ECCouncil 312-50v13 Exam Overview:
| Certification Vendor: | EC-Council |
| Exam Name: | Certified Ethical Hacker (CEH) Exam |
| Exam Number: | 312-50v13 |
| Exam Format: | Multiple Choice, Drag & Drop, Hands-on Performance Based |
| Exam Duration: | 240 minutes |
| Available Languages: | English |
| Certificate Validity Period: | 3 years |
| Passing Score: | 70% |
| Real Exam Qty: | 125 |
| Exam Price: | USD 1,199 |
| Related Certifications: | CEH (Master) |
| Sample Questions: | ECCouncil 312-50v13 Sample Questions |
| Exam Way: | In-person at Pearson VUE testing centers or Online Proctored (OnVue) |
| Pre Condition: | Mandatory: 2 years of work experience in the domain OR completion of an EC-Council official training. For candidates without experience, an alternative is to take the CEH exam and submit an exam eligibility application with USD 100 fee. |
| Official Syllabus URL: | https://www.eccouncil.org/certifications/certified-ethical-hacker/ |
ECCouncil 312-50v13 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Cloud and Container Attacks | 10% | - Cloud Attacks and Security
|
| Wireless Network Attacks | 9% | - Wireless Network Concepts
|
| Mobile Platform and IoT Attacks | 7% | - IoT and OT Attacks
|
| System Hacking | 17% | - System Hacking Tools and Countermeasures
|
| Enumeration | 15% | - Enumeration Process
|
| Vulnerability Analysis | 7% | - Vulnerability Assessment Concepts
|
| Information Security and Ethical Hacking Overview | 6% | - Information Security Overview
|
| Web Application Attacks | 19% | - Web Application Concepts and Attacks
|
| Malware Threats | 8% | - Malware and Its Types
|
| Sniffing and Evasion | 10% | - Social Engineering
|
| Cryptography and Post-Exploitation | 13% | - Cryptography Concepts
|
| Reconnaissance Techniques | 21% | - Footprinting and Reconnaissance
|
ECCouncil Certified Ethical Hacker Exam (CEHv13) Sample Questions:
1. An attacker places a malicious VM on the same physical server as a target VM in a multi-tenant cloud environment. The attacker then extracts cryptographic keys using CPU timing analysis.
What type of attack was conducted?
A) Side-channel attack
B) Cache poisoned denial of service (CPDoS)
C) Metadata spoofing
D) Cloud cryptojacking
2. A penetration tester is tasked with mapping an organization's network while avoiding detection by sophisticated intrusion detection systems (IDS). The organization employs advanced IDS capable of recognizing common scanning patterns. Which scanning technique should the tester use to effectively discover live hosts and open ports without triggering the IDS?
A) Perform an ICMP Echo scan to ping all network devices
B) Conduct a TCP Connect scan using randomized port sequences
C) Execute a FIN scan by sending TCP packets with the FIN flag set
D) Use an Idle scan leveraging a third-party zombie host
3. You are using a public Wi-Fi network inside a coffee shop. Before surfing the web, you use your VPN to prevent intruders from sniffing your traffic. If you did not have a VPN, how would you identify whether someone is performing an ARP spoofing attack on your laptop?
A) You should use netstat to check for any suspicious connections with another IP address within the LAN.
B) You cannot identify such an attack and must use a VPN to protect your traffic.
C) You should check your ARP table and see if there is one IP address with two different MAC addresses.
D) You should scan the network using Nmap to check the MAC addresses of all the hosts and look for duplicates.
4. Ethical hacker Jane Smith is attempting to perform an SQL injection attack. She wants to test the response time of a true or false response and wants to use a second command to determine whether the database will return true or false results for user IDs. Which two SQL injection types would give her the results she is looking for?
A) Time-based and union-based
B) Union-based and error-based
C) Out of band and boolean-based
D) Time-based and boolean-based
5. A penetration tester is assessing a company's executive team for vulnerability to sophisticated social engineering attacks by impersonating a trusted vendor and leveraging internal communications. What is the most effective social engineering technique to obtain sensitive executive credentials without being detected?
A) Develop a fake social media profile to connect with executives and request private information
B) Conduct a phone call posing as the CEO to request immediate password changes from executives
C) Send a mass phishing email with a malicious link disguised as a company-wide update
D) Create a targeted spear-phishing email that references recent internal projects and requests credential verification
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: D | Question # 3 Answer: D | Question # 4 Answer: B | Question # 5 Answer: D |

We're so confident of our products that we provide no hassle product exchange.


By Elizabeth


