CEH Need to Know

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/113

flashcard set

Earn XP

Description and Tags

Know these cold

Last updated 10:00 PM on 6/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

114 Terms

1
New cards
Which protocol is used to query Active Directory?
LDAP (389)
2
New cards
Which protocol is primarily responsible for authentication in Active Directory?
Kerberos (88)
3
New cards
What does LDAP primarily do?
Query directory information (users, groups, OUs)
4
New cards
What does Kerberos primarily do?
Authentication
5
New cards
What file stores local Windows password hashes?
SAM
6
New cards
What file stores domain credentials in Active Directory?
NTDS.dit
7
New cards
Which Windows process commonly contains credentials in memory?
LSASS.exe
8
New cards
What attack reuses NTLM hashes?
Pass-the-Hash
9
New cards
What attack reuses Kerberos tickets?
Pass-the-Ticket
10
New cards
What attack extracts Kerberos service ticket hashes for offline cracking?
Kerberoasting
11
New cards
Which authentication protocol is associated with Pass-the-Ticket?
Kerberos
12
New cards
Which authentication protocol is associated with Pass-the-Hash?
NTLM
13
New cards
14
New cards
An attacker manipulates database queries through user input. Attack?
SQL Injection
15
New cards
An attacker injects OS commands through application input. Attack?
Command Injection
16
New cards
JavaScript executes in a victim's browser. Attack?
XSS
17
New cards
A logged-in user is tricked into performing actions. Attack?
CSRF
18
New cards
A server is tricked into making requests to internal resources. Attack?
SSRF
19
New cards
../../../etc/passwd indicates what attack?
Directory Traversal
20
New cards
Reading local files through a vulnerable application is called?
LFI (Local File Inclusion)
21
New cards
Including remote files into an application is called?
RFI (Remote File Inclusion)
22
New cards
XSS primarily targets what?
Browser
23
New cards
CSRF primarily targets what?
Authenticated user session
24
New cards
SSRF primarily targets what?
Server-side request processing
25
New cards
SQL Injection primarily targets what?
Database
26
New cards
Command Injection primarily targets what?
Operating System
27
New cards
Stored XSS persists where?
Application/database
28
New cards
Reflected XSS persists where?
It does not persist; reflected immediately
29
New cards
Which attack is more likely to steal session cookies?
XSS
30
New cards
31
New cards
FTP port?
21
32
New cards
SSH port?
22
33
New cards
Telnet port?
23
34
New cards
SMTP port?
25
35
New cards
DNS port?
53
36
New cards
HTTP port?
80
37
New cards
Kerberos port?
88
38
New cards
POP3 port?
110
39
New cards
SNMP ports?
161/162
40
New cards
LDAP port?
389
41
New cards
HTTPS port?
443
42
New cards
SMB port?
445
43
New cards
RDP port?
3389
44
New cards
45
New cards
Which Nmap flag performs a SYN scan?
-sS
46
New cards
Which Nmap flag performs a TCP Connect scan?
-sT
47
New cards
Which Nmap flag performs version detection?
-sV
48
New cards
Which Nmap flag performs OS detection?
-O
49
New cards
Which Nmap flag performs aggressive scanning?
-A
50
New cards
Which Nmap flag skips host discovery?
-Pn
51
New cards
Which scan is generally stealthier: SYN or TCP Connect?
SYN Scan
52
New cards
What response usually indicates a closed TCP port during a SYN scan?
RST
53
New cards
54
New cards
Which wireless protocol is considered broken?
WEP
55
New cards
WPA primarily uses what?
TKIP
56
New cards
WPA2 primarily uses what?
AES
57
New cards
WPA3 introduces what key feature?
SAE (Simultaneous Authentication of Equals)
58
New cards
What is an Evil Twin attack?
Rogue access point using the same SSID as a legitimate AP
59
New cards
What attack disconnects wireless clients from an AP?
Deauthentication Attack
60
New cards
61
New cards
AES is symmetric or asymmetric?
Symmetric
62
New cards
RSA is symmetric or asymmetric?
Asymmetric
63
New cards
ECC is symmetric or asymmetric?
Asymmetric
64
New cards
Diffie-Hellman is primarily used for?
Key Exchange
65
New cards
SHA-256 is what type of function?
Hash Function
66
New cards
MD5 is considered what?
Broken/Insecure
67
New cards
Hashing primarily provides?
Integrity
68
New cards
Digital signatures provide?
Integrity, Authentication, and Non-Repudiation
69
New cards
70
New cards
Which cloud model provides the most customer control?
IaaS
71
New cards
Which cloud model provides the least customer control?
SaaS
72
New cards
Developers manage applications but not infrastructure. Which model?
PaaS
73
New cards
Difference between VM and Container?
VM has a full guest OS; Container shares the host kernel
74
New cards
75
New cards
What malware self-replicates without user action?
Worm
76
New cards
What malware disguises itself as legitimate software?
Trojan
77
New cards
What malware hides processes/files to maintain access?
Rootkit
78
New cards
What malware encrypts files for payment?
Ransomware
79
New cards
80
New cards
Generic fraudulent email attack?
Phishing
81
New cards
Targeted phishing attack?
Spear Phishing
82
New cards
Phishing targeting executives?
Whaling
83
New cards
Voice-based phishing?
Vishing
84
New cards
SMS-based phishing?
Smishing
85
New cards
86
New cards
Single-source denial of service attack?
DoS
87
New cards
Multi-source denial of service attack?
DDoS
88
New cards
Few passwords against many accounts?
Password Spraying
89
New cards
Many passwords against one account?
Brute Force
90
New cards
Using leaked credentials across many sites?
Credential Stuffing
91
New cards
92
New cards
Tool commonly used for vulnerability scanning?
Nessus
93
New cards
Open-source vulnerability scanner?
OpenVAS
94
New cards
Tool commonly used for packet analysis?
Wireshark
95
New cards
Tool commonly used for exploitation?
Metasploit
96
New cards
Tool commonly used for web testing?
Burp Suite
97
New cards
Tool commonly used for password cracking?
John the Ripper
98
New cards
GPU-accelerated password cracking tool?
Hashcat
99
New cards
Wireless attack suite?
Aircrack-ng
100
New cards
OSINT relationship mapping tool?
Maltego