Updated Aug-2026 Test Engine to Practice 312-50v13 Dumps & Practice Exam
Dumps Collection 312-50v13 Test Engine Dumps Training With 1102 Questions
NEW QUESTION # 346
Scenario: Joe turns on his home computer to access personal online banking. When he enters the URL www.bank.com, the website is displayed, but it prompts him to re-enter his credentials as if he has never visited the site before. When he examines the website URL closer, he finds that the site is not secure and the web address appears different. What type of attack he is experiencing?
- A. DNS hijacking
- B. ARP cache poisoning
- C. DHCP spoofing
- D. DoS attack
Answer: A
NEW QUESTION # 347
A newly joined employee. Janet, has been allocated an existing system used by a previous employee. Before issuing the system to Janet, it was assessed by Martin, the administrator. Martin found that there were possibilities of compromise through user directories, registries, and other system parameters. He also Identified vulnerabilities such as native configuration tables, incorrect registry or file permissions, and software configuration errors. What is the type of vulnerability assessment performed by Martin?
- A. Distributed assessment
- B. Host-based assessment
- C. Credentialed assessment
- D. Database assessment
Answer: B
Explanation:
The host-based vulnerability assessment (VA) resolution arose from the auditors' got to periodically review systems. Arising before the net becoming common, these tools typically take an "administrator's eye" read of the setting by evaluating all of the knowledge that an administrator has at his or her disposal.
Uses
Host VA tools verify system configuration, user directories, file systems, registry settings, and all forms of other info on a number to gain information about it. Then, it evaluates the chance of compromise. it should also live compliance to a predefined company policy so as to satisfy an annual audit. With administrator access, the scans area unit less possible to disrupt traditional operations since the computer code has the access it has to see into the complete configuration of the system.
What it Measures Host
VA tools will examine the native configuration tables and registries to spot not solely apparent vulnerabilities, however additionally "dormant" vulnerabilities - those weak or misconfigured systems and settings which will be exploited when an initial entry into the setting. Host VA solutions will assess the safety settings of a user account table; the access management lists related to sensitive files or data; and specific levels of trust applied to other systems. The host VA resolution will a lot of accurately verify the extent of the danger by determinant however way any specific exploit could also be ready to get.
Types of Vulnerability Assessment Host-based assessments are a type of security check that involve conducting a configuration-level check to identify system configurations, user directories, file systems, registry settings, and other parameters to evaluate the possibility of compromise. Host-based scanners assess systems to identify vulnerabilities such as native configuration tables, incorrect registry or file permissions, and software configuration errors. (P.528/512)
NEW QUESTION # 348
Switches maintain a CAM Table that maps individual MAC addresses on the network to physical ports on the switch. In a MAC flooding attack, a switch is fed with many Ethernet frames, each containing different source MAC addresses, by the attacker. Switches have a limited memory for mapping various MAC addresses to physical ports.
What happens when the CAM table becomes full?
- A. The CAM overflow table will cause the switch to crash causing Denial of Service
- B. Switch then acts as hub by broadcasting packets to all machines on the network
- C. Every packet is dropped and the switch sends out SNMP alerts to the IDS port
- D. The switch replaces outgoing frame switch factory default MAC address of FF:FF:FF:FF:FF:FF
Answer: B
Explanation:
Comprehensive and Detailed Explanation:
In a MAC flooding attack, tools like macof (shown in the image) rapidly generate a large number of Ethernet frames with spoofed source MAC addresses. These are sent to the switch to overflow its CAM (Content Addressable Memory) table.
Once the CAM table is full:
The switch can no longer learn new MAC-to-port associations.
It fails open and starts broadcasting all incoming traffic to all ports.
This causes the switch to act like a hub.
Consequently, the attacker can:
Sniff traffic that would otherwise be switched.
Intercept data not destined for their system.
From CEH v13 Courseware:
Module 8: Sniffing # Switch-Based Attacks # MAC Flooding
Incorrect Options:
B: A switch typically does not crash but reverts to hub behavior.
C: There is no factory default override behavior like this.
D: Packets are not dropped-this would defeat the attack's purpose.
Reference:CEH v13 Study Guide - Module 8: MAC Flooding and Layer 2 AttacksCisco Security Best Practices - Switch CAM Table Protection
NEW QUESTION # 349
During a stealth penetration test for a multinational shipping company, ethical hacker Daniel Reyes gains local access to an engineering workstation and deploys a specialized payload that installs below the operating system. On subsequent reboots, the payload executes before any system-level drivers or services are active, giving Daniel covert control over the machine without triggering antivirus or endpoint detection tools. Weeks later, system administrators report suspicious network activity, but repeated forensic scans fail to locate any malicious processes or user-level traces. Which type of rootkit did Daniel most likely use to maintain this level of stealth and persistence?
