312-50 Exam Details

  • Exam Code
    :312-50
  • Exam Name
    :Certified Ethical Hacker
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :765 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-50 Online Questions & Answers

  • Question 291:

    What is the key advantage of Session Hijacking?

    A. It can be easily done and does not require sophisticated skills.
    B. You can take advantage of an authenticated connection.
    C. You can successfully predict the sequence number generation.
    D. You cannot be traced in case the hijack is detected.

  • Question 292:

    Sandra is the security administrator of ABC.com. One day she notices that the ABC.com Oracle database server has been compromised and customer information along with financial data has been stolen. The financial loss will be estimated in millions of dollars if the database gets into the hands of competitors. Sandra wants to report this crime to the law enforcement agencies immediately. Which organization coordinates computer crime investigations throughout the United States?

    A. NDCA
    B. NICP
    C. CIRP
    D. NPC
    E. CIA

  • Question 293:

    You are sniffing as unprotected WiFi network located in a JonDonalds Cybercafe with Ethereal to capture hotmail e-mail traffic. You see lots of people using their laptops browsing the web while snipping brewed coffee from JonDonalds. You want to sniff their email message traversing the unprotected WiFi network.

    Which of the following ethereal filters will you configure to display only the packets with the hotmail messages?

    A. (http contains "hotmail") andand ( http contains "Reply-To")
    B. (http contains "e-mail" ) andand (http contains "hotmail")
    C. (http = "login.passport.com" ) andand (http contains "SMTP")
    D. (http = "login.passport.com" ) andand (http contains "POP3")

  • Question 294:

    Which FTP transfer mode is required for FTP bounce attack?

    A. Active Mode
    B. Passive Mode
    C. User Mode
    D. Anonymous Mode

  • Question 295:

    Which type of scan does not open a full TCP connection?

    A. Stealth Scan
    B. XMAS Scan
    C. Null Scan
    D. FIN Scan

  • Question 296:

    How does a denial-of-service attack work?

    A. A hacker tries to decipher a password by using a system, which subsequently crashes the network
    B. A hacker attempts to imitate a legitimate user by confusing a computer or even another person
    C. A hacker prevents a legitimate user (or group of users) from accessing a service
    D. A hacker uses every character, word, or letter he or she can think of to defeat authentication

  • Question 297:

    The following excerpt is taken from a honeyput log. The log captures activities across three days. There are several intrusion attempts; however, a few are successful. Study the log given below and answer the following question:

    (Note: The objective of this questions is to test whether the student has learnt about passive OS fingerprinting (which should tell them the OS from log captures):

    can they tell a SQL injection attack signature; can they infer if a user ID has been created by an attacker and whether they can read plain source destination entries from log entries.)

    What can you infer from the above log?

    A. The system is a windows system which is being scanned unsuccessfully.
    B. The system is a web application server compromised through SQL injection.
    C. The system has been compromised and backdoored by the attacker.
    D. The actual IP of the successful attacker is 24.9.255.53.

  • Question 298:

    SNMP is a protocol used to query hosts, servers and devices about performance or health status data. Hackers have used this protocol for a long time to gather great amount of information about remote hosts. Which of the following features makes this possible?

    A. It is susceptible to sniffing
    B. It uses TCP as the underlying protocol
    C. It is used by ALL devices on the market
    D. It uses a community string sent as clear text

  • Question 299:

    Which of the following built-in C/C++ functions you should avoid to prevent your program from buffer overflow attacks?

    A. strcpy()
    B. strcat()
    C. streadd()
    D. strscock()

  • Question 300:

    Which of the following tools are used for footprinting?(Choose four.

    A. Sam Spade
    B. NSLookup
    C. Traceroute
    D. Neotrace
    E. Cheops

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.