Exam Details

  • Exam Code
    :312-50V9
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :614 Q&As
  • Last Updated
    :Apr 14, 2025

EC-COUNCIL EC-COUNCIL Certifications 312-50V9 Questions & Answers

  • Question 161:

    Which of the following types of firewall inspects only header information in network traffic?

    A. Packet filter

    B. Stateful inspection

    C. Circuit-level gateway

    D. Application-level gateway

  • Question 162:

    The precaution of prohibiting employees from bringing personal computing devices into a facility is what type of security control?

    A. Physical

    B. Procedural

    C. Technical

    D. Compliance

  • Question 163:

    A pentester gains access to a Windows application server and needs to determine the settings of the built-in Windows firewall. Which command would be used?

    A. Netsh firewall show config

    B. WMIC firewall show config

    C. Net firewall show config

    D. Ipconfig firewall show config

  • Question 164:

    During a penetration test, a tester finds a target that is running MS SQL 2000 with default credentials. The tester assumes that the service is running with Local System account. How can this weakness be exploited to access the system?

    A. Using the Metasploit psexec module setting the SA / Admin credential

    B. Invoking the stored procedure xp_shell to spawn a Windows command shell

    C. Invoking the stored procedure cmd_shell to spawn a Windows command shell

    D. Invoking the stored procedure xp_cmdshell to spawn a Windows command shell

  • Question 165:

    What is the main difference between a "Normal" SQL Injection and a "Blind" SQL Injection vulnerability?

    A. The request to the web server is not visible to the administrator of the vulnerable application.

    B. The attack is called "Blind" because, although the application properly filters user input, it is still vulnerable to code injection.

    C. The successful attack does not show an error message to the administrator of the affected application.

    D. The vulnerable application does not display errors with information about the injection results to the attacker.

  • Question 166:

    One way to defeat a multi-level security solution is to leak data via

    A. a bypass regulator.

    B. steganography.

    C. a covert channel.

    D. asymmetric routing.

  • Question 167:

    Which of the following conditions must be given to allow a tester to exploit a Cross-Site Request Forgery (CSRF) vulnerable web application?

    A. The victim user must open the malicious link with an Internet Explorer prior to version 8.

    B. The session cookies generated by the application do not have the HttpOnly flag set.

    C. The victim user must open the malicious link with a Firefox prior to version 3.

    D. The web application should not use random tokens.

  • Question 168:

    What is the name of the international standard that establishes a baseline level of confidence in the security functionality of IT products by providing a set of requirements for evaluation?

    A. Blue Book

    B. ISO 26029

    C. Common Criteria

    D. The Wassenaar Agreement

  • Question 169:

    Which type of antenna is used in wireless communication?

    A. Omnidirectional

    B. Parabolic

    C. Uni-directional

    D. Bi-directional

  • Question 170:

    During a wireless penetration test, a tester detects an access point using WPA2 encryption. Which of the following attacks should be used to obtain the key?

    A. The tester must capture the WPA2 authentication handshake and then crack it.

    B. The tester must use the tool inSSIDer to crack it using the ESSID of the network.

    C. The tester cannot crack WPA2 because it is in full compliance with the IEEE 802.11i standard.

    D. The tester must change the MAC address of the wireless network card and then use the AirTraf tool to obtain the key.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V9 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.