CEH v13 Glossary: 58 Ethical Hacking Terms (2026)
The 58 CEH v13 terms that decide the 312-50 exam, from footprinting vs enumeration to IDS vs IPS and XSS vs CSRF, each with a plain definition, the exam cue and the defence that goes with it.
- 58Terms defined
- 70+Acronyms
- 312-50Exam
- 125Questions
- 60-85%Pass mark

Table of Contents
How to use this glossary
CEH questions are short, but they are dense with vocabulary. A single stem can hinge on whether an activity is footprinting or enumeration, whether a device only alerts or also blocks, or whether a flaw runs script in the victim's browser or forges a request from it. Miss the word and two answers look equally right. This glossary explains each term the way the 312-50 exam uses it, and pairs every attack concept with the countermeasure the exam expects you to choose.
The terms are mapped to EC-Council's CEH Exam Blueprint v5.0, which groups the v13 content into nine domains; Network and Perimeter Hacking is the heaviest at 24%. As of September 2026 CEH v13 is the current version and EC-Council has announced no successor. The exam is 125 multiple-choice questions in four hours, and the cut score varies between roughly 60% and 85% depending on the question form you receive.
Every term below is tagged with the exam domain it belongs to. This is where the vocabulary load sits across the 312-50 blueprint:
- IntroInformation Security and Ethical Hacking Overview6%8 terms
- ReconReconnaissance Techniques17%10 terms
- SystemSystem Hacking Phases and Attack Techniques15%9 terms
- NetworkNetwork and Perimeter Hacking24%10 terms
- WebWeb Application Hacking14%6 terms
- Wi-FiWireless Network Hacking5%3 terms
- IoT/OTMobile, IoT and OT Hacking10%4 terms
- CloudCloud Computing5%3 terms
- CryptoCryptography5%5 terms
Each card has three layers: a plain-English definition, an On the exam line describing how questions use the term, and — where one exists — the term it is most often confused with. Click that link to jump straight to the rival definition.
The A–Z glossary
- APTAdvanced Persistent ThreatSystem
A well-resourced, usually state-linked or organised adversary that gains access and stays undetected for a long period to pursue a specific objective.
On the examKeywords are 'long-term', 'stealthy' and 'targeted'. A smash-and-grab attack is not an APT, however sophisticated.
- ARP PoisoningNetwork
Sending forged ARP replies so hosts associate the attacker's MAC address with another host's IP, placing the attacker in the traffic path.
On the examDefensive answers: Dynamic ARP Inspection, static ARP entries for critical hosts, and port security. It is a layer 2 man-in-the-middle technique.
Don’t confuse with MAC Flooding
- Asymmetric EncryptionCrypto
Encryption with a mathematically linked public and private key pair. It solves key distribution and enables digital signatures but is slower than symmetric.
On the examEncrypt with the recipient's public key for confidentiality; sign with your own private key for authenticity. RSA and ECC are the examples.
Don’t confuse with Symmetric Encryption
- Banner GrabbingRecon
Reading the text a service announces on connection - server software and version - to identify what is running and whether it is vulnerable.
On the examThe countermeasure answer is suppressing or altering service banners. Distinguish active grabbing (connecting) from passive (reading captured traffic).
- BotnetIoT/OT
A network of compromised devices - often poorly secured IoT devices - controlled remotely through command and control to launch attacks such as DDoS.
On the examIoT scenarios with default credentials point to botnet recruitment. The fix is changing defaults, patching firmware and segmenting IoT devices.
- CASBCloud Access Security BrokerCloud
A control point between users and cloud services that enforces policy, gives visibility into cloud use and helps detect shadow IT and data leakage.
On the examIf a scenario asks how to discover unsanctioned cloud apps or enforce data policy across SaaS, CASB is the answer.
- CIA TriadConfidentiality, Integrity, AvailabilityIntro
The three security goals every control protects: keeping data secret from the wrong people, keeping it accurate and unaltered, and keeping systems reachable by the people who need them.
On the examQuestions describe an attack's effect and ask which property it hit. Sniffing breaks confidentiality, tampering breaks integrity, a flood that takes a site down breaks availability.
- Command InjectionWeb
A flaw where an application passes unsanitised input to a system shell, so injected input runs as operating-system commands on the server.
On the examSeparate it from SQL injection by the target: the OS shell, not the database. The fix is avoiding shell calls and strict allow-list validation.
