Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: certbig75

312-50v13 Exam Dumps - ECCouncil CEH v13 Questions and Answers

Question # 94

A U.S.-based online securities trading firm in New York is reviewing its transaction authentication process. The security team confirms that each transaction is processed by first generating a hash of the transaction data. The hash value is then signed using the sender ' s private key. During verification, the recipient uses the corresponding public key to validate the signature before approving the transaction. The system documentation specifies that the same algorithm supports encryption, digital signatures, and key exchange mechanisms within the organization ' s secure communications infrastructure. Which encryption algorithm is being used in this implementation?

Options:

A.

ElGamal

B.

Diffie-Hellman

C.

DSA

D.

RSA

Buy Now
Question # 95

Repeated failed login attempts are followed by a sudden surge in outbound data traffic from a critical server. What should be your initial course of action?

Options:

A.

Audit all outbound traffic and analyze destination IPs

B.

Immediately disconnect the server from the network

C.

Perform real-time monitoring and log analysis to understand the activity

D.

Change server credentials and force password resets

Buy Now
Question # 96

You are conducting a security audit at a government agency. During your walkthrough, you observe a temporary contractor sitting in the staff lounge using their smartphone to discretely record employees as they enter passwords into their systems. Upon further investigation, you find discarded documents in a nearby trash bin containing sensitive project information. What type of attack is most likely being performed?

Options:

A.

Cisco-in attack

B.

Insider attack

C.

Distribution attack

D.

Passive attack

Buy Now
Question # 97

A manufacturing company in Columbus, Ohio, reported a surge in internal support tickets after employees received an alarming email appearing to originate from an independent cybersecurity researcher.

The message claimed that a newly discovered malware strain was actively targeting corporate email systems and stated that several Fortune 500 organizations had already been compromised. It encouraged recipients to immediately circulate the message within their departments “to minimize exposure,” warning that failure to act quickly could result in data loss.

The email did not request credentials, payment, or direct downloads. However, it relied heavily on dramatic language and cited unverifiable statistics to increase urgency and credibility.

From a social engineering classification standpoint, how should this technique be categorized?

Options:

A.

Scareware Designed to Trick Users into Installing Rogue Software

B.

Spam Email Used for Mass Unsolicited Distribution

C.

Chain Letters that Incentivize Forwarding Messages

D.

Hoax Letters that Spread False Security Warnings

Buy Now
Question # 98

Systems are communicating with unknown external entities, raising concerns about exfiltration or malware. Which strategy most directly identifies and mitigates the risk?

Options:

A.

Aggressive zero-trust shutdown

B.

Deep forensic analysis

C.

Behavioral analytics profiling normal interactions

D.

Employee awareness training

Buy Now
Question # 99

As part of a quarterly security review at EvoTrans Logistics, a global freight optimization firm, you have been brought in as a senior cybersecurity analyst to audit perimeter firewall configurations across cloud-hosted application clusters. During your investigation, you notice that TCP port 1433 is open on a virtual machine tagged as svc-node-east-14, which was provisioned by a now-defunct third-party vendor. The node is not referenced in any current infrastructure diagrams, yet live traffic logs suggest it is still handling requests during peak hours. No documentation exists regarding its service role, but you are tasked with flagging misconfigurations that may violate policy or expose critical services unnecessarily. Based on your understanding of standard port assignments, you must determine what service this port likely represents and whether its exposure warrants escalation.

Which of the following services is most likely running on this port and requires immediate review?

Options:

A.

sqlsrv

B.

SqlNet

C.

ms-sql-s

D.

ms-sql-m

Buy Now
Question # 100

As part of a red team campaign against a pharmaceutical company in Boston, ethical hacker Alex begins with a successful spear-phishing attack that delivers an initial payload to a manager ' s laptop. After gaining access, Alex pivots to harvesting cached credentials and using them to move laterally across the internal network. Soon, routers, printers, and several file servers are compromised, expanding the red team ' s control beyond the original host. At this point, Alex has not yet targeted sensitive research data, but the team has built a broader foothold within the environment.

