Exam Certified Ethical Hacker v11 Exam
Number 312-50v11
File Name Certified Ethical Hacker v11 Exam.CertDumps.312-50v11.2022-01-11.1e.255q.vcex
Size 1.1 Mb
Posted January 11, 2022
Demo Questions

Question 1
Identify the UDP port that Network Time Protocol (NTP) uses as its primary means of communication?

  • A: 113
  • B: 69
  • C: 123
  • D: 161

Question 2
An attacker identified that a user and an access point are both compatible with WPA2 and WPA3 encryption. The attacker installed a rogue access point with only WPA2 compatibility in the vicinity and forced the victim to go through the WPA2 four-way handshake to get connected. After the connection was established, the attacker used automated tools to crack WPA2-encrypted messages. What is the attack performed in the above scenario?

  • A: Timing-based attack
  • B: Side-channel attack
  • C: Downgrade security attack
  • D: Cache-based attack

Question 3
Clark is a professional hacker. He created and configured multiple domains pointing to the same host to switch quickly between the domains and avoid detection. 
Identify the behavior of the adversary In the above scenario.

  • A: use of command-line interface
  • B: Data staging
  • C: Unspecified proxy activities
  • D: Use of DNS tunneling

Question 4
Elante company has recently hired James as a penetration tester. He was tasked with performing enumeration on an organization's network. In the process of enumeration, James discovered a service that is accessible to external sources. This service runs directly on port 21. What is the service enumerated byjames in the above scenario?

  • A: Border Gateway Protocol (BGP)
  • B: File Transfer Protocol (FTP)
  • C: Network File System (NFS)
  • D: Remote procedure call (RPC)

Question 5
When considering how an attacker may exploit a web server, what is web server footprinting ?

  • A: When an attacker implements a vulnerability scanner to identify weaknesses
  • B: When an attacker creates a complete profile of the site's external links and file structures
  • C: When an attacker gathers system-level data, including account details and server names
  • D: When an attacker uses a brute-force attack to crack a web-server password

Question 6
You receive an e-mail like the one shown below. When you click on the link contained in the mail, you are redirected to a website seeking you to download free Anti-Virus software. 
Dear valued customers, 
We are pleased to announce the newest version of Antivirus 2010 for Windows which will probe you with total security against the latest spyware, malware, viruses, Trojans and other online threats. Simply visit the link below and enter your antivirus code:


or you may contact us at the following address:
Media Internet Consultants, Edif. Neptuno, Planta 
Baja, Ave. Ricardo J. Alfaro, Tumba Muerto, n/a Panama 
How will you determine if this is Real Anti-Virus or Fake Anti-Virus website?

  • A: Look at the website design, if it looks professional then it is a Real Anti-Virus website
  • B: Connect to the site using SSL, if you are successful then the website is genuine
  • C: Search using the URL and Anti-Virus product name into Google and lookout for suspicious warnings against this site
  • D: Download and install Anti-Virus software from this suspicious looking site, your Windows 7 will prompt you and stop the installation if the downloaded file is a malware
  • E: Download and install Anti-Virus software from this suspicious looking site, your Windows 7 will prompt you and stop the installation if the downloaded file is a malware

Question 7
Which of the following is the structure designed to verify and authenticate the identity of individuals within the enterprise taking part in a data exchange? 

  • A: SOA
  • B: biometrics
  • C: single sign on
  • D: PKI

Question 8
Ethical hacker jane Smith is attempting to perform an SQL injection attach. She wants to test the response time of a true or false response and wants to use a second command to determine whether the database will return true or false results for user IDs. which two SQL Injection types would give her the results she is looking for?

  • A: Out of band and boolean-based
  • B: Time-based and union-based
  • C: union-based and error-based
  • D: Time-based and boolean-based

Question 9
Ben purchased a new smartphone and received some updates on it through the OTA method. He received two messages: one with a PIN from the network operator and another asking him to enter the PIN received from the operator. As soon as he entered the PIN, the smartphone started functioning in an abnormal manner. 
What is the type of attack performed on Ben in the above scenario?

  • A: Advanced SMS phishing 
  • B: Bypass SSL pinning
  • C: Phishing
  • D: Tap 'n ghost attack

Question 10
What is the BEST alternative if you discover that a rootkit has been installed on one of your computers?

  • A: Copy the system files from a known good system
  • B: Perform a trap and trace
  • C: Delete the files and try to determine the source
  • D: Reload from a previous backup
  • E: Reload from known good media