- A. Bootkit
- B. Kernel-mode Rootkit
- C. Firmware Rootkit
- D. Hypervisor Rootkit
Answer: A
Explanation:
The payload executes before the operating system and its drivers load, indicating it is embedded in the boot process. This behavior is characteristic of a bootkit, which infects the boot sequence to gain early execution and maintain stealthy persistence.
NEW QUESTION # 350
A skilled ethical hacker was assigned to perform a thorough OS discovery on a potential target.
They decided to adopt an advanced fingerprinting technique and sent a TCP packet to an open TCP port with specific flags enabled. Upon receiving the reply, they noticed the flags were SYN and ECN-Echo. Which test did the ethical hacker conduct and why was this specific approach adopted?
- A. Test 1: The test was conducted because SYN and ECN-Echo flags enabled to allow the hacker to probe the nature of the response and subsequently determine the OS fingerprint
- B. Test 2: This test was chosen because a TCP packet with no flags enabled is known as a NULL packet and this would allow the hacker to assess the OS of the target
- C. Test 6: The hacker selected this test because a TCP packet with the ACK flag enabled sent to a closed TCP port would yield more information about the OS
- D. Test 3: The test was executed to observe the response of the target system when a packet with URC, PSH, SYN, and FIN flags was sent, thereby identifying the OS
Answer: A
NEW QUESTION # 351
Todd has been asked by the security officer to purchase a counter-based authentication system. Which of the following best describes this type of system?
- A. A biometric system that bases authentication decisions on physical attributes.
- B. An authentication system that uses passphrases that are converted into virtual passwords.
- C. An authentication system that creates one-time passwords that are encrypted with secret keys.
- D. A biometric system that bases authentication decisions on behavioral attributes.
Answer: C
NEW QUESTION # 352
A penetration tester discovers malware on a system that disguises itself as legitimate software but performs malicious actions in the background. What type of malware is this?
- A. Worm
- B. Trojan
- C. Rootkit
- D. Spyware
Answer: B
Explanation:
A Trojan masquerades as legitimate or harmless software to trick users into installing it, while secretly performing malicious actions in the background without self-replication.
NEW QUESTION # 353
While browsing his Facebook feed, Matt sees a picture one of his friends posted with the caption, "Learn more about your friends!", along with a number of personal questions. Matt is suspicious and texts his friend, who confirms that he did indeed post it. With assurance that the post is legitimate, Matt responds to the questions in the post. A few days later, Matt's bank account has been accessed, and the password has been changed. What most likely happened?
- A. Matt inadvertently provided his password when responding to the post.
- B. Matt inadvertently provided the answers to his security questions when responding to the post.
- C. Matt's bank account login information was brute forced.
- D. Matt's computer was infected with a keylogger.
Answer: B
Explanation:
This scenario demonstrates a classic social engineering tactic often referred to as "social media quizzes" or
"engagement bait", commonly used in open-source intelligence gathering (OSINT) and pretexting attacks.
From CEH v13 Module 01: Introduction to Ethical Hacking and Module 09: Social Engineering, attackers may create seemingly innocent posts that ask users to share answers to common questions like:
What was your first pet's name?
What's your mother's maiden name?
What city were you born in?
What's your favorite food?
These questions mirror the types of security questions used by banks and other services for account recovery or authentication. By answering these in public forums or comments, users unknowingly disclose data that can be used to:
Bypass security questions
Reset passwords
Perform targeted account takeovers
Why Other Options Are Incorrect:
B: Matt's bank account login information was brute forced.
Unlikely. Most banks implement account lockout policies and multi-factor authentication that would prevent brute force attempts.
C: Matt inadvertently provided his password when responding to the post.
Incorrect. Passwords are not usually asked in public-facing posts. Users are unlikely to provide literal passwords unless heavily tricked by phishing.
D: Matt's computer was infected with a keylogger.
Possible but less likely. The context suggests that the only suspicious behavior was responding to the Facebook post, which doesn't imply malware installation or downloading.
