Skip to content
ScopefileGet the app

Module 1Domain 1 of 9Information Security and Ethical Hacking Overview

What ethical hacking is, and what Module 1 of the CEH tests

Ethical hacking is authorized, scoped testing that finds weaknesses the way an attacker would, then reports them so they get fixed. Module 1 defines the terms the rest of the certification leans on: who is allowed to test, under what agreement, inside which frameworks, and against which laws.

Exam
312-50
Domain
1 of 9
Domain weight
6%
This file
~6%
Targets
17

The vocabulary module

Module 1 is the Information Security and Ethical Hacking Overview domain, which EC-Council's blueprint v5.0 weights at 6% of the exam (as of Oct 11, 2026). It is the vocabulary layer, so most of its material is recall: hacker classes, the five phases, control types and functions, the goals of information security, and the laws that govern a given kind of data.

That makes it cheap to study and quick to bank. The value is in telling look-alike terms apart under time pressure, so spend an evening fixing the definitions and move on. Deeper attack mechanics begin in footprinting and reconnaissance. Two ideas underpin everything else: what separates authorized testing from a crime, covered in ethical hacking versus penetration testing, and the ordered method every engagement follows.

Hacker classes by intent

White hat
The class this certification trains for. How it is separated from the others is set out on hacker classes.
Black hat
Acts without authorization, for personal or malicious gain.
Gray hat
Acts without clear authorization but without clearly malicious intent, the ambiguous middle.
Hacktivist
Driven by a political or social cause rather than money.
Script kiddie
Runs tools built by others without understanding them.
State-sponsored
Works for a government, usually well resourced and patient.
Insider
A trusted person whose legitimate access is the whole problem.

The five phases, in order

The CEH methodology runs these five phases; the later modules map onto them.
A five-step chain: reconnaissance, scanning, gaining access, maintaining access, then clearing tracks.01Reconlearn the target02Scanningfind live hosts03Accessuse a weakness04Persistencekeep the foothold05Cleanuphide the activityA five-step chain: reconnaissance, scanning, gaining access, maintaining access, then clearing tracks.01Reconlearn the target02Scanningfind live hosts03Accessuse a weakness04Persistencekeep the foothold05Cleanuphide the activity

Place the activity in the right framework

The v13 course outline names three models, and they are easy to confuse. The CEH five phases describe the shape of an engagement. The Cyber Kill Chain describes an intrusion as seven stages from early reconnaissance through to acting on the objective. MITRE ATT&CK is not a sequence at all; it is a catalog of adversary tactics and techniques you map observed behavior onto. The side-by-side detail sits on the five phases of ethical hacking.

A defender learns the order for a practical reason: each phase leaves different traces, so knowing where an activity sits tells you what evidence to look for and when prevention is already past and only containment is left.

Controls and laws, classified

Sort a safeguard into a type and a function, and recognize which regime governs which data.
FamilyBuckets to recognizeThe distinction
Control typeAdministrative, technical, physicalWhat kind of safeguard it is
Control functionPreventive, detective, correctiveWhat it does across the timeline of an incident
Security goalsConfidentiality, integrity, availability, non-repudiationWhich property a safeguard or an attack affects
Laws and standardsPCI DSS, HIPAA, SOX, GDPR, data-protection actsWhich regime governs the data in question
Governance inputsRisk management, threat intelligence, incident managementWhere a program activity fits

Data drives the law: payment card data sits under PCI DSS, patient health data under HIPAA, personal data of EU residents under GDPR.

Drill the Module 1 vocabulary

Term-matching and short scenarios from the overview domain. Lock the answer first, then read the note under every option.

Answered 0/17Hits 0

T-01

A penetration tester identifies an unpatched, legacy payment processing server residing on the same subnet as the primary target. The payment server is explicitly excluded from the engagement scope. What is the correct action?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AEven a non-intrusive scan is active testing of a system the client excluded, which breaches the agreed scope.
  2. BManual exploitation of an out-of-scope system is unauthorized access, however careful the tester is.
  3. CSending any payload to an excluded server violates the engagement terms and may disrupt payment processing.
  4. DCorrect: the tester must leave excluded systems alone and report the observation to the client, who can decide whether to authorize testing.
T-02

