Eccouncil

312-50v11 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 391-question bank.

Provider
Eccouncil
Question bank
391
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for 312-50v11, a certification listed under Eccouncil. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Eccouncil. The certification credential is issued by Eccouncil, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    While performing online banking using a Web browser, a user receives an email that contains a link to an interesting Web site. When the user clicks on the link, another Web browser session starts and displays a video of cats playing a piano. The next business day, the user receives what looks like an email from his bank, indicating that his bank account has been accessed from a foreign country. The email asks the user to call his bank and verify the authorization of a funds transfer that took place. What Web browser-based security vulnerability was exploited to compromise the user?

    Choose one answer.

    • Clickjacking
    • Cross-Site Scripting
    • Cross-Site Request Forgery
    • Web form input validation
  2. Question 2 · 1

    Which is the first step followed by Vulnerability Scanners for scanning a network?

    Choose one answer.

    • OS Detection
    • Firewall detection
    • TCP/UDP Port scanning
    • Checking if the remote host is alive
  3. Question 3 · 1

    Your company performs penetration tests and security assessments for small and medium-sized business in the local area. During a routine security assessment, you discover information that suggests your client is involved with human trafficking. What should you do?

    Choose one answer.

    • Confront the client in a respectful manner and ask her about the data.
    • Copy the data to removable media and keep it in case you need it.
    • Ignore the data and continue the assessment until completed as agreed.
    • Immediately stop work and contact the proper legal authorities.
  4. Question 4 · 1

    The establishment of a TCP connection involves a negotiation called three-way handshake. What type of message does the client send to the server in order to begin this negotiation?

    Choose one answer.

    • ACK
    • SYN
    • RST
    • SYN-ACK
  5. Question 5 · 1

    Which type of security feature stops vehicles from crashing through the doors of a building?

    Choose one answer.

    • Bollards
    • Receptionist
    • Mantrap
    • Turnstile
  6. Question 6 · 1

    The company ABC recently contracts a new accountant. The accountant will be working with the financial statements. Those financial statements need to be approved by the CFO and then they will be sent to the accountant but the CFO is worried because he wants to be sure that the information sent to the accountant was not modified once he approved it. Which of the following options can be useful to ensure the integrity of the data?

    Choose one answer.

    • The CFO can use a hash algorithm in the document once he approved the financial statements
    • The CFO can use an excel file with a password
    • The financial statements can be sent twice, one by email and the other delivered in USB and the accountant can compare both to be sure is the same document
    • The document can be sent to the accountant using an exclusive USB for that document
  7. Question 7 · 1

    What is the purpose of a demilitarized zone on a network?

    Choose one answer.

    • To scan all traffic coming through the DMZ to the internal network
    • To only provide direct access to the nodes within the DMZ and protect the network behind it
    • To provide a place to put the honeypot
    • To contain the network devices you wish to protect
  8. Question 8 · 1

    Which of the following Linux commands will resolve a domain name into IP address?

    Choose one answer.

    • >host-t a hackeddomain.com
    • >host-t ns hackeddomain.com
    • >host -t soa hackeddomain.com
    • >host -t AXFR hackeddomain.com
  9. Question 9 · 1

    Shellshock allowed an unauthorized user to gain access to a server. It affected many Internet-facing services, which OS did it not directly affect?

    Choose one answer.

    • Linux
    • Unix
    • OS X
    • Windows
  10. Question 10 · 1

    Which regulation defines security and privacy controls for Federal information systems and organizations?

    Choose one answer.

    • HIPAA
    • EU Safe Harbor
    • PCI-DSS
    • NIST-800-53
  11. Question 11 · 1

    What is a `Collision attack` in cryptography?

    Choose one answer.

    • Collision attacks try to get the public key
    • Collision attacks try to break the hash into three parts to get the plaintext value
    • Collision attacks try to break the hash into two parts, with the same bytes in each part to get the private key
    • Collision attacks try to find two inputs producing the same hash
  12. Question 12 · 1

    Which of the following programs is usually targeted at Microsoft Office products?

    Choose one answer.

    • Polymorphic virus
    • Multipart virus
    • Macro virus
    • Stealth virus
  13. Question 13 · 1

    Which of the following tools can be used for passive OS fingerprinting?

    Choose one answer.

    • nmap
    • tcpdump
    • tracert
    • ping
  14. Question 14 · 1

    Which of the following describes the characteristics of a Boot Sector Virus?

    Choose one answer.

    • Modifies directory table entries so that directory entries point to the virus code instead of the actual program.
    • Moves the MBR to another location on the RAM and copies itself to the original location of the MBR.
    • Moves the MBR to another location on the hard disk and copies itself to the original location of the MBR.
    • Overwrites the original MBR and only executes the new virus code.
  15. Question 15 · 1

    Your company was hired by a small healthcare provider to perform a technical assessment on the network. What is the best approach for discovering vulnerabilities on a Windows-based computer?

    Choose one answer.

    • Use the built-in Windows Update tool
    • Use a scan tool like Nessus
    • Check MITRE.org for the latest list of CVE findings
    • Create a disk image of a clean Windows installation

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free