Don’t confuse with SQL Injection
- ContainerCloud
A lightweight package that bundles an application with its dependencies and shares the host's kernel, isolated through namespaces and control groups.
On the examContainer escape risk comes from the shared kernel. Defensive answers: minimal images, image scanning, no privileged containers.
- CSRFCross-Site Request ForgeryWeb
An attack that makes a logged-in user's browser send an unwanted request to a site that trusts the user's session, such as changing an email address.
On the examThe fix is anti-CSRF tokens and SameSite cookies. If no script runs in the victim's page, it is CSRF, not XSS.
Don’t confuse with XSS
- CVSSCommon Vulnerability Scoring SystemRecon
An open standard that rates vulnerability severity from 0 to 10 using base, temporal and environmental metrics.
On the examKnow the bands: 0.1-3.9 low, 4.0-6.9 medium, 7.0-8.9 high, 9.0-10.0 critical. Questions give a score and ask the band.
Don’t confuse with Vulnerability Scanning
- Cyber Kill ChainIntro
Lockheed Martin's seven-stage model of an intrusion: reconnaissance, weaponization, delivery, exploitation, installation, command and control, actions on objectives. Defenders use it to break an attack early.
On the examYou will be given an activity, such as a phishing email landing in an inbox, and asked which stage it represents. Delivery vs exploitation is the usual trap.
Don’t confuse with MITRE ATT&CK
- DDoSDistributed Denial of ServiceNetwork
An attack that overwhelms a service's bandwidth, connections or resources from many sources at once, making it unavailable to legitimate users.
On the examIt attacks availability. Mitigation answers are upstream scrubbing, rate limiting and CDN absorption, not blocking a single IP.
- Defense in DepthIntro
Layering independent controls - physical, network, host, application, data and people - so a failure in one layer does not expose the asset.
On the examThe right answer to 'best overall strategy' questions is usually layered controls rather than any single product, however strong.
- Digital SignatureCrypto
A hash of a message encrypted with the sender's private key. Anyone with the public key can verify who sent it and that it was not changed.
On the examSignatures give integrity, authentication and non-repudiation - but not confidentiality. Non-repudiation is the keyword that points here.
Don’t confuse with Hashing
- Directory TraversalWeb
A flaw where manipulated file paths such as ../ sequences let a user reach files outside the web application's intended directory.
On the examLook for ../ or encoded variants in a URL in the stem. The fix is canonicalising paths and restricting file access to an allow-list.
- EnumerationRecon
Actively connecting to target systems to extract details such as user names, shares, services, groups and SNMP data. It follows scanning and involves direct interaction.
On the examThe difference from footprinting is active connection. Pulling user lists from a service or directory is enumeration; expect questions that hinge on that line.
Don’t confuse with Footprinting
- Evil TwinWi-Fi
A malicious access point that copies a legitimate network's name to lure users into connecting, placing the attacker in the middle of their traffic.
On the examAn evil twin impersonates a known SSID to attract clients. A rogue access point is an unauthorised device plugged into the real network.
Don’t confuse with Rogue Access Point
- Fileless MalwareSystem
Malicious code that runs in memory and abuses legitimate built-in tools such as scripting engines, leaving few or no files on disk for antivirus to scan.
On the examWhen the stem says signature antivirus found nothing on disk, think fileless. Behaviour monitoring and script logging are the defensive answers.
- Five Phases of HackingIntro
CEH's framework for an attack or assessment: reconnaissance, scanning, gaining access, maintaining access and clearing tracks. The course and exam are organised around it.
On the examExpect to order activities or place one in a phase. Port scanning is scanning, not reconnaissance; installing persistence is maintaining access, not gaining it.
- FootprintingRecon
Collecting information about a target organisation - domains, IP ranges, staff, technologies, physical locations - to map its attack surface before any direct interaction.
On the examFootprinting is broad information gathering; if the activity queries public sources without touching the target's systems, it is passive footprinting.
Don’t confuse with Enumeration
- Google DorkingRecon
Using advanced search operators such as site:, filetype: and intitle: to find information a site exposes unintentionally, like indexed documents or login pages.
On the examRecognise operator syntax in a question stem. It is passive recon, and the fix is controlling what search engines can index, not blocking Google.
- HashingCrypto
A one-way function that turns input of any size into a fixed-length digest. Any change to the input changes the digest, which is how integrity is verified.
On the examHashing provides integrity, not confidentiality, and cannot be decrypted. MD5 and SHA-1 are weak because of collisions; SHA-256 is the safe choice.
