312-50V12 Exam Details

  • Exam Code
    :312-50V12
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v12)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :596 Q&As
  • Last Updated
    :May 30, 2026

EC-COUNCIL 312-50V12 Online Questions & Answers

  • Question 161:

    You are a penetration tester working to test the user awareness of the employees of the client xyz. You harvested two employees' emails from some public sources and are creating a client-side backdoor to send it to the employees via email. Which stage of the cyber kill chain are you at?

    A. Reconnaissance
    B. Command and control
    C. Weaponization
    D. Exploitation

  • Question 162:

    A security analyst is investigating a potential network-level session hijacking incident. During the investigation, the analyst finds that the attacker has been using a technique in which they injected an authentic-looking reset packet using a spoofed source IP address and a guessed acknowledgment number. As a result, the victim's connection was reset. Which of the following hijacking techniques has the attacker most likely used?

    A. TCP/IP hijacking
    B. UDP hijacking
    C. RST hijacking
    D. Blind hijacking

  • Question 163:

    An attacker has installed a RAT on a host. The attacker wants to ensure that when a user attempts to go to "www.MyPersonalBank.com", the user is directed to a phishing site. Which file does the attacker need to modify?

    A. Boot.ini
    B. Sudoers
    C. Networks
    D. Hosts

  • Question 164:

    An organization has been experiencing intrusion attempts despite deploying an Intrusion Detection System (IDS) and Firewalls. As a Certified Ethical Hacker, you are asked to reinforce the intrusion detection process and recommend a better rule-based approach. The IDS uses Snort rules and the new recommended tool should be able to complement it. You suggest using YARA rules with an additional tool for rule generation. Which of the following tools would be the best choice for this purpose and why?

    A. AutoYara - Because it automates the generation of YARA rules from a set of malicious and benign files
    B. yarGen - Because it generates YARA rules from strings identified in malware files while removing strings that also appear in goodware files
    C. YaraRET - Because it helps in reverse engineering Trojans to generate YARA rules
    D. koodous - Because it combines social networking with antivirus signatures and YARA rules to detect malware

  • Question 165:

    What does the following command in netcat do? nc -l -u -p55555 < /etc/passwd

    A. logs the incoming connections to /etc/passwd file
    B. loads the /etc/passwd file to the UDP port 55555
    C. grabs the /etc/passwd file when connected to UDP port 55555
    D. deletes the /etc/passwd file when connected to the UDP port 55555

  • Question 166:

    Which of the following Google advanced search operators helps an attacker in gathering information about websites that are similar to a specified target URL?

    A. [inurl:]
    B. [related:]
    C. [info:]
    D. [site:]

  • Question 167:

    An attacker changes the profile information of a particular user (victim) on the target website. The attacker uses this string to update the victim's profile to a text file and then submit the data to the attacker's database.

    < iframe src=""http://www.vulnweb.com/updateif.php"" style=""display:none"" > < /iframe >

    What is this type of attack (that can use either HTTP GET or HTTP POST) called?

    A. Browser Hacking
    B. Cross-Site Scripting
    C. SQL Injection
    D. Cross-Site Request Forgery

  • Question 168:

    Morris, an attacker, wanted to check whether the target AP is in a locked state. He attempted using different utilities to identify WPS-enabled APs in the target wireless network. Ultimately, he succeeded with one special command-line utility. Which of the following command-line utilities allowed Morris to discover the WPS-enabled APs?

    A. wash
    B. ntptrace
    C. macof
    D. net View

  • Question 169:

    The network users are complaining because their system are slowing down. Further, every time they attempt to go a website, they receive a series of pop-ups with advertisements. What types of malware have the system been infected with?

    A. Virus
    B. Spyware
    C. Trojan
    D. Adware

  • Question 170:

    You are logged in as a local admin on a Windows 7 system and you need to launch the Computer Management Console from command line. Which command would you use?

    A. c:\compmgmt.msc
    B. c:\services.msc
    C. c:\ncpa.cp
    D. c:\gpedit

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V12 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.