312-50V13 Exam Details

  • Exam Code
    :312-50V13
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v13)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :879 Q&As
  • Last Updated
    :May 27, 2026

EC-COUNCIL 312-50V13 Online Questions & Answers

  • Question 791:

    Multiple internal workstations and IoT devices are compromised and transmitting large volumes of traffic to numerous external targets under botnet control. Which type of denial-of-service attack best describes this situation?

    A. An attack where compromised internal devices participate in a botnet and flood external targets
    B. An attack relying on spoofed IP addresses to trick external servers
    C. A direct botnet flood without spoofing intermediary services
    D. An internal amplification attack using spoofed DNS responses

  • Question 792:

    A Security Engineer at a medium-sized accounting firm has been tasked with discovering how much information can be obtained from the firm's public facing web servers. The engineer decides to start by using netcat to port 80.

    The engineer receives this output:

    HTTP/1.1 200 OK

    Server: Microsoft-IIS/6

    Expires: Tue, 17 Jan 2011 01:41:33 GMT

    Date: Mon, 16 Jan 2011 01:41:33 GMT

    Content-Type: text/html

    Accept-Ranges: bytes

    Last Modified: Wed, 28 Dec 2010 15:32:21 GMT

    ETag:"b0aac0542e25c31:89d"

    Content-Length: 7369

    Which of the following is an example of what the engineer performed?

    A. Banner grabbing
    B. SQL injection
    C. Whois database query
    D. Cross-site scripting

  • Question 793:

    During network analysis, clients are receiving incorrect gateway and DNS settings due to a rogue DHCP server. What security feature should the administrator enable to prevent this in the future?

    A. DHCP snooping on trusted interfaces
    B. ARP inspection across VLANs
    C. Port security on all trunk ports
    D. Static DHCP reservations for clients

  • Question 794:

    During the process of encryption and decryption, what keys are shared?

    A. Private keys
    B. User passwords
    C. Public keys
    D. Public and private keys

  • Question 795:

    An attacker has installed a RAT on a host. The attacker wants to ensure that when a user attempts to go to "www.MyPersonalBank.com", the user is directed to a phishing site.

    Which file does the attacker need to modify?

    A. Boot.ini
    B. Sudoers
    C. Networks
    D. Hosts

  • Question 796:

    Vlady wants to improve security awareness among non-technical employees who demonstrate poor security practices. What should be his first step?

    A. Warning to those who write passwords on post-it notes
    B. Developing a strict information security policy
    C. Information security awareness training
    D. Conducting one-to-one discussions with employees

  • Question 797:

    A hacker is an intelligent individual with excellent computer skills and the ability to explore a computer's software and hardware without the owner's permission. Their intention can either be to simply gain knowledge or to illegally make changes.

    Which of the following class of hacker refers to an individual who works both offensively and defensively at various times?

    A. White Hat
    B. Suicide Hacker
    C. Gray Hat
    D. Black Hat

  • Question 798:

    John is an incident handler at a financial institution. His steps in a recent incident are not up to the standards of the company. John frequently forgets some steps and procedures while handling responses as they are very stressful to perform. Which of the following actions should John take to overcome this problem with the least administrative effort?

    A. Create an incident checklist.
    B. Select someone else to check the procedures.
    C. Increase his technical skills.
    D. Read the incident manual every time it occurs.

  • Question 799:

    On performing a risk assessment, you need to determine the potential impacts when some of the critical business processes of the company interrupt its service.

    What is the name of the process by which you can determine those critical businesses?

    A. Emergency Plan Response (EPR)
    B. Business Impact Analysis (BIA)
    C. Risk Mitigation
    D. Disaster Recovery Planning (DRP)

  • Question 800:

    You are a security officer of a company. You had an alert from IDS that indicates that one PC on your Intranet is connected to a blacklisted IP address (C2 Server) on the Internet. The IP address was blacklisted just before the alert. You are starting an investigation to roughly analyze the severity of the situation. Which of the following is appropriate to analyze?

    A. IDS log
    B. Event logs on domain controller
    C. Internet Firewall/Proxy log
    D. Event logs on the PC

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V13 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.