Don’t confuse with Digital Signature
- HoneypotNetwork
A decoy system with no production purpose, deployed to attract attackers so their techniques can be observed and they are diverted from real assets.
On the examAny traffic to a honeypot is suspicious by definition. Low vs high interaction honeypots is the usual detail.
- ICSIndustrial Control SystemIoT/OT
Systems that monitor and control industrial processes, including SCADA, distributed control systems and PLCs. Availability and safety usually outrank confidentiality.
On the examIn OT scenarios the priority is safety and availability, so aggressive active scanning of live controllers is usually the wrong answer.
Don’t confuse with Purdue Model
- IDSIntrusion Detection SystemNetwork
A system that monitors network or host activity and alerts on suspicious patterns. It observes and reports; it does not block.
On the examIf the requirement is 'alert only' or passive monitoring, choose IDS. False positive vs false negative definitions are frequently asked.
Don’t confuse with IPS
- IPSIntrusion Prevention SystemNetwork
An inline system that inspects traffic and actively blocks or drops what it identifies as malicious, in addition to alerting.
On the examIPS sits inline and can stop traffic; a false positive therefore blocks legitimate users - a trade-off questions probe.
Don’t confuse with IDS
- JailbreakingIoT/OT
Removing the manufacturer's restrictions on a mobile operating system (rooting on Android) to gain full control, which also disables built-in security protections.
On the examFrom a defender's view, jailbroken devices are high risk; MDM policies that detect and block them are the expected answer.
- MAC FloodingNetwork
Overloading a switch's CAM table with fake MAC addresses so it fails open and floods frames to all ports, exposing traffic.
On the examThe countermeasure is port security limiting MAC addresses per port. Contrast with ARP poisoning, which targets hosts, not the switch.
Don’t confuse with ARP Poisoning
- MITRE ATT&CKAdversarial Tactics, Techniques, and Common KnowledgeIntro
A public knowledge base that catalogues real attacker behaviour as tactics (the goal) and techniques (how the goal is reached), used to map detections and threat intelligence.
On the examDistinguish it from the Kill Chain: ATT&CK is a detailed matrix of observed techniques, the Kill Chain a linear sequence. 'Tactic' means why, 'technique' means how.
Don’t confuse with Cyber Kill Chain
- OSINTOpen-Source IntelligenceRecon
Intelligence built from publicly available sources such as websites, job postings, social media, public records and code repositories.
On the examA job advert revealing the firewall brand and server OS is a classic OSINT leak. The defensive answer is reducing what the organisation publishes.
- OWASP Top 10Web
The Open Worldwide Application Security Project's ranked list of the most critical web application security risk categories, updated every few years.
On the examKnow it is an awareness list of risk categories, not a compliance standard or a tool. Broken access control currently sits at the top.
- PhishingNetwork
Fraudulent messages that impersonate a trusted party to trick recipients into clicking, opening an attachment or disclosing information. Spear phishing targets specific people; whaling targets executives.
On the examSpear phishing vs whaling vs generic phishing is a common distinction. Defences: training, email authentication (SPF, DKIM, DMARC) and reporting.
Don’t confuse with Social Engineering
- PKIPublic Key InfrastructureCrypto
The system of certificate authorities, certificates, registration and revocation that binds public keys to verified identities.
On the examKnow the roles: the CA issues and signs, the RA verifies identity, and CRL or OCSP report revoked certificates.
- Privilege EscalationSystem
Gaining rights beyond those originally granted. Vertical escalation moves to a higher privilege level; horizontal escalation reaches another user's resources at the same level.
On the examVertical vs horizontal is the tested distinction. Defensive answers are least privilege, patching and removing unneeded rights.
- Purdue ModelIoT/OT
A reference architecture that separates industrial networks into levels, from physical processes and controllers up to enterprise IT, with a DMZ between OT and IT.
On the examQuestions test segmentation: traffic between enterprise IT and control levels should pass through the industrial DMZ.
Don’t confuse with ICS
- Rainbow TableSystem
A precomputed table mapping hash values back to the inputs that produce them, trading storage for speed against weak, unsalted password hashes.
On the examThe countermeasure is always salting, which makes precomputed tables useless. 'Longer hashing time' or 'encrypting the table' are distractors.
Don’t confuse with Salting
- RansomwareSystem
Malware that encrypts or locks the victim's data and demands payment for the key, often combined with data theft for double extortion.