To mitigate the risk of zero-day exploits bypassing network perimeter controls, an organization wants to implement a defense-in-depth strategy. Which combination provides the MOST robust layered detection capability?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: network IDS, endpoint detection and response, and centralized logging give overlapping visibility that can catch unknown attacks through behavior.
  2. BPassword rules and mandatory access controls are preventive controls that provide no detection when a zero-day is exploited.
  3. CDisk encryption and offline backups protect data and recovery but do not detect an intrusion in progress.
  4. DTwo perimeter controls stack defenses at the same layer and miss attacks that bypass the edge, contrary to defense in depth.
T-03

What practice involves the restriction of user permissions to access sensitive information within a company's database?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APatching fixes software flaws but does not decide which users may view sensitive records.
  2. BSocial engineering manipulates people into revealing information; it is an attack technique, not a protective practice.
  3. CEncryption protects data from being read if intercepted or stolen, but it does not by itself define who is allowed access.
  4. DCorrect: access control restricts who can view or change data based on identity and role, ideally following least privilege.
T-04

During an authorized penetration test, you accidentally access a database containing unsecured Protected Health Information (PHI). Under HIPAA regulations, what is the required IMMEDIATE action?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: the tester should stop accessing the data and escalate at once to the client's compliance contact, who owns HIPAA breach assessment and notification.
  2. BDeleting regulated data destroys evidence the client needs for its breach assessment and may itself breach the engagement terms.
  3. CNotifying individuals within 60 days is the covered entity's obligation under the HIPAA Breach Notification Rule, not the tester's immediate task.
  4. DBypassing the client to contact law enforcement is not required by HIPAA and skips the client's own incident process.
T-05

In the context of risk assessment, what is the formula for calculating risk?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: risk is commonly expressed as the likelihood of an event multiplied by its impact, which lets organizations prioritize scenarios.
  2. BAdding threat and vulnerability before multiplying by asset value is not a standard risk formula.
  3. CDividing asset value by threat level would make risk shrink as threats grow, which makes no sense.
  4. DThreat and vulnerability shape likelihood, but this version leaves out impact, so it is incomplete as a risk formula.
T-06

An analyst observes a single outbound network alert to an unknown IP address and immediately declares a system breach. What is the critical analytical error in this scenario?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABlocking the address may be a later containment step, but it does not fix the error of drawing a conclusion from one alert.
  2. BCorrect: one alert is a lead, not proof; analysts should correlate it with logs, endpoint telemetry and threat intelligence before declaring a breach.
  3. CWhether the payload was encrypted is a detail; the error is the leap from a single alert to a confirmed breach.
  4. DRestarting the endpoint would destroy volatile evidence and is unrelated to the flawed reasoning.
T-07

In which phase of a penetration test is information gathered that is critical for planning and executing the entire test?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACovering tracks happens at the end of an attack and does not gather information for planning.
  2. BCorrect: reconnaissance collects information about the target, such as domains, people and technologies, that guides every later phase.
  3. CGaining access is where vulnerabilities are exploited, using information already gathered earlier.
  4. DScanning builds on reconnaissance by actively probing hosts and services, but the foundational information gathering happens before it.
T-08

During an authorized penetration test at a municipal water facility, an analyst discovers an active, unauthorized intrusion into the SCADA network currently altering chemical levels to toxic concentrations. What is the BEST immediate action?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: an imminent threat to public safety overrides normal reporting, so emergency services and the client's incident response team must be alerted at once.
  2. BDocumenting for a final report ignores an ongoing threat to human life that demands immediate escalation.
  3. CRoutine ticketing under a service agreement is far too slow for an active attack endangering public health.
  4. DDisconnecting systems is an operational decision for the facility, and unilateral action could disrupt safety controls or exceed the tester's authority.
T-09

What does the term 'non-repudiation' refer to in information security?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APreventing unauthorized access is the job of access control and authentication; non-repudiation concerns proving who performed an action after the fact.
  2. BEncryption for confidentiality hides content from outsiders, but it does not prove which party sent a message or performed an action.
  3. CMultifactor authentication strengthens identity verification at login, yet it does not by itself create the lasting proof that non-repudiation requires.
  4. DCorrect: non-repudiation means a party cannot credibly deny an action, typically achieved with digital signatures and trustworthy audit logs that tie actions to identities.
T-10

