312-50 Exam Details

  • Exam Code
    :312-50
  • Exam Name
    :Certified Ethical Hacker
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :765 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-50 Online Questions & Answers

  • Question 241:

    A particular database threat utilizes a SQL injection technique to penetrate a target system. How would an attacker use this technique to compromise a database?

    A. An attacker uses poorly designed input validation routines to create or alter SQL commands to gain access to unintended data or execute commands of the database
    B. An attacker submits user input that executes an operating system command to compromise a target system
    C. An attacker gains control of system to flood the target system with requests, preventing legitimate users from gaining access
    D. An attacker utilizes an incorrect configuration that leads to access with higher-than-expected privilege of the database

  • Question 242:

    If you come across a sheepdip machine at your client's site, what should you do?

    A. A sheepdip computer is used only for virus-checking.
    B. A sheepdip computer is another name for a honeypot
    C. A sheepdip coordinates several honeypots.
    D. A sheepdip computers defers a denial of service attack.

  • Question 243:

    Which of the following activities will NOT be considered as passive footprinting?

    A. Go through the rubbish to find out any information that might have been discarded.
    B. Search on financial site such as Yahoo Financial to identify assets.
    C. Scan the range of IP address found in the target DNS database.
    D. Perform multiples queries using a search engine.

  • Question 244:

    Which of the following is an attack in which a secret value like a hash is captured and then reused at a later time to gain access to a system without ever decrypting or decoding the hash.

    A. Replay Attacks
    B. Brute Force Attacks
    C. Cryptography Attacks
    D. John the Ripper Attacks

  • Question 245:

    What type of attack changes its signature and/or payload to avoid detection by antivirus programs?

    A. Polymorphic
    B. Rootkit
    C. Boot sector
    D. File infecting

  • Question 246:

    While examining a log report you find out that an intrusion has been attempted by a machine whose IP address is displayed as 0xde.0xad.0xbe.0xef. It looks to you like a hexadecimal number. You perform a ping 0xde.0xad.0xbe.0xef. Which of the following IP addresses will respond to the ping and hence will likely be responsible for the the intrusion ?

    A. 192.10.25.9
    B. 10.0.3.4
    C. 203.20.4.5
    D. 222.273.290.239
    E. 222.173.290.239

  • Question 247:

    E-mail scams and mail fraud are regulated by which of the following?

    A. 18 U.S.C. par. 1030 Fraud and Related activity in connection with Computers
    B. 18 U.S.C. par. 1029 Fraud and Related activity in connection with Access Devices
    C. 18 U.S.C. par. 1362 Communication Lines, Stations, or Systems
    D. 18 U.S.C. par. 2510 Wire and Electronic Communications Interception and Interception of Oral Communication

  • Question 248:

    Simon is security analyst writing signatures for a Snort node he placed internally that captures all mirrored traffic from his border firewall. From the following signature, what will Snort look for in the payload of the suspected packets?

    alert tcp $EXTERNAL_NET any -> $HOME_NET 27374 (msg: "BACKDOOR SIG - SubSseven 22";flags: A+; content: "|0d0a5b52504c5d3030320d0a|"; reference:arachnids,485;) alert

    A. The payload of 485 is what this Snort signature will look for.
    B. Snort will look for 0d0a5b52504c5d3030320d0a in the payload.
    C. Packets that contain the payload of BACKDOOR SIG - SubSseven 22 will be flagged.
    D. From this snort signature, packets with HOME_NET 27374 in the payload will be flagged.

  • Question 249:

    You have successfully brute forced basic authentication configured on a Web Server using Brutus hacking tool. The username/password is "Admin" and "Bettlemani@". You logon to the system using the brute forced password and plant

    backdoors and rootkits.

    After downloading various sensitive documents from the compromised machine, you proceed to clear the log files to hide your trace..

    Which event log located at C:\Windows\system32\config contains the trace of your brute force attempts?

    A. AppEvent.Evt
    B. SecEvent.Evt
    C. SysEvent.Evt
    D. WinEvent.Evt

  • Question 250:

    NTP allows you to set the clocks on your systems very accurately, to within 100ms and sometimes- even 10ms. Knowing the exact time is extremely important for enterprise security. Various security protocols depend on an accurate source of time information in order to prevent "playback" attacks. These protocols tag their communications with the current time, to prevent attackers from replaying the same communications, e.g., a login/password interaction or even an entire communication, at a later date. One can circumvent this tagging, if the clock can be set back to the time the communication was recorded. An attacker attempts to try corrupting the clocks on devices on your network. You run Wireshark to detect the NTP traffic to see if there are any irregularities on the network. What port number you should enable in Wireshark display filter to view NTP packets?

    A. TCP Port 124
    B. UDP Port 125
    C. UDP Port 123
    D. TCP Port 126

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.