Skip to content
ScopefileGet the app

Flash deck30 cards312-50

CEH flashcards

Thirty CEH flashcards for pure recall: scan types, the ports behind enumeration, attack-and-defense pairs, malware families and crypto terms. Read the front, answer out loud, then flip.

Exam
312-50
Updated
Oct 11, 2026

Scans, ports, pairs, malware, crypto

  1. CARD 01

    TCP connect scan

    Show answerHide answer

    Completes the full three-way handshake on each port. Reliable and needs no special privileges, but every connection can land in the target's logs.

  2. CARD 02

    Half-open (SYN) scan

    Show answerHide answer

    A SYN/ACK reply means open, a RST means closed. The scanner never finishes the handshake, so fewer application logs record it; also called a stealth scan.

  3. CARD 03

    Inverse-flag scans: FIN, NULL, Xmas

    Show answerHide answer

    Probes without a SYN. Under the TCP standard a closed port answers RST and an open one stays silent. Windows hosts answer RST either way, so results there cannot be trusted.

  4. CARD 04

    Idle (zombie) scan

    Show answerHide answer

    Infers port state from a third host's IP ID counter, so the target only ever sees the zombie's address. Hosts with randomized IP IDs make useless zombies.

  5. CARD 05

    ACK scan

    Show answerHide answer

    Maps firewall filtering: an unfiltered port answers RST, a filtered one stays silent or returns an ICMP error. It cannot tell open from closed.

  6. CARD 06

    UDP scan

    Show answerHide answer

    No handshake to read. An ICMP port-unreachable reply means closed; silence means open or filtered. Slow, because silence means waiting out timeouts.

  7. CARD 07

    NetBIOS enumeration

    Show answerHide answer

    Ports 137–139 (name, datagram and session services). Exposes computer names, workgroups and shares. Defense: turn off NetBIOS over TCP/IP where nothing needs it.

  8. CARD 08

    SNMP enumeration

    Show answerHide answer

    UDP 161, traps on 162. Default community strings let anyone read device and account data. Defense: change the defaults, move to SNMPv3.

  9. CARD 09

    LDAP enumeration

    Show answerHide answer

    TCP 389, or 636 for LDAPS. Anonymous binds expose users, groups and directory structure. Defense: block anonymous binds, require LDAPS.

  10. CARD 10

    NTP enumeration

    Show answerHide answer

    UDP 123. A time server can reveal the hosts that sync with it. Defense: restrict who may query it.

  11. CARD 11

    SMTP enumeration

    Show answerHide answer

    TCP 25. The VRFY and EXPN verbs confirm which mailboxes exist. Defense: disable both and answer valid and invalid users the same way.

  12. CARD 12

    DNS zone transfer

    Show answerHide answer

    TCP 53. An unrestricted transfer hands over the whole zone, every host name at once. Defense: allow transfers only to your own secondary servers.

  13. CARD 13

    MAC flooding

    Show answerHide answer

    Fills a switch's CAM table with fake addresses until it floods frames out of every port. Defense: port security, capping MAC addresses per port.

  14. CARD 14

    ARP poisoning

    Show answerHide answer

    Forged ARP replies tie the attacker's MAC to another host's IP, putting the attacker in the middle. Defense: Dynamic ARP Inspection, checked against DHCP snooping bindings.

  15. CARD 15

    DHCP starvation

    Show answerHide answer

    Drains the address pool with fake requests, often to make room for a rogue DHCP server. Defense: DHCP snooping with trusted ports, plus port security.

  16. CARD 16

    Rainbow table

    Show answerHide answer

    Precomputed hash-to-password lookups for offline cracking. Defense: a unique salt per password makes the precomputation worthless.

  17. CARD 17

    Password spraying

    Show answerHide answer

    One or two common passwords tried across many accounts, staying under lockout thresholds. Defense: MFA and alerts on failures spread across accounts.

  18. CARD 18

    Credential stuffing

    Show answerHide answer

    Username and password pairs leaked from one site replayed on another. Defense: MFA and screening new passwords against breached-password lists.

  19. CARD 19

    Session fixation

    Show answerHide answer

    The attacker plants a known session ID before the victim logs in, then reuses it. Defense: issue a fresh session ID at authentication.

  20. CARD 20

    SQL injection

    Show answerHide answer

    User input changes the structure of a database query. Primary defense: parameterized queries, backed by input validation and least-privilege database accounts.

  21. CARD 21

    Virus vs worm

    Show answerHide answer

    A virus attaches to a host file and spreads when that file runs. A worm copies itself across networks with no host file and no user action.

  22. CARD 22

    Trojan

    Show answerHide answer

    Malware disguised as something the user wants. It does not replicate; the victim installs it.

  23. CARD 23

    Rootkit

    Show answerHide answer

    Hides itself and other malware by modifying the operating system, sometimes the kernel. A scan from trusted, offline media is the reliable way to spot it.

  24. CARD 24

    Fileless malware

    Show answerHide answer

    Runs in memory and through legitimate system tools, leaving little on disk for signature scanners. Behavior monitoring is the countermeasure.

  25. CARD 25

    Polymorphic vs metamorphic virus

    Show answerHide answer

    Polymorphic: encrypted body and a mutating decryptor around the same core code. Metamorphic: rewrites its entire code each generation.

  26. CARD 26

    Symmetric vs asymmetric encryption

    Show answerHide answer

    Symmetric: one shared key, fast, for bulk data (AES). Asymmetric: a public and private key pair, slower, for key exchange and signatures (RSA, ECC).

  27. CARD 27

    Hash

    Show answerHide answer

    A one-way, fixed-length digest that proves integrity. SHA-256 is current; MD5 and SHA-1 are broken for collisions.

  28. CARD 28

    Digital signature

    Show answerHide answer

    A hash signed with the sender's private key and checked with their public key. Integrity, authentication and non-repudiation, with no confidentiality.

  29. CARD 29

    CRL vs OCSP

    Show answerHide answer

    Both report revoked certificates. A CRL is a list the CA publishes periodically; OCSP answers a live query about one certificate.

  30. CARD 30

    Steganography vs cryptography

    Show answerHide answer

    Steganography hides that a message exists; cryptography hides what it says. Steganalysis is detecting the hidden message.

How to run the deck

Ten minutes a day beats an hour on Sunday. Go front to back once, set aside every card you missed, and run only that pile again before you close the page. A card you miss two days running is a sign to read its file: the scan cards come from scanning networks and port scan types, the switch attacks from layer 2 attacks and defenses, the password cards from password attack types, the injection card from SQL injection types, and the malware cards from virus vs worm vs trojan.

The crypto block is the cheapest to bank. Cryptography is 5% of the exam under EC-Council's blueprint v5.0 (checked Oct 11, 2026) and almost pure definition, so it suits cards better than reading; the cryptography module file and symmetric vs asymmetric vs hashing fill in the rest.

Sources