Updated Nov 16, 2021 Verified 312-50v10 dumps Q&As - 100% Pass [Q298-Q317]

Share

Updated Nov 16, 2021 Verified 312-50v10 dumps Q&As - 100% Pass

New 2021 Latest Questions 312-50v10 Dumps - Use Updated EC-COUNCIL Exam


How to study the 312-50v10 Exam

Exams4sures expert team recommends you to prepare some notes on these topics along with it don’t forget to practice EC Council Certified Ethical Hacker v10 Exam 312-50v10 Exam which been written by our expert team, Both these will help you a lot to clear this exam with good marks.


Target Audience and Prerequisites

Putting hard-work in acing the EC-Council 312-50v10 test will bring the most benefits for professionals working in job roles like security officers, security professionals, auditors, and site administrators. Appearing for this exam is only possible if the application process is completed triumphantly. Each candidates has to pass through this phase. Additionally, industry experts insinuate taking-up the associated training to make this learning journey a lot more uncomplicated.

 

NEW QUESTION 298
Which of the following is a primary service of the U.S. Computer Security Incident Response Team (CSIRT)?

  • A. CSIRT provides a penetration testing service to support exception reporting on incidents worldwide by individuals and multi-national corporations.
  • B. CSIRT provides a computer security surveillance service to supply a government with important intelligence information on individuals travelling abroad.
  • C. CSIRT provides a vulnerability assessment service to assist law enforcement agencies with profiling an individual's property or company's asset.
  • D. CSIRT provides an incident response service to enable a reliable and trusted single point of contact for reporting computer security incidents worldwide.

Answer: D

 

NEW QUESTION 299
Which access control mechanism allows for multiple systems to use a central authentication server (CAS)
that permits users to authenticate once and gain access to multiple systems?

  • A. Discretionary Access Control (DAC)
  • B. Windows authentication
  • C. Single sign-on
  • D. Role Based Access Control (RBAC)

Answer: C

 

NEW QUESTION 300
WPA2 uses AES for wireless data encryption at which of the following encryption levels?

  • A. 128 bit and CRC
  • B. 128 bi and TKIP
  • C. 128 bit and CCMP
  • D. 64 bit and CCMP

Answer: C

 

NEW QUESTION 301
For messages sent through an insecure channel, a properly implemented digital signature gives the receiver reason to believe the message was sent by the claimed sender. While using a digital signature, the message digest is encrypted with which key?

  • A. Receiver's private key
  • B. Receiver's public key
  • C. Sender's public key
  • D. Sender's private key

Answer: D

 

NEW QUESTION 302
Study the following log extract and identify the attack.

  • A. Unicode Directory Traversal Attack
  • B. Multiple Domain Traversal Attack
  • C. Cross Site Scripting
  • D. Hexcode Attack

Answer: A

 

NEW QUESTION 303
What term describes the amount of risk that remains after the vulnerabilities are classified and the countermeasures have been deployed?

  • A. Deferred risk
  • B. Impact risk
  • C. Inherent risk
  • D. Residual risk

Answer: D

Explanation:
The residual risk is the risk or danger of an action or an event, a method or a (technical) process that, although being abreast with science, still conceives these dangers, even if all theoretically possible safety measures would be applied (scientifically conceivable measures); in other words, the amount of risk left over after natural or inherent risks have been reduced by risk controls.
References: https://en.wikipedia.org/wiki/Residual_risk

 

NEW QUESTION 304
Which of the following scanning method splits the TCP header into several packets and makes it difficult for packet filters to detect the purpose of the packet?

  • A. IPID scanning
  • B. SYN/FIN scanning using IP fragments
  • C. ICMP Echo scanning
  • D. ACK flag probe scanning

Answer: B

 

NEW QUESTION 305
Which of the following LM hashes represent a password of less than 8 characters? (Choose two.)

  • A. BA810DBA98995F1817306D272A9441BB
  • B. CEC52EB9C8E3455DC2265B23734E0DAC
  • C. 44EFCE164AB921CQAAD3B435B51404EE
  • D. 0182BD0BD4444BF836077A718CCDF409
  • E. E52CAC67419A9A224A3B108F3FA6CB6D
  • F. B757BF5C0D87772FAAD3B435B51404EE

Answer: C,F

 

NEW QUESTION 306
Alice encrypts her data using her public key PK and stores the encrypted data in the cloud.
Which of the following attack scenarios will compromise the privacy of her data?

