312-50V8 Exam Details

  • Exam Code
    :312-50V8
  • Exam Name
    :Certified Ethical Hacker v8
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1008 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-50V8 Online Questions & Answers

  • Question 551:

    Destination unreachable administratively prohibited messages can inform the hacker to what?

    A. That a circuit level proxy has been installed and is filtering traffic
    B. That his/her scans are being blocked by a honeypot or jail
    C. That the packets are being malformed by the scanning software
    D. That a router or other packet-filtering device is blocking traffic
    E. That the network is functioning normally

  • Question 552:

    Steve scans the network for SNMP enabled devices.

    Which port number Steve should scan?

    A. 150
    B. 161
    C. 169
    D. 69

  • Question 553:

    A network administrator discovers several unknown files in the root directory of his Linux FTP server. One of the files is a tarball, two are shallscript files, and the third is a binary file is named "nc." The FTP server's access logs show that the anonymous user account logged in the server, uploaded the files, and extracted the contents of the tarball and ran the script using a function providedby the FTP server's software. The ps command shows that the nc file is running as process, and the netstat command shows the nc process is listening on a network port.

    Which kind of vulnerability must be present to make this remote attack possible?

    A. Filesystem permissions
    B. Brute Force Login
    C. Privilege Escalation
    D. Directory Traversal

  • Question 554:

    How does the Address Resolution Protocol (ARP) work?

    A. It sends a reply packet for a specific IP, asking for the MAC address.
    B. It sends a reply packet to all the network elements, asking for the MAC address from a specific IP.
    C. It sends a request packet to all the network elements, asking for the domainname from a specific IP.
    D. It sends a request packet to all the network elements, asking for the MAC address from a specific IP.

  • Question 555:

    NetBIOS over TCP/IP allows files and/or printers to be shared over the network. You are trying to intercept the traffic from a victim machine to a corporate network printer. You are attempting to hijack the printer network connection from your laptop by sniffing the wire.

    Which port does SMB over TCP/IP use?

    A. 443
    B. 139
    C. 179
    D. 445

  • Question 556:

    Take a look at the following attack on a Web Server using obstructed URL:

    http://www.example.com/script.ext?template%2e%2e%2e%2e%2e%2f%2e%2f%65%74%

    63%2f%70%61%73%73%77%64

    The request is made up of:

    %2e%2e%2f%2e%2e%2f%2e%2f% = ../../../

    %65%74%63 = etc

    %2f = /

    %70%61%73%73%77%64 = passwd

    How would you protect information systems from these attacks?

    A. Configure Web Server to deny requests involving Unicode characters.
    B. Create rules in IDS to alert on strange Unicode requests.
    C. Use SSL authentication on Web Servers.
    D. Enable Active Scripts Detection at the firewall and routers.

  • Question 557:

    Which Windows system tool checks integrity of critical files that has been digitally signed by Microsoft?

    A. signverif.exe
    B. sigverif.exe
    C. msverif.exe
    D. verifier.exe

  • Question 558:

    Exhibit:

    The following is an entry captured by a network IDS.You are assigned the task of analyzing this entry. You notice the value 0x90, which is the most common NOOP instruction for the

    Intel processor. You figure that the attacker is attempting a buffer overflow attack. You also notice "/bin/sh" in the ASCII part of the output. As an analyst what would you conclude about the attack?

    A. The buffer overflow attack has been neutralized by the IDS
    B. The attacker is creating a directory on the compromised machine
    C. The attacker is attempting a buffer overflow attack and has succeeded
    D. The attacker is attempting an exploit that launches a command-line shell

  • Question 559:

    Which of the following network attacks relies on sending an abnormally large packet size that exceeds TCP/IP specifications?

    A. Ping of death
    B. SYN flooding
    C. TCP hijacking
    D. Smurf attack

  • Question 560:

    Which of the following represent weak password? (Select 2 answers)

    A. Passwords that contain letters,special characters,and numbers ExamplE. ap1$%##f@52
    B. Passwords that contain only numbers ExamplE. 23698217
    C. Passwords that contain only special characters ExamplE. and*#@!(%)
    D. Passwords that contain letters and numbers ExamplE. meerdfget123
    E. Passwords that contain only letters ExamplE. QWERTYKLRTY
    F. Passwords that contain only special characters and numbers ExamplE. 123@$45
    G. Passwords that contain only letters and special characters ExamplE. bob@andba
    H. Passwords that contain Uppercase/Lowercase from a dictionary list ExamplE. OrAnGe

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V8 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.