Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free EC-Council Certified Ethical Hacker 312-50 Exam Questions

Page: 1 / 62 Total 924 questions

Want more questions? Get Premium Access.

Question 1

Which of the following is one primary difference between a malicious hacker and an ethical hacker?

Correct Answer: D. Ethical hackers use the same methods but strive to do no harm.
Explanation:

The correct answer is D. Ethical hackers use the same methods but strive to do no harm. CEH-aligned guidance emphasizes that a Certified Ethical Hacker understands weaknesses and vulnerabilities and uses the same knowledge and tools as a malicious hacker, but in a lawful and legitimate manner to assess the security posture of target systems. The key difference is not the toolset or technical method; it is authorization, purpose, scope, and intent. Ethical hackers operate with the customer's approval, follow rules of engagement, document findings, and work to improve security. Malicious hackers use similar skills and tools for personal gain, destruction, data theft, or activity outside the owner's interest. Option A is incorrect because ethical and malicious hackers may use the same tools. Option B is misleading because ethical hackers do not obtain permission to steal data or intentionally bring down systems outside agreed scope. Option C is incorrect because malicious hackers are not inherently more advanced. Therefore, D is the best answer.


Question 2

During a penetration test at a shipping company in Miami, ethical hacker Daniel delivers a disguised email attachment containing a hidden payload. Once executed by employees, the compromised workstations begin to silently communicate with a remote server under Daniel's control. Over the following week, he confirms that multiple infected endpoints can receive synchronized commands and perform background tasks simultaneously, including sending bursts of outbound traffic on demand.

Which type of malicious component is Daniel most likely simulating in this assessment?

Correct Answer: B. Botnet Agents
Explanation:

The correct answer is B. Botnet Agents because the behavior described matches a command-and-control (C2) driven malware model where multiple compromised systems (''bots'' or ''zombies'') communicate with a remote controller and can be issued coordinated commands. In CEH-aligned malware concepts, a botnet is a collection of infected endpoints under centralized or distributed control. The malicious component installed on each infected workstation is commonly referred to as a bot/bot agent, which ''checks in'' to a C2 server to receive instructions and execute tasks silently in the background.

Several details strongly indicate botnet agent behavior: the payload is delivered via a disguised email attachment (a common initial infection vector), compromised machines silently communicate outbound to a remote server, and---most importantly---Daniel confirms multiple infected endpoints can receive synchronized commands and carry out actions simultaneously. The example of ''sending bursts of outbound traffic on demand'' aligns with typical botnet capabilities such as orchestrated DDoS traffic generation, mass scanning, spam sending, credential stuffing, or distributed task execution. The sustained observation ''over the following week'' also fits a botnet model where infected hosts maintain persistence and periodically beacon to C2 for updates and instructions.

Why the other options do not fit: Spyware primarily focuses on covertly collecting information (keystrokes, screenshots, browsing data) rather than executing synchronized commands across many machines. Scareware relies on alarming messages to trick users into paying or installing unwanted software; it does not describe silent C2 coordination. PUAs are typically unwanted but not necessarily malicious, often installed via bundling and usually lack structured C2 for coordinated remote command execution.

Therefore, the malicious component being simulated is best identified as botnet agents operating under C2 control.


Question 3

During a red team assessment at New England Insurance in Boston, ethical hacker Daniel sends a series of spoofed TCP packets carrying the reset flag to a server hosting client applications. As a result, several active sessions between employees and the server are abruptly terminated, causing temporary disruption of legitimate work. Daniel uses this demonstration to highlight how attackers can forcibly tear down sessions without completing a full hijack.

Which type of network-level session hijacking technique is Daniel simulating?

Correct Answer: B. RST Hijacking
Explanation:

The technique described is RST hijacking because the attacker sends spoofed TCP packets with the RST (reset) flag to forcibly terminate established TCP sessions. In TCP, an RST packet is used to immediately abort a connection. If an attacker can craft packets that appear to belong to an existing session (matching the 4-tuple and using plausible sequence/acknowledgment values), the receiving endpoint may accept the reset and tear down the connection. This creates disruption---sessions drop, users are disconnected, and applications experience errors---without the attacker needing to fully take over the session or inject meaningful application data.

The scenario matches this exactly: ''spoofed TCP packets carrying the reset flag,'' followed by ''active sessions...abruptly terminated.'' That is the hallmark outcome of RST-based session disruption. It is often used as a demonstration of how fragile sessions can be when attackers can spoof traffic within a path (or on the same network segment) and when defensive controls do not validate or protect sessions adequately.