On the examThe best recovery answer is tested offline backups, not paying. Prevention answers include patching, least privilege and email filtering.
- Rogue Access PointWi-Fi
An unauthorised wireless access point connected to an organisation's wired network, often by an employee, creating an uncontrolled entry point.
On the examDetection answers are wireless intrusion prevention and regular wireless surveys. The risk is a bypass of the perimeter, not impersonation.
Don’t confuse with Evil Twin
- RootkitSystem
Malware designed to hide itself and other malicious activity by subverting the operating system, kernel or firmware, often surviving reboots.
On the examDetection answers involve integrity checking or booting from trusted media, because a compromised OS cannot be trusted to report on itself.
Don’t confuse with Trojan
- Rules of EngagementRoEIntro
The signed agreement that defines what an ethical hacker may test, when, from where and with which techniques. It is what separates an authorised assessment from a crime.
On the examIf a scenario asks what must exist before any testing starts, the answer is written authorisation and agreed scope - never 'start with passive recon'.
Don’t confuse with Scope
- SaltingSystem
Adding a unique random value to each password before hashing, so identical passwords produce different hashes and precomputed tables no longer work.
On the examIf the question asks how to defeat rainbow tables, choose salting. Combine with a slow hashing algorithm for the full defence.
Don’t confuse with Rainbow Table
- ScopeIntro
The explicit list of systems, networks, addresses and methods included in an engagement, plus what is excluded. Anything outside it is off limits, even if it looks vulnerable.
On the examA tester who finds an adjacent server outside scope should stop and report, not test it. Expect 'expand the test yourself' as the tempting wrong answer.
Don’t confuse with Rules of Engagement
- Session HijackingNetwork
Taking over an established, authenticated session by stealing or predicting its session identifier, bypassing the need to log in.
On the examCountermeasures: encrypted transport, random session IDs, regenerating IDs after login and short timeouts. Know network-level vs application-level hijacking.
Don’t confuse with Sniffing
- SniffingNetwork
Capturing and inspecting network traffic. Passive sniffing listens on a shared medium; active sniffing manipulates a switched network to redirect traffic.
On the examEncryption of traffic is the core countermeasure. Passive vs active sniffing, and hub vs switch, are the tested distinctions.
Don’t confuse with Session Hijacking
- Social EngineeringNetwork
Manipulating people rather than technology into revealing information or granting access, exploiting trust, urgency, authority or helpfulness.
On the examThe strongest countermeasure answer is security awareness training plus verification procedures. Tailgating, pretexting and impersonation are all in scope.
Don’t confuse with Phishing
- SQL InjectionSQLiWeb
A flaw where user input is placed into a database query unsafely, letting an attacker change the query's logic to read or modify data.
On the examThe primary fix is parameterised queries (prepared statements); input validation and least-privilege database accounts are supporting controls.
Don’t confuse with Command Injection
- SteganographySystem
Hiding data inside another file - an image, audio clip or document - so the existence of the message is concealed, not just its content.
On the examSteganography conceals existence; encryption conceals content. Steganalysis is the detection discipline named in answers.
- Symmetric EncryptionCrypto
Encryption using a single shared secret key for both encryption and decryption. It is fast and suited to bulk data; AES is the standard example.
On the examThe weakness tested is key distribution. AES, DES and 3DES are symmetric; RSA and ECC are not.
Don’t confuse with Asymmetric Encryption
- TCP SYN ScanRecon
A half-open port scan: the scanner sends SYN, reads the reply and never completes the handshake. SYN/ACK means open, RST means closed.
On the examCalled 'stealth' or 'half-open' in questions. Know the reply logic cold, and that modern IDS still logs it despite the name.
Don’t confuse with Xmas Scan
- TrojanSystem
Malware disguised as legitimate software. It does not self-replicate; it relies on the user to install it and then delivers a hidden payload.
On the examDistinguish from worms (self-propagating) and viruses (attach to files). A 'free utility' carrying a backdoor is a trojan.
Don’t confuse with Rootkit
- Vulnerability ScanningRecon
Automated checking of systems against a database of known weaknesses and misconfigurations, producing a prioritised report without exploiting anything.
On the examScanning identifies; it does not prove exploitability. A credentialed scan gives more accurate results than an uncredentialed one.
Don’t confuse with CVSS
- WHOISRecon
A lookup service that returns domain registration records: registrar, dates, name servers and, where not privacy-protected, contact details.
On the examAsked which tool reveals a domain's registrar or name servers without touching the target? WHOIS. Registration privacy is the countermeasure.
