312-50V10 Exam Details

  • Exam Code
    :312-50V10
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :747 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-50V10 Online Questions & Answers

  • Question 481:

    Suppose your company has just passed a security risk assessment exercise. The results display that the risk of the breach in the main company application is 50%. Security staff has taken some measures and implemented the necessary controls. After that, another security risk assessment was performed showing that risk has decreased to 10%. The risk threshold for the application is 20%. Which of the following risk decisions will be the best for the project in terms of its successful continuation with the most business profit?

    A. Accept the risk
    B. Introduce more controls to bring risk to 0%
    C. Mitigate the risk
    D. Avoid the risk

  • Question 482:

    Which vital role does the U.S. Computer Security Incident Response Team (CSIRT) provide?

    A. Incident response services to any user, company, government agency, or organization in partnership with the Department of Homeland Security
    B. Maintenance of the nation's Internet infrastructure, builds out new Internet infrastructure, and decommissions old Internet infrastructure
    C. Registration of critical penetration testing for the Department of Homeland Security and public and private sectors
    D. Measurement of key vulnerability assessments on behalf of the Department of Defense (DOD) and State Department, as well as private sectors

  • Question 483:

    Bob, a system administrator at TPNQM SA, concluded one day that a DMZ is not needed if he properly configures the firewall to allow access just to servers/ports, which can have direct internet access, and block the access to workstations.

    Bob also concluded that DMZ makes sense just when a stateful firewall is available, which is not the case of TPNQM SA.

    In this context, what can you say?

    A. Bob can be right since DMZ does not make sense when combined with stateless firewalls
    B. Bob is partially right. He does not need to separate networks if he can create rules by destination IPs, one by one
    C. Bob is totally wrong. DMZ is always relevant when the company has internet servers and workstations
    D. Bob is partially right. DMZ does not make sense when a stateless firewall is available

  • Question 484:

    Which of the following is the BEST approach to prevent Cross-site Scripting (XSS) flaws?

    A. Use digital certificates to authenticate a server prior to sending data.
    B. Verify access right before allowing access to protected information and UI controls.
    C. Verify access right before allowing access to protected information and UI controls.
    D. Validate and escape all information sent to a server.

  • Question 485:

    What is not a PCI compliance recommendation?

    A. Limit access to card holder data to as few individuals as possible.
    B. Use encryption to protect all transmission of card holder data over any public network.
    C. Rotate employees handling credit card transactions on a yearly basis to different departments.
    D. Use a firewall between the public network and the payment card data.

  • Question 486:

    Which of the following is a serious vulnerability in the popular OpenSSL cryptographic software library? This weakness allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet.

    A. Heartbleed Bug
    B. POODLE
    C. SSL/TLS Renegotiation Vulnerability
    D. Shellshock

  • Question 487:

    A medium-sized healthcare IT business decides to implement a risk management strategy. Which of the following is NOT one of the five basic responses to risk?

    A. Delegate
    B. Avoid
    C. Mitigate
    D. Accept

  • Question 488:

    When you are getting information about a web server, it is very important to know the HTTP Methods (GET, POST, HEAD, PUT, DELETE, TRACE) that are available because there are two critical methods (PUT and DELETE). PUT can upload a file to the server and DELETE can delete a file from the server. You can detect all these methods (GET, POST, HEAD, PUT, DELETE, TRACE) using NMAP script engine.

    What nmap script will help you with this task?

    A. http-methods
    B. http enum
    C. http-headers
    D. http-git

  • Question 489:

    Which of the following act requires employer's standard national numbers to identify them on standard transactions?

    A. SOX
    B. HIPAA
    C. DMCA
    D. PCI-DSS

  • Question 490:

    An attacker has been successfully modifying the purchase price of items purchased on the company's web site. The security administrators verify the web server and Oracle database have not been compromised directly. They have also verified the Intrusion Detection System (IDS) logs and found no attacks that could have caused this. What is the mostly likely way the attacker has been able to modify the purchase price?

    A. By using SQL injection
    B. By changing hidden form values
    C. By using cross site scripting
    D. By utilizing a buffer overflow attack

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.