312-50V11 Exam Details

  • Exam Code
    :312-50V11
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v11)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :528 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-50V11 Online Questions & Answers

  • Question 201:

    User A is writing a sensitive email message to user B outside the local network. User A has chosen to use PKI to secure his message and ensure only user B can read the sensitive email. At what layer of the OSI layer does the encryption and decryption of the message take place?

    A. Application
    B. Transport
    C. Session
    D. Presentation

  • Question 202:

    You are working as a Security Analyst in a company XYZ that owns the whole subnet range of 23.0.0.0/8 and 192.168.0.0/8.

    While monitoring the data, you find a high number of outbound connections. You see that IP's owned by XYZ (Internal) and private IP's are communicating to a Single Public IP. Therefore, the Internal IP's are sending data to the Public IP.

    After further analysis, you find out that this Public IP is a blacklisted IP, and the internal communicating devices are compromised.

    What kind of attack does the above scenario depict?

    A. Botnet Attack
    B. Spear Phishing Attack
    C. Advanced Persistent Threats
    D. Rootkit Attack

  • Question 203:

    The security administrator of ABC needs to permit Internet traffic in the host 10.0.0.2 and UDP traffic in the host

    10.0.0.3. He also needs to permit all FTP traffic to the rest of the network and deny all other traffic. After he applied his ACL configuration in the router, nobody can access the ftp, and the permitted hosts cannot access the Internet. According to the next configuration, what is happening in the network?

    access-list 102 deny tcp any any access-list 104 permit udp host 10.0.0.3 any access-list 110 permit tcp host 10.0.0.2 eq www any access-list 108 permit tcp any eq ftp any

    A. The ACL 104 needs to be first because is UDP
    B. The first ACL is denying all TCP traffic and the other ACLs are being ignored by the router
    C. The ACL for FTP must be before the ACL 110
    D. The ACL 110 needs to be changed to port 80

  • Question 204:

    Elliot is in the process of exploiting a web application that uses SQL as a back-end database. He's determined that the application is vulnerable to SQL injection, and has introduced conditional timing delays into injected queries to determine whether they are successful. What type of SQL injection is Elliot most likely performing?

    A. Error-based SQL injection
    B. Blind SQL injection
    C. Union-based SQL injection
    D. NoSQL injection

  • Question 205:

    You need to deploy a new web-based software package for your organization. The package requires three separate servers and needs to be available on the Internet. What is the recommended architecture in terms of server placement?

    A. All three servers need to be placed internally
    B. A web server facing the Internet, an application server on the internal network, a database server on the internal network
    C. A web server and the database server facing the Internet, an application server on the internal network
    D. All three servers need to face the Internet so that they can communicate between themselves

  • Question 206:

    What is the minimum number of network connections in a multihomed firewall?

    A. 3
    B. 5
    C. 4
    D. 2

  • Question 207:

    James is working as an ethical hacker at Technix Solutions. The management ordered James to discover how vulnerable its network is towards footprinting attacks. James took the help of an open-source framework for performing automated reconnaissance activities. This framework helped James in gathering information using free tools and resources. What is the framework used by James to conduct footprinting and reconnaissance activities?

    A. WebSploit Framework
    B. Browser Exploitation Framework
    C. OSINT framework
    D. SpeedPhish Framework

  • Question 208:

    You are a Network Security Officer. You have two machines. The first machine (192.168.0.99) has snort installed, and the second machine (192.168.0.150) has kiwi syslog installed. You perform a syn scan in your network, and you notice that kiwi syslog is not receiving the alert message from snort. You decide to run wireshark in the snort machine to check if the messages are going to the kiwi syslog machine. What Wireshark filter will show the connections from the snort machine to kiwi syslog machine?

    A. tcp.srcport= = 514 andand ip.src= = 192.168.0.99
    B. tcp.srcport= = 514 andand ip.src= = 192.168.150
    C. tcp.dstport= = 514 andand ip.dst= = 192.168.0.99
    D. tcp.dstport= = 514 andand ip.dst= = 192.168.0.150

  • Question 209:

    You work for Acme Corporation as Sales Manager. The company has tight network security restrictions. You are trying to steal data from the company's Sales database (Sales.xls) and transfer them to your home computer. Your company filters and monitors traffic that leaves from the internal network to the Internet. How will you achieve this without raising suspicion?

    A. Encrypt the Sales.xls using PGP and e-mail it to your personal gmail account
    B. Package the Sales.xls using Trojan wrappers and telnet them back your home computer
    C. You can conceal the Sales.xls database in another file like photo.jpg or other files and send it out in an innocent looking email or file transfer using Steganography techniques
    D. Change the extension of Sales.xls to sales.txt and upload them as attachment to your hotmail account

  • Question 210:

    Which access control mechanism allows for multiple systems to use a central authentication server (CAS) that permits users to authenticate once and gain access to multiple systems?

    A. Role Based Access Control (RBAC)
    B. Discretionary Access Control (DAC)
    C. Single sign-on
    D. Windows authentication

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V11 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.