🌍 Ethical Hacking · flashcards
Ethical Hacking Introduction to Ethical Hacking Flashcards
51 question-and-answer cards covering Introduction to Ethical Hacking as it is examined in Ethical Hacking. 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.
24 sample cards from the Introduction to Ethical Hacking deck
Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.
What U.S. law is the primary statute against unauthorized computer access?
The Computer Fraud and Abuse Act (CFAA) of 1986, which criminalizes accessing a computer without authorization or exceeding authorized access.
What UK law governs unauthorized computer access?
The Computer Misuse Act of 1990, covering unauthorized access, unauthorized access with intent to commit further offenses, and unauthorized modification/impairment of computer material.
What EU regulation heavily influences how ethical hackers must handle personal data?
The GDPR (General Data Protection Regulation), which governs the collection, processing, and protection of personal data of EU residents and imposes strict breach-notification and privacy requirements.
Name two other well-known security/privacy compliance frameworks an ethical hacker may encounter.
HIPAA (U.S. healthcare data) and PCI DSS (payment card data). Others include SOX, ISO/IEC 27001, and NIST frameworks.
What single legal document must be in place before any ethical hacking engagement begins?
Written authorization—commonly a signed scope-of-work with a 'Rules of Engagement' and often a 'Get Out of Jail Free' authorization letter—granting explicit permission to test the defined targets.
What is a 'Get Out of Jail Free' letter in penetration testing?
A signed authorization letter from the client naming the tester, the systems in scope, and the time window, which proves the testing is legally sanctioned if the tester is questioned by staff or law enforcement.
What is the difference between scope and Rules of Engagement (RoE) in a pentest agreement?
Scope defines what may be tested (IP ranges, apps, domains) and what is off-limits. Rules of Engagement define how testing is conducted—timing, methods allowed/forbidden, escalation contacts, and handling of sensitive data.
What does a Statement of Work (SOW) specify in a penetration testing agreement?
The specific deliverables, timeline, tasks, pricing, and responsibilities for the engagement, defining exactly what work will be performed.
Why is a Non-Disclosure Agreement (NDA) important in ethical hacking engagements?
Because testers gain access to sensitive systems and data; the NDA legally binds them to keep client information, vulnerabilities, and findings confidential.
What is the difference between black-box, white-box, and gray-box testing?
Black-box: tester has no prior knowledge of the target. White-box: tester has full knowledge (source code, architecture, credentials). Gray-box: tester has partial knowledge, simulating an insider or a user with limited access.
What is the difference between a vulnerability assessment and a penetration test?
A vulnerability assessment identifies and lists potential weaknesses (breadth, often automated) without exploiting them. A penetration test actively exploits vulnerabilities to demonstrate real-world impact (depth).
What is responsible (coordinated) disclosure?
The practice of privately reporting a discovered vulnerability to the affected vendor and giving them reasonable time to fix it before any public disclosure, minimizing harm to users.
What is a bug bounty program?
A program where organizations invite ethical hackers to find and report vulnerabilities in exchange for recognition and monetary rewards, under defined legal rules (a form of authorized testing).
State three core principles of an ethical hacker's code of conduct.
1) Obtain explicit authorization before testing; 2) Stay strictly within the agreed scope; 3) Protect confidentiality and report all findings honestly. (Also: do no harm and act with integrity.)
Why must an ethical hacker never exceed the agreed scope, even if they find an easy path elsewhere?
Because access beyond the authorized scope is unauthorized—legally it becomes illegal hacking and breaches the client's trust and the engagement contract, regardless of good intentions.
What ethical obligation does a hacker have upon accidentally discovering sensitive data (e.g., personal or medical records)?
To stop, avoid copying or misusing it, protect its confidentiality, document the exposure minimally, and report it responsibly to the client per the agreed handling procedures.
What is the flagship entry-level certification named directly for ethical hacking, and who issues it?
The Certified Ethical Hacker (CEH), issued by the EC-Council.
Which certification is known for its rigorous 24-hour hands-on exam and the motto 'Try Harder'?
The OSCP (Offensive Security Certified Professional), from Offensive Security (OffSec).
Name a widely respected vendor-neutral entry certification for general cybersecurity, often a starting point before specializing in ethical hacking.
CompTIA Security+ (with CompTIA PenTest+ as a more offense-focused follow-on).
Name two skill areas a beginner should build before penetration testing.
Networking fundamentals (TCP/IP, ports, protocols) and operating systems (especially Linux/Kali and Windows); plus at least one scripting language such as Python or Bash.
What is Kali Linux?
A Debian-based Linux distribution pre-loaded with hundreds of penetration-testing and security tools (e.g., Nmap, Metasploit, Burp Suite, Wireshark), widely used by ethical hackers.
How can an aspiring ethical hacker legally build practical, portfolio-worthy experience?
By practicing on intentionally vulnerable, sanctioned environments—CTF (Capture The Flag) competitions, platforms like Hack The Box and TryHackMe, home labs, and authorized bug bounty programs—then documenting write-ups.
What should a strong ethical hacking portfolio contain?
Documented CTF/lab write-ups, sample (sanitized) pentest reports, relevant certifications, personal projects or tools, blog posts, and evidence of bug bounty or open-source contributions—demonstrating both skill and clear communication.
Why are networking and community involvement valuable for an ethical hacking career?
Communities (conferences like DEF CON/Black Hat, local meetups, forums, Discords, CTF teams) provide mentorship, up-to-date knowledge, collaboration, reputation-building, and job opportunities in a fast-evolving field.
What this deck covers
The Introduction to Ethical Hacking deck follows the Ethical Hacking Introduction to Ethical Hacking syllabus — 3 chapters and 12 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 17.0 cards per chapter.
Answers are written to be recallable, not just readable — averaging about 175 characters, which is long enough to carry the reasoning and short enough to say out loud.
A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.
Introduction to Ethical Hacking flashcards FAQ
How many Introduction to Ethical Hacking flashcards are in this Ethical Hacking deck?
51 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.
Are these Ethical Hacking flashcards free?
Yes. The preview here is free to read with no signup, and the full 51-card deck is free inside the Examius app.
What do the Introduction to Ethical Hacking cards cover?
They follow the Ethical Hacking Introduction to Ethical Hacking syllabus — 3 chapters and 12 topics — so the questions track what is actually examinable.
How should I use these flashcards?
Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.