Official Bank 0/573

Ethical Hacker Certified (312-50) - EC-Council Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
573 Total Questions
1
Question
Session splicing is an IDS evasion technique in which an attacker delivers data in multiple, small sized packets to the target computer, making it very difficult for an IDS to detect the attack signatures.

Which tool can be used to perform session splicing attacks?
Options
A Burp
B Whisker
C tcpsplice
D Hydra
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
What is a NULL scan?
Options
A A scan in which certain flags are off
B A scan in which all flags are turned off
C A scan in which the packet size is set to zero
D A scan with an illegal packet size
E A scan in which all flags are on
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
The security administrator of ABC needs to permit Internet traffic in the host 10.0.0.2 and UDP traffic in the host 10.0.0.3. He also needs to permit all FTP traffic to the rest of the network and deny all other traffic. After he applied his ACL configuration in the router, nobody can access the ftp, and the permitted hosts cannot access the Internet. According to the next configuration, what is happening in the network? access-list 102 deny tcp any any access-list 104 permit udp host 10.0.0.3 any access-list 110 permit tcp host 10.0.0.2 eq www any access-list 108 permit tcp any eq ftp any
Options
A The first ACL is denying all TCP traffic and the other ACLs are being ignored by the router
B The ACL 110 needs to be changed to port 80
C The ACL 104 needs to be first because is UDP
D The ACL for FTP must be before the ACL 110
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Nathan is testing some of his network devices. Nathan is using Macof to try and flood the ARP cache of these switches.
If these switches' ARP cache is successfully flooded, what will be the result?
Options
A The switches will route all traffic to the broadcast address created collisions.
B The switches will drop into hub mode if the ARP cache is successfully flooded.
C If the ARP cache is flooded, the switches will drop into pix mode making it less susceptible to
attacks.
D Depending on the switch manufacturer, the device will either delete every entry in its ARP cache or reroute packets to the nearest switch.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Which Nmap switch helps evade IDS or firewalls?
Options
A -D
B -n/-R
C -0N/-0X/-0G
D -T
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.