EC-COUNCIL 312-50v10 Certification All-in-One Exam Guide Oct-2022 [Q301-Q322]

Share

EC-COUNCIL 312-50v10 Certification All-in-One Exam Guide Oct-2022

Get Real 312-50v10 Exam Dumps [Oct-2022] Practice Tests

NEW QUESTION 301
Which tool allows analysts and pen testers to examine links between data using graphs and link analysis?

  • A. Maltego
  • B. Cain & Abel
  • C. Metasploit
  • D. Wireshark

Answer: A

 

NEW QUESTION 302
PGP, SSL, and IKE are all examples of which type of cryptography?

  • A. Public Key
  • B. Secret Key
  • C. Digest
  • D. Hash Algorithm

Answer: A

Explanation:
Public-key algorithms are fundamental security ingredients in cryptosystems, applications and protocols. They underpin various Internet standards, such as Secure Sockets Layer (SSL),Transport Layer Security (TLS), S/MIME, PGP, Internet Key Exchange (IKE or IKEv2), and GPG.
References: https://en.wikipedia.org/wiki/Public-key_cryptography

 

NEW QUESTION 303
Based on the following extract from the log of a compromised machine, what is the hacker really trying to steal?

  • A. SAM file
  • B. har.txt
  • C. wwwroot
  • D. Repair file

Answer: A

 

NEW QUESTION 304
Which regulation defines security and privacy controls for Federal information systems and organizations?

  • A. HIPAA
  • B. NIST-800-53
  • C. PCI-DSS
  • D. EU Safe Harbor

Answer: B

Explanation:
Explanation/Reference:

 

NEW QUESTION 305
>NMAP -sn 192.168.11.200-215 The NMAP command above performs which of the following?

  • A. A ping scan
  • B. A port scan
  • C. An operating system detect
  • D. A trace sweep

Answer: A

 

NEW QUESTION 306
Which tool allows analysts and pen testers to examine links between data using graphs and link analysis?

  • A. Maltego
  • B. Cain & Abel
  • C. Metasploit
  • D. Wireshark

Answer: A

Explanation:
Explanation
Maltego is proprietary software used for open-source intelligence and forensics, developed by Paterva.
Maltego focuses on providing a library of transforms for discovery of data from open sources, and visualizing that information in a graph format, suitable for link analysis and data mining.
References: https://en.wikipedia.org/wiki/Maltego

 

NEW QUESTION 307
You are tasked to configure the DHCP server to lease the last 100 usable IP addresses in subnet to. 1.4.0/23. Which of the following IP addresses could be teased as a result of the new configuration?

  • A. 10.1.4.156
  • B. 10..1.5.200
  • C. 10.1.4.254
  • D. 210.1.55.200

Answer: B

 

NEW QUESTION 308
You are logged in as a local admin on a Windows 7 system and you need to launch the Computer Management Console from command line.
Which command would you use?

  • A. c:\gpedit
  • B. c:\compmgmt.msc
  • C. c:\ncpa.cp
  • D. c:\services.msc

Answer: B

Explanation:
Explanation
To start the Computer Management Console from command line just type compmgmt.msc
/computer:computername in your run box or at the command line and it should automatically open the Computer Management console.
References:
http://www.waynezim.com/tag/compmgmtmsc/

 

NEW QUESTION 309
An attacker has installed a RAT on a host. The attacker wants to ensure that when a user attempts to go to "www.MyPersonalBank.com", that the user is directed to a phishing site.
Which file does the attacker need to modify?

  • A. Sudoers
  • B. Boot.ini
  • C. Networks
  • D. Hosts

Answer: D

 

NEW QUESTION 310
A penetration tester is conducting a port scan on a specific host. The tester found several ports opened that were confusing in concluding the Operating System (OS) version installed. Considering the NMAP result below, which of the following is likely to be installed on the target machine by the OS?

  • A. The host is likely a Linux machine.
  • B. The host is likely a printer.
  • C. The host is likely a Windows machine.
  • D. The host is likely a router.

Answer: B

 

NEW QUESTION 311
You are attempting to crack LM Manager hashed from Windows 2000 SAM file. You will be using LM Brute force hacking tool for decryption. What encryption algorithm will you be decrypting?

  • A. DES
  • B. MD4
  • C. SSL
  • D. SHA

Answer: A

 

NEW QUESTION 312
In this attack, a victim receives an e-mail claiming from PayPal stating that their account has been disabled and confirmation is required before activation. The attackers then scam to collect not one but two credit card numbers, ATM PIN number and other personal details. Ignorant users usually fall prey to this scam.
Which of the following statement is incorrect related to this attack?

