Exam Details

  • Exam Code
    :312-50
  • Exam Name
    :Certified Ethical Hacker
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :614 Q&As
  • Last Updated
    :May 28, 2025

EC-COUNCIL EC-COUNCIL Certifications 312-50 Questions & Answers

  • Question 201:

    _________ is a tool that can hide processes from the process list, can hide files, registry entries, and intercept keystrokes.

    A. Trojan

    B. RootKit

    C. DoS tool

    D. Scanner

    E. Backdoor

  • Question 202:

    Exhibit

    You receive an e-mail with the message displayed in the exhibit. From this e-mail you suspect that this message was sent by some hacker since you have using their e- mail services for the last 2 years and they never sent out an e-mail as

    this. You also observe the URL in the message and confirm your suspicion about 340590649. You immediately enter the following at the Windows 2000 command prompt.

    ping 340590649

    You get a response with a valid IP address. What is the obstructed IP address in the e-mail URL?

    A. 192.34.5.9

    B. 10.0.3.4

    C. 203.2.4.5

    D. 199.23.43.4

  • Question 203:

    This kind of password cracking method uses word lists in combination with numbers and special characters:

    A. Hybrid

    B. Linear

    C. Symmetric

    D. Brute Force

  • Question 204:

    Which of the following is the primary objective of a rootkit?

    A. It opens a port to provide an unauthorized service

    B. It creates a buffer overflow

    C. It replaces legitimate programs

    D. It provides an undocumented opening in a program

  • Question 205:

    Which of the following LM hashes represent a password of less than 8 characters? (Select 2)

    A. BA810DBA98995F1817306D272A9441BB

    B. 44EFCE164AB921CQAAD3B435B51404EE

    C. 0182BD0BD4444BF836077A718CCDF409

    D. CEC52EB9C8E3455DC2265B23734E0DAC

    E. B757BF5C0D87772FAAD3B435B51404EE

    F. E52CAC67419A9A224A3B108F3FA6CB6D

  • Question 206:

    E-mail scams and mail fraud are regulated by which of the following?

    A. 18 U.S.C. par. 1030 Fraud and Related activity in connection with Computers

    B. 18 U.S.C. par. 1029 Fraud and Related activity in connection with Access Devices

    C. 18 U.S.C. par. 1362 Communication Lines, Stations, or Systems

    D. 18 U.S.C. par. 2510 Wire and Electronic Communications Interception and Interception of Oral Communication

  • Question 207:

    What is the algorithm used by LM for Windows2000 SAM ?

    A. MD4

    B. DES

    C. SHA

    D. SSL

  • Question 208:

    In the context of password security, a simple dictionary attack involves loading a dictionary file (a text file full of dictionary words) into a cracking application such as L0phtCrack or John the Ripper, and running it against user accounts located by the application. The larger the word and word fragment selection, the more effective the dictionary attack is. The brute force method is the most inclusive, although slow. It usually tries every possible letter and number combination in its automated exploration.

    If you would use both brute force and dictionary methods combined together to have variation of words, what would you call such an attack?

    A. Full Blown

    B. Thorough

    C. Hybrid

    D. BruteDics

  • Question 209:

    You are attempting to crack LM Manager hashed from Windows 2000 SAM file. You will be using LM Brute force hacking tool for decryption. What encryption algorithm will you be decrypting?

    A. MD4

    B. DES

    C. SHA

    D. SSL

  • Question 210:

    A user on your Windows 2000 network has discovered that he can use L0phtcrack to sniff the SMB exchanges which carry user logons. The user is plugged into a hub with 23 other systems. However, he is unable to capture any logons though he knows that other users are logging in.

    What do you think is the most likely reason behind this?

    A. There is a NIDS present on that segment.

    B. Kerberos is preventing it.

    C. Windows logons cannot be sniffed.

    D. L0phtcrack only sniffs logons to web servers.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.