312-50V8 Exam Details

  • Exam Code
    :312-50V8
  • Exam Name
    :Certified Ethical Hacker v8
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1008 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-50V8 Online Questions & Answers

  • Question 331:

    Every company needs a formal written document which spells out to employees precisely what they are allowed to use the company's systems for, what is prohibited, and what will happen to them if they break the rules. Two printed copies of the policy should be given to every employee as soon as possible after they join the organization. The employee should be asked to sign one copy, which should be safely filed by the company. No one should be allowed to use the company's computer systems until they have signed the policy in acceptance of its terms.

    What is this document called?

    A. Information Audit Policy (IAP)
    B. Information Security Policy (ISP)
    C. Penetration Testing Policy (PTP)
    D. Company Compliance Policy (CCP)

  • Question 332:

    You are manually conducting Idle Scanning using Hping2. During your scanning you notice that almost every query increments the IPID regardless of the port being queried. One or two of the queries cause the IPID to increment by more than one value.

    Why do you think this occurs?

    A. The zombie you are using is not truly idle.
    B. A stateful inspection firewall is resetting your queries.
    C. Hping2 cannot be used for idle scanning.
    D. These ports are actually open on the target system.

  • Question 333:

    Let's imagine three companies (A, B and C), all competing in a challenging global environment. Company A and B are working together in developing a product that will generate a major competitive advantage for them. Company A has a secure DNS server while company B has a DNS server vulnerable to spoofing. With a spoofing attack on the DNS server of company B, company C gains access to outgoing e-mails from company B.

    How do you prevent DNS spoofing? (Select the Best Answer.)

    A. Install DNS logger and track vulnerable packets
    B. Disable DNS timeouts
    C. Install DNS Anti-spoofing
    D. Disable DNS Zone Transfer

  • Question 334:

    The Open Web Application Security Project (OWASP) testing methodology addresses the need to secure web applications by providing which one of the following services?

    A. An extensible security framework named COBIT
    B. A list of flaws and how to fix them
    C. Web application patches
    D. A security certification for hardened web applications

  • Question 335:

    A specific site received 91 ICMP_ECHO packets within 90 minutes from 47 different sites.

    77 of the ICMP_ECHO packets had an ICMP ID:39612 and Seq:57072. 13 of the ICMP_ECHO packets had an ICMP ID:0 and Seq:0.

    What can you infer from this information?

    A. The packets were sent by a worm spoofing the IP addresses of 47 infected sites
    B. ICMP ID and Seq numbers were most likely set by a tool and not by the operating system
    C. All 77 packets came from the same LAN segment and hence had the same ICMP ID and Seq number
    D. 13 packets were from an external network and probably behind a NAT,as they had an ICMP ID 0 and Seq 0

  • Question 336:

    TCP/IP Session Hijacking is carried out in which OSI layer?

    A. Datalink layer
    B. Transport layer
    C. Network layer
    D. Physical layer

  • Question 337:

    Which types of detection methods are employed by Network Intrusion Detection Systems (NIDS)? (Choose two.)

    A. Signature
    B. Anomaly
    C. Passive
    D. Reactive

  • Question 338:

    If a tester is attempting to ping a target that exists but receives no response or a response that states the destination is unreachable, ICMP may be disabled and the network may be using TCP. Which other option could the tester use to get a response from a host using TCP?

    A. Hping
    B. Traceroute
    C. TCP ping
    D. Broadcast ping

  • Question 339:

    Wayne is the senior security analyst for his company. Wayne is examining some traffic logs on a server and came across some inconsistencies. Wayne finds some IP packets from a

    computer purporting to be on the internal network. The packets originate from 192.168.12.35 with a TTL of 15. The server replied to this computer and received a response from 192.168.12.35 with a TTL of 21.

    What can Wayne infer from this traffic log?

    A. The initial traffic from 192.168.12.35 was being spoofed.
    B. The traffic from 192.168.12.25 is from a Linux computer.
    C. The TTL of 21 means that the client computer is on wireless.
    D. The client computer at 192.168.12.35 is a zombie computer.

  • Question 340:

    Virus Scrubbers and other malware detection program can only detect items that they are aware of. Which of the following tools would allow you to detect unauthorized changes or modifications of binary files on your system by unknown malware?

    A. System integrity verification tools
    B. Anti-Virus Software
    C. A properly configured gateway
    D. There is no way of finding out until a new updated signature file is released

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V8 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.