312-50V13 Exam Details

  • Exam Code
    :312-50V13
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v13)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :879 Q&As
  • Last Updated
    :May 27, 2026

EC-COUNCIL 312-50V13 Online Questions & Answers

  • Question 121:

    Which iOS jailbreaking technique patches the kernel during the device boot so that it becomes jailbroken after each successive reboot?

    A. Tethered jailbreaking
    B. Semi-tethered jailbreaking
    C. Untethered jailbreaking
    D. Semi-Untethered jailbreaking

  • Question 122:

    "........is an attack type for a rogue Wi-Fi access point that appears to be a legitimate one offered on the premises, but actually has been set up to eavesdrop on wireless communications. It is the wireless version of the phishing scam. An attacker fools wireless users into connecting a laptop or mobile phone to a tainted hot- spot by posing as a legitimate provider. This type of attack may be used to steal the passwords of

    unsuspecting users by either snooping the communication link or by phishing, which involves setting up a fraudulent web site and luring people there."

    Fill in the blank with appropriate choice.

    A. Evil Twin Attack
    B. Sinkhole Attack
    C. Collision Attack
    D. Signal Jamming Attack

  • Question 123:

    A penetration tester intercepts HTTP requests between a user and a vulnerable web server. The tester observes that the session ID is embedded in the URL, and the web application does not regenerate the session upon login. Which session hijacking technique is most likely to succeed in this scenario?

    A. Injecting JavaScript to steal session cookies via cross-site scripting
    B. DNS cache poisoning to redirect users to fake sites
    C. Session fixation by pre-setting the token in a URL
    D. Cross-site request forgery exploiting user trust in websites

  • Question 124:

    Jake, a network security specialist, is trying to prevent network-level session hijacking attacks in his company.

    While studying different types of such attacks, he learns about a technique where an attacker inserts their machine into the communication between a client and a server, making it seem like the packets are flowing through the original path.

    This technique is primarily used to reroute the packets.

    Which of the following types of network-level session hijacking attacks is Jake studying?

    A. RST Hijacking
    B. Man-in-the-middle Attack Using Forged ICMP and ARP Spoofing
    C. UDP Hijacking
    D. TCP/IP Hijacking

  • Question 125:

    In the field of cryptanalysis, what is meant by a "rubber-hose" attack?

    A. Forcing the targeted keystream through a hardware-accelerated device such as an ASIC.
    B. A backdoor placed into a cryptographic algorithm by its creator.
    C. Extraction of cryptographic secrets through coercion or torture.
    D. Attempting to decrypt ciphertext by making logical assumptions about the contents of the original plaintext.

  • Question 126:

    As a cybersecurity professional, you are responsible for securing a high-traffic web application that uses MySQL as its backend database. Recently, there has been a surge of unauthorized login attempts, and you suspect that a seasoned black-hat hacker is behind them. This hacker has shown proficiency in SQL Injection and appears to be using the 'UNION' SQL keyword to trick the login process into returning additional data.

    However, your application's security measures include filtering special characters in user inputs, a method usually effective against such attacks. In this challenging environment, if the hacker still intends to exploit this SQL Injection vulnerability, which strategy is he most likely to employ?

    A. The hacker alters his approach and injects a `DROP TABLE' statement, a move that could potentially lead to the loss of vital data stored in the application's database
    B. The hacker tries to manipulate the 'UNION' keyword in such a way that it triggers a database error, potentially revealing valuable information about the database's structure
    C. The hacker switches tactics and resorts to a `time-based blind' SQL Injection attack, which would force the application to delay its response, thereby revealing information based on the duration of the delay
    D. The hacker attempts to bypass the special character filter by encoding his malicious input, which could potentially enable him to successfully inject damaging SQL queries

  • Question 127:

    Which of the following provides a security professional with most information about the system's security posture?

    A. Phishing, spamming, sending trojans
    B. Social engineering, company site browsing, tailgating
    C. Wardriving, warchalking, social engineering
    D. Port scanning, banner grabbing, service identification

  • Question 128:

    Clark is gathering sensitive information about a competitor and uses a tool to input the target's server IP address to identify network range, OS, and topology. What tool is he using?

    A. AOL
    B. ARIN
    C. DuckDuckGo
    D. Baidu

  • Question 129:

    Encrypted session tokens vary in length, indicating inconsistent encryption strength. What is the best mitigation?

    A. Rotate keys frequently
    B. Enforce MFA for privileged users
    C. Implement uniform encryption strength
    D. Centralized logging

  • Question 130:

    Null sessions are un-authenticated connections (not using a username or password.) to an NT or 2000 system. Which TCP and UDP ports must you filter to check null sessions on your network?

    A. 137 and 139
    B. 137 and 443
    C. 139 and 443
    D. 139 and 445

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V13 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.