareness.
What this deck covers
The Introduction to Ethical Hacking and Reconnaissance deck follows the Certified Ethical Hacker (CEH) Introduction to Ethical Hacking and Reconnaissance syllabus — 3 chapters and 12 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 17.0 cards per chapter.
Answers are written to be recallable, not just readable — averaging about 172 characters, which is long enough to carry the reasoning and short enough to say out loud.
A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.
Introduction to Ethical Hacking and Reconnaissance flashcards FAQ
How many Introduction to Ethical Hacking and Reconnaissance flashcards are in this Certified Ethical Hacker (CEH) deck?
51 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.
Are these Certified Ethical Hacker (CEH) flashcards free?
Yes. The preview here is free to read with no signup, and the full 51-card deck is free inside the Examius app.
What do the Introduction to Ethical Hacking and Reconnaissance cards cover?
They follow the Certified Ethical Hacker (CEH) Introduction to Ethical Hacking and Reconnaissance syllabus — 3 chapters and 12 topics — so the questions track what is actually examinable.
How should I use these flashcards?
Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.