Skip to content
ScopefileGet the app

Technique fileIntro to ethical hacking

White hat, black hat, gray hat: the hacker classes CEH uses

A gray hat hacker sits between the other two hats: no authorization from the system's owner, yet none of the black hat's hostile aim. CEH places every actor on two axes, authorization and motive, and the class follows from where the actor lands.

Exam
312-50
Domain
1 · Overview
Targets
6

Two axes, one label

Skill level and tooling tell you little about which class an actor belongs to. Authorization is the first axis, and it is binary: a signed agreement exists or it does not. Motive is the second: money, ideology, a government's tasking, revenge, curiosity, bragging rights.

The hat colors carry the core of this topic in the Introduction to Ethical Hacking module. The named groups (hacktivists, state-sponsored actors, insiders and the rest) are a short memorization list you can finish in one sitting. Do that, then spend your hours on the heavier modules.

Whatever the label, the work itself follows the same sequence of steps, laid out in the five phases of ethical hacking. The class describes who is acting and why; the phases describe what they do.

The classes, one line each

White hat
Works under contract, scope and rules of engagement, and reports to the owner. This is the role CEH certifies.
Black hat
Acts without authorization and with hostile intent toward the owner.
Gray hat
Acts without authorization but without hostile intent. Still unlawful in most jurisdictions, because the missing authorization is the offense.
Script kiddie
Short on skill; borrows tooling built by others without understanding how it works.
Hacktivist
Acts for a political or social cause.
State-sponsored hacker
Acts on behalf of a government.
Cyber terrorist
Aims to spread fear or cause serious disruption for ideological ends, often aimed at critical infrastructure.
Insider
An employee, contractor or partner who misuses access they legitimately hold.
Suicide hacker
Indifferent to being caught or punished, as long as the attack lands.

Authorization against motive

Where the four headline classes sit when authorization meets intent
Where the four headline classes sit when authorization meets intentHostile intentNo hostile intentAuthorizedInsider misuseWhite hatNot authorizedBlack hatGray hat

Label the actor

Authorization first, motive second. The notes under each option explain the near misses.

Answered 0/6Hits 0

T-01

What is the main difference between a white hat and a black hat hacker?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ATool choice does not separate hacker classes; both groups use commercial, open-source and custom tooling interchangeably.
  2. BEthical hackers deliberately use the same techniques as criminals, because realistic testing requires emulating real adversaries.
  3. CCorrect: authorization from the system owner and the intent to improve security are what make a hacker a white hat rather than a criminal.
  4. DHacker classes are defined by authorization and intent, not by the kind of organization targeted; both groups touch every sector.
T-02

Which group focuses on testing security vulnerabilities in software applications without the prior consent of the software owner, often reporting their findings discreetly?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AWhite hats test only with the owner's prior permission, so probing software without consent falls outside that category.
  2. BBlack hats also lack consent, but they exploit or sell findings for gain rather than quietly reporting them to the owner.
  3. CCorrect: gray hats probe without authorization yet usually disclose flaws to the owner, mixing unauthorized access with non-malicious intent.
  4. DRed hat is an informal label for vigilantes who attack black hats, and it is not part of the core CEH hacker-class model.
T-03

Which term describes an individual who lacks advanced hacking skills but leverages pre-written scripts or tools to exploit targets on the internet?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA phreaker manipulates telephone networks and signaling systems, which is a specialty defined by target, not by lack of skill.
  2. BCorrect: script kiddies run ready-made scripts and tools written by others without understanding how they work internally.
  3. CA sniffer is a packet-capture tool or the act of capturing traffic, not a category of attacker.
  4. DNoob hacker is casual slang, not the recognized term; the industry and the CEH syllabus use script kiddie for this profile.
T-04

If you are known for breaking into computer systems and stealing sensitive information, often selling it for profit, what type of hacker are you MOST LIKELY to be?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AGray hats break rules without permission but typically disclose flaws instead of stealing and selling data for profit.
  2. BWhite hats work with authorization to improve security and never steal or sell sensitive information.
  3. CCorrect: unauthorized intrusion for personal or financial gain, such as selling stolen data, is the defining behavior of a black hat.
  4. DRed hat is an informal label for vigilantes who target black hats, not for criminals who monetize stolen data.
T-05

An outside group with no link to a chemical company defaces its website and leaks internal emails about a pollution incident, posting a statement that the goal is public accountability. No ransom or payment is demanded. Which attacker class best fits this group?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AGray hats probe systems without permission and usually disclose flaws, but their label is not defined by attacking a target to promote a cause.
  2. BScript kiddie describes low skill and reliance on ready-made tools; the scenario is defined by the political or social motive instead.
  3. CCorrect: hacktivists break into or deface systems to publicize a political or social cause, with no financial demand, exactly as this group does.
  4. DAn insider works for or with the organization; the stem states the group is external and has no link to the company.
T-06

Investigators find an intruder stayed hidden in a defense contractor's network for 18 months, quietly copying engineering designs. The operation used custom tooling and large resources, and its tasking traced back to a foreign government's intelligence service. Which attacker class is this?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: a long, well-funded, stealthy intrusion directed by a government for espionage is the defining profile of a state-sponsored attacker.
  2. BHacktivists want publicity for a cause; a silent 18-month theft of designs with no public statement does not match that motive.
  3. CA profit-driven black hat would sell data or extort the victim; government tasking and pure espionage point to a different class.
  4. DCyber terrorists aim to cause fear or visible disruption; this operation was designed to stay quiet and collect intelligence for a state.

Labels and the law

Is gray hat hacking legal?

Usually no. In most computer-misuse laws the offense is access without authorization, whatever the motive. An ethical hacker never starts work without written permission.

How is an insider different from an outside black hat?

The insider already holds legitimate access, so perimeter controls do little. Defenders lean on least privilege, separation of duties and monitoring of how authorized accounts are used.

What is a suicide hacker?

An attacker who accepts being caught, or even jailed, as the price of the attack. The defining trait is indifference to consequences, which also removes deterrence as a defense.

Where does a career start?

Every route into this work runs through authorized practice: labs, contracts, bug bounty programs with published rules. The path to becoming an ethical hacker lays out the steps and where CEH fits.