This module covers the foundational concepts of ethical hacking, including the CIA triad, hacker classifications, penetration testing methodologies, and the five stages of hacking. These are the core principles every Certified Ethical Hacker must master.
The CEHStudy app carries 27 flashcards for Module 1 across 5 sections — open the Module 1 deck alongside this page.
Key Topics Covered
Information security overview and core principles
CIA triad: Confidentiality, Integrity, Availability
Penetration testing types: black box, grey box, white box, blind, double-blind
Red team vs blue team operations
Important Terms & Concepts
Hack value: A hacker's evaluation of whether a target is worth pursuing. High hack value examples include credit card data over names.
Vulnerability: A weakness that can compromise the system and be used for an attack (e.g., policy weaknesses, implementation errors).
Exploit: Code or technique that takes advantage of a vulnerability.
Zero-day attack: Exploiting a previously unknown vulnerability before a patch exists.
Window of Vulnerability (WOV): Time from vulnerability discovery until most systems are patched — often measured in days (e.g., 28 days).
Daisy chaining: Using one compromised device to access subsequent devices on the network.
Botnet: A network of infected machines controlled by attackers for malicious activities like DDoS.
Advanced Persistent Threat (APT): A stealthy, long-term threat actor targeting high-value organizations using sophisticated malware and low-and-slow data extraction.
Penetration Testing Methodologies
Black box: No prior knowledge — simulates external attack, more realistic but costlier
Grey box: Partial knowledge — balances realism and cost-effectiveness
White box: Full knowledge — most cost-effective for thorough testing
Blind test: Tester has no info; target knows about the test
Double-blind: Neither tester nor target knows — most reliable but expensive
How to Study This Module
Review all key terms before starting flashcard sessions
Focus on understanding the differences between hacker types and penetration testing approaches
Memorize the 5 stages of hacking in order: Reconnaissance → Scanning → Gaining Access → Maintaining Access → Clearing Tracks
Use the flashcard app to practice until you can answer every card confidently
Frequently Asked Questions
Is Module 1 important for the CEH exam? Yes. Introduction to Ethical Hacking is foundational — questions about the CIA triad, hacker types, and hacking stages appear on every CEH exam.
How many cards are in this module? Module 1 contains flashcards covering all 8 sections: Information Security Overview, CIA Triad, Functionality/Usability/Security Triangle, Document Types, Hacker Types, Hacking Stages, Security Threats, and Penetration Testing.
Introduction to Ethical Hacking is the foundational domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. It covers the CIA triad, hacker classifications, penetration testing methodologies, and the five stages of the hacking lifecycle. Module 1 accounts for about 5% of CEH v13 exam questions.
Key Concepts in Introduction to Ethical Hacking
CIA Triad: The three pillars of information security — Confidentiality (protecting data from unauthorized access), Integrity (ensuring data accuracy and completeness), and Availability (guaranteeing reliable access to systems).
Hacker Classification Taxonomy: Black hat (malicious), white hat (authorized), grey hat (ethically ambiguous), script kiddies, hacktivists, and state-sponsored threat actors — each carries different legal and operational implications.
The Five Stages of Hacking: A sequential attack methodology — Reconnaissance, Scanning and Enumeration, Gaining Access, Maintaining Access, and Covering Tracks (Clearing Logs).
Penetration Testing Engagement Models: Black box (zero knowledge), grey box (partial knowledge), and white box (full disclosure) testing define the scope and methodology of authorized security assessments.
Common Exam Mistakes in Module 1
Mixing the five stages of hacking with pentest phases: The attack's five stages run reconnaissance, scanning, gaining access, maintaining access, then covering tracks; a penetration test engagement runs preparation, assessment, and conclusion (post-assessment). Identify which ladder a scenario describes.
Adding instead of multiplying in risk math: Risk = Threats × Vulnerabilities × Impact (equivalently Consequence × Likelihood), and ALE = SLE × ARO. Adding these factors is wrong.
Treating vulnerability assessment as a penetration test: VA identifies and quantifies vulnerabilities across a broad surface; PT actively exploits specific ones to demonstrate business impact. When a scenario says "prove what an attacker could actually do," the answer is penetration testing, not VA.
Tools & Frameworks Used in Ethical Hacking
Module 1 is conceptual, but the exam still names these tools:
PTES (Penetration Testing Execution Standard): the seven-phase engagement standard, pre-engagement through reporting — the reference model for organizing an assessment
OSSTMM: open-source testing methodology with standardized metrics so results are measurable and comparable
NIST SP 800-115: US government guide to IT security testing, in planning, testing, and documentation phases
OWASP Testing Guide: web application assessment methodology for application-layer scope
Kali Linux: the penetration testing distribution used for hands-on practice; its layout is assumed at the CEH level
Metasploit: exploit framework whose modules map to the gaining-access and maintaining-access stages
Nmap: the first tool pointed at a target; dissected in full in Module 3
Worked Example: Estimating Annualized Loss Expectancy
An internet-facing finance portal runs an outdated SSL library with a known memory-corruption bug. The CISO estimates a single successful exploitation costs $25,000 in incident response and card re-issuance (the SLE), and such an attempt lands twice per year (ARO = 2).
Walk through: ALE = SLE × ARO = $25,000 × 2 = $50,000 per year — compare that figure, not a raw severity label, against control costs. The unpatched library is the vulnerability; the corrupting code is the exploit. Exploitation threatens confidentiality and integrity; discovery sits in the assessment phase of a penetration test.
How to Study Introduction to Ethical Hacking for the CEH v13 Exam
To study Module 1:
Review the key terms above, focusing on precise definitions of the CIA triad components
Practice with the flashcards above — hit 90%+ recall before moving to Module 2
Write a one-page summary mapping the five hacking stages to a public incident report or breach post-mortem
Frequently Asked Questions About Introduction to Ethical Hacking
What is the difference between a vulnerability and an exploit?
A vulnerability is a weakness that could be exploited (such as a misconfigured service or outdated software). An exploit is the specific code, technique, or sequence of actions that takes advantage of it. Expect scenarios asking you to tell the two apart.
Why is the CIA triad so heavily tested on the CEH exam?
The CIA triad (Confidentiality, Integrity, Availability) underpins all information security — every CEH domain, from network scanning to cryptography, protects one or more CIA properties. Knowing which property an attack threatens is tested across domains, not just Module 1.