Why the other options are incorrect:

UDP hijacking (A) doesn't apply because UDP is connectionless and has no RST flag or session teardown mechanism like TCP.

Blind hijacking (C) refers to injecting traffic without seeing responses (guessing sequence numbers), but the specific mechanism asked here is the reset-flag termination; ''blind'' could be a property of how it's done, not the named technique.

TCP/IP hijacking (D) is a broader category that includes multiple methods of taking over or manipulating TCP sessions. The question is specifically about using RST packets to kill sessions, which is most precisely called RST hijacking.

Therefore, the correct answer is B. RST Hijacking.


Question 4

In the sunlit tech oasis of Phoenix, Arizona, ethical hacker Nadia Patel explores the security posture of LearnSphere, a U.S.-based e-learning platform serving thousands of students. During her testing, Nadia intentionally submits invalid inputs to the platform's content delivery system. Instead of returning a generic failure notice, the application responds with detailed system information, including database query strings and directory paths. Such responses provide attackers with valuable insights into the application's internal workings, which could be used to craft more precise and damaging attacks.

Which issue is being demonstrated?

Correct Answer: C. Verbose Error Messages
Explanation:

The issue described is verbose error messages, where an application reveals excessive technical details when handling invalid input. The scenario states that the platform returns ''detailed system information, including database query strings and directory paths'' instead of a generic error. Exposing internal paths and query strings is a common symptom of verbose error handling: stack traces, SQL statements, file system locations, framework versions, and configuration hints can appear in responses when exception handling is misconfigured or when debug settings are enabled in production.

These details are valuable to attackers because they reduce guesswork. Directory paths can reveal the operating system, deployment layout, and sensitive file locations; database query strings can reveal table/column names and query structure, enabling more effective SQL injection payloads or targeted data extraction. Verbose errors can also leak usernames, internal hostnames, API endpoints, and even secrets if mishandled. Even if the initial invalid request does not compromise the system, the leaked information can significantly improve the attacker's ability to craft subsequent attacks with higher precision.

Why the other options are less accurate:

Improper error handling (A) is a broader category and could include verbose errors, but the question's best match is the specific symptom: detailed internal information disclosure.

Directory traversal (B) involves manipulating path input to access unauthorized files; here, the application is revealing paths due to errors, not being coerced into reading arbitrary files.

CORS misconfiguration (D) relates to cross-origin browser access controls and is unrelated to leaking stack traces or database queries.

Therefore, the correct answer is C. Verbose Error Messages.


Question 5

Malware remains dormant until triggered and changes its code with each infection. What malware type is responsible, and how should it be mitigated?

Correct Answer: B. Polymorphic malware
Explanation:

This scenario precisely matches polymorphic malware, a type of advanced malware described in CEH v13 Malware Threats. Polymorphic malware dynamically alters its code, encryption, or signature each time it propagates, allowing it to evade traditional signature-based antivirus detection.

Additionally, the malware's ability to remain dormant until triggered indicates logic-based activation, which is common in advanced threats designed to avoid sandbox detection.

CEH v13 emphasizes that polymorphic malware cannot be reliably detected using static signatures. Instead, organizations must rely on behavior-based detection, heuristic analysis, and advanced threat protection systems capable of identifying suspicious runtime behavior.

Options A, C, and D do not match the described behavior. Adware focuses on advertising. Worms self-propagate aggressively. Rootkits focus on stealth and persistence, not code mutation.

Therefore, Option B is the correct answer.


Question 6

During a strategic security briefing at Meridian Global Analytics in Washington, D.C., executives review a series of coordinated activities targeting national infrastructure. These activities include manipulating digital media to influence public perception, disrupting communication networks, and degrading critical systems to weaken institutional stability without direct conventional military engagement.

What form of conflict best describes this type of coordinated activity?

Correct Answer: B. Information Warfare
Explanation:

The correct answer is B. Information Warfare.

The scenario describes the strategic use of information, communication systems, digital influence, and disruption of critical systems to gain an advantage over an opponent. This aligns with Information Warfare.

CEH-aligned material defines information warfare as the use of information and communication technology to gain an advantage over an opponent or enemy. It also explains that offensive information warfare prevents, modifies, or disrupts information and information-based processes by affecting confidentiality, integrity, and availability .

Option A. Cyber Espionage is incorrect because espionage focuses mainly on stealing information, not broadly manipulating perception and degrading infrastructure.

Option C. Hacktivism is incorrect because hacktivism is usually ideologically or politically motivated activism using hacking techniques.

