Flash deck30 cards312-50
CEH flashcards
Thirty CEH flashcards for pure recall: scan types, the ports behind enumeration, attack-and-defense pairs, malware families and crypto terms. Read the front, answer out loud, then flip.
- Exam
- 312-50
- Updated
- Oct 11, 2026
Scans, ports, pairs, malware, crypto
- CARD 01
TCP connect scan
Show answerHide answer
Completes the full three-way handshake on each port. Reliable and needs no special privileges, but every connection can land in the target's logs.
- CARD 02
Half-open (SYN) scan
Show answerHide answer
A SYN/ACK reply means open, a RST means closed. The scanner never finishes the handshake, so fewer application logs record it; also called a stealth scan.
- CARD 03
Inverse-flag scans: FIN, NULL, Xmas
Show answerHide answer
Probes without a SYN. Under the TCP standard a closed port answers RST and an open one stays silent. Windows hosts answer RST either way, so results there cannot be trusted.
- CARD 04
Idle (zombie) scan
Show answerHide answer
Infers port state from a third host's IP ID counter, so the target only ever sees the zombie's address. Hosts with randomized IP IDs make useless zombies.
- CARD 05
ACK scan
Show answerHide answer
Maps firewall filtering: an unfiltered port answers RST, a filtered one stays silent or returns an ICMP error. It cannot tell open from closed.
- CARD 06
UDP scan
Show answerHide answer
No handshake to read. An ICMP port-unreachable reply means closed; silence means open or filtered. Slow, because silence means waiting out timeouts.
- CARD 07
NetBIOS enumeration
Show answerHide answer
Ports 137–139 (name, datagram and session services). Exposes computer names, workgroups and shares. Defense: turn off NetBIOS over TCP/IP where nothing needs it.
- CARD 08
SNMP enumeration
Show answerHide answer
UDP 161, traps on 162. Default community strings let anyone read device and account data. Defense: change the defaults, move to SNMPv3.
- CARD 09
LDAP enumeration
Show answerHide answer
TCP 389, or 636 for LDAPS. Anonymous binds expose users, groups and directory structure. Defense: block anonymous binds, require LDAPS.
- CARD 10
NTP enumeration
Show answerHide answer
UDP 123. A time server can reveal the hosts that sync with it. Defense: restrict who may query it.
- CARD 11
SMTP enumeration
Show answerHide answer
TCP 25. The
VRFYandEXPNverbs confirm which mailboxes exist. Defense: disable both and answer valid and invalid users the same way. - CARD 12
DNS zone transfer
Show answerHide answer
TCP 53. An unrestricted transfer hands over the whole zone, every host name at once. Defense: allow transfers only to your own secondary servers.
- CARD 13
MAC flooding
Show answerHide answer
Fills a switch's CAM table with fake addresses until it floods frames out of every port. Defense: port security, capping MAC addresses per port.
- CARD 14
ARP poisoning
Show answerHide answer
Forged ARP replies tie the attacker's MAC to another host's IP, putting the attacker in the middle. Defense: Dynamic ARP Inspection, checked against DHCP snooping bindings.
- CARD 15
DHCP starvation
Show answerHide answer
Drains the address pool with fake requests, often to make room for a rogue DHCP server. Defense: DHCP snooping with trusted ports, plus port security.
- CARD 16
Rainbow table
Show answerHide answer
Precomputed hash-to-password lookups for offline cracking. Defense: a unique salt per password makes the precomputation worthless.
- CARD 17
Password spraying
Show answerHide answer
One or two common passwords tried across many accounts, staying under lockout thresholds. Defense: MFA and alerts on failures spread across accounts.
- CARD 18
Credential stuffing
Show answerHide answer
Username and password pairs leaked from one site replayed on another. Defense: MFA and screening new passwords against breached-password lists.
- CARD 19
Session fixation
Show answerHide answer
The attacker plants a known session ID before the victim logs in, then reuses it. Defense: issue a fresh session ID at authentication.
- CARD 20
SQL injection
Show answerHide answer
User input changes the structure of a database query. Primary defense: parameterized queries, backed by input validation and least-privilege database accounts.
- CARD 21
Virus vs worm
Show answerHide answer
A virus attaches to a host file and spreads when that file runs. A worm copies itself across networks with no host file and no user action.
- CARD 22
Trojan
Show answerHide answer
Malware disguised as something the user wants. It does not replicate; the victim installs it.
- CARD 23
Rootkit
Show answerHide answer
Hides itself and other malware by modifying the operating system, sometimes the kernel. A scan from trusted, offline media is the reliable way to spot it.
- CARD 24
Fileless malware
Show answerHide answer
Runs in memory and through legitimate system tools, leaving little on disk for signature scanners. Behavior monitoring is the countermeasure.
- CARD 25
Polymorphic vs metamorphic virus
Show answerHide answer
Polymorphic: encrypted body and a mutating decryptor around the same core code. Metamorphic: rewrites its entire code each generation.
- CARD 26
Symmetric vs asymmetric encryption
Show answerHide answer
Symmetric: one shared key, fast, for bulk data (AES). Asymmetric: a public and private key pair, slower, for key exchange and signatures (RSA, ECC).
- CARD 27
Hash
Show answerHide answer
A one-way, fixed-length digest that proves integrity. SHA-256 is current; MD5 and SHA-1 are broken for collisions.
- CARD 28
Digital signature
Show answerHide answer
A hash signed with the sender's private key and checked with their public key. Integrity, authentication and non-repudiation, with no confidentiality.
- CARD 29
CRL vs OCSP
Show answerHide answer
Both report revoked certificates. A CRL is a list the CA publishes periodically; OCSP answers a live query about one certificate.
- CARD 30
Steganography vs cryptography
Show answerHide answer
Steganography hides that a message exists; cryptography hides what it says. Steganalysis is detecting the hidden message.
How to run the deck
Ten minutes a day beats an hour on Sunday. Go front to back once, set aside every card you missed, and run only that pile again before you close the page. A card you miss two days running is a sign to read its file: the scan cards come from scanning networks and port scan types, the switch attacks from layer 2 attacks and defenses, the password cards from password attack types, the injection card from SQL injection types, and the malware cards from virus vs worm vs trojan.
The crypto block is the cheapest to bank. Cryptography is 5% of the exam under EC-Council's blueprint v5.0 (checked Oct 11, 2026) and almost pure definition, so it suits cards better than reading; the cryptography module file and symmetric vs asymmetric vs hashing fill in the rest.