312-50V12 Exam Questions
322 real 312-50V12 exam questions with expert-verified answers and explanations. Page 4 of 7.
- Question #151Network and Perimeter Hacking
Jake, a network security specialist, is trying to prevent network-level session hijacking attacks in his company. While studying different types of such attacks, he learns about a...
Session hijackingMan-in-the-middle (MitM)ARP spoofingICMP redirect attacks - Question #152Information Security and Ethical Hacking Overview
Given the complexities of an organization's network infrastructure, a threat actor has exploited an unidentified vulnerability, leading to a major data breach. As a Certified Ethic...
Adaptive securitycontinual security monitoringthreat intelligencerisk management - Question #153Web Application Hacking
As a cybersecurity professional, you are responsible for securing a high-traffic web application that uses MySQL as its backend database. Recently, there has been a surge of unauth...
SQL Injectionblind SQLitime-based SQLiinput filtering bypass - Question #154Web Application Hacking
You're the security manager for a tech company that uses a database to store sensitive customer data. You have implemented countermeasures against SQL injection attacks. Recently,...
SQL Injection payloadsdata destructiondatabase manipulationimpact assessment - Question #155System Hacking Phases and Attack Techniques
A malicious user has acquired a Ticket Granting Service from the domain controller using a valid user's Ticket Granting Ticket in a Kerberoasting attack. He exhorted the TGS ticket...
KerberoastingTGS ticketActive Directory attacksincident response - Question #156Wireless Network, Mobile, IoT, and OT Hacking
You are a cybersecurity consultant for a healthcare organization that utilizes Internet of Medical Things (IoMT) devices, such as connected insulin pumps and heart rate monitors, t...
IoMT securitynetwork segmentationransomware protectiondevice isolation - Question #157Wireless Network, Mobile, IoT, and OT Hacking
You are a cybersecurity consultant for a global organization. The organization has adopted a Bring Your Own Device (BYOD)policy, but they have recently experienced a phishing incid...
BYOD securityMobile Device Management (MDM)phishing preventionmobile security - Question #158System Hacking Phases and Attack Techniques
XYZ company recently discovered a potential vulnerability on their network, originating from misconfigurations. It was found that some of their host servers had enabled debugging f...
Misconfiguration vulnerabilityprivilege escalationunauthorized accessserver security - Question #159Information Security and Ethical Hacking Overview
An organization suspects a persistent threat from a cybercriminal. They hire an ethical hacker, John, to evaluate their system security. John identifies several vulnerabilities and...
ethical hackingvulnerability managementrisk assessmentorganizational responsibility - Question #160System Hacking Phases and Attack Techniques
An ethical hacker is attempting to crack NTLM hashed passwords from a Windows SAM file using a rainbow table attack. He has dumped the on-disk contents of the SAM file successfully...
NTLM hashesLM hashespassword crackingWindows security - Question #161Reconnaissance Techniques
A Certified Ethical Hacker (CEH) is given the task to perform an LDAP enumeration on a target system. The system is secured and accepts connections only on secure LDAP. The CEH use...
LDAP enumerationsecure LDAPPython scriptingSSL/TLS - Question #162Wireless Network, Mobile, IoT, and OT Hacking
You are a cybersecurity consultant for a major airport that offers free Wi-Fi to travelers. The management is concerned about the possibility of "Evil Twin" attacks, where a malici...
Evil Twin attacksWi-Fi securitysocial engineeringuser awareness - Question #163Reconnaissance Techniques
As a Certified Ethical Hacker, you are conducting a footprinting and reconnaissance operation against a target organization. You discover a range of IP addresses associated with th...
DNS reconnaissancereverse DNS lookupDNSReconfootprinting - Question #164Reconnaissance Techniques
You are an ethical hacker tasked with conducting an enumeration of a company's network. Given a Windows Answered Marked for Review 37.6% system with NetBIOS enabled, port 139 open,...
NetBIOS enumerationIPv6nbtstatnetwork scanning - Question #165Network and Perimeter Hacking
During a red team assessment, a CEH is given a task to perform network scanning on the target network without revealing its IP address. They are also required to find an open port...
stealth scanningIPID header scanZenmap/Nmapnetwork reconnaissance - Question #166Information Security and Ethical Hacking Overview
A large corporation is planning to implement preventive measures to counter a broad range of social engineering techniques. The organization has implemented a signature-based IDS,...
social engineeringemployee trainingsecurity awarenesspreventive measures - Question #167Web Application Hacking
An audacious attacker is targeting a web server you oversee. He intends to perform a Slow HTTP POST attack, by manipulating 'a' HTTP connection. Each connection sends a byte of dat...
