312-50V12 Exam Details

  • Exam Code
    :312-50V12
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v12)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :596 Q&As
  • Last Updated
    :May 30, 2026

EC-COUNCIL 312-50V12 Online Questions & Answers

  • Question 481:

    Which of the following types of SQL injection attacks extends the results returned by the original query, enabling attackers to run two or more statements if they have the same structure as the original one?

    A. Error-based injection
    B. Boolean-based blind SQL injection
    C. Blind SQL injection
    D. Union SQL injection

  • Question 482:

    The Payment Card Industry Data Security Standard (PCI DSS) contains six different categories of control objectives. Each objective contains one or more requirements, which must be followed in order to achieve compliance. Which of the following requirements would best fit under the objective, "Implement strong access control measures"?

    A. Regularly test security systems and processes.
    B. Encrypt transmission of cardholder data across open, public networks.
    C. Assign a unique ID to each person with computer access.
    D. Use and regularly update anti-virus software on all systems commonly affected by malware.

  • Question 483:

    A "Server-Side Includes" attack refers to the exploitation of a web application by injecting scripts in HTML pages or executing arbitrary code remotely. Which web-page file type, if it exists on the web server, is a strong indication that the server is vulnerable to this kind of attack?

    A. .stm
    B. .html
    C. .rss
    D. .cms

  • Question 484:

    An attacker attaches a rogue router in a network. He wants to redirect traffic to a LAN attached to his router as part of a man-in-the-middle attack. What measure on behalf of the legitimate admin can mitigate this attack?

    A. Make sure that legitimate network routers are configured to run routing protocols with authentication.
    B. Disable all routing protocols and only use static routes
    C. Only using OSPFv3 will mitigate this risk.
    D. Redirection of the traffic cannot happen unless the admin allows it explicitly.

  • Question 485:

    The "Gray-box testing" methodology enforces what kind of restriction?

    A. Only the external operation of a system is accessible to the tester.
    B. The internal operation of a system in only partly accessible to the tester.
    C. Only the internal operation of a system is known to the tester.
    D. The internal operation of a system is completely known to the tester.

  • Question 486:

    Jude, a pen tester working in Keiltech Ltd., performs sophisticated security testing on his company's network infrastructure to identify security loopholes. In this process, he started to circumvent the network protection tools and firewalls used

    in the company. He employed a technique that can create forged TCP sessions by carrying out multiple SYN, ACK, and RST or FIN packets. Further, this process allowed Jude to execute DDoS attacks that can exhaust the network

    resources.

    What is the attack technique used by Jude for finding loopholes in the above scenario?

    A. UDP flood attack
    B. Ping-of-death attack
    C. Spoofed session flood attack
    D. Peer-to-peer attack

  • Question 487:

    You have successfully comprised a server having an IP address of 10.10.0.5. You would like to enumerate all machines in the same network quickly. What is the best Nmap command you will use?

    A. nmap -T4 -q 10.10.0.0/24
    B. nmap -T4 -F 10.10.0.0/24
    C. nmap -T4 -r 10.10.1.0/24
    D. nmap -T4 -O 10.10.0.0/24

  • Question 488:

    Samuel a security administrator, is assessing the configuration of a web server. He noticed that the server permits SSlv2 connections, and the same private key certificate is used on a different server that allows SSLv2 connections. This

    vulnerability makes the web server vulnerable to attacks as the SSLv2 server can leak key information.

    Which of the following attacks can be performed by exploiting the above vulnerability?

    A. DROWN attack
    B. Padding oracle attack
    C. Side-channel attack
    D. DUHK attack

  • Question 489:

    What is the algorithm used by LM for Windows2000 SAM?

    A. MD4
    B. DES
    C. SHA
    D. SSL

  • Question 490:

    A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should take before enabling the audit feature?

    A. Perform a vulnerability scan of the system.
    B. Determine the impact of enabling the audit feature.
    C. Perform a cost/benefit analysis of the audit feature.
    D. Allocate funds for staffing of audit log review.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V12 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.