- WPA3Wi-Fi Protected Access 3Wi-Fi
The current Wi-Fi security standard. WPA3-Personal replaces the pre-shared key handshake with SAE, which resists offline password guessing.
On the examAs the 'most secure' wireless option, WPA3 beats WPA2; WEP is broken and should never be the answer. SAE is the keyword.
- Xmas ScanRecon
A scan that sets the FIN, PSH and URG flags together. Against systems that follow the TCP RFC, a closed port answers with RST and an open port stays silent.
On the examFlag combinations appear directly. Windows hosts answer RST regardless, so results against Windows are unreliable - a favourite detail.
Don’t confuse with TCP SYN Scan
- XSSCross-Site ScriptingWeb
A flaw that lets attacker-supplied script run in another user's browser in the context of a trusted site. Types are stored, reflected and DOM-based.
On the examFixes are output encoding and a Content Security Policy. XSS abuses the user's trust in the site; CSRF abuses the site's trust in the user.
Don’t confuse with CSRF
- Zero-DayIntro
A vulnerability the vendor does not yet know about or has not patched, so no fix exists when it is first exploited. Signature-based tools cannot recognise it.
On the examWhen a question says no patch or signature exists, the defensive answer is behaviour-based detection, segmentation or compensating controls - not 'apply the latest update'.
Terms the exam loves to confuse
These six pairs produce many of the CEH questions where two options both sound plausible. Each card gives the single clue that decides it.
FootprintingGathering information about the organisation, often from public sources, without directly engaging its systems.
EnumerationActively connecting to target services to pull specific details such as user names, shares and service data.
The tellIf the activity makes a direct connection to the target and extracts named details, it is enumeration. Public-source research is footprinting.
IDSWatches traffic or host activity and raises alerts. It is typically out of band and never drops packets itself.
IPSSits inline, inspects traffic and actively blocks what it judges malicious, as well as alerting.
The tellThe verb decides it: 'detect' or 'alert' means IDS, 'prevent', 'block' or 'drop' means IPS. Inline placement also points to IPS.
XSSInjected script executes in another user's browser under the trusted site's origin.
CSRFThe victim's browser is tricked into sending an authenticated request the user never intended.
The tellIf attacker script runs in the page, it is XSS. If a forged request rides the victim's existing session with no script injected, it is CSRF.
ARP PoisoningForged ARP replies trick hosts into sending traffic for another IP to the attacker's MAC address.
MAC FloodingFake MAC addresses fill the switch's CAM table so it floods frames out of every port.
The tellTarget the hosts' ARP caches, fix with Dynamic ARP Inspection: ARP poisoning. Target the switch table, fix with port security: MAC flooding.
Evil TwinAn attacker-controlled access point broadcasting the same network name as a legitimate one to lure clients.
Rogue Access PointAn unauthorised access point physically connected to the organisation's own wired network.
The tellImpersonating a known SSID to capture clients is an evil twin. An unapproved device plugged into the internal network is a rogue AP.
Symmetric EncryptionOne shared secret key encrypts and decrypts. Fast, good for bulk data, but the key must be distributed securely.
Asymmetric EncryptionA public and private key pair. Slower, but solves key exchange and enables digital signatures.
The tellBulk data speed or a single shared key means symmetric. Key exchange, signatures or non-repudiation means asymmetric.
Acronym quick-scan
EC-Council does not publish an official acronym list for CEH, so this list collects the abbreviations that appear most often across the v13 modules and exam-style questions.
