312-50V13 Exam Details

  • Exam Code
    :312-50V13
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v13)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :879 Q&As
  • Last Updated
    :May 27, 2026

EC-COUNCIL 312-50V13 Online Questions & Answers

  • Question 471:

    Which of the following is the BEST way to defend against network sniffing?

    A. Using encryption protocols to secure network communications
    B. Register all machines MAC Address in a Centralized Database
    C. Use Static IP Address
    D. Restrict Physical Access to Server Rooms hosting Critical Servers

  • Question 472:

    You are a penetration tester and are about to perform a scan on a specific server. The agreement that you signed with the client contains the following specific condition for the scan: "The attacker must scan every port on the server several times using a set of spoofed sources IP addresses. " Suppose that you are using Nmap to perform this scan. What flag will you use to satisfy this requirement?

    A. The -A flag
    B. The -g flag
    C. The -f flag
    D. The -D flag

  • Question 473:

    A large corporate network is being subjected to repeated sniffing attacks. To increase security, the company's IT department decides to implement a combination of several security measures. They permanently add theMAC address of the gateway to the ARP cache, switch to using IPv6 instead of IPv4, implement the use of encrypted sessions such as SSH instead of Telnet, and use Secure File Transfer Protocol instead of FTP.

    However, they are still faced with the threat of sniffing. Considering the countermeasures, what should be their next step to enhance network security?

    A. Use HTTP instead of HTTPS for protecting usernames and passwords
    B. Implement network scanning and monitoring tools
    C. Enable network identification broadcasts
    D. Retrieve MAC addresses from the OS

  • Question 474:

    During a security assessment, an attacker identifies a flaw in a multi-user file system. The system first verifies access rights to a temporary file created by a user. However, immediately after this verification, and before the file is processed, the attacker manages to swap the original file with a malicious version. This manipulation happens in the brief interval between the system's access verification and the moment it handles the file, resulting in the malicious file being treated as legitimate. Which vulnerability is the attacker exploiting?

    A. Time-of-validation/time-of-execution issue in resource management logic.
    B. Improper certificate validation in trusted communication channels.
    C. Integer overflow during arithmetic computations with limited memory bounds.
    D. Null pointer dereference leading to unexpected application behavior.

  • Question 475:

    During an Xmas scan, what indicates a port is closed?

    A. No return response
    B. RST
    C. ACK
    D. SYN

  • Question 476:

    Which of the following tools can be used to perform a zone transfer?

    A. NSLookup
    B. Finger
    C. Dig
    D. Sam Spade
    E. Host
    F. Netcat
    G. Neotrace

  • Question 477:

    While using your bank's online servicing you notice the following string in the URL bar:

    " http://www.MyPersonalBank.com/account?id368940911028389 andDamount10980andCamount21"

    You observe that if you modify the Damount and Camount values and submit the request, that data on the web page reflects the changes.

    Which type of vulnerability is present on this site?

    A. Cookie Tampering
    B. SQL Injection
    C. Web Parameter Tampering
    D. XSS Reflection

  • Question 478:

    User A is writing a sensitive email message to user B outside the local network. User A has chosen to use PKI to secure his message and ensure only user B can read the sensitive email. At what layer of the OSI layer does the encryption and decryption of the message take place?

    A. Application
    B. Transport
    C. Session
    D. Presentation

  • Question 479:

    Shellshock allowed an unauthorized user to gain access to a server. It affected many Internet-facing services, which OS did it not directly affect?

    A. Linux
    B. Unix
    C. OS X
    D. Windows

  • Question 480:

    Why would you consider sending an email to an address that you know does not exist within the company you are performing a Penetration Test for?

    A. To determine who is the holder of the root account
    B. To perform a DoS
    C. To create needless SPAM
    D. To illicit a response back that will reveal information about email servers and how they treat undeliverable mail
    E. To test for virus protection

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V13 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.