Option D. Cyberterrorism is incorrect because cyberterrorism is intended to create fear, panic, or violence for political or ideological objectives. The broader coordinated use of information and communication capabilities is best classified as information warfare.

Therefore, the best answer is B. Information Warfare.


Question 7

A health-tech startup in Raleigh, North Carolina operates a Kubernetes cluster supporting patient-facing microservices. During an authorized security assessment, a certified ethical hacker reviews internal cluster activity records available to operations personnel.

While analyzing these records, the tester notices that authentication artifacts associated with service accounts are recorded within system-generated output. The tester determines that if an individual obtained access to these records, they could reuse the captured authentication material to interact with cluster resources under the same privileges.

Which Kubernetes vulnerability best corresponds to this condition?

Correct Answer: D. Exposed Bearer Tokens in Logs
Explanation:

The correct answer is D. Exposed Bearer Tokens in Logs.

The scenario states that authentication artifacts associated with Kubernetes service accounts are appearing in logs or system-generated output. If those values can be reused to access cluster resources, they are functioning as bearer credentials. A bearer token grants access to whoever possesses it, so exposing it in logs creates a serious privilege-reuse risk.

Option A. No Certificate Revocation is incorrect because the weakness does not involve inability to revoke TLS or client certificates.

Option B. Unauthenticated HTTPS Connections is incorrect because the issue is not that HTTPS connections lack authentication. The issue is that valid authentication tokens are being logged.

Option C. No Non-repudiation is incorrect because non-repudiation concerns proving who performed an action. The scenario concerns credential exposure.

Option D. Exposed Bearer Tokens in Logs is correct because service-account bearer tokens recorded in logs could be reused by anyone who can access those logs.

Therefore, the best answer is D. Exposed Bearer Tokens in Logs.


Question 8

During a quarterly vulnerability management review at RedCore Motors, Priya finalizes the deployment of Nessus Essentials across the company's IT infrastructure. The solution is selected for its ability to support diverse technologies including operating systems, databases, web servers, and virtual environments. While preparing a training session for junior analysts, Priya asks them to identify a capability that Nessus Essentials is specifically designed to provide as part of its scanning process.

Correct Answer: B. Checks for outdated versions of over 1,250 servers
Explanation:

The correct answer is Checks for outdated versions of over 1,250 servers. In CEH vulnerability assessment coverage, Nessus Essentials is presented as a vulnerability scanning solution that can assess a wide variety of technologies, including operating systems, web servers, databases, network devices, and virtualized environments. Its core role is identifying weaknesses, missing patches, insecure configurations, and exposure conditions across supported platforms. The option about checking outdated versions across a very broad range of server technologies best reflects that scanner-oriented capability. Patch management is not the primary function of Nessus Essentials, because it identifies vulnerabilities rather than directly managing patch deployment. Agent-based detection may be used in some security products, but that is not the defining capability highlighted in this CEH-style framing. High-speed asset discovery is a feature associated more strongly with specialized discovery platforms, whereas Nessus is centered on vulnerability enumeration and assessment. CEH study material emphasizes understanding the purpose of common security tools, and Nessus is generally classified as a scanner that detects outdated software versions and known vulnerabilities so remediation can be prioritized across the environment. That is why option B is the most accurate fit.


Question 9

In a controlled testing environment in Houston, Sarah, an ethical hacker, is tasked with evaluating the security posture of a financial firm's network using the cyber kill chain methodology. She begins by simulating an attack, starting with gathering publicly available data about the company's employees and infrastructure. Next, she plans to craft a mock phishing email to test employee responses, followed by deploying a harmless payload to assess system vulnerabilities. As part of her authorized penetration test, what phase of the cyber kill chain should Sarah prioritize to simulate the adversary's approach effectively?

Correct Answer: B. Reconnaissance
Explanation:

Reconnaissance is the correct phase because the scenario explicitly states Sarah starts by gathering publicly available information about employees and infrastructure. In the Cyber Kill Chain, reconnaissance is the first phase where an attacker collects intelligence to understand the target and identify the most effective paths for compromise. In CEH-aligned methodology, this includes open-source intelligence activities such as discovering employee names, roles, emails, technology stack clues, exposed services, and organizational patterns that help craft realistic and convincing attack lures.

The question mentions that Sarah plans to craft a mock phishing email and later deploy a harmless payload. Those actions map to later kill chain phases: delivery is when the phishing email or malicious link is sent to the target, and exploitation is when a vulnerability is triggered to execute code or gain access. Weaponization is the step where an attacker prepares the malicious artifact, such as packaging an exploit with a payload or preparing a document or link to deliver. However, the key wording is that Sarah ''begins'' by collecting public information and is asked which phase she should prioritize to simulate the adversary's approach effectively. That is reconnaissance, because effective phishing and subsequent steps depend on accurate target profiling, believable pretexts, and identifying likely weak points based on what is learned during intelligence gathering.

