Exam Details

  • Exam Code
    :312-50
  • Exam Name
    :Certified Ethical Hacker
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :614 Q&As
  • Last Updated
    :Apr 16, 2025

EC-COUNCIL EC-COUNCIL Certifications 312-50 Questions & Answers

  • Question 311:

    How would you prevent session hijacking attacks?

    A. Using biometrics access tokens secures sessions against hijacking

    B. Using non-Internet protocols like http secures sessions against hijacking

    C. Using hardware-based authentication secures sessions against hijacking

    D. Using unpredictable sequence numbers secures sessions against hijacking

  • Question 312:

    You want to carry out session hijacking on a remote server. The server and the client are communicating via TCP after a successful TCP three way handshake. The server has just received packet #120 from the client. The client has a receive window of 200 and the server has a receive window of 250. Within what range of sequence numbers should a packet, sent by the client fall in order to be accepted by the server?

    A. 200-250

    B. 121-371

    C. 120-321

    D. 121-231

    E. 120-370

  • Question 313:

    What is Hunt used for?

    A. Hunt is used to footprint networks

    B. Hunt is used to sniff traffic

    C. Hunt is used to hack web servers

    D. Hunt is used to intercept traffic i.e. man-in-the-middle traffic

    E. Hunt is used for password cracking

  • Question 314:

    Which is the right sequence of packets sent during the initial TCP three way handshake?

    A. FIN, FIN-ACK, ACK

    B. SYN, URG, ACK

    C. SYN, ACK, SYN-ACK

    D. SYN, SYN-ACK, ACK

  • Question 315:

    What type of cookies can be generated while visiting different web sites on the Internet?

    A. Permanent and long term cookies.

    B. Session and permanent cookies.

    C. Session and external cookies.

    D. Cookies are all the same, there is no such thing as different type of cookies.

  • Question 316:

    What is the key advantage of Session Hijacking?

    A. It can be easily done and does not require sophisticated skills.

    B. You can take advantage of an authenticated connection.

    C. You can successfully predict the sequence number generation.

    D. You cannot be traced in case the hijack is detected.

  • Question 317:

    John is using tokens for the purpose of strong authentication. He is not confident that his security is considerably strong.

    In the context of Session hijacking why would you consider this as a false sense of security?

    A. The token based security cannot be easily defeated.

    B. The connection can be taken over after authentication.

    C. A token is not considered strong authentication.

    D. Token security is not widely used in the industry.

  • Question 318:

    Bob is going to perform an active session hijack against company. He has acquired the target that allows session oriented connections (Telnet) and performs sequence prediction on the target operating system. He manages to find an active session due to the high level of traffic on the network.

    So, what is Bob most likely to do next?

    A. Take over the session.

    B. Reverse sequence prediction.

    C. Guess the sequence numbers.

    D. Take one of the parties' offline.

  • Question 319:

    Barney is looking for a Windows NT/2000/XP command-line tool that can be used to assign display or modify ACLs (Access Control Lists) to files or folders and that could also be used within batch files. Which of the following tools could be used for this purpose?

    A. PERM.EXE

    B. CACLS.EXE

    C. CLACS.EXE

    D. NTPERM.EXE

  • Question 320:

    Data is sent over the network as clear text (unencrypted) when Basic Authentication is configured on Web Servers.

    A. True

    B. False

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.