312-50V11 Exam Details

  • Exam Code
    :312-50V11
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v11)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :528 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-50V11 Online Questions & Answers

  • Question 301:

    Jude, a pen tester, examined a network from a hacker's perspective to identify exploits and vulnerabilities accessible to the outside world by using devices such as firewalls, routers, and servers. In this process, he also estimated the threat of network security attacks and determined the level of security of the corporate network.

    What is the type of vulnerability assessment that Jude performed on the organization?

    A. External assessment
    B. Passive assessment
    C. Host-based assessment
    D. Application assessment

  • Question 302:

    What is the main security service a cryptographic hash provides?

    A. Integrity and ease of computation
    B. Message authentication and collision resistance
    C. Integrity and collision resistance
    D. Integrity and computational in-feasibility

  • Question 303:

    Cross-site request forgery involves:

    A. A request sent by a malicious user from a browser to a server
    B. Modification of a request by a proxy between client and server
    C. A browser making a request to a server without the user's knowledge
    D. A server making a request to another server without the user's knowledge

  • Question 304:

    You are tasked to configure the DHCP server to lease the last 100 usable IP addresses in subnet to. 1.4.0/23. Which of the following IP addresses could be teased as a result of the new configuration?

    A. 210.1.55.200
    B. 10.1.4.254
    C. 10..1.5.200
    D. 10.1.4.156

  • Question 305:

    CyberTech Inc. recently experienced SQL injection attacks on its official website. The company appointed Bob, a security professional, to build and incorporate defensive strategies against such attacks. Bob adopted a practice whereby only a list of entities such as the data type, range, size, and value, which have been approved for secured access, is accepted. What is the defensive technique employed by Bob in the above scenario?

    A. Output encoding
    B. Enforce least privileges
    C. Whitelist validation
    D. Blacklist validation

  • Question 306:

    Geena, a cloud architect, uses a master component in the Kubernetes cluster architecture that scans newly generated pods and allocates a node to them. This component can also assign nodes based on factors such as the overall resource requirement, data locality, software/hardware/policy restrictions, and internal workload interventions.

    Which of the following master components is explained in the above scenario?

    A. Kube-controller-manager
    B. Kube-scheduler
    C. Kube-apiserver
    D. Etcd cluster

  • Question 307:

    What is a NULL scan?

    A. A scan in which all flags are turned off
    B. A scan in which certain flags are off
    C. A scan in which all flags are on
    D. A scan in which the packet size is set to zero
    E. A scan with an illegal packet size

  • Question 308:

    Which of the following is considered an exploit framework and has the ability to perform automated attacks on services, ports, applications and unpatched security flaws in a computer system?

    A. Wireshark
    B. Maltego
    C. Metasploit
    D. Nessus

  • Question 309:

    Scenario1:

    1.Victim opens the attacker's web site.

    2.Attacker sets up a web site which contains interesting and attractive content like 'Do you want to make $1000 in a day?'.

    3.Victim clicks to the interesting and attractive content URL.

    4.Attacker creates a transparent 'iframe' in front of the URL which victim attempts to click, so victim thinks that he/she clicks to the 'Do you want to make $1000 in a day?' URL but actually he/she clicks to the content or URL that exists in the

    transparent 'iframe' which is setup by the attacker.

    What is the name of the attack which is mentioned in the scenario?

    A. Session Fixation
    B. HTML Injection
    C. HTTP Parameter Pollution
    D. Clickjacking Attack

  • Question 310:

    When configuring wireless on his home router, Javik disables SSID broadcast. He leaves authentication "open" but sets the SSID to a 32-character string of random letters and numbers. What is an accurate assessment of this scenario from a security perspective?

    A. Since the SSID is required in order to connect, the 32-character string is sufficient to prevent brute-force attacks.
    B. Disabling SSID broadcast prevents 802.11 beacons from being transmitted from the access point, resulting in a valid setup leveraging "security through obscurity".
    C. It is still possible for a hacker to connect to the network after sniffing the SSID from a successful wireless association.
    D. Javik's router is still vulnerable to wireless hacking attempts because the SSID broadcast setting can be enabled using a specially crafted packet sent to the hardware address of the access point.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V11 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.