July 21, 2026
Elite Hacker Certification L1 — Crackthelab
Introduction to Ethical Hacking
By Niyazhnayakodi
4 min read
Introduction to Ethical Hacking
Task — 1
Ethical Hacking & Types of Hackers
What is Ethical Hacking?
Ethical hacking is the authorized practice of testing systems, networks, or applications to identify security weaknesses before malicious attackers exploit them. Ethical hacking is performed with written permission, defined scope, and responsible reporting.
What is Hacking?
Hacking is the process of identifying, analyzing, and exploiting vulnerabilities or weaknesses in systems, networks, applications, or devices to gain access, manipulate operations, or extract information.
Types of Hackers
Different hacker categories are defined by their intent, authorization, and methods.
White Hat Hacker
A White Hat Hacker is a cybersecurity professional who performs authorized security testing with written permission from the organization. Their goal is to identify and fix vulnerabilities before malicious attackers can exploit them. They follow defined scopes, ethical guidelines, and responsible disclosure practices. White Hats commonly work as penetration testers, security analysts, or consultants.
Black Hat Hacker
A Black Hat Hacker uses hacking techniques illegally for personal gain, financial profit, or disruption. They exploit vulnerabilities without authorization and often hide their identity to avoid detection. Common activities include ransomware attacks, phishing, data theft, and fraud. Their actions violate cyber laws and ethical standards.
Grey Hat Hacker
A Grey Hat Hacker operates between ethical and illegal boundaries by finding vulnerabilities without permission but usually without malicious intent. They may disclose security flaws publicly or report them directly to organizations. Although their intentions may not be harmful, their actions are still unauthorized. Grey Hat activities are not considered fully ethical.
Script Kiddie
A Script Kiddie is an inexperienced hacker who uses pre-made tools and scripts created by others. They usually lack deep technical knowledge and rely on automated software to perform attacks. Their motives often include curiosity, fun, ego, or peer recognition. Script kiddies commonly perform low-level attacks.
Hacktivist
A Hacktivist uses hacking skills to promote political, social, or ideological causes. Their attacks may include website defacement, data leaks, or DDoS attacks against governments or organizations. They are motivated by activism rather than financial gain. Despite their intentions, their actions are generally illegal.
State-Sponsored Hacker
A State-Sponsored Hacker is a highly skilled cyber operator supported by a government for espionage, sabotage, or intelligence gathering. These attackers target critical infrastructure, military systems, and organizations of national interest. They use advanced tools, malware, and long-term attack strategies. Such groups are often referred to as APTs (Advanced Persistent Threats).
Suicide Hacker
A Suicide Hacker performs cyber attacks without attempting to hide their identity or avoid consequences. They are often motivated by revenge, ideology, or the desire to cause maximum disruption. Unlike most attackers, they do not fear arrest or punishment. Their reckless behavior can make them highly dangerous.
Cybercriminal
A Cybercriminal is a professional attacker who conducts illegal cyber activities mainly for financial gain. They may operate individually or within organized crime groups. Common crimes include ransomware, banking fraud, identity theft, and selling stolen data. Cybercriminals often treat hacking as a business operation.
Insider Threat
An Insider Threat is a trusted individual such as an employee, contractor, or partner who misuses legitimate access to harm an organization. Insider threats may be intentional or accidental. Because insiders already have authorized access, they are difficult to detect. They can cause data leaks, sabotage, or financial loss.
Questions
Q1
What is the complete full form of the cybersecurity certification abbreviation CEH?
Your answer — certified ethical hacker
Q2
Which type of hacker commonly uses pre-made tools without understanding their internal working?
Your answer — script kiddie
Q3
Can ethical hackers legally exploit vulnerabilities during authorized penetration testing engagements?
Your answer — yes
Q4
Which hacker type performs cyber attacks mainly for political or social causes?
Your answer — hacktivist
Q5
Most cybercriminal organizations perform illegal activities primarily to generate financial profit online.
Your answer — true
Q6
Which hacker category frequently deploys ransomware attacks mainly for financial gain purposes?
Your answer — cybercriminal
Q7
Can Black Hat hackers legally perform unauthorized attacks against company systems worldwide?
Your answer — no
Q8
Which hacker type usually performs attacks without fearing punishment or legal consequences?
Your answer — suicide hacker
Q9
Scenario: A trusted employee intentionally leaks confidential company files to external attackers.
Your answer — insider threat
Q10
Can Grey Hat hackers legally perform testing activities without obtaining proper authorization beforehand?
Your answer — no
Q11
Which hacker category performs authorized security testing with official written permission?
Your answer — white hat
Q12
Which hacker type operates between ethical and illegal boundaries without malicious intentions?
Your answer — grey hat
Task 2
CIA Triad & Internet Layers
The CIA Triad
The three foundational principles of information security.
- Confidentiality — Ensures only authorized users can access information.
- Integrity — Ensures data remains accurate and unmodified.
- Availability — Ensures resources remain accessible when needed.
Internet Layers
These layers differ based on accessibility, indexing, and anonymity.
Surface Web
The Surface Web is the publicly accessible part of the internet that can be indexed and displayed by standard search engines like Google or Microsoft Bing.
Deep Web
The Deep Web refers to all online content that is not indexed by search engines and requires authentication, authorization, or direct access links.
Dark Web
The Dark Web is a small portion of the Deep Web that is intentionally hidden and accessible only through specialized software such as Tor Browser.
Questions
Q1
Which CIA Triad principle ensures that information remains accurate and unmodified?
Your answer — integrity
Q2
Which CIA Triad principle ensures unauthorized users cannot access sensitive information illegally?
Your answer — confidentiality
Q3
Within the CIA Triad, availability ensures authorized resources remain accessible when needed.
Your answer — true
Q4
Which internet layer contains publicly accessible websites indexed by major search engines?
Your answer — surface web
Q5
The Surface Web can be indexed and accessed using traditional search engines.
Your answer — true
Q6
The Deep Web usually requires authorization, credentials, or direct access links.
Your answer — true
Q7
Which internet layer commonly requires Tor Browser for anonymous user access?
Your answer — dark web
Q8
What is the official full form of the VPN?
Your answer — virtual private network
Q9
What cybersecurity term describes a weakness that attackers can potentially exploit successfully?
Your answer — vulnerability