312-50 Exam Details

  • Exam Code
    :312-50
  • Exam Name
    :Certified Ethical Hacker
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :765 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-50 Online Questions & Answers

  • Question 491:

    Which of the following buffer overflow exploits are related to Microsoft IIS web server? (Choose three)

    A. Internet Printing Protocol (IPP) buffer overflow
    B. Code Red Worm
    C. Indexing services ISAPI extension buffer overflow
    D. NeXT buffer overflow

  • Question 492:

    Peter is a Linux network admin. As a knowledgeable security consultant, he turns to you to look for help on a firewall. He wants to use Linux as his firewall and use the latest freely available version that is offered. What do you recommend? Select the best answer.

    A. Ipchains
    B. Iptables
    C. Checkpoint FW for Linux
    D. Ipfwadm

  • Question 493:

    An attacker has been successfully modifying the purchase price of items purchased at a web site. The security administrators verify the web server and Oracle database have not been compromised directly. They have also verified the IDS logs and found no attacks that could have caused this. What is the mostly likely way the attacker has been able to modify the price?

    A. By using SQL injection
    B. By using cross site scripting
    C. By changing hidden form values in a local copy of the web page
    D. There is no way the attacker could do this without directly compromising either the web server or the database

  • Question 494:

    Web servers often contain directories that do not need to be indexed. You create a text file with search engine indexing restrictions and place it on the root directory of the Web Server.

    User-agent: * Disallow: /images/ Disallow: /banners/ Disallow: /Forms/ Disallow: /Dictionary/ Disallow: /_borders/ Disallow: /_fpclass/ Disallow: /_overlay/ Disallow: /_private/ Disallow: /_themes/

    What is the name of this file?

    A. robots.txt
    B. search.txt
    C. blocklist.txt
    D. spf.txt

  • Question 495:

    Daryl is a network administrator working for Dayton Technologies. Since Daryl's background is in web application development, many of the programs and applications his company uses are web-based. Daryl sets up a simple forms-based logon screen for all the applications he creates so they are secure.

    The problem Daryl is having is that his users are forgetting their passwords quite often and sometimes he does not have the time to get into his applications and change the passwords for them. Daryl wants a tool or program that can monitor web-based passwords and notify him when a password has been changed so he can use that tool whenever a user calls him and he can give them their password right then.

    What tool would work best for Daryl's needs?

    A. Password sniffer
    B. L0phtcrack
    C. John the Ripper
    D. WinHttrack

  • Question 496:

    You are doing IP spoofing while you scan your target. You find that the target has port 23 open.Anyway you are unable to connect. Why?

    A. A firewall is blocking port 23
    B. You cannot spoof + TCP
    C. You need an automated telnet tool
    D. The OS does not reply to telnet even if port 23 is open

  • Question 497:

    Yancey is a network security administrator for a large electric company. This company provides power for over 100,000 people in Las Vegas. Yancey has worked for his company for over 15 years and has become very successful. One day, Yancey comes in to work and finds out that the company will be downsizing and he will be out of a job in two weeks. Yancey is very angry and decides to place logic bombs, viruses, Trojans, and backdoors all over the network to take down the company once he has left. Yancey does not care if his actions land him in jail for 30 or more years, he just wants the company to pay for what they are doing to him. What would Yancey be considered?

    A. Yancey would be considered a Suicide Hacker
    B. Since he does not care about going to jail, he would be considered a Black Hat
    C. Because Yancey works for the company currently; he would be a White Hat
    D. Yancey is a Hacktivist Hacker since he is standing up to a company that is downsizing

  • Question 498:

    What are twp types of ICMP code used when using the ping command?

    A. It uses types 0 and 8.
    B. It uses types 13 and 14.
    C. It uses types 15 and 17.
    D. The ping command does not use ICMP but uses UDP.

  • Question 499:

    _____ is a type of symmetric-key encryption algorithm that transforms a fixed-length block of plaintext (unencrypted text) data into a block of ciphertext (encrypted text) data of the same length.

    A. Bit Cipher
    B. Hash Cipher
    C. Block Cipher
    D. Stream Cipher

  • Question 500:

    How do you defend against Privilege Escalation?

    A. Use encryption to protect sensitive data
    B. Restrict the interactive logon privileges
    C. Run services as unprivileged accounts
    D. Allow security settings of IE to zero or Low
    E. Run users and applications on the least privileges

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.