Official Bank 0/573

Eccouncil Certified Ethical Hacker V13 (312-50 v13) - EC-Council Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
573 Total Questions
1
Question
A company’s policy requires employees to perform file transfers using protocols which encrypt traffic. You suspect some employees are still performing file transfers using unencrypted protocols because the employees do not like changes. You have positioned a network sniffer to capture traffic
from the laptops used by employees in the data ingest department. Using Wireshark to examine the
captured traffic, which command can be used as display filter to find unencrypted file transfers?
Options
A tcp.port = = 21 | | tcp.port = =22
B tcp.port = 23
C tcp.port ! = 21
D tcp.port = = 21
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Email is transmitted across the Internet using the Simple Mail Transport Protocol. SMTP does not encrypt email, leaving the information in the message vulnerable to being read by an unauthorized person. SMTP can upgrade a connection between two mail servers to use TLS. Email transmitted by SMTP over TLS is encrypted. What is the name of the command used by SMTP to transmit email over TLS?
Options
A UPGRADETLS
B STARTTLS
C FORCETLS
D OPPORTUNISTICTLS
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Harris is attempting to identify the OS running on his target machine. He inspected the initial TTL in the IP header and the related TCP window size and obtained the following results: TTL: 64 Window Size: 5840

What is the OS running on the target machine?
Options
A Mac OS
B Linux OS
C Windows OS
D Solaris OS
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Clark is a professional hacker. He created and configured multiple domains pointing to the same host to switch quickly between the domains and avoid detection. Identify the behavior of the adversary In the above scenario.
Options
A Data staging
B Use of DNS tunneling
C Unspecified proxy activities
D use of command-line interface
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
In the process of implementing a network vulnerability assessment strategy for a tech company, the security analyst is confronted with the following scenarios:

1) A legacy application is discovered on the network, which no longer receives updates from the
vendor.

2) Several systems in the network are found running outdated versions of web browsers prone to
distributed attacks.

3) The network firewall has been configured using default settings and passwords.

4) Certain TCP/IP protocols used in the organization are inherently insecure.
The security analyst decides to use vulnerability scanning software. Which of the following limitations of vulnerability assessment should the analyst be most cautious about in this context?
Options
A Vulnerability scanning software is not immune to software engineering flaws that might lead to serious vulnerabilities being missed
B Vulnerability scanning software cannot define the impact of an identified vulnerability on different business operations
C Vulnerability scanning software is limited in its ability to detect vulnerabilities at a given point in time
D Vulnerability scanning software is limited in its ability to perform live tests on web applications to detect errors or unexpected behavior
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.