Exam Details

  • Exam Code
    :312-50
  • Exam Name
    :Ethical Hacker Certified
  • Certification
    :Certified Ethical Hacker
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :765 Q&As
  • Last Updated
    :May 15, 2024

EC-COUNCIL Certified Ethical Hacker 312-50 Questions & Answers

  • Question 11:

    Which of the following tools are used for footprinting?(Choose four.

    A. Sam Spade

    B. NSLookup

    C. Traceroute

    D. Neotrace

    E. Cheops

  • Question 12:

    You receive an email with the following message:

    Hello Steve,

    We are having technical difficulty in restoring user database record after the recent blackout. Your account data is corrupted. Please logon to the SuperEmailServices.com and change your password.

    http://[email protected]/support/logon.htm

    If you do not reset your password within 7 days, your account will be permanently disabled locking you out from our e-mail services.

    Sincerely,

    Technical Support

    SuperEmailServices

    From this e-mail you suspect that this message was sent by some hacker since you have been using their e-mail services for the last 2 years and they have never sent out an e-mail such as this. You also observe the URL in the message and

    confirm your suspicion about 0xde.0xad.0xbde.0xef which looks like hexadecimal numbers. You immediately enter the following at Windows 2000 command prompt:

    Ping 0xde.0xad.0xbe.0xef

    You get a response with a valid IP address.

    What is the obstructed IP address in the e-mail URL?

    A. 222.173.190.239

    B. 233.34.45.64

    C. 54.23.56.55

    D. 199.223.23.45

  • Question 13:

    A very useful resource for passively gathering information about a target company is:

    A. Host scanning

    B. Whois search

    C. Traceroute

    D. Ping sweep

  • Question 14:

    Your company trainee Sandra asks you which are the four existing Regional Internet Registry (RIR's)?

    A. APNIC, PICNIC, ARIN, LACNIC

    B. RIPE NCC, LACNIC, ARIN, APNIC

    C. RIPE NCC, NANIC, ARIN, APNIC

    D. RIPE NCC, ARIN, APNIC, LATNIC

  • Question 15:

    Snort has been used to capture packets on the network. On studying the packets, the penetration tester finds it to be abnormal. If you were the penetration tester, why would you find this abnormal? (Note: The student is being tested on concept learnt during passive OS fingerprinting, basic TCP/IP connection concepts and the ability to read packet signatures from a sniff dumo.) 05/20-17:06:45.061034 192.160.13.4:31337 -> 172.16.1.101:1 TCP TTL:44 TOS:0x10 ID:242 ***FRP** Seq: 0XA1D95 Ack: 0x53 Win: 0x400

    05/20-17:06:58.685879 192.160.13.4:31337 -> 172.16.1.101:1024 TCP TTL:44 TOS:0x10 ID:242 ***FRP** Seg: 0XA1D95 Ack: 0x53 Win: 0x400 What is odd about this attack? (Choose the most appropriate statement)

    A. This is not a spoofed packet as the IP stack has increasing numbers for the three flags.

    B. This is back orifice activity as the scan comes from port 31337.

    C. The attacker wants to avoid creating a sub-carrier connection that is not normally valid.

    D. There packets were created by a tool; they were not created by a standard IP stack.

  • Question 16:

    How does Traceroute map the route that a packet travels from point A to point B?

    A. It uses a TCP Timestamp packet that will elicit a time exceed in transit message.

    B. It uses a protocol that will be rejected at the gateways on its way to its destination.

    C. It manipulates the value of time to live (TTL) parameter packet to elicit a time exceeded in transit message.

    D. It manipulated flags within packets to force gateways into generating error messages.

  • Question 17:

    To what does "message repudiation" refer to what concept in the realm of email security?

    A. Message repudiation means a user can validate which mail server or servers a message was passed through.

    B. Message repudiation means a user can claim damages for a mail message that damaged their reputation.

    C. Message repudiation means a recipient can be sure that a message was sent from a particular person.

    D. Message repudiation means a recipient can be sure that a message was sent from a certain host.

    E. Message repudiation means a sender can claim they did not actually send a particular message.

  • Question 18:

    A Company security System Administrator is reviewing the network system log files. He notes the following: What should he assume has happened and what should he do about the situation?

    A. He should contact the attacker's ISP as soon as possible and have the connection disconnected.

    B. He should log the event as suspicious activity, continue to investigate, and take further steps according to site security policy.

    C. He should log the file size, and archive the information, because the router crashed.

    D. He should run a file system check, because the Syslog server has a self correcting file system problem.

    E. He should disconnect from the Internet discontinue any further unauthorized use, because an attack has taken place.

  • Question 19:

    You are footprinting an organization to gather competitive intelligence. You visit the company's website for contact information and telephone numbers but do not find it listed there. You know that they had the entire staff directory listed on their website 12 months ago but not it is not there.

    How would it be possible for you to retrieve information from the website that is outdated?

    A. Visit google's search engine and view the cached copy.

    B. Visit Archive.org web site to retrieve the Internet archive of the company's website.

    C. Crawl the entire website and store them into your computer.

    D. Visit the company's partners and customers website for this information.

  • Question 20:

    Which one of the following is defined as the process of distributing incorrect Internet Protocol (IP) addresses/names with the intent of diverting traffic?

    A. Network aliasing

    B. Domain Name Server (DNS) poisoning

    C. Reverse Address Resolution Protocol (ARP)

    D. Port scanning

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.