312-50 Exam Details

  • Exam Code
    :312-50
  • Exam Name
    :Certified Ethical Hacker
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :765 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-50 Online Questions & Answers

  • Question 571:

    Global deployment of RFC 2827 would help mitigate what classification of attack?

    A. Sniffing attack
    B. Denial of service attack
    C. Spoofing attack
    D. Reconnaissance attack
    E. Prot Scan attack

  • Question 572:

    What happens during a SYN flood attack?

    A. TCP connection requests floods a target machine is flooded with randomized source address and ports for the TCP ports.
    B. A TCP SYN packet, which is a connection initiation, is sent to a target machine, giving the target host's address as both source and destination, and is using the same port on the target host as both source and destination.
    C. A TCP packet is received with the FIN bit set but with no ACK bit set in the flags field.
    D. A TCP packet is received with both the SYN and the FIN bits set in the flags field.

  • Question 573:

    A Company security System Administrator is reviewing the network system log files. He notes the following: What should he assume has happened and what should he do about the situation?

    A. He should contact the attacker's ISP as soon as possible and have the connection disconnected.
    B. He should log the event as suspicious activity, continue to investigate, and take further steps according to site security policy.
    C. He should log the file size, and archive the information, because the router crashed.
    D. He should run a file system check, because the Syslog server has a self correcting file system problem.
    E. He should disconnect from the Internet discontinue any further unauthorized use, because an attack has taken place.

  • Question 574:

    Which of the following command line switch would you use for OS detection in Nmap?

    A. -D
    B. -O
    C. -P
    D. -X

  • Question 575:

    Bob waits near a secured door, holding a box. He waits until an employee walks up to the secured door and uses the special card in order to access the restricted area of the target company. Just as the employee opens the door, Bob walks up to the employee (still holding the box) and asks the employee to hold the door open so that he can enter. What is the best way to undermine the social engineering activity of tailgating?

    A. issue special cards to access secured doors at the company and provide a one-time only brief description of use of the special card
    B. to post a sign that states "no tailgating" next to the special card reader adjacent to the secured door
    C. setup a mock video camera next to the special card reader adjacent to the secured door
    D. to educate all of the employees of the company on best security practices on a recurring basis

  • Question 576:

    Exhibit: You have captured some packets in Ethereal. You want to view only packets sent from 10.0.0.22. What filter will you apply?

    A. ip = 10.0.0.22
    B. ip.src == 10.0.0.22
    C. ip.equals 10.0.0.22
    D. ip.address = 10.0.0.22

  • Question 577:

    Your boss is attempting to modify the parameters of a Web-based application in order to alter the SQL statements that are parsed to retrieve data from the database. What would you call such an attack?

    A. SQL Input attack
    B. SQL Piggybacking attack
    C. SQL Select attack
    D. SQL Injection attack

  • Question 578:

    Which tool/utility can help you extract the application layer data from each TCP connection from a log file into separate files?

    A. Snort
    B. argus
    C. TCPflow
    D. Tcpdump

  • Question 579:

    What command would you type to OS fingerprint a server using the command line?

    A. Option A
    B. Option B
    C. Option C
    D. Option D

  • Question 580:

    Matthew re-injects a captured wireless packet back onto the network. He does this hundreds of times within a second. The packet is correctly encrypted and Matthew assumes it is an ARP request packet. The wireless host responds with a

    stream of responses, all individually encrypted with different IVs.

    What is this attack most appropriately called?

    A. Spoof Attack
    B. Replay Attack
    C. Inject Attack
    D. Rebound Attack

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.