  • A. Antivirus, anti-spyware, and firewall software can very easily detect these type of attacks
  • B. Review credit card and bank account statements regularly
  • C. Do not trust telephone numbers in e-mails or popup ads
  • D. Do not reply to email messages or popup ads asking for personal or financial information
  • E. Do not send credit card numbers, and personal or financial information via e-mail

Answer: A

 

NEW QUESTION 313
What tool should you use when you need to analyze extracted metadata from files you collected when you were in the initial stage of penetration test (information gathering)?

  • A. Metagoofil
  • B. Armitage
  • C. cdpsnarf
  • D. Dimitry

Answer: A

 

NEW QUESTION 314
Why would you consider sending an email to an address that you know does not exist within the company you are performing a Penetration Test for?

  • A. To determine who is the holder of the root account
  • B. To test for virus protection
  • C. To illicit a response back that will reveal information about email servers and how they treat undeliverable mail
  • D. To create needless SPAM
  • E. To perform a DoS

Answer: C

 

NEW QUESTION 315
Jesse receives an email with an attachment labeled "Court_Notice_21206.zip". Inside the zip file is a file named "Court_Notice_21206.docx.exe" disguised as a word document.
Upon execution, a window appears stating, "This word document is corrupt." In the background, the file copies itself to Jesse APPDATA\local directory and begins to beacon to a C2 server to download additional malicious binaries.
What type of malware has Jesse encountered?

  • A. Worm
  • B. Key-Logger
  • C. Trojan
  • D. Macro Virus

Answer: C

Explanation:
In computing, Trojan horse, or Trojan, is any malicious computer program which is used to hack into a computer by misleading users of its true intent. Although their payload can be anything, many modern forms act as a backdoor, contacting a controller which can then have unauthorized access to the affected computer.
References: https://en.wikipedia.org/wiki/Trojan_horse_(computing)

 

NEW QUESTION 316
A certified ethical hacker (CEH) is approached by a friend who believes her husband is cheating. She offers to pay to break into her husband's email account in order to find proof so she can take him to court. What is the ethical response?

  • A. Say yes; the friend needs help to gather evidence.
  • B. Say no; the friend is not the owner of the account.
  • C. Say no; make sure that the friend knows the risk she's asking the CEH to take.
  • D. Say yes; do the job for free.

Answer: B

 

NEW QUESTION 317
When purchasing a biometric system, one of the considerations that should be reviewed is the processing speed. Which of the following best describes what it is meant by processing?

  • A. The amount of time it takes to convert biometric data into a template on a smart card
  • B. How long it takes to setup individual user accounts
  • C. The amount of time and resources that are necessary to maintain a biometric system
  • D. The amount of time it takes to be either accepted or rejected from when an individual provides identification and authentication information

Answer: D

 

NEW QUESTION 318

What does the option * indicate?

  • A. t
  • B. n
  • C. a
  • D. s

Answer: B

 

NEW QUESTION 319
What is the term coined for logging, recording and resolving events in a company?

  • A. Incident Management Process
  • B. Internal Procedure
  • C. Security Policy
  • D. Metrics

Answer: A

 

NEW QUESTION 320
An Internet Service Provider (ISP) has a need to authenticate users connecting via analog modems, Digital Subscriber Lines (DSL), wireless data services, and Virtual Private Networks (VPN) over a Frame Relay network.
Which AAA protocol is the most likely able to handle this requirement?

  • A. Kerberos
  • B. TACACS+
  • C. RADIUS
  • D. DIAMETER

Answer: C

 

NEW QUESTION 321
You just set up a security system in your network. In what kind of system would you find the following string of characters used as a rule within its configuration?
alert tcp any any -> 192.168.100.0/24 21 (msg: "FTP on the network!";)

  • A. An Intrusion Detection System
  • B. A Router IPTable
  • C. FTP Server rule
  • D. A firewall IPTable

Answer: A

Explanation:
Snort is an open source network intrusion detection system (NIDS) for networks .
Snort rule example:
This example is a rule with a generator id of 1000001.
alert tcp any any -> any 80 (content:"BOB"; gid:1000001; sid:1; rev:1;) References: http://manual-snort-org.s3-website-us-east-1.amazonaws.com/node31.html

 

NEW QUESTION 322
......

Last 312-50v10 practice test reviews: Practice Test EC-COUNCIL dumps: https://pass4sure.dumps4pdf.com/312-50v10-valid-braindumps.html