Therefore, to match the described starting point and the kill chain sequence, the prioritized phase is Reconnaissance.


Question 10

During a penetration test at a logistics company in Atlanta, Georgia, you examine the configuration of network devices and discover that they rely on legacy communication mechanisms lacking encryption and integrity checks. These mechanisms allow neighboring systems to exchange operational data without verification, exposing the infrastructure to potential manipulation. What type of vulnerability is most clearly present?

Correct Answer: D. Insecure routing protocols
Explanation:

The best answer is D. Insecure routing protocols because the scenario describes legacy neighbor-to-neighbor device communications that lack encryption and integrity validation, allowing operational routing data to be exchanged without verification. In CEH-aligned network hacking concepts, this is a classic weakness of older or improperly secured routing protocols (and related network control-plane exchanges) where routers trust updates from neighbors and do not cryptographically validate the authenticity and integrity of routing information.

When routing updates are accepted without strong verification, an attacker who can position themselves on the same segment (or spoof a trusted neighbor) may inject or manipulate routing information. This can enable attacks such as route injection, route poisoning, man-in-the-middle (MITM) traffic redirection, blackholing traffic, or causing instability/denial of service by continuously advertising bad routes. The mention of ''neighboring systems'' and ''operational data'' strongly maps to routing adjacencies where devices exchange reachability and topology information. The absence of integrity checks makes it feasible to alter routing messages in transit or forge them, and the absence of encryption can expose routing details that further assists reconnaissance and targeted manipulation.

Why the other options are less accurate:

Firewall vulnerabilities relate to filtering and policy enforcement, but the core issue here is the trust model and protection of routing/control messages, not firewall rule flaws.

Lack of password protection is too generic and typically refers to weak/no credentials on management access, not unauthenticated routing exchanges.

Lack of authentication is conceptually related, but the question asks for the type of vulnerability most clearly present given ''legacy communication mechanisms'' between neighbors carrying operational data---this is most specifically categorized in CEH terms as insecure routing protocols (i.e., routing updates lacking authentication/integrity and sometimes encryption).

In practice, organizations mitigate this by enabling routing protocol authentication (where supported), using cryptographic integrity protections, restricting routing adjacencies, and segmenting or filtering routing/control-plane traffic to trusted peers only.


Question 11

In downtown Chicago, Illinois, security analyst Mia Torres investigates a breach at Windy City Enterprises, a logistics firm running an Apache HTTP Server. The attacker exploited a known vulnerability in an outdated version, gaining unauthorized access to customer shipment data. Mia's analysis reveals the server lacked recent security updates, leaving it susceptible to remote code execution. Determined to prevent future incidents, Mia recommends a strategy to the IT team to address this exposure.

Which approach should Mia recommend to secure Windy City Enterprises' Apache HTTP Server against such vulnerabilities?

Correct Answer: D. Conduct an extensive risk assessment to determine which segments of the network are most vulnerable or at high risk that need to be patched first
Explanation:

The correct answer is D because the root cause of the breach was an unpatched, outdated Apache HTTP Server vulnerable to remote code execution. According to CEH principles under Security Operations and Incident Response, vulnerability management and risk assessment are critical components of defensive security strategy. An extensive risk assessment enables the organization to identify vulnerable assets, prioritize patching based on severity and business impact, and implement a structured remediation plan.

Risk assessment is part of the vulnerability management lifecycle, which includes asset identification, vulnerability scanning, risk evaluation, prioritization, patch management, and verification. By determining which systems are most exposed and critical, the organization can apply patches and security updates systematically, reducing the attack surface. Since the breach occurred due to a known vulnerability, proper patch management and regular security updates would have prevented exploitation.

Options A, B, and C represent hardening or segmentation techniques but do not directly address the core issue of outdated software vulnerabilities. Blocking ports and using dedicated machines are good security practices; however, they do not eliminate the risk of exploitation if the web server software itself remains unpatched. Therefore, implementing a comprehensive risk assessment process followed by prioritized patch management aligns directly with CEH-recommended best practices for preventing similar future incidents.


Question 12

A large media-streaming company receives complaints that its web application is timing out or failing to load. Security analysts observe the web server is overwhelmed with a large number of open HTTP connections, transmitting data extremely slowly. These connections remain open indefinitely, exhausting server resources without consuming excessive bandwidth. The team suspects an application-layer DoS attack. Which attack is most likely responsible?

