312-50V13 Exam Details

  • Exam Code
    :312-50V13
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v13)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :879 Q&As
  • Last Updated
    :May 27, 2026

EC-COUNCIL 312-50V13 Online Questions & Answers

  • Question 651:

    Jake, a professional hacker, installed spyware on a target iPhone to spy on the target user's activities. He can take complete control of the target mobile device by jailbreaking the device remotely and record audio, capture screenshots, and monitor all phone calls and SMS messages. What is the type of spyware that Jake used to infect the target device?

    A. DroidSheep
    B. Androrat
    C. Zscaler
    D. Trident

  • Question 652:

    A company's customer data in a cloud environment has been exposed due to an unknown vulnerability.

    Which type of issue most likely led to the incident?

    A. Side-channel attack on the hypervisor
    B. Denial-of-Service (DoS) attack on cloud servers
    C. Brute-force attack on user passwords
    D. Exploitation of misconfigured security groups

  • Question 653:

    While testing a web application in development, you notice that the web server does not properly ignore the "dot dot slash" (../) character string and instead returns the file listing of a folder structure of the server.

    What kind of attack is possible in this scenario?

    A. Cross-site scripting
    B. Denial of service
    C. SQL injection
    D. Directory traversal

  • Question 654:

    Which indicator most strongly confirms a MAC flooding attack?

    A. Multiple IPs to one MAC
    B. Multiple MACs to one IP
    C. Numerous MAC addresses on a single switch port
    D. Increased ARP requests

  • Question 655:

    A penetration tester discovers that a web application uses unsanitized user input to dynamically generate file paths. The tester identifies that the application is vulnerable to Remote File Inclusion (RFI). Which action should the tester take to exploit this vulnerability?

    A. Inject a SQL query into the input field to perform SQL injection
    B. Use directory traversal to access sensitive system files on the server
    C. Provide a URL pointing to a remote malicious script to include it in the web application
    D. Upload a malicious shell to the server and execute commands remotely

  • Question 656:

    Dayn, an attacker, wanted to detect if any honeypots are installed in a target network. For this purpose, he used a time-based TCP fingerprinting method to validate the response to a normal computer and the response of a honeypot to a manual SYN request.

    Which of the following techniques is employed by Dayn to detect honeypots?

    A. Detecting honeypots running on VMware
    B. Detecting the presence of Honeyd honeypots
    C. Detecting the presence of Snort_inline honeypots
    D. Detecting the presence of Sebek-based honeypots

  • Question 657:

    joe works as an it administrator in an organization and has recently set up a cloud computing service for the organization. To implement this service, he reached out to a telecom company for providing Internet connectivity and transport services between the organization and the cloud service provider, in the NIST cloud deployment reference architecture, under which category does the telecom company fall in the above scenario?

    A. Cloud booker
    B. Cloud consumer
    C. Cloud carrier
    D. Cloud auditor

  • Question 658:

    One customer's malicious activity impacts other tenants. Which control would best prevent this?

    A. Strong encryption
    B. Secure log management
    C. Multi-tenant isolation
    D. Strong authentication

  • Question 659:

    You are a Network Security Officer. You have two machines. The first machine (192.168.0.99) has Snort installed, and the second machine (192.168.0.150) has Kiwi Syslog installed. You perform a SYN scan in your network, and you notice that Kiwi Syslog is not receiving the alert message from Snort. You decide to run Wireshark on the Snort machine to check if the messages are going to the Kiwi Syslog machine. What Wireshark filter will show the connections from the Snort machine to Kiwi Syslog machine?

    A. tcp.srcport==514 andand ip.src==192.168.0.99
    B. tcp.srcport==514 andand ip.src==192.168.150
    C. tcp.dstport==514 andand ip.dst==192.168.0.99
    D. tcp.dstport==514 andand ip.dst==192.168.0.150

  • Question 660:

    Which tool is best for sniffing plaintext HTTP traffic?

    A. Nessus
    B. Nmap
    C. Netcat
    D. Wireshark

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V13 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.