312-50V12 Exam Details

  • Exam Code
    :312-50V12
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v12)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :596 Q&As
  • Last Updated
    :May 30, 2026

EC-COUNCIL 312-50V12 Online Questions & Answers

  • Question 301:

    John the Ripper is a technical assessment tool used to test the weakness of which of the following?

    A. Passwords
    B. File permissions
    C. Firewall rulesets
    D. Usernames

  • Question 302:

    You are a security officer of a company. You had an alert from IDS that indicates that one PC on your Intranet is connected to a blacklisted IP address (C2 Server) on the Internet. The IP address was blacklisted just before the alert. You are starting an investigation to roughly analyze the severity of the situation. Which of the following is appropriate to analyze?

    A. IDS log
    B. Event logs on domain controller
    C. Internet Firewall/Proxy log.
    D. Event logs on the PC

  • Question 303:

    Which of the following tools are used for enumeration? (Choose three.)

    A. SolarWinds
    B. USER2SID
    C. Cheops
    D. SID2USER
    E. DumpSec

  • Question 304:

    Within the context of Computer Security, which of the following statements describes Social Engineering best?

    A. Social Engineering is the act of publicly disclosing information
    B. Social Engineering is the means put in place by human resource to perform time accounting
    C. Social Engineering is the act of getting needed information from a person rather than breaking into a system
    D. Social Engineering is a training program within sociology studies

  • Question 305:

    Under what conditions does a secondary name server request a zone transfer from a primary name server?

    A. When a primary SOA is higher that a secondary SOA
    B. When a secondary SOA is higher that a primary SOA
    C. When a primary name server has had its service restarted
    D. When a secondary name server has had its service restarted
    E. When the TTL falls to zero

  • Question 306:

    Richard, an attacker, targets an MNC In this process, he uses a footprinting technique to gather as much information as possible. Using this technique, he gathers domain information such as the target domain name, contact details of its

    owner, expiry date, and creation date.

    With this information, he creates a map of the organization's network and misleads domain owners with social engineering to obtain internal details of its network. What type of footprinting technique is employed by Richard?

    A. VPN footprinting
    B. Email footprinting
    C. VoIP footprinting
    D. Whois footprinting

  • Question 307:

    A cyber attacker has initiated a series of activities against a high-profile organization following the Cyber Kill Chain Methodology. The attacker is presently in the "Delivery" stage. As an Ethical Hacker, you are trying to anticipate the

    adversary's next move.

    What is the most probable subsequent action from the attacker based on the Cyber Kill Chain Methodology?

    A. The attacker will attempt to escalate privileges to gain complete control of the compromised system.
    B. The attacker will exploit the malicious payload delivered to the target organization and establish a foothold.
    C. The attacker will initiate an active connection to the target system to gather more data.
    D. The attacker will start reconnaissance to gather as much information as possible about the target.

  • Question 308:

    A post-breach forensic investigation revealed that a known vulnerability in Apache Struts was to blame for the Equifax data breach that affected 143 million customers. A fix was available from the software vendor for several months prior 10

    the intrusion.

    This Is likely a failure in which of the following security processes?

    A. vendor risk management
    B. Security awareness training
    C. Secure deployment lifecycle
    D. Patch management

  • Question 309:

    Sarah, a system administrator, was alerted of potential malicious activity on the network of her company. She discovered a malicious program spread through the instant messenger application used by her team. The attacker had obtained access to one of her teammate's messenger accounts and started sending files across the contact list. Which best describes the attack scenario and what measure could have prevented it?

    A. Instant Messenger Applications; verifying the sender's identity before opening any files.
    B. Insecure Patch Management; updating application software regularly.
    C. Rogue/Decoy Applications; ensuring software is labeled as TRUSTED.
    D. Portable Hardware Media/Removable Devices; disabling Autorun functionality.

  • Question 310:

    Calvin, a software developer, uses a feature that helps him auto-generate the content of a web page without manual involvement and is integrated with SSI directives. This leads to a vulnerability in the developed web application as this feature accepts remote user inputs and uses them on the page. Hackers can exploit this feature and pass malicious SSI directives as input values to perform malicious activities such as modifying and erasing server files. What is the type of injection attack Calvin's web application is susceptible to?

    A. Server-side template injection
    B. Server-side JS injection
    C. CRLF injection
    D. Server-side includes injection

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V12 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.