- ACLAccess Control List
- AESAdvanced Encryption Standard
- APTAdvanced Persistent Threat
- ARPAddress Resolution Protocol
- C2Command and Control
- CACertificate Authority
- CAMContent Addressable Memory
- CASBCloud Access Security Broker
- CIAConfidentiality, Integrity, Availability
- CRLCertificate Revocation List
- CSPContent Security Policy
- CSRFCross-Site Request Forgery
- CVECommon Vulnerabilities and Exposures
- CVSSCommon Vulnerability Scoring System
- DAIDynamic ARP Inspection
- DDoSDistributed Denial of Service
- DHCPDynamic Host Configuration Protocol
- DKIMDomainKeys Identified Mail
- DMARCDomain-based Message Authentication, Reporting and Conformance
- DMZDemilitarized Zone
- DNSDomain Name System
- DoSDenial of Service
- ECCElliptic Curve Cryptography
- EDREndpoint Detection and Response
- FTPFile Transfer Protocol
- HIDSHost-based Intrusion Detection System
- HTTPHypertext Transfer Protocol
- IaaSInfrastructure as a Service
- ICMPInternet Control Message Protocol
- ICSIndustrial Control System
- IDSIntrusion Detection System
- IoTInternet of Things
- IPSIntrusion Prevention System
- IPsecInternet Protocol Security
- LDAPLightweight Directory Access Protocol
- MACMedia Access Control
- MDMMobile Device Management
- MFAMulti-Factor Authentication
- MitMMan-in-the-Middle
- NIDSNetwork-based Intrusion Detection System
- NTPNetwork Time Protocol
- OCSPOnline Certificate Status Protocol
- OSINTOpen-Source Intelligence
- OTOperational Technology
- OWASPOpen Worldwide Application Security Project
- PaaSPlatform as a Service
- PKIPublic Key Infrastructure
- PLCProgrammable Logic Controller
- RARegistration Authority
- RATRemote Access Trojan
- RoERules of Engagement
- RSARivest-Shamir-Adleman
- SaaSSoftware as a Service
- SAESimultaneous Authentication of Equals
- SCADASupervisory Control and Data Acquisition
- SHASecure Hash Algorithm
- SIEMSecurity Information and Event Management
- SMBServer Message Block
- SMTPSimple Mail Transfer Protocol
- SNMPSimple Network Management Protocol
- SPFSender Policy Framework
- SQLiSQL Injection
- SSIDService Set Identifier
- SSLSecure Sockets Layer
- TLSTransport Layer Security
- TTLTime to Live
- VLANVirtual Local Area Network
- VPNVirtual Private Network
- WAFWeb Application Firewall
- WEPWired Equivalent Privacy
- WIPSWireless Intrusion Prevention System
- WPAWi-Fi Protected Access
- XSSCross-Site Scripting
How to make the terms stick
CEH rewards recognising a technique from a one-line description and matching it to its countermeasure, so study the terms in pairs.
- Learn each attack with its fixFor every attack term, write the single countermeasure the exam expects beside it: salting for rainbow tables, port security for MAC flooding, parameterised queries for SQL injection. Many questions simply ask for that pairing.
- Place every term in a phaseSort the terms into the five phases of hacking and the nine blueprint domains. Questions often ask which phase an activity belongs to, and the ordering sticks better once each term has a home.
- Practise in a legal labUse your own virtual lab or an authorised training range to see scans, captures and web flaws in action. Seeing a tool's output once makes its exam description instantly recognisable.
Knowing the word is not the same as answering the question
Knowing a definition is not the same as recognising it in a 125-question paper under time pressure. Practice questions test these terms in context, the way the 312-50 exam does.
App StoreGoogle PlayFree practice testCEH v13 exam pageFAQ
How many terms do I need to know for CEH v13?
There is no official count. The v13 course spans twenty modules and hundreds of tools and techniques, but most questions hinge on a few dozen core concepts - the phases of hacking, scan types, common web flaws, network attacks and cryptography basics. Master the terms in this glossary first, then extend to tool names from your course material.
Does the CEH exam ask for definitions directly?
Some questions do, but most describe a situation - a log entry, a symptom or an attacker's action - and ask you to name the technique or choose the countermeasure. That is why each card here includes how the exam uses the term, not just what it means.
Are CEH v13 terms different from v12?
The core vocabulary is largely the same. v13 adds emphasis on AI-assisted techniques across the phases, alongside updated cloud, container and OT content. The nine-domain blueprint structure carries over, so terms learned for v12 remain useful, but study from v13 material.
Is CEH vocabulary useful for other security exams?
Yes. Terms such as the CIA triad, IDS versus IPS, XSS versus CSRF, salting and PKI appear across Security+, CySA+ and CISSP. CEH frames them from the attacker's viewpoint, which makes it a useful companion to the defensive framing of those exams.
Sources
Scope and domain names on this page come from EC-Council’s published exam objectives; definitions are ours, written for exam prep:
- https://www.eccouncil.org/train-certify/certified-ethical-hacker-ceh/
- https://cert.eccouncil.org/wp-content/uploads/2024/04/CEH-Exam-Blueprint-v5.pdf
- https://owasp.org/www-project-top-ten/
- https://attack.mitre.org/
Checked September 30, 2026. Exam objectives are revised on the vendor’s schedule — if a term here is not in the current objectives, the objectives win.
