Exam Details

  • Exam Code
    :312-50V9
  • Exam Name
    :EC-Council Certified Ethical Hacker (C|EH v9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :614 Q&As
  • Last Updated
    :Apr 14, 2025

EC-COUNCIL EC-COUNCIL Certifications 312-50V9 Questions & Answers

  • Question 521:

    What is a NULL scan?

    A. A scan in which all flags are turned off

    B. A scan in which certain flags are off

    C. A scan in which all flags are on

    D. A scan in which the packet size is set to zero

    E. A scan with an illegal packet size

  • Question 522:

    What is the proper response for a NULL scan if the port is open?

    A. SYN

    B. ACK

    C. FIN

    D. PSH

    E. RST

    F. No response

  • Question 523:

    Which of the following statements about a zone transfer is correct? (Choose three.)

    A. A zone transfer is accomplished with the DNS

    B. A zone transfer is accomplished with the nslookup service

    C. A zone transfer passes all zone information that a DNS server maintains

    D. A zone transfer passes all zone information that a nslookup server maintains

    E. A zone transfer can be prevented by blocking all inbound TCP port 53 connections

    F. Zone transfers cannot occur on the Internet

  • Question 524:

    Sandra has been actively scanning the client network on which she is doing a vulnerability assessment

    test.

    While conducting a port scan she notices open ports in the range of 135 to 139.

    What protocol is most likely to be listening on those ports?

    A. Finger

    B. FTP C. Samba

    D. SMB

  • Question 525:

    SNMP is a protocol used to query hosts, servers, and devices about performance or health status data. This protocol has long been used by hackers to gather great amount of information about remote hosts. Which of the following features makes this possible? (Choose two.)

    A. It used TCP as the underlying protocol.

    B. It uses community string that is transmitted in clear text.

    C. It is susceptible to sniffing.

    D. It is used by all network devices on the market.

  • Question 526:

    Which of the following command line switch would you use for OS detection in Nmap?

    A. -D

    B. -O

    C. -P

    D.璛

  • Question 527:

    Why would an attacker want to perform a scan on port 137?

    A. To discover proxy servers on a network

    B. To disrupt the NetBIOS SMB service on the target host

    C. To check for file and print sharing on Windows systems

    D. To discover information about a target host using NBTSTAT

  • Question 528:

    Which Type of scan sends a packets with no flags set?

    A. Open Scan

    B. Null Scan

    C. Xmas Scan

    D. Half-Open Scan

  • Question 529:

    Study the log below and identify the scan type.

    A. nmap -sR 192.168.1.10

    B. nmap -sS 192.168.1.10

    C. nmap -sV 192.168.1.10

    D. nmap -sO -T 192.168.1.10

  • Question 530:

    You have initiated an active operating system fingerprinting attempt with nmap against a target system: What operating system is the target host running based on the open ports shown above?

    A. Windows XP

    B. Windows 98 SE

    C. Windows NT4 Server

    D. Windows 2000 Server

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-50V9 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.