Reference from CEH v13 Study Guide and Course Material:
CEH v13 Official Module 09 - Social Engineering, Slide: Common Social Engineering Techniques (Quizzes, Pretexting) CEH Engage - Social Engineering Phase EC-Council iLabs - Performing Social Engineering Attacks Simulation CEH v13 Courseware Notes - Reconnaissance Using OSINT and Public Social Platforms
NEW QUESTION # 354
What is the common name for a vulnerability disclosure program opened by companies In platforms such as HackerOne?
- A. Vulnerability hunting program
- B. White-hat hacking program
- C. Ethical hacking program
- D. Bug bounty program
Answer: D
Explanation:
Bug bounty programs allow independent security researchers to report bugs to an companies and receive rewards or compensation. These bugs area unit sometimes security exploits and vulnerabilities, although they will additionally embody method problems, hardware flaws, and so on.
The reports area unit usually created through a program travel by associate degree freelance third party (like Bugcrowd or HackerOne). The companies can got wind of (and run) a program curated to the organization's wants.
Programs is also non-public (invite-only) wherever reports area unit unbroken confidential to the organization or public (where anyone will sign in and join). they will happen over a collection timeframe or with without stopping date (though the second possibility is a lot of common).
Who uses bug bounty programs?
Many major organizations use bug bounties as an area of their security program, together with AOL, Android, Apple, Digital Ocean, and goldman Sachs. you'll read an inventory of all the programs offered by major bug bounty suppliers, Bugcrowd and HackerOne, at these links.
Why do corporations use bug bounty programs?
Bug bounty programs provide corporations the flexibility to harness an outsized cluster of hackers so as to seek out bugs in their code.
This gives them access to a bigger variety of hackers or testers than they'd be able to access on a one-on-one basis. It {can also|also will|can even|may also|may} increase the probabilities that bugs area unit found and reported to them before malicious hackers can exploit them.
It may also be an honest publicity alternative for a firm. As bug bounties became a lot of common, having a bug bounty program will signal to the general public and even regulators that a corporation incorporates a mature security program.
This trend is likely to continue, as some have began to see bug bounty programs as an business normal that all companies ought to invest in.
Why do researchers and hackers participate in bug bounty programs?
Finding and news bugs via a bug bounty program may end up in each money bonuses and recognition. In some cases, it will be a good thanks to show real-world expertise once you are looking for employment, or will even facilitate introduce you to parents on the protection team within an companies.
This can be full time income for a few of us, income to supplement employment, or the way to point out off your skills and find a full time job.
It may also be fun! it is a nice (legal) probability to check out your skills against huge companies and government agencies.
What area unit the disadvantages of a bug bounty program for independent researchers and hackers?
A lot of hackers participate in these varieties of programs, and it will be tough to form a major quantity of cash on the platform.
In order to say the reward, the hacker has to be the primary person to submit the bug to the program. meaning that in apply, you may pay weeks searching for a bug to use, solely to be the person to report it and build no cash.
Roughly ninety seven of participants on major bug bounty platforms haven't sold-out a bug.
In fact, a 2019 report from HackerOne confirmed that out of quite three hundred,000 registered users, solely around two.5% received a bounty in their time on the platform.
Essentially, most hackers are not creating a lot of cash on these platforms, and really few square measure creating enough to switch a full time wage (plus they do not have advantages like vacation days, insurance, and retirement planning).
What square measure the disadvantages of bug bounty programs for organizations?
These programs square measure solely helpful if the program ends up in the companies realizeing issues that they weren't able to find themselves (and if they'll fix those problems)!
If the companies is not mature enough to be able to quickly rectify known problems, a bug bounty program is not the right alternative for his or her companies.
Also, any bug bounty program is probably going to draw in an outsized range of submissions, several of which can not be high-quality submissions. a corporation must be ready to cope with the exaggerated volume of alerts, and also the risk of a coffee signal to noise magnitude relation (essentially that it's probably that they're going to receive quite few unhelpful reports for each useful report).
Additionally, if the program does not attract enough participants (or participants with the incorrect talent set, and so participants are not able to establish any bugs), the program is not useful for the companies.
The overwhelming majority of bug bounty participants consider web site vulnerabilities (72%, per HackerOn), whereas solely a number of (3.5%) value more highly to seek for package vulnerabilities.
This is probably because of the actual fact that hacking in operation systems (like network hardware and memory) needs a big quantity of extremely specialised experience. this implies that firms may even see vital come on investment for bug bounties on websites, and not for alternative applications, notably those that need specialised experience.
This conjointly implies that organizations which require to look at AN application or web site among a selected time-frame may not need to rely on a bug bounty as there is no guarantee of once or if they receive reports.
