312-50 Exam Details

  • Exam Code
    :312-50
  • Exam Name
    :Certified Ethical Hacker
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :765 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-50 Online Questions & Answers

  • Question 351:

    Which of the following Nmap commands would be used to perform a stack fingerprinting?

    A. Nmap -O -p80
    B. Nmap -hU -Q
    C. Nmap -sT -p
    D. Nmap -u -o -w2
    E. Nmap -sS -0p target

  • Question 352:

    Which of the following represents the initial two commands that an IRC client sends to join an IRC network?

    A. USER, NICK
    B. LOGIN, NICK
    C. USER, PASS
    D. LOGIN, USER

  • Question 353:

    Which of the following is true of the wireless Service Set ID (SSID)? (Select all that apply.)

    A. Identifies the wireless network
    B. Acts as a password for network access
    C. Should be left at the factory default setting
    D. Not broadcasting the SSID defeats NetStumbler and other wireless discovery tools

  • Question 354:

    Hayden is the network security administrator for her company, a large finance firm based in Miami. Hayden just returned from a security conference in Las Vegas where they talked about all kinds of old and new security threats; many of which she did not know of. Hayden is worried about the current security state of her company's network so she decides to start scanning the network from an external IP address. To see how some of the hosts on her network react, she sends out SYN packets to an IP range. A number of IPs responds with a SYN/ACK response. Before the connection is established she sends RST packets to those hosts to stop the session. She does this to see how her intrusion detection system will log the traffic. What type of scan is Hayden attempting here?

    A. Hayden is attempting to find live hosts on her company's network by using an XMAS scan
    B. She is utilizing a SYN scan to find live hosts that are listening on her network
    C. The type of scan, she is using is called a NULL scan
    D. Hayden is using a half-open scan to find live hosts on her network

  • Question 355:

    The GET method should never be used when sensitive data such as credit card is being sent to a CGI program. This is because any GET command will appear in the URL, and will be logged by any servers. For example, let's say that you've entered your credit card information into a form that uses the GET method. The URL may appear like this:

    https://www.xsecurity-bank.com/creditcard.asp?cardnumber=453453433532234

    The GET method appends the credit card number to the URL. This means that anyone with access to a server log will be able to obtain this information. How would you protect from this type of attack?

    A. Never include sensitive information in a script
    B. Use HTTPS SSLv3 to send the data instead of plain HTTPS
    C. Replace the GET with POST method when sending data
    D. Encrypt the data before you send using GET method

  • Question 356:

    SYN Flood is a DOS attack in which an attacker deliberately violates the three-way handshake and opens a large number of half-open TCP connections.

    The signature for SYN Flood attack is:

    A. The source and destination address having the same value.
    B. The source and destination port numbers having the same value.
    C. A large number of SYN packets appearing on a network without the corresponding reply packets.
    D. A large number of SYN packets appearing on a network with the corresponding reply packets.

  • Question 357:

    One of the most common and the best way of cracking RSA encryption is to being to derive the two prime numbers, which are used in the RSA PKI mathematical process. If the two numbers p and q are discovered through a _________________ process, then the private key can be derived.

    A. Factorization
    B. Prime Detection
    C. Hashing
    D. Brute-forcing

  • Question 358:

    Ivan is auditing a corporate website. Using Winhex, he alters a cookie as shown below.

    Before Alteration: Cookie: lang=en-us; ADMIN=no; y=1 ; time=10:30GMT ;

    After Alteration: Cookie: lang=en-us; ADMIN=yes; y=1 ; time=12:30GMT ;

    What attack is being depicted here?

    A. Cookie Stealing
    B. Session Hijacking
    C. Cross Site Scripting
    D. Parameter Manipulation

  • Question 359:

    Which of the following systems would not respond correctly to an nmap XMAS scan?

    A. Windows 2000 Server running IIS 5
    B. Any Solaris version running SAMBA Server
    C. Any version of IRIX
    D. RedHat Linux 8.0 running Apache Web Server

  • Question 360:

    Neil is a network administrator working in Istanbul. Neil wants to setup a protocol analyzer on his network that will receive a copy of every packet that passes through the main office switch. What type of port will Neil need to setup in order to accomplish this?

    A. Neil will have to configure a Bridged port that will copy all packets to the protocol analyzer.
    B. Neil will need to setup SPAN port that will copy all network traffic to the protocol analyzer.
    C. He will have to setup an Ether channel port to get a copy of all network traffic to the analyzer.
    D. He should setup a MODS port which will copy all network traffic.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.