Correct Answer: C. A Slowloris attack that keeps numerous HTTP connections open to exhaust server resources.
Explanation:

The Certified Ethical Hacker (CEH) Web Application Hacking and DoS/DDoS module identifies Slowloris as an application-layer denial-of-service attack that targets web servers by maintaining a large number of half-open HTTP connections.

Slowloris works by sending partial HTTP requests very slowly, preventing the server from closing the connections. CEH documentation highlights that this attack does not rely on high bandwidth, making it difficult to detect using traditional network-based defenses.

Option C accurately matches the described symptoms and CEH's definition.

Options A and B are network-layer flooding attacks, which were explicitly ruled out.

Option D is a packet fragmentation attack, not an application-layer DoS technique.

CEH stresses tuning connection timeouts and using reverse proxies as mitigations.


Question 13

During a targeted intrusion against a cloud infrastructure company in Salt Lake City, Utah, an attacker distributes a modified installation package of a legitimate network diagnostic utility widely used by employees. Before distributing the package, the attacker binds a malicious remote-access payload with the original executable so that both components are installed together.

When users launch the diagnostic tool, it performs its normal troubleshooting functions, while the hidden payload simultaneously executes in the background and establishes communication with a remote command server.

From a malware deployment perspective, what technique best describes this approach?

Correct Answer: A. Wrapper
Explanation:

The correct answer is A. Wrapper.

A wrapper binds a malicious payload to a legitimate executable so that both run when the user opens the file. The user sees the expected legitimate application, while the hidden malicious payload executes in the background.

CEH Trojan material explains that a wrapper attaches an executable application to a Trojan executable, wraps both programs into a single file, and causes the Trojan to install while the user only sees the legitimate application running . Another CEH reference defines a wrapper as a non-malicious file that binds the malicious file to propagate the Trojan and avoid detection .

Option B. Downloader is incorrect because a downloader retrieves malware from a remote location after execution.

Option C. Packer is incorrect because a packer compresses or obfuscates executable code to make detection harder.

Option D. Dropper is incorrect because a dropper is designed to deliver or install malware onto the victim system, but the key behavior here is binding a malicious payload with a legitimate executable.

Therefore, the best answer is A. Wrapper.


Question 14

As part of a passive reconnaissance engagement for a university research network, you are tasked with mapping potential administrative exposure points across .edu domains. Your objective is to identify web pages that might allow privileged backend access, such as misconfigured administrative interfaces, using only publicly indexed information. To ensure efficiency and compliance, you decide to use advanced Google search operators to refine your search results. Your goal is to locate URLs across educational domains that may contain restricted backend functionality.

Which of the following search strings would most effectively support this goal?

Correct Answer: C. site:.edu inurl:admin
Explanation:

The question focuses on passive reconnaissance using Google advanced search operators, a technique commonly referred to in CEH materials as Google hacking or Google dorking. This method leverages publicly indexed data without directly interacting with the target systems, making it a non-intrusive reconnaissance approach. The goal here is to locate potentially exposed administrative interfaces within .edu domains.

Option C, site:.edu inurl:admin, is the most effective query for this purpose. The site operator restricts results to the .edu top-level domain, ensuring that only educational institutions are searched. The inurl operator filters results to pages where the term ''admin'' appears in the URL itself. Administrative panels and backend management interfaces frequently include terms such as admin, administrator, or adminpanel directly in the URL path. Therefore, this search string increases the likelihood of discovering exposed login portals or backend directories.

Option A focuses on PDF files with ''admin'' in the title, which is unlikely to reveal active administrative interfaces. Option B searches for pages with ''admin login'' in the title, which may find login pages but is less precise than filtering by URL structure. Option D searches anchor text references, which does not directly identify actual admin pages.

In CEH methodology, properly constructed Google dorks such as inurl:admin combined with site-specific filtering are effective in identifying exposed resources while maintaining passive reconnaissance discipline.


Question 15

During a cryptographic audit of a legacy system, a security analyst observes that an outdated block cipher is leaking key-related information when analyzing large sets of plaintext--ciphertext pairs. What approach might an attacker exploit here?

Correct Answer: B. Use linear approximations to infer secret bits
Explanation:

CEH covers classical cryptanalytic attacks, including linear cryptanalysis, which uses statistical correlations between plaintext and ciphertext to infer bits of the secret key. If a cipher leaks structural patterns across many data samples, linear approximations can be computed to break the cipher.