Finally, it are often probably risky to permit freelance researchers to try to penetrate your network. this could end in public speech act of bugs, inflicting name harm within the limelight (which could end in individuals not eager to purchase the organizations' product or service), or speech act of bugs to additional malicious third parties, United Nations agency may use this data to focus on the organization.
NEW QUESTION # 355
What does an ACK scan mainly identify?
- A. Services
- B. Closed ports
- C. Open ports
- D. Firewall rules
Answer: D
Explanation:
An ACK scan is primarily used to determine whether ports are filtered or unfiltered by a firewall. It helps identify firewall rules and packet-filtering behavior rather than directly determining whether ports are open or closed.
NEW QUESTION # 356
A DNS server responds with different IP addresses rapidly for the same domain, pointing to constantly changing hosts. What technique is being used?
- A. DNS tunneling
- B. Fast flux
- C. DNS poisoning
- D. Zone transfer
Answer: B
Explanation:
The correct answer is C, Fast flux. Fast flux is a DNS-based evasion technique commonly associated with botnets, malware hosting, phishing infrastructure, and command-and-control resilience. In fast flux, one domain name is mapped to many rapidly changing IP addresses, often with very short DNS TTL values. This causes clients resolving the same domain to receive different destination hosts over time, making takedown, blocking, and attribution harder. CEH DNS fundamentals explain that DNS translates human-readable names into IP addresses and that DNS responses may contain address mappings that are cached according to Time-to- Live values. The described behavior-rapidly rotating IP addresses for the same domain-matches fast flux, not DNS tunneling, which hides data inside DNS queries; not DNS poisoning, which inserts false DNS records; and not zone transfer, which copies DNS zone records between servers. Therefore, the technique being used is fast flux.
NEW QUESTION # 357
In a recent cybersecurity incident, Google's response team in the United States investigated a severe attack that briefly disrupted services and customer-facing platforms for approximately 2-3 minutes. Server logs recorded a sudden surge in traffic, peaking at 398 million requests per second, which caused active connections to drop unexpectedly. The attack was traced to numerous compromised devices, likely orchestrated through malicious tools promoted on social media. Based on this information, what type of attack was most likely executed against Google's infrastructure?
- A. RST Attack
- B. TCP SACK Panic Attack
- C. HTTP GET/POST Attack
- D. SYN Flood Attack
Answer: C
Explanation:
The attack generated an extremely high volume of requests per second targeting application services, which is characteristic of an HTTP flood. Such attacks use GET or POST requests to overwhelm web servers and disrupt availability, often launched through botnets.
NEW QUESTION # 358
Null sessions are un-authenticated connections (not using a username or password.) to an NT or 2000 system.
Which TCP and UDP ports must you filter to check null sessions on your network?
- A. 137 and 139
- B. 137 and 443
- C. 139 and 445
- D. 139 and 443
Answer: C
NEW QUESTION # 359
You work for Acme Corporation as Sales Manager. The company has tight network security restrictions. You are trying to steal data from the company's Sales database (Sales.xls) and transfer them to your home computer. Your company filters and monitors traffic that leaves from the internal network to the Internet.
How will you achieve this without raising suspicion?
- A. You can conceal the Sales.xls database in another file like photo.jpg or other files and send it out in an innocent looking email or file transfer using Steganography techniques
- B. Package the Sales.xls using Trojan wrappers and telnet them back your home computer
- C. Encrypt the Sales.xls using PGP and e-mail it to your personal gmail account
- D. Change the extension of Sales.xls to sales.txt and upload them as attachment to your hotmail account
Answer: A
NEW QUESTION # 360
During a routine security audit, administrators found that cloud storage backups were illegally accessed and modified. What countermeasure would most directly mitigate such incidents in the future?
- A. Regularly conducting SQL injection testing.
- B. Deploying biometric entry systems.
- C. Implementing resource auto-scaling.
- D. Adopting the 3-2-1 backup model.
Answer: D
Explanation:
The 3-2-1 backup model ensures multiple copies of data are stored on different media, with at least one copy kept offline or immutable, which directly mitigates the risk of unauthorized access or modification of backups by providing recovery options and protecting backup integrity.
NEW QUESTION # 361
......
ECCouncil 312-50v13 Dumps Cover Real Exam Questions: https://www.exams-boost.com/312-50v13-valid-materials.html
Real 312-50v13 dumps - Real ECCouncil dumps PDF: https://drive.google.com/open?id=10LvvG3KkMO2NHbbQ1EUJ9Kflhz3zYV3d