Week 1: Ethical Hacking Foundations and Rules of Engagement
Week of Sun, Aug 23 · week closes Sat, Aug 29
This week's items
- Weekly Quiz 1points in Canvas
- Discussion Board 1points in Canvas
- Lab 1points in Canvas
Exact due times are in Canvas. Late assignments are NOT accepted. Complete all assignments before the due date.
Read this week
- TestOut Ethical Hacker Pro — Ch 1–3 — Commercial text; named here for reference.
- NIST Cybersecurity Framework — Getting Started — Free — covers the governance framework context of Ch 1.
Textbook chapters (TestOut EHP): CFAA — 18 U.S.C. § 1030
Know these cold
- The five phases of ethical hacking: reconnaissance, scanning, gaining access, maintaining access, and covering tracks — each phase has a defensive mirror in the security team's response cycle.
- Governance frameworks (NIST CSF, ISO 27001, COBIT) define the policies, standards, and procedures that ethical hackers assess during security audits.
- Threat actor classification by motivation: script kiddies (low skill, opportunistic), hacktivists (ideological), organized crime (financial), nation-states (espionage), and insiders (access-enabled misuse).
- The CIA triad — Confidentiality, Integrity, Availability — is the organizing principle for every security control and every vulnerability classification.
- Rules of Engagement are a legal contract: they define exactly which systems may be tested, what techniques are permitted, the testing window, and the reporting process.
- Responsible disclosure requires reporting a vulnerability to the affected vendor before public release — giving them time to develop and distribute a patch.
- Standards: Maryland Blueprint Pillar 3 · CEH v12 Domain 1 (Information Security and Ethical Hacking) · PGCC INT-2681 Outcomes 2, 3, 7, 8.
Meerk's quiz — open the Week 1 gate
10 questions, no time limit. 85% on your first attempt in a 24-hour window opens the gate. Retakes inside the window are practice — they help you learn, they don't count. Work alone; the point is to know it, not to have seen it.
Dinner Table Question
Ask at home: A friend asks you to 'check if their ex's email is secure.' What are the legal and ethical problems with this request?
En español: Un amigo te pide que 'verifiques si el correo de su ex es seguro.' ¿Cuáles son los problemas legales y éticos de esta petición?