Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: certbig75

312-50v13 Exam Dumps - ECCouncil CEH v13 Questions and Answers

Question # 79

An IDS generates alerts during normal user activity. What is the most likely cause?

Options:

A.

Firewall failure

B.

IDS outdated

C.

Excessive IDS sensitivity causing false positives

D.

Users triggering protocols

Buy Now
Question # 80

A regional healthcare provider in Minneapolis, Minnesota began experiencing intermittent connectivity issues across a newly activated access-layer network segment. Shortly after a contractor connected a diagnostic device to an unused switch port, multiple employee workstations failed to receive valid network configurations. System logs showed repeated address negotiation attempts from affected hosts, while monitoring tools recorded a rapid sequence of configuration requests originating from a single switch interface. Within minutes, additional clients on the segment encountered similar assignment failures. From a sniffing standpoint, which technique most accurately explains this behavior?

Options:

A.

IRDP Spoofing

B.

DHCP Starvation

C.

Rogue DHCP Server

D.

MAC Spoofing

Buy Now
Question # 81

Which attack abuses business logic?

Options:

A.

XSS

B.

Logic flaw

C.

CSRF

D.

SQLi

Buy Now
Question # 82

During a penetration test, you perform extensive DNS interrogation to gather intelligence about a target organization. Considering the inherent limitations of DNS-based reconnaissance, which of the following pieces of information cannot be directly obtained through DNS interrogation?

Options:

A.

The specific usernames and passwords used by the organization’s employees.

B.

The estimated geographical location of the organization’s servers derived from IP addresses.

C.

The subdomains associated with the organization’s primary internet domain.

D.

The IP addresses associated with the organization’s mail servers.

Buy Now
Question # 83

When referring to the domain name service, what is a zone?

Options:

A.

A collection of domains

B.

The zone namespace

C.

A collection of alias records

D.

A collection of resource records

Buy Now
Question # 84

What is a “Collision attack” in cryptography?

Options:

A.

Collision attacks try to find two inputs producing the same hash

B.

Collision attacks try to get the public key

C.

Collision attacks try to break the hash into three parts to get the plaintext value

D.

Collision attacks try to break the hash into two parts, with the same bytes in each part to get the private key

Buy Now
Question # 85

The establishment of a TCP connection involves a negotiation called three-way handshake. What type of message does the client send to the server in order to begin this negotiation?

Options:

A.

RST

B.

ACK

C.

SYN-ACK

D.

SYN

Buy Now
Question # 86

Attackers exfiltrate data using steganography embedded in images. What is the best countermeasure?

Options:

A.

Block all outbound traffic

B.

Deploy IPS

C.

Monitor outbound traffic for anomalies

D.

Use steganalysis tools

Buy Now
Question # 87

During a targeted phishing campaign, a malicious HTML attachment reconstructs malware locally using obfuscated JavaScript without making external network calls, bypassing firewalls and IDS inspection. Which evasion technique is being employed?

Options:

A.

HTML smuggling

B.

Port forwarding

C.

Cross-site scripting

D.

HTTP header spoofing

Buy Now
Question # 88

What is GINA?

Options:

A.

GUI Installed Network Application CLASS

B.

Gateway Interface Network Application

C.

Graphical Identification and Authentication DLL

D.

Global Internet National Authority (G-USA)

Buy Now
Question # 89

During a red team engagement at a retail company in Atlanta, ethical hacker James crafts a session with the company ' s shopping portal and deliberately shares that session ID with an unsuspecting employee by embedding it in a link. When the employee clicks and logs in, their activity is bound to the attacker ' s pre-assigned session. Later, James retrieves the employee ' s input from that same session to demonstrate the flaw to management.

Which session hijacking technique is James most likely using?

Options:

A.

Session Donation Attack

B.

Session Replay Attack

C.

Session Prediction

D.

Session Fixation Attack

Buy Now
Question # 90

During a penetration test for a U.S.-based retail company, John gains access to a secondary server that responds unusually to structured queries. By sending a specially crafted request, he receives a full list of subdomains, MX records, and aliases belonging to the target organization. The response exposes sensitive internal mappings that could be leveraged for further attacks.

Which tool was MOST likely used to perform this enumeration?

Options:

A.

smtp-user-enum.pl -u user -t host

B.

ldapsearch -h -x

C.

nbtstat -A

D.

dig @server axfr

Buy Now
Question # 91

What is MAC spoofing used for?

Options:

A.

Encryption

B.

IDS

C.

Bypass filters

D.

Logging

Buy Now
Question # 92

During an authorized security assessment at a municipal power distribution facility in Omaha, Nebraska, a certified ethical hacker performs passive traffic analysis between the control center and several remote substations.

The tester observes structured request-response messages used to read coil status and write register values on industrial controllers. All communication occurs over TCP port 502, and the protocol does not provide built-in encryption or authentication.

Based on these characteristics, which OT communication protocol is operating within this environment?

Options:

A.

IEC 60870-5-104

B.

MODBUS

C.

DNP3

D.

OPC UA

Buy Now
Question # 93

Bob received this text message on his mobile phone: “Hello, this is Scott Smelby from the Yahoo Bank. Kindly contact me for a vital transaction on: scottsmelby@yahoo.com”. Which statement below is true?

Options:

A.

This is a scam because Bob does not know Scott.

B.

This is probably a legitimate message as it comes from a respectable organization.

C.

Bob should write to scottsmelby@yahoo.com to verify the identity of Scott.

D.

This is a scam as everybody can get a @yahoo address, not the Yahoo customer service employees.

Buy Now
Exam Code: 312-50v13
Exam Name: Certified Ethical Hacker Exam (CEH v13 AI)
Last Update: Sep 12, 2026
Questions: 860
312-50v13 pdf

312-50v13 PDF

$21.25  $84.99
312-50v13 Engine

312-50v13 Testing Engine

$23.75  $94.99
312-50v13 PDF + Engine

312-50v13 PDF + Testing Engine

$33.75  $134.99