  • A. Hacker Harry breaks into the cloud server and steals the encrypted data
  • B. None of these scenarios compromise the privacy of Alice's data
  • C. Agent Andrew subpoenas Alice, forcing her to reveal her private key. However, the cloud server successfully resists Andrew's attempt to access the stored data
  • D. Alice also stores her private key in the cloud, and Harry breaks into the cloud server as before

Answer: D

 

NEW QUESTION 307
Bob is going to perform an active session hijack against Brownies Inc. He has found a target that allows session oriented connections (Telnet) and performs the sequence prediction on the target operating system. He manages to find an active session due to the high level of traffic on the network. What is Bob supposed to do next?

  • A. Guess the sequence numbers
  • B. Reverse sequence prediction
  • C. Take one of the parties offline
  • D. Take over the session

Answer: A

 

NEW QUESTION 308
What does a type 3 code 13 represent? (Choose two.)

  • A. Administratively prohibited
  • B. Network unreachable
  • C. Echo request
  • D. Time exceeded
  • E. Port unreachable
  • F. Destination unreachable

Answer: A,F

 

NEW QUESTION 309
In order to show improvement of security over time, what must be developed?

  • A. Reports
  • B. Taxonomy of vulnerabilities
  • C. Metrics
  • D. Testing tools

Answer: C

Explanation:
Explanation
Today, management demands metrics to get a clearer view of security.
Metrics that measure participation, effectiveness, and window of exposure, however, offer information the organization can use to make plans and improve programs.
References:
http://www.infoworld.com/article/2974642/security/4-security-metrics-that-matter.html

 

NEW QUESTION 310
Which of the following cryptography attack methods is usually performed without the use of a computer?

  • A. Rubber hose attack
  • B. Rainbow table attack
  • C. Ciphertext-only attack
  • D. Chosen key attack

Answer: A

 

NEW QUESTION 311
It is a widely used standard for message logging. It permits separation of the software that generates messages, the system that stores them, and the software that reports and analyzes them. This protocol is specifically designed for transporting event messages. Which of the following is being described?

  • A. SNMP
  • B. ICMP
  • C. SMS
  • D. SYSLOG

Answer: D

 

NEW QUESTION 312
A penetration tester is attempting to scan an internal corporate network from the internet without alerting the border sensor. Which is the most efficient technique should the tester consider using?

  • A. Scanning using fragmented IP packets
  • B. Tunneling over high port numbers
  • C. Spoofing an IP address
  • D. Tunneling scan over SSH

Answer: D

 

NEW QUESTION 313
Which Type of scan sends a packets with no flags set?

  • A. Open Scan
  • B. Null Scan
  • C. Half-Open Scan
  • D. Xmas Scan

Answer: B

 

NEW QUESTION 314
What tool should you use when you need to analyze extracted metadata from files you collected when you were in the initial stage of penetration test (information gathering)?

  • A. cdpsnarf
  • B. Dimitry
  • C. Armitage
  • D. Metagoofil

Answer: D

 

NEW QUESTION 315
What is the best description of SQL Injection?

  • A. It is an attack used to gain unauthorized access to a database.
  • B. It is an attack used to modify code in an application.
  • C. It is a Denial of Service Attack.
  • D. It is a Man-in-the-Middle attack between your SQL Server and Web App Server.

Answer: A

Explanation:
SQL injection is a code injection technique, used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution (e.g. to dump the database contents to the attacker).
References: https://en.wikipedia.org/wiki/SQL_injection

 

NEW QUESTION 316
A company firewall engineer has configured a new DMZ to allow public systems to be located away from the internal network. The engineer has three security zones set:

The engineer wants to configure remote desktop access from a fixed IP on the remote network to a remote desktop server in the DMZ. Which rule would best fit this requirement?

  • A. Permit 217.77.88.12 11.12.13.50 RDP 3389
  • B. Permit 217.77.88.12 11.12.13.0/24 RDP 3389
  • C. Permit 217.77.88.0/24 11.12.13.0/24 RDP 3389
  • D. Permit 217.77.88.0/24 11.12.13.50 RDP 3389

Answer: A

 

NEW QUESTION 317
......

Latest 312-50v10 Exam Dumps EC-COUNCIL Exam from Training: https://www.exams4sures.com/EC-COUNCIL/312-50v10-practice-exam-dumps.html