312-50V11 Exam Details

  • Exam Code
    :312-50V11
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v11)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :528 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-50V11 Online Questions & Answers

  • Question 461:

    What is GINA?

    A. Gateway Interface Network Application
    B. GUI Installed Network Application CLASS
    C. Global Internet National Authority (G-USA)
    D. Graphical Identification and Authentication DLL

  • Question 462:

    Dayn, an attacker, wanted to detect if any honeypots are installed in a target network. For this purpose, he used a time-based TCP fingerprinting method to validate the response to a normal computer and the response of a honeypot to a manual SYN request. Which of the following techniques is employed by Dayn to detect honeypots?

    A. Detecting honeypots running on VMware
    B. Detecting the presence of Honeyd honeypots
    C. Detecting the presence of Snort_inline honeypots
    D. Detecting the presence of Sebek-based honeypots

  • Question 463:

    The tools which receive event logs from servers, network equipment, and applications, and perform analysis and correlation on those logs, and can generate alarms for security relevant issues, are known as what?

    A. network Sniffer
    B. Vulnerability Scanner
    C. Intrusion prevention Server
    D. Security incident and event Monitoring

  • Question 464:

    What is not a PCI compliance recommendation?

    A. Use a firewall between the public network and the payment card data.
    B. Use encryption to protect all transmission of card holder data over any public network.
    C. Rotate employees handling credit card transactions on a yearly basis to different departments.
    D. Limit access to card holder data to as few individuals as possible.

  • Question 465:

    If a tester is attempting to ping a target that exists but receives no response or a response that states the destination is unreachable, ICMP may be disabled and the network may be using TCP. Which other option could the tester use to get a response from a host using TCP?

    A. Traceroute
    B. Hping
    C. TCP ping
    D. Broadcast ping

  • Question 466:

    What is the proper response for a NULL scan if the port is closed?

    A. SYN
    B. ACK
    C. FIN
    D. PSH
    E. RST
    F. No response

  • Question 467:

    Which of the following describes the characteristics of a Boot Sector Virus?

    A. Modifies directory table entries so that directory entries point to the virus code instead of the actual program.
    B. Moves the MBR to another location on the RAM and copies itself to the original location of the MBR.
    C. Moves the MBR to another location on the hard disk and copies itself to the original location of the MBR.
    D. Overwrites the original MBR and only executes the new virus code.

  • Question 468:

    An incident investigator asks to receive a copy of the event logs from all firewalls, proxy servers, and Intrusion Detection Systems (IDS) on the network of an organization that has experienced a possible breach of security. When the investigator attempts to correlate the information in all of the logs, the sequence of many of the logged events do not match up.

    What is the most likely cause?

    A. The network devices are not all synchronized.
    B. Proper chain of custody was not observed while collecting the logs.
    C. The attacker altered or erased events from the logs.
    D. The security breach was a false positive.

  • Question 469:

    What is the algorithm used by LM for Windows2000 SAM?

    A. MD4
    B. DES
    C. SHA
    D. SSL

  • Question 470:

    By using a smart card and pin, you are using a two-factor authentication that satisfies

    A. Something you are and something you remember
    B. Something you have and something you know
    C. Something you know and something you are
    D. Something you have and something you are

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V11 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.