As an ethical hacker, you are hired to test the security of a company's network. You follow all legal protocols and ensure you have explicit permission from the company. What type of hacker are you?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AGray hats act without permission, so a tester with explicit authorization does not fit this label.
  2. BCorrect: a professional who tests with the owner's explicit permission and follows legal agreements is a white hat.
  3. CBlue hat is an informal label for outside testers invited to check products before release, not the standard term for authorized ethical hackers.
  4. DBlack hats break in without permission for malicious or personal gain.
T-11

An organization grants its junior developers local administrator rights on their workstations and read-write access to production database backups. Which principle is primarily violated, enabling potential lateral movement?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ADefense in depth is about layering controls; the core flaw here is granting more rights than the job needs.
  2. BMandatory access control is a specific model using system-enforced labels, and its misuse is not what the scenario describes.
  3. CSeparation of duties splits critical tasks among people to prevent fraud, which differs from simply granting excess rights.
  4. DCorrect: local admin rights and write access to production backups exceed what developers need, violating least privilege and easing lateral movement.
T-12

What is the primary purpose of a security policy?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AIdentifying threats is the job of risk assessment and threat modeling, which inform policy but are not its purpose.
  2. BCorrect: a security policy states management's intent and sets the rules and requirements that standards and procedures implement.
  3. CDetailed technical configurations belong in standards, baselines and procedures, not the high-level policy.
  4. DPolicies may mention consequences, but penalties are a small part rather than the primary purpose.
T-13

Which component of the CIA triad ensures that information cannot be modified in an unauthorized or undetected manner?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AConfidentiality keeps information from being disclosed to unauthorized parties; it does not by itself detect or prevent unauthorized changes to the data.
  2. BAuthentication verifies who a user or system is; it supports security but is not one of the three CIA triad components.
  3. CAvailability ensures that authorized users can reach systems and data when needed, which is unrelated to protecting data from unauthorized modification.
  4. DCorrect: integrity ensures data is not altered without authorization or without detection, typically enforced with hashes, digital signatures and access controls.
T-14

What is assured by the confidentiality and nondisclosure agreements signed in the context of an IT security consultancy?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AFixing vulnerabilities is covered by statements of work or remediation contracts, not confidentiality agreements.
  2. BUptime and performance are covered by service level agreements, not nondisclosure agreements.
  3. CCorrect: NDAs legally bind the consultant to protect the client's sensitive information and findings from unauthorized disclosure.
  4. DSatisfaction is a service quality goal, not something a nondisclosure agreement guarantees.
T-15

Which of the following activities is NOT typically part of an ethical hacker's methodology?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AReconnaissance is a standard first phase of an ethical hacking methodology.
  2. BVulnerability scanning and assessment is a core part of authorized testing.
  3. CCorrect: exploiting anything without explicit authorization is illegal and unethical, whatever the motive.
  4. DDocumentation and reporting are essential, because the report is how the client learns what to fix.
T-16

Which of the following actions involves an ethical hacker attempting to uncover potential entry points in a network?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: penetration testing actively looks for and validates entry points, such as vulnerable services or weak credentials, under authorization.
  2. BThreat modeling analyzes systems on paper to anticipate threats rather than actively probing a live network.
  3. CVulnerability swiping is not a recognized security practice or testing method; it is an invented distractor term.
  4. DA security audit evaluates controls against a standard or policy rather than actively searching for exploitable entry points.
T-17

While performing a security assessment for a client, you are approached by an employee from another department within the same organization. They offer you a significant sum of money to exploit a vulnerability in the company's HR system to retrieve confidential employee data. Is it ethical or unethical to comply with this request?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThe sensitivity of the data does not change the fact that the access would be unauthorized.
  2. BCorrect: accepting payment to exploit systems and take confidential data without proper authorization violates professional ethics and the law.
  3. CEthics go beyond legality, and in any case this request would also break computer misuse and privacy laws.
  4. DAn employee from another department cannot authorize access to HR data, so complying would be unethical and illegal.

Where Module 1 trips people up

Is the overview module worth much study time?

It is 6% of the exam under blueprint v5.0 (as of Oct 11, 2026), and it is mostly recall, so it rewards a short, focused pass over the terms rather than days of work.

Do I need to memorize legal text?

No. You match a kind of data to the regime that governs it, payment data to PCI DSS, health data to HIPAA, EU personal data to GDPR, rather than reciting statute.

Sources