312-50 Exam Details

  • Exam Code
    :312-50
  • Exam Name
    :Certified Ethical Hacker
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :765 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-50 Online Questions & Answers

  • Question 121:

    Why do you need to capture five to ten million packets in order to crack WEP with AirSnort?

    A. All IVs are vulnerable to attack
    B. Air Snort uses a cache of packets
    C. Air Snort implements the FMS attack and only encrypted packets are counted
    D. A majority of weak IVs transmitted by access points and wireless cards are not filtered by contemporary wireless manufacturers

  • Question 122:

    Bob reads an article about how insecure wireless networks can be. He gets approval from his management to implement a policy of not allowing any wireless devices on the network. What other steps does Bob have to take in order to successfully implement this? (Select 2 answer.)

    A. Train users in the new policy.
    B. Disable all wireless protocols at the firewall.
    C. Disable SNMP on the network so that wireless devices cannot be configured.
    D. Continuously survey the area for wireless devices.

  • Question 123:

    Exhibit: Given the following extract from the snort log on a honeypot, what do you infer from the attack?

    A. A new port was opened
    B. A new user id was created
    C. The exploit was successful
    D. The exploit was not successful

  • Question 124:

    In the context of Windows Security, what is a 'null' user?

    A. A user that has no skills
    B. An account that has been suspended by the admin
    C. A pseudo account that has no username and password
    D. A pseudo account that was created for security administration purpose

  • Question 125:

    An attacker is attempting to telnet into a corporation's system in the DMZ. The attacker doesn't want to get caught and is spoofing his IP address. After numerous tries he remains unsuccessful in connecting to the system. The attacker rechecks that the target system is actually listening on Port 23 and he verifies it with both nmap and hping2. He is still unable to connect to the target system.

    What is the most probable reason?

    A. The firewall is blocking port 23 to that system.
    B. He cannot spoof his IP and successfully use TCP.
    C. He needs to use an automated tool to telnet in.
    D. He is attacking an operating system that does not reply to telnet even when open.

  • Question 126:

    What is the proper response for a NULL scan if the port is closed?

    A. SYN
    B. ACK
    C. FIN
    D. PSH
    E. RST
    F. No response

  • Question 127:

    Rebecca is a security analyst and knows of a local root exploit that has the ability to enable local users to use available exploits to gain root privileges. This vulnerability exploits a condition in the Linux kernel within the execve() system call. There is no known workaround that exists for this vulnerability. What is the correct action to be taken by Rebecca in this situation as a recommendation to management?

    A. Rebecca should make a recommendation to disable the () system call
    B. Rebecca should make a recommendation to upgrade the Linux kernel promptly
    C. Rebecca should make a recommendation to set all child-process to sleep within the execve()
    D. Rebecca should make a recommendation to hire more system administrators to monitor all child processes to ensure that each child process can't elevate privilege

  • Question 128:

    What type of Virus is shown here?

    A. Cavity Virus
    B. Macro Virus
    C. Boot Sector Virus
    D. Metamorphic Virus
    E. Sparse Infector Virus

  • Question 129:

    Stephanie works as senior security analyst for a manufacturing company in Detroit. Stephanie manages network security throughout the organization. Her colleague Jason told her in confidence that he was able to see confidential corporate information posted on the external website http://www.jeansclothesman.com. He tries random URLs on the company's website and finds confidential information leaked over the web. Jason says this happened about a month ago. Stephanie visits the said URLs, but she finds nothing. She is very concerned about this, since someone should be held accountable if there was sensitive information posted on the website.

    Where can Stephanie go to see past versions and pages of a website?

    A. She should go to the web page Samspade.org to see web pages that might no longer be on the website
    B. If Stephanie navigates to Search.com; she will see old versions of the company website
    C. Stephanie can go to Archive.org to see past versions of the company website
    D. AddressPast.com would have any web pages that are no longer hosted on the company's website

  • Question 130:

    Sniffing is considered an active attack.

    A. True
    B. False

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.