Which phase of the Advanced Persistent Threat (APT) lifecycle is Alex simulating?

Options:

A.

Initial Intrusion

B.

Persistence

C.

Search & Exfiltration

D.

Expansion

Buy Now
Question # 101

The configuration allows a wired or wireless network interface controller to pass all traffic it receives to the Central Processing Unit (CPU), rather than passing only the frames that the controller is intended to receive. Which of the following is being described?

Options:

A.

Promiscuous mode

B.

Port forwarding

C.

WEM

D.

Multi-cast mode

Buy Now
Question # 102

What does DEP block?

Options:

A.

Encryption

B.

Logging

C.

Execution in data memory

D.

Scanning

Buy Now
Question # 103

An attacker, using a rogue wireless AP, performed an MITM attack and injected an HTML code to embed a malicious applet in all HTTP connections. When users accessed any page, the applet ran and exploited many machines. Which one of the following tools the hacker probably used to inject HTML code?

Options:

A.

Wireshark

B.

Aircrack-ng

C.

Ettercap

D.

Tcpdump

Buy Now
Question # 104

Which of the following is a component of a risk assessment?

Options:

A.

Administrative safeguards

B.

Logical interface

C.

Physical security

D.

DMZ

Buy Now
Question # 105

You are part of the red team assigned to evaluate the physical and social vulnerabilities of a government contractor ' s office located in a metropolitan business hub. During your pretexting phase, you decide to simulate the role of a third-party IT technician. Upon arrival, the receptionist allows you entry without verifying credentials, assuming you ' re there for scheduled printer maintenance. While moving through the workspace, you casually observe open terminals, unattended printouts, and discarded sticky notes at workstations. You later report several user credentials and partial access details acquired during this visit.

Which social engineering technique does this scenario best illustrate?

Options:

A.

Shoulder Surfing

B.

Eavesdropping

C.

Impersonation

D.

Dumpster Diving

Buy Now
Question # 106

During a penetration test at IntelliCore Systems in Raleigh, North Carolina, ethical hacker Javier directs a wave of repetitive web requests against the company ' s portal that overloads backend scripts which process search queries and form submissions. As a result, legitimate customers experience long delays and occasional timeouts while attempting to log in or complete transactions.

Which DoS/DDoS technique is Javier most likely demonstrating?

Options:

A.

Slowloris

B.

UDP Flood

C.

Peer-to-Peer Attack

D.

HTTP GET/POST Attack

Buy Now
Question # 107

Null sessions are un-authenticated connections (not using a username or password.) to an NT or 2000 system. Which TCP and UDP ports must you filter to check null sessions on your network?

Options:

A.

139 and 443

B.

137 and 139

C.

137 and 443

D.

139 and 445

Buy Now
Question # 108

In Miami, Florida, cybersecurity analyst Laura Bennett is responding to a series of unauthorized access attempts targeting Sunshine Credit Union’s online banking platform. She observes unusual network activity that suggests attackers may be intercepting session IDs transmitted over unsecured connections to hijack active user sessions. To prevent further compromise, Laura works with the network team to apply a control that secures session-related communications throughout the entire portal, ensuring sensitive tokens are no longer exposed to interception during user interactions.

What countermeasure should Laura implement to prevent session hijacking in this scenario?

Options:

A.

Regenerate the session ID after a successful login

B.

Implement SSL to encrypt all information in transit via the network

C.

Use restrictive cache directives such as Cache-Control no-cache

D.

Do not create sessions for unauthenticated users

Buy Now
Exam Code: 312-50v13
Exam Name: Certified Ethical Hacker Exam (CEH v13 AI)
Last Update: Sep 12, 2026
Questions: 860
312-50v13 pdf

312-50v13 PDF

$21.25  $84.99
312-50v13 Engine

312-50v13 Testing Engine

$23.75  $94.99
312-50v13 PDF + Engine

312-50v13 PDF + Testing Engine

$33.75  $134.99