Slow HTTP POSTDoS attacksweb server attacksresource exhaustion - Question #168Information Security and Ethical Hacking Overview
A large organization has recently performed a vulnerability assessment using Nessus Professional, and the security team is now preparing the final report. They have identified a hi...
vulnerability assessmentNessusreportingpenetration testing lifecycle - Question #169System Hacking Phases and Attack Techniques
Recently, the employees of a company have been receiving emails that seem to be from their colleagues, but with suspicious attachments. When opened, these attachments appear to ins...
malware preventionpatch managementsoftware updatesemail security - Question #170System Hacking Phases and Attack Techniques
A network security analyst, while conducting penetration testing, is aiming to identify a service account password using the Kerberos authentication protocol. They have a valid use...
KerberoastingKerberospassword crackingactive directory attacks - Question #171Wireless Network, Mobile, IoT, and OT Hacking
As a cybersecurity analyst at IoT Defend, you are working with a large utility company that uses Industrial Control Systems (ICS) in its operational technology (OT) environment. Th...
IoT securityOT securityvulnerability assessmentICS - Question #172Network and Perimeter Hacking
A penetration tester is performing an enumeration on a client's network. The tester has acquired permission to perform enumeration activities. They have identified a remote inter-p...
IPC$ shareenumerationnetwork scanningbrute force - Question #173Wireless Network, Mobile, IoT, and OT Hacking
As a cybersecurity analyst at TechSafe Inc., you are working on a project to improve the security of a smart home system. This IoT-enabled system controls various aspects of the ho...
IoT securitynetwork segmentationsmart home securitydefense in depth - Question #174Web Application Hacking
During your summer internship at a tech company, you have been asked to review the security settings of their web server. While inspecting, you notice the server reveals detailed e...
web server securityerror handlinginformation disclosurevulnerability management - Question #175Cryptography
You are the chief security officer at AlphaTech, a tech company that specializes in data storage solutions. Your company is developing a new cloud storage platform where users can...
symmetric encryptionkey exchangeDiffie-Hellmancryptography - Question #176Cloud Computing
You work as a cloud security specialist at SkyNet Solutions. One of your clients is a healthcare organization that plans to migrate its electronic health record (EHR) system to the...
cloud securitydata encryptionclient-side encryptionkey management - Question #177Reconnaissance Techniques
A certified ethical hacker is conducting a Whois footprinting activity on a specific domain. The individual is leveraging various tools such as Batch IP Converter and Whois Analyze...
WhoisfootprintingThin WhoisThick Whois - Question #178Cryptography
You are a cybersecurity professional managing cryptographic systems for a global corporation. The company uses a mix of Elliptic Curve Cryptography (ECC) for key exchange and symme...
cryptographyAESECCquantum computingkey strength - Question #179Cloud Computing
You are a security analyst for CloudSec, a company providing cloud security solutions. One of your clients, a financial institution, wants to shift its operations to a public cloud...
CASBcloud securitysecurity monitoringpolicy enforcement - Question #180Web Application Hacking
Consider a hypothetical situation where an attacker, known for his proficiency in SQL Injection attacks, is targeting your web server. This adversary meticulously crafts 'q' malici...
SQL injectiontime-based attackattack detectionweb vulnerability - Question #181Wireless Network, Mobile, IoT, and OT Hacking
You are an ethical hacker contracted to conduct a security audit for a company. During the audit, you discover that the company's wireless network is using WEP encryption. You unde...
WEP vulnerabilityWPA2wireless securityAES encryption - Question #182Cryptography
You are the lead cybersecurity analyst at a multinational corporation that uses a hybrid encryption system to secure inter-departmental communications. The system uses RSA encrypti...
hybrid encryptionRSAAESquantum cryptographykey sizes - Question #183Information Security and Ethical Hacking Overview
An experienced cyber attacker has created a fake LinkedIn profile, successfully impersonating a high-ranking official from a well-established company, to execute a social engineeri...
whalingsocial engineeringimpersonationtargeted attack - Question #184Wireless Network, Mobile, IoT, and OT Hacking
As a cybersecurity analyst for a large corporation, you are auditing the company's mobile device management (MDM) policy. One of your areas of concern is data leakage from company-...
