312-50V13 Exam Details

  • Exam Code
    :312-50V13
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v13)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :879 Q&As
  • Last Updated
    :May 27, 2026

EC-COUNCIL 312-50V13 Online Questions & Answers

  • Question 281:

    A cyber adversary wants to enumerate firewall rules while minimizing noise and mimicking normal traffic behavior.

    Which reconnaissance technique enables mapping of firewall filtering behavior using TTL- manipulated packets?

    A. Sending ICMP Echo requests to the network's broadcast address
    B. Passive DNS monitoring to observe domain-to-IP relationships
    C. Conducting full SYN scans on all ports for each discovered IP
    D. Firewalking with manipulated TTL values to analyze ACL responses

  • Question 282:

    A penetration tester is evaluating a web application that does not properly validate the authenticity of HTTP requests. The tester suspects the application is vulnerable to Cross-Site Request Forgery (CSRF). Which approach should the tester use to exploit this vulnerability?

    A. Execute a directory traversal attack to access restricted server files
    B. Create a malicious website that sends a crafted request on behalf of the user when visited
    C. Perform a brute-force attack on the application's login page to guess weak credentials
    D. Inject a SQL query into the input fields to perform SQL injection

  • Question 283:

    Which type of malware spreads from one system to another or from one network to another and causes similar types of damage as viruses do to the infected system?

    A. Rootkit
    B. Trojan
    C. Worm
    D. Adware

  • Question 284:

    Suppose that you test an application for the SQL injection vulnerability. You know that the backend database is based on Microsoft SQL Server. In the login/password form, you enter the following credentials:

    Username: attack' or 1=1 --

    Password: 123456

    Based on the above credentials, which of the following SQL commands are you expecting to be executed by the server, if there is indeed an SQL injection vulnerability?

    A. select * from Users where UserName = 'attack'' or 1=1 -- and UserPassword = '123456'
    B. select * from Users where UserName = 'attack' or 1=1 -- and UserPassword = '123456'
    C. select * from Users where UserName = 'attack or 1=1 -- and UserPassword = '123456'
    D. select * from Users where UserName = 'attack' or 1=1 --' and UserPassword = '123456'

  • Question 285:

    Which of the following options represents a conceptual characteristic of an anomaly-based IDS over a signature-based IDS?

    A. Produces less false positives
    B. Can identify unknown attacks
    C. Requires vendor updates for a new threat
    D. Cannot deal with encrypted network traffic

  • Question 286:

    Which type of attack attempts to overflow the content-addressable memory (CAM) table in an Ethernet switch?

    A. Evil twin attack
    B. DNS cache flooding
    C. MAC flooding
    D. DDoS attack

  • Question 287:

    Study the snort rule given below:

    From the options below, choose the exploit against which this rule applies.

    [Image shows two Snort rules with alert messages for NETBIOS DCERPC ISystemActivator bind attempt, targeting TCP ports 135 and 445. References include CVE: CAN-2003-0352.]

    A. WebDav
    B. SQL Slammer
    C. MS Blaster
    D. MyDoom

  • Question 288:

    A company's Web development team has become aware of a certain type of security vulnerability in their Web software. To mitigate the possibility of this vulnerability being exploited, the team wants to modify the software requirements to disallow users from entering HTML as input into their Web application.

    What kind of Web application vulnerability likely exists in their software?

    A. Cross-site scripting vulnerability
    B. SQL injection vulnerability
    C. Web site defacement vulnerability
    D. Gross-site Request Forgery vulnerability

  • Question 289:

    Sarah, a system administrator, was alerted of potential malicious activity on the network of her company. She discovered a malicious program spread through the instant messenger application used by her team. The attacker had obtained access to one of her teammate's messenger accounts and started sending files across the contact list.

    Which best describes the attack scenario and what measure could have prevented it?

    A. Instant Messenger Applications; verifying the sender's identity before opening any files
    B. Insecure Patch Management; updating application software regularly
    C. Rogue/Decoy Applications; ensuring software is labeled as TRUSTED
    D. Portable Hardware Media/Removable Devices; disabling Autorun functionality

  • Question 290:

    Matthew, a black hat, has managed to open a meterpreter session to one of the kiosk machines in Evil Corp's lobby. He checks his current SID, which is:

    S-1-5-21-1223352397-1872883824-861252104-501

    What needs to happen before Matthew has full administrator access?

    A. He must perform privilege escalation.
    B. He needs to disable antivirus protection.
    C. He needs to gain physical access.
    D. He already has admin privileges, as shown by the "501" at the end of the SID.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V13 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.