
EC-COUNCIL Certified Ethical Hacker v8 - 312-50v8 Exam Questions
QUESTION NO: 1
Which property ensures that a hash function will not produce the same hashed value for two different messages?
Which property ensures that a hash function will not produce the same hashed value for two different messages?
Correct Answer: A
QUESTION NO: 2
An nmap command that includes the host specification of 202.176.56-57.* will scan _______ number of hosts.
An nmap command that includes the host specification of 202.176.56-57.* will scan _______ number of hosts.
Correct Answer: B
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 3
Most cases of insider abuse can be traced to individuals who are introverted, incapable of dealing with stress or conflict, and frustrated with their job, office politics, and lack of respect or promotion. Disgruntled employees may pass company secrets and intellectual property to competitors for monitory benefits.
Here are some of the symptoms of a disgruntled employee:
a.Frequently leaves work early, arrive late or call in sick
b.Spends time surfing the Internet or on the phone
c.Responds in a confrontational, angry, or overly aggressive way to simple requests or comments
d.Always negative; finds fault with everything
These disgruntled employees are the biggest threat to enterprise security. How do you deal with these threats? (Select 2 answers)
Most cases of insider abuse can be traced to individuals who are introverted, incapable of dealing with stress or conflict, and frustrated with their job, office politics, and lack of respect or promotion. Disgruntled employees may pass company secrets and intellectual property to competitors for monitory benefits.
Here are some of the symptoms of a disgruntled employee:
a.Frequently leaves work early, arrive late or call in sick
b.Spends time surfing the Internet or on the phone
c.Responds in a confrontational, angry, or overly aggressive way to simple requests or comments
d.Always negative; finds fault with everything
These disgruntled employees are the biggest threat to enterprise security. How do you deal with these threats? (Select 2 answers)
Correct Answer: A,B
QUESTION NO: 4
Which of the following commands runs snort in packet logger mode?
Which of the following commands runs snort in packet logger mode?
Correct Answer: B
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 5
While performing a ping sweep of a subnet you receive an ICMP reply of Code 3/Type 13 for all the pings sent out.
What is the most likely cause behind this response?
While performing a ping sweep of a subnet you receive an ICMP reply of Code 3/Type 13 for all the pings sent out.
What is the most likely cause behind this response?
Correct Answer: B
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 6
After studying the following log entries, how many user IDs can you identify that the attacker has tampered with?
1.mkdir -p /etc/X11/applnk/Internet/.etc
2.mkdir -p /etc/X11/applnk/Internet/.etcpasswd
3.touch -acmr /etc/passwd /etc/X11/applnk/Internet/.etcpasswd
4.touch -acmr /etc /etc/X11/applnk/Internet/.etc
5.passwd nobody -d
6./usr/sbin/adduser dns -d/bin -u 0 -g 0 -s/bin/bash
7.passwd dns -d
8.touch -acmr /etc/X11/applnk/Internet/.etcpasswd /etc/passwd
9.touch -acmr /etc/X11/applnk/Internet/.etc /etc
After studying the following log entries, how many user IDs can you identify that the attacker has tampered with?
1.mkdir -p /etc/X11/applnk/Internet/.etc
2.mkdir -p /etc/X11/applnk/Internet/.etcpasswd
3.touch -acmr /etc/passwd /etc/X11/applnk/Internet/.etcpasswd
4.touch -acmr /etc /etc/X11/applnk/Internet/.etc
5.passwd nobody -d
6./usr/sbin/adduser dns -d/bin -u 0 -g 0 -s/bin/bash
7.passwd dns -d
8.touch -acmr /etc/X11/applnk/Internet/.etcpasswd /etc/passwd
9.touch -acmr /etc/X11/applnk/Internet/.etc /etc
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 7
What is the proper response for a FIN scan if the port is closed?
What is the proper response for a FIN scan if the port is closed?
Correct Answer: C
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 8
What type of session hijacking attack is shown in the exhibit?

What type of session hijacking attack is shown in the exhibit?

Correct Answer: B
QUESTION NO: 9
When analyzing the IDS logs, the system administrator notices connections from outside of the LAN have been sending packets where the Source IP address and Destination IP address are the same. There have been no alerts sent via email or logged in the IDS. Which type of an alert is this?
When analyzing the IDS logs, the system administrator notices connections from outside of the LAN have been sending packets where the Source IP address and Destination IP address are the same. There have been no alerts sent via email or logged in the IDS. Which type of an alert is this?
Correct Answer: A
QUESTION NO: 10
Snort has been used to capture packets on the network. On studying the packets, the penetration tester finds it to be abnormal. If you were the penetration tester, why would you find this abnormal?
What is odd about this attack? (Choose the most appropriate statement)
Snort has been used to capture packets on the network. On studying the packets, the penetration tester finds it to be abnormal. If you were the penetration tester, why would you find this abnormal?
What is odd about this attack? (Choose the most appropriate statement)
Correct Answer: D
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 11
Matthew re-injects a captured wireless packet back onto the network. He does this hundreds of times within a second. The packet is correctly encrypted and Matthew assumes it is an ARP request packet. The wireless host responds with a stream of responses, all individually encrypted with different IVs. What is this attack most appropriately called?
Matthew re-injects a captured wireless packet back onto the network. He does this hundreds of times within a second. The packet is correctly encrypted and Matthew assumes it is an ARP request packet. The wireless host responds with a stream of responses, all individually encrypted with different IVs. What is this attack most appropriately called?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).




