312-50V12 Exam Details

  • Exam Code
    :312-50V12
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v12)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :596 Q&As
  • Last Updated
    :May 30, 2026

EC-COUNCIL 312-50V12 Online Questions & Answers

  • Question 231:

    In the context of Windows Security, what is a 'null' user?

    A. A user that has no skills
    B. An account that has been suspended by the admin
    C. A pseudo account that has no username and password
    D. A pseudo account that was created for security administration purpose

  • Question 232:

    Which of the following describes the characteristics of a Boot Sector Virus?

    A. Modifies directory table entries so that directory entries point to the virus code instead of the actual program.
    B. Moves the MBR to another location on the RAM and copies itself to the original location of the MBR.
    C. Moves the MBR to another location on the hard disk and copies itself to the original location of the MBR.
    D. Overwrites the original MBR and only executes the new virus code.

  • Question 233:

    Tony wants to integrate a 128-bit symmetric block cipher with key sizes of 128,192, or 256 bits into a software program, which involves 32 rounds of computational operations that include substitution and permutation operations on four 32-bit word blocks using 8-variable S-boxes with 4-bit entry and 4-bit exit. Which of the following algorithms includes all the above features and can be integrated by Tony into the software program?

    A. TEA
    B. CAST-128
    C. RC5
    D. serpent

  • Question 234:

    Sam, a web developer, was instructed to incorporate a hybrid encryption software program into a web application to secure email messages. Sam used an encryption software, which is a free implementation of the OpenPGP standard that uses both symmetric-key cryptography and asymmetric-key cryptography for improved speed and secure key exchange. What is the encryption software employed by Sam for securing the email messages?

    A. PGP
    B. S/MIME
    C. SMTP
    D. GPG

  • Question 235:

    A penetration tester was assigned to scan a large network range to find live hosts. The network is known for using strict TCP filtering rules on its firewall, which may obstruct common host discovery techniques. The tester needs a method that can bypass these firewall restrictions and accurately identify live systems. What host discovery technique should the tester use?

    A. UDP Ping Scan
    B. lCMP ECHO Ping Scan
    C. ICMP Timestamp Ping Scan
    D. TCP SYN Ping Scan

  • Question 236:

    Study the snort rule given below and interpret the rule.

    alert tcp any any --> 192.168.1.0/24 (content:"|00 01 86 a5|"; msG. "mountd access";)

    A. An alert is generated when a TCP packet is generated from any IP on the 192.168.1.0 subnet and destined to any IP on port 111
    B. An alert is generated when any packet other than a TCP packet is seen on the network and destined for the 192.168.1.0 subnet
    C. An alert is generated when a TCP packet is originated from port 111 of any IP address to the 192.168.1.0 subnet
    D. An alert is generated when a TCP packet originating from any IP address is seen on the network and destined for any IP address on the 192.168.1.0 subnet on port 111

  • Question 237:

    What is the first step for a hacker conducting a DNS cache poisoning (DNS spoofing) attack against an organization?

    A. The attacker queries a nameserver using the DNS resolver.
    B. The attacker makes a request to the DNS resolver.
    C. The attacker forges a reply from the DNS resolver.
    D. The attacker uses TCP to poison the ONS resofver.

  • Question 238:

    Ricardo has discovered the username for an application in his targets environment. As he has a limited amount of time, he decides to attempt to use a list of common passwords he found on the Internet. He compiles them into a list and then feeds that list as an argument into his password-cracking application, what type of attack is Ricardo performing?

    A. Known plaintext
    B. Password spraying
    C. Brute force
    D. Dictionary

  • Question 239:

    James is working as an ethical hacker at Technix Solutions. The management ordered James to discover how vulnerable its network is towards footprinting attacks. James took the help of an open-source framework for performing automated reconnaissance activities. This framework helped James in gathering information using free tools and resources. What is the framework used by James to conduct footprinting and reconnaissance activities?

    A. WebSploit Framework
    B. Browser Exploitation Framework
    C. OSINT framework
    D. SpeedPhish Framework

  • Question 240:

    What is the purpose of a demilitarized zone on a network?

    A. To scan all traffic coming through the DMZ to the internal network
    B. To only provide direct access to the nodes within the DMZ and protect the network behind it
    C. To provide a place to put the honeypot
    D. To contain the network devices you wish to protect

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V12 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.