Eccouncil

312-50v10 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 179-question bank.

Provider
Eccouncil
Question bank
179
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for 312-50v10, a certification listed under Eccouncil. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Eccouncil. The certification credential is issued by Eccouncil, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    An unauthorized individual enters a building following an employee through the employee entrance after the lunch rush. What type of breach has the individual just performed?

    Choose one answer.

    • Reverse Social Engineering
    • Tailgating
    • Piggybacking
    • Announced
  2. Question 2 · 1

    _________ is a set of extensions to DNS that provide the origin authentication of DNS data to DNS clients (resolvers) so as to reduce the threat of DNS poisoning, spoofing, and similar types of attacks.

    Choose one answer.

    • DNSSEC
    • Resource records
    • Resource transfer
    • Zone transfer
  3. Question 3 · 1

    Internet Protocol Security IPSec is actually a suite of protocols. Each protocol within the suite provides different functionality. Collective IPSec does everything except.

    Choose one answer.

    • Work at the Data Link Layer
    • Protect the payload and the headers
    • Encrypt
    • Authenticate
  4. Question 4 · 1

    On performing a risk assessment, you need to determine the potential impacts when some of the critical business process of the company interrupt its service. What is the name of the process by which you can determine those critical business?

    Choose one answer.

    • Risk Mitigation
    • Emergency Plan Response (EPR)
    • Disaster Recovery Planning (DRP)
    • Business Impact Analysis (BIA)
  5. Question 5 · 1

    Which regulation defines security and privacy controls for Federal information systems and organizations?

    Choose one answer.

    • HIPAA
    • EU Safe Harbor
    • PCI-DSS
    • NIST-800-53
  6. Question 6 · 1

    PGP, SSL, and IKE are all examples of which type of cryptography?

    Choose one answer.

    • Hash Algorithm
    • Digest
    • Secret Key
    • Public Key
  7. Question 7 · 1

    You are a security officer of a company. You had an alert from IDS that indicates that one PC on your Intranet is connected to a blacklisted IP address (C2 Server) on the Internet. The IP address was blacklisted just before the alert. You are staring an investigation to roughly analyze the severity of the situation. Which of the following is appropriate to analyze?

    Choose one answer.

    • Event logs on the PC
    • Internet Firewall/Proxy log
    • IDS log
    • Event logs on domain controller
  8. Question 8 · 1

    It has been reported to you that someone has caused an information spillage on their computer. You go to the computer, disconnect it from the network, remove the keyboard and mouse, and power it down. What step in incident handling did you just complete?

    Choose one answer.

    • Discovery
    • Recovery
    • Containment
    • Eradication
  9. Question 9 · 1

    Which of the following cryptography attack is an understatement for the extraction of cryptographic secrets (e.g. the password to an encrypted file) from a person by a coercion or torture?

    Choose one answer.

    • Chosen-Cipher text Attack
    • Ciphertext-only Attack
    • Timing Attack
    • Rubber Hose Attack
  10. Question 10 · 1

    In cryptanalysis and computer security, 'pass the hash' is a hacking technique that allows an attacker to authenticate to a remote server/service by using the underlying NTLM and/or LanMan hash of a user's password, instead of requiring the associated plaintext password as is normally the case. Metasploit Framework has a module for this technique: psexec. The psexec module is often used by penetration testers to obtain access to a given system whose credentials are known. It was written by sysinternals and has been integrated within the framework. The penetration testers successfully gain access to a system through some exploit, use meterpreter to grab the passwords or other methods like fgdump, pwdump, or cachedump and then utilize rainbowtables to crack those hash values. Which of the following is true hash type and sort order that is used in the psexec module's 'smbpass' option?

    Choose one answer.

    • LM:NT
    • NTLM:LM
    • NT:LM
    • LM:NTLM
  11. Question 11 · 1

    You are looking for SQL injection vulnerability by sending a special character to web applications. Which of the following is the most useful for quick validation?

    Choose one answer.

    • Double quotation
    • Backslash
    • Semicolon
    • Single quotation
  12. Question 12 · 1

    A virus that attempts to install itself inside the file it is infecting is called?

    Choose one answer.

    • Tunneling virus
    • Cavity virus
    • Polymorphic virus
    • Stealth virus
  13. Question 13 · 1

    Cross-site request forgery involves:

    Choose one answer.

    • A request sent by a malicious user from a browser to a server
    • Modification of a request by a proxy between client and server
    • A browser making a request to a server without the user's knowledge
    • A server making a request to another server without the user's knowledge
  14. Question 14 · 1

    Which of the following is considered as one of the most reliable forms of TCP scanning?

    Choose one answer.

    • TCP Connect/Full Open Scan
    • Half-open Scan
    • NULL Scan
    • Xmas Scan
  15. Question 15 · 1

    What does the option * indicate?

    Choose one answer.

    Question illustration 1
    • s
    • t
    • n
    • a

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free