Exam Details

  • Exam Code
    :312-50V9
  • Exam Name
    :Certified Ethical Hacker Exam V9
  • Certification
    :CEH V9
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :614 Q&As
  • Last Updated
    :Apr 30, 2024

EC-COUNCIL CEH V9 312-50V9 Questions & Answers

  • Question 1:

    A certified ethical hacker (CEH) is approached by a friend who believes her husband is cheating. She offers to pay to break into her husband's email account in order to find proof so she can take him to court. What is the ethical response?

    A. Say no; the friend is not the owner of the account.

    B. Say yes; the friend needs help to gather evidence.

    C. Say yes; do the job for free.

    D. Say no; make sure that the friend knows the risk she's asking the CEH to take.

  • Question 2:

    A computer technician is using a new version of a word processing software package when it is discovered that a special sequence of characters causes the entire computer to crash. The technician researches the bug and discovers that no one else experienced the problem. What is the appropriate next step?

    A. Ignore the problem completely and let someone else deal with it.

    B. Create a document that will crash the computer when opened and send it to friends.

    C. Find an underground bulletin board and attempt to sell the bug to the highest bidder.

    D. Notify the vendor of the bug and do not disclose it until the vendor gets a chance to issue a fix.

  • Question 3:

    Which initial procedure should an ethical hacker perform after being brought into an organization?

    A. Begin security testing.

    B. Turn over deliverables.

    C. Sign a formal contract with non-disclosure.

    D. Assess what the organization is trying to protect.

  • Question 4:

    A consultant has been hired by the V.P. of a large financial organization to assess the company's security posture. During the security testing, the consultant comes across child pornography on the V.P.'s computer. What is the consultant's obligation to the financial organization?

    A. Say nothing and continue with the security testing.

    B. Stop work immediately and contact the authorities.

    C. Delete the pornography, say nothing, and continue security testing.

    D. Bring the discovery to the financial organization's human resource department.

  • Question 5:

    A certified ethical hacker (CEH) completed a penetration test of the main headquarters of a company almost two months ago, but has yet to get paid. The customer is suffering from financial problems, and the CEH is worried that the company will go out of business and end up not paying. What actions should the CEH take?

    A. Threaten to publish the penetration test results if not paid.

    B. Follow proper legal procedures against the company to request payment.

    C. Tell other customers of the financial problems with payments from this company.

    D. Exploit some of the vulnerabilities found on the company webserver to deface it.

  • Question 6:

    An ethical hacker for a large security research firm performs penetration tests, vulnerability tests, and risk assessments. A friend recently started a company and asks the hacker to perform a penetration test and vulnerability assessment of the new company as a favor. What should the hacker's next step be before starting work on this job?

    A. Start by foot printing the network and mapping out a plan of attack.

    B. Ask the employer for authorization to perform the work outside the company.

    C. Begin the reconnaissance phase with passive information gathering and then move into active information gathering.

    D. Use social engineering techniques on the friend's employees to help identify areas that may be susceptible to attack.

  • Question 7:

    International Organization for Standardization (ISO) standard 27002 provides guidance for compliance by outlining

    A. guidelines and practices for security controls.

    B. financial soundness and business viability metrics.

    C. standard best practice for configuration management.

    D. contract agreement writing standards.

  • Question 8:

    Which type of security document is written with specific step-by-step details?

    A. Process

    B. Procedure

    C. Policy

    D. Paradigm

  • Question 9:

    Which of the following guidelines or standards is associated with the credit card industry?

    A. Control Objectives for Information and Related Technology (COBIT)

    B. Sarbanes-Oxley Act (SOX)

    C. Health Insurance Portability and Accountability Act (HIPAA)

    D. Payment Card Industry Data Security Standards (PCI DSS)

  • Question 10:

    Which method can provide a better return on IT security investment and provide a thorough and comprehensive assessment of organizational security covering policy, procedure design, and implementation?

    A. Penetration testing

    B. Social engineering

    C. Vulnerability scanning

    D. Access control list reviews

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V9 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.