MDMmobile securitydata leakageapp control - Question #185Reconnaissance Techniques
A certified ethical hacker is carrying out an email footprinting exercise on a targeted organization using eMailTrackerPro. They want to map out detailed information about the reci...
email footprintingeMailTrackerProreconnaissance toolsinformation gathering - Question #186Wireless Network, Mobile, IoT, and OT Hacking
You are a cybersecurity trainee tasked with securing a small home network. The homeowner is concerned about potential "Wi-Fi eavesdropping," where unauthorized individuals could in...
Wi-Fi securitywireless encryptioneavesdropping preventionhome network security - Question #187Network and Perimeter Hacking
A well-resourced attacker intends to launch a highly disruptive DDoS attack against a major online retailer. The attacker aims to exhaust all the network resources while keeping th...
DDoS attackbotnetvolumetric attackattack concealment - Question #188Information Security and Ethical Hacking Overview
A large organization is investigating a possible identity theft case where an attacker has created a new identity by combining multiple pieces of information from different victims...
identity theftsynthetic identityfraudsocial engineering - Question #189Information Security and Ethical Hacking Overview
A company recently experienced a debilitating social engineering attack that led to substantial identity theft. An inquiry found that the employee inadvertently provided critical i...
social engineeringemployee trainingsecurity awarenessidentity theft prevention - Question #190System Hacking Phases and Attack Techniques
An IT company has just implemented new security controls to their network and system setup. As a Certified Ethical Hacker, your responsibility is to assess the possible vulnerabili...
vulnerability assessmentmisconfigurationsecurity auditinitial assessment - Question #191Reconnaissance Techniques
An ethical hacker has been tasked with assessing the security of a major corporation's network. She suspects the network uses default SNMP community strings. To exploit this, she p...
SNMP enumerationnetwork reconnaissancesnmp-checkdefault community strings - Question #192Information Security and Ethical Hacking Overview
During a recent vulnerability assessment of a major corporation's IT systems, the security team identified several potential risks. They want to use a vulnerability scoring system...
CVSSvulnerability scoringbase metrictemporal metricenvironmental metric - Question #193Wireless Network, Mobile, IoT, and OT Hacking
You are a cybersecurity consultant at SecureIoT Inc. A manufacturing company has contracted you to strengthen the security of their Industrial IoT (IIoT) devices used in their oper...
IIoT securityOT securitynetwork segmentationindustrial control systems - Question #194System Hacking Phases and Attack Techniques
In an advanced digital security scenario, a multinational enterprise is being targeted with a complex series of assaults aimed to disrupt operations, manipulate data integrity, and...
side-channel attackhardware vulnerabilitymicroarchitectural attacksdata manipulation - Question #195System Hacking Phases and Attack Techniques
In the process of implementing a network vulnerability assessment strategy for a tech company, the security analyst is confronted with the following scenarios: 1) A legacy applicat...
vulnerability assessmentvulnerability scanningscanner limitationsimpact analysis - Question #196Web Application Hacking
In your cybersecurity class, you are learning about common security risks associated with web servers. One topic that comes up is the risk posed by using default server settings. W...
web server securitydefault settingsinformation disclosurehardening - Question #197Wireless Network, Mobile, IoT, and OT Hacking
As a junior security analyst for a small business, you are tasked with setting up the company's first wireless network. The company wants to ensure the network is secure from poten...
wireless securityWPA2WPA3network setup - Question #198Reconnaissance Techniques
During a reconnaissance mission, an ethical hacker uses Maltego, a popular footprinting tool, to collect information about a target organization. The information includes the targe...
footprintingMaltegosocial engineeringreconnaissanceinformation gathering - Question #199System Hacking Phases and Attack Techniques
An organization has been experiencing intrusion attempts despite deploying an Intrusion Detection System (IDS) and Firewalls. As a Certified Ethical Hacker, you are asked to reinfo...
YARA rulesmalware analysisthreat detectionrule generation - Question #200Web Application Hacking
During an attempt to perform an SQL injection attack, a certified ethical hacker is focusing on the identification of database engine type by generating an ODBC error. The ethical...
SQL injectionblind SQLidatabase enumerationweb application attacks