312-50v10 Sample Questions

312-50v10 Sample Questions & Answers

Free Certified Ethical Hacker (CEH v10) practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full 312-50v10 simulator →

Showing 10 of 20 free samples.

  1. Question 1

    Which of the following options represents a conceptual characteristic of an anomaly-based IDS over a signature-based IDS?

    Show answer & explanation

    Correct answer: B

    Anomaly-based IDS systems can identify unknown attacks by establishing a baseline of normal network behavior and flagging deviations from this baseline. Unlike signature-based IDS that only detect known attack patterns, anomaly-based systems can detect zero-day attacks and novel attack techniques that have not been previously catalogued.

  2. Question 2

    You are logged in as a local admin on a Windows 7 system and you need to launch the Computer Management Console from command line. Which command would you use?

    Show answer & explanation

    Correct answer: B

    The command "compmgmt.msc" launches the Computer Management Console in Windows. The .msc extension indicates a Microsoft Management Console snap-in, and compmgmt is the specific snap-in for computer management functions including disk management, services, and system tools.

  3. Question 3

    Which of the following act requires employer’s standard national numbers to identify them on standard transactions?

    Show answer & explanation

    Correct answer: B

    HIPAA (Health Insurance Portability and Accountability Act) requires the use of standard national employer identification numbers for healthcare transactions. This standardization helps ensure proper identification of healthcare entities in electronic transactions and maintains consistency across the healthcare industry.

  4. Question 4

    In Wireshark, the packet bytes panes show the data of the current packet in which format?

    Show answer & explanation

    Correct answer: D

    Wireshark displays packet data in the packet bytes pane in hexadecimal format, with corresponding ASCII representation on the right. This hex format allows security professionals to analyze raw packet contents at the byte level, which is essential for protocol analysis and network forensics.

  5. Question 5

    _________ is a set of extensions to DNS that provide the origin authentication of DNS data to DNS clients (resolvers) so as to reduce the threat of DNS poisoning, spoofing, and similar types of attacks.

    Show answer & explanation

    Correct answer: A

    DNSSEC (DNS Security Extensions) provides cryptographic authentication for DNS data, ensuring the integrity and authenticity of DNS responses. It uses digital signatures to verify that DNS responses have not been tampered with, effectively preventing DNS spoofing, cache poisoning, and man-in-the-middle attacks on DNS queries.

  6. Question 6

    PGP, SSL, and IKE are all examples of which type of cryptography?

    Show answer & explanation

    Correct answer: D

    PGP (Pretty Good Privacy), SSL/TLS, and IKE (Internet Key Exchange) are all examples of public key cryptography systems. These protocols use asymmetric encryption with public and private key pairs to establish secure communications, authenticate parties, and exchange symmetric keys securely.

  7. Question 7

    Which of the following is considered as one of the most reliable forms of TCP scanning?

    Show answer & explanation

    Correct answer: A

    TCP Connect scan (also called Full Open scan) is the most reliable form of TCP scanning because it completes the full three-way handshake with the target port. This provides accurate results about port states, though it is also the most detectable method since it establishes complete connections that are logged by the target system.

  8. Question 8

    Which of the following scanning method splits the TCP header into several packets and makes it difficult for packet filters to detect the purpose of the packet?

    Show answer & explanation

    Correct answer: B

    SYN/FIN scanning using IP fragments splits the TCP header across multiple IP packets, making it difficult for packet filters and firewalls to detect the scanning attempt. This fragmentation technique helps evade detection systems that cannot reassemble fragmented packets to analyze the complete TCP header.

  9. Question 9

    Which of the following is the BEST way to defend against network sniffing?

    Show answer & explanation

    Correct answer: C

    Using encryption protocols like HTTPS, SSL/TLS, VPN, and SSH is the best defense against network sniffing because encrypted communications remain unreadable even if intercepted. While physical security and network segmentation help, encryption ensures that captured packets cannot reveal sensitive information to attackers.

  10. Question 10

    You have successfully gained access to a Linux server and would like to ensure that the succeeding outgoing traffic from this server will not be caught by Network-Based Intrusion Detection Systems (NIDS). What is the best way to evade the NIDS?

    Show answer & explanation

    Correct answer: C

    Encryption is the most effective method to evade Network-Based Intrusion Detection Systems (NIDS) because encrypted traffic cannot be analyzed for malicious content patterns. When outgoing traffic is encrypted using protocols like SSL/TLS or VPN, the NIDS cannot inspect the packet contents to detect suspicious activities or attack signatures.

Ready for the real thing?

The full 312-50v10 simulator has every exam-style question, timed mode, and instant scoring.