ECcouncil certification preparation
312-50V13 Practice Questions
Practice exam-style questions, check your answers, and review explanations and source references where they are available.
- Exam
- 312-50V13
- Provider
- ECcouncil
- Full set
- 573 questions
- Last Update Check
Your network infrastructure is under a SYN flood attack. The attacker has crafted an automated
botnet to
simultaneously send 's' SYN packets per second to the server. You have put measures in place to
manage ‘f
SYN packets per second, and the system is designed to deal with this number without any
performance issues.
If 's' exceeds ‘f', the network infrastructure begins to show signs of overload. The system's response
time
increases exponentially (24k), where 'k' represents each additional SYN packet above the ff limit.
Now, considering 's=500' and different 'f values, in which scenario is the server most likely to
experience overload and significantly increased response times?
Question 1 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Robin, an attacker, is attempting to bypass the firewalls of an organization through the DNS tunneling
method in order to exfiltrate dat
a. He is using the NSTX tool for bypassing the firewalls. On which of the following ports should Robin
run the NSTX tool?
Question 2 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
In the context of password security, a simple dictionary attack involves loading a dictionary file (a text
file full of dictionary words) into a cracking application such as L0phtCrack or John the Ripper, and
running it against user accounts located by the application. The larger the word and word fragment
selection, the more effective the dictionary attack is. The brute force method is the most inclusive,
although slow. It usually tries every possible letter and number combination in its automated
exploration. If you would use both brute force and dictionary methods combined together to have
variation of words, what would you call such an attack?
Question 3 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Email is transmitted across the Internet using the Simple Mail Transport Protocol. SMTP does not
encrypt email, leaving the information in the message vulnerable to being read by an unauthorized
person. SMTP can upgrade a connection between two mail servers to use TLS. Email transmitted by
SMTP over TLS is encrypted. What is the name of the command used by SMTP to transmit email over
TLS?
Question 4 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
What is one of the advantages of using both symmetric and asymmetric cryptography in SSL/TLS?
Question 5 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Which Nmap switch helps evade IDS or firewalls?
Question 6 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A newly joined employee. Janet, has been allocated an existing system used by a previous employee.
Before issuing the system to Janet, it was assessed by Martin, the administrator. Martin found that
there were possibilities of compromise through user directories, registries, and other system
parameters. He also Identified vulnerabilities such as native configuration tables, incorrect registry or
file permissions, and software configuration errors. What is the type of vulnerability assessment
performed by Martin?
Question 7 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Based on the below log, which of the following sentences are true?
Mar 1, 2016, 7:33:28 AM 10.240.250.23 - 54373 10.249.253.15 - 22 tcp_ip
Question 8 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Your company suspects a potential security breach and has hired you as a Certified Ethical Hacker to
investigate. You discover evidence of footprinting through search engines and advanced Google
hacking techniques. The attacker utilized Google search operators to extract sensitive information.
You further notice queries that indicate the use of the Google Hacking Database (GHDB) with an
emphasis on VPN footprinting.
Which of the following Google advanced search operators would be the LEAST useful in providing the
attacker with sensitive VPN-related information?
Question 9 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
How does a denial-of-service attack work?
Question 10 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 10
Source context
How this practice set is maintained
Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.
Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.
