312-50V13 Exam Details

  • Exam Code
    :312-50V13
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v13)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :879 Q&As
  • Last Updated
    :May 27, 2026

EC-COUNCIL 312-50V13 Online Questions & Answers

  • Question 451:

    A penetration tester is hired by a company to assess its vulnerability to social engineering attacks targeting its IT department. The tester decides to use a sophisticated pretext involving technical jargon and insider information to deceive employees into revealing their network credentials.

    What is the most effective social engineering technique the tester should employ to maximize the chances of obtaining valid credentials without raising suspicion?

    A. Conduct a phone call posing as a high-level executive requesting urgent password resets
    B. Send a generic phishing email with a malicious attachment to multiple employees
    C. Create a convincing fake IT support portal that mimics the company's internal systems
    D. Visit the office in person as a maintenance worker to gain physical access to terminals

  • Question 452:

    Which address translation scheme would allow a single public IP address to always correspond to a single machine on an internal network, allowing "server publishing"?

    A. Overloading Port Address Translation
    B. Dynamic Port Address Translation
    C. Dynamic Network Address Translation
    D. Static Network Address Translation

  • Question 453:

    Which of the following statements is FALSE with respect to Intrusion Detection Systems?

    A. Intrusion Detection Systems can be configured to distinguish specific content in network packets
    B. Intrusion Detection Systems can easily distinguish a malicious payload in encrypted traffic
    C. Intrusion Detection Systems require constant update of the signature library
    D. Intrusion Detection Systems can examine the contents of the data in context of the network protocol

  • Question 454:

    Joel, a professional hacker, targeted a company and identified the types of websites frequently visited by its employees. Using this information, he searched for possible loopholes in these websites and injected a malicious script that can redirect users from the web page and download malware onto a victim's machine. Joel waits for the victim to access the infected web application so as to compromise the victim's machine. Which of the following techniques is used by Joel in the above scenario?

    A. DNS rebinding attack
    B. Clickjacking attack
    C. MarioNet attack
    D. Watering hole attack

  • Question 455:

    A penetration tester is conducting an external assessment of a corporate web server. They start by accessing https://www.targetcorp.com/robots.txt and observe multiple Disallow entries that reference directories such as /admin-panel/, /backup/, and /confidentialdocs/. When the tester directly visits these paths via a browser, they find that access is not restricted by authentication and gain access to sensitive files, including server configuration and unprotected credentials. Which stage of the web server attack methodology is demonstrated in this scenario?

    A. Injecting malicious SQL queries to access sensitive database records
    B. Performing a cross-site request forgery (CSRF) attack to manipulate user actions
    C. Gathering information through exposed indexing instructions
    D. Leveraging the directory traversal flaw to access critical server files

  • Question 456:

    A penetration tester alters the "file" parameter in a web application (e.g., view?file=report.txt) to ../../../../etc /passwd and successfully accesses restricted system files. What attack method does this scenario illustrate?

    A. Conduct a brute-force attack to obtain administrative credentials
    B. Use directory traversal sequences in URL parameters to retrieve unauthorized system content
    C. Inject malicious scripts into web pages to manipulate content via XSS vulnerabilities
    D. Exploit buffer overflow issues by injecting oversized data in HTTP request headers

  • Question 457:

    what firewall evasion scanning technique make use of a zombie system that has low network activity as well as its fragment identification numbers?

    A. Decoy scanning
    B. Packet fragmentation scanning
    C. Spoof source address scanning
    D. Idle scanning

  • Question 458:

    The collection of potentially actionable, overt, and publicly available information is known as

    A. Open-source intelligence
    B. Real intelligence
    C. Social intelligence
    D. Human intelligence

  • Question 459:

    Which technique is most likely used to evade detection by an Intrusion Detection System (IDS)?

    A. Fragmenting malicious packets into smaller segments
    B. Using self-replicating malware
    C. Sending phishing emails
    D. Flooding the IDS with ping requests

  • Question 460:

    A penetration tester is tasked with assessing the security of a smart home IoT device that communicates with a mobile app over an unencrypted connection. The tester wants to intercept the communication and extract sensitive information. What is the most effective approach to exploit this vulnerability?

    A. Perform a brute-force attack on the device's Wi-Fi credentials
    B. Use a man-in-the-middle (MitM) attack to intercept and analyze the unencrypted traffic
    C. Execute a SQL injection attack on the IoT device's cloud management portal
    D. Use a dictionary attack to guess the admin login credentials of the device

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V13 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.