312-50v13 Sample Questions

312-50v13 Sample Questions & Answers

Sniffing, social engineering, and malware threats carry the heaviest weighting, on top of footprinting and scanning, vulnerability analysis and system hacking, evading defenses to reach web servers and applications, wireless, mobile, IoT, OT, cloud, and cryptography.

Launch the full 312-50v13 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Reconnaissance Techniques · AI-Powered Tools (ShellGPT)

    An ethical hacker is tasked with performing reconnaissance on a target company, acmecorp.com. The hacker wants to use the new AI-powered ShellGPT tool, as covered in CEH v13, to automate the generation of a complex nmap command. The goal is to perform an aggressive scan (-A), on the most common 1000 ports, against all hosts discovered in the acmecorp.com domain, while saving the output in all available formats (-oA). Which natural language query would be most effective to provide to ShellGPT to generate the desired command?

    Show answer & explanation

    Correct answer: C

    ShellGPT is designed to interpret natural language to generate commands. The most effective query is a clear, descriptive sentence that specifies the tool (nmap), the action (perform an aggressive scan), the target (acmecorp.com), and the desired output options (save the output in all formats to a file named 'acmescan'). This level of detail allows the AI to correctly map the request to the appropriate nmap flags (-A for aggressive, -oA acmescan for output in all formats). The other options are either too vague or use incorrect syntax for a natural language query tool.

  2. Question 2Intermediate

    Network and Perimeter Hacking · DNS Tunneling

    A security analyst is investigating a data exfiltration incident. The attacker used a DNS tunneling technique to bypass the corporate firewall. The analyst is reviewing packet captures and notices an unusually high volume of TXT record queries to a suspicious domain. The data appears to be encoded. Which of the following tools is specifically designed to create and manage DNS tunnels for data exfiltration or C2 communications?

    Show answer & explanation

    Correct answer: B

    Iodine is a well-known tool used for tunneling IPv4 data through a DNS server. It is a popular choice for attackers to exfiltrate data or establish a command-and-control (C2) channel in highly restricted networks where only DNS traffic is allowed. It works by encapsulating data within DNS queries and responses, often using TXT or NULL record types. Dnsrecon is for DNS enumeration, Wireshark is a packet analyzer, and Netcat is a versatile networking utility but does not create DNS tunnels natively.

  3. Question 3Advanced

    Web Application Hacking · GraphQL API Hacking

    A penetration tester is evaluating the security of an API endpoint that uses GraphQL. Unlike traditional REST APIs, GraphQL allows clients to request exactly the data they need. The tester wants to check for excessive data exposure vulnerabilities. Which type of GraphQL query would be most useful for discovering all possible data types and fields the API can return, potentially revealing sensitive information not intended for the public?

    Show answer & explanation

    Correct answer: C

    GraphQL has a built-in feature called introspection, which allows a client to query the server for information about the API's schema, including all available types, fields, queries, and mutations. If introspection is enabled on a production server (a common misconfiguration), an attacker can send an introspection query to get a complete map of the API's capabilities. This can reveal hidden or sensitive data fields that they can then attempt to query directly.

  4. Question 4Intermediate

    Malware Threats · Fileless Malware

    An incident response team is analyzing an attack on their organization. The attacker gained initial access, established persistence, and then used a 'living off the land' technique by abusing PowerShell to perform lateral movement and exfiltrate data. The activity was difficult to detect because it did not involve dropping any malicious executables onto the disk. Which of the following malware categories best describes this attack?

    Show answer & explanation

    Correct answer: B

    Fileless malware is a type of malicious software that exists only as in-memory artifacts. It does not write any part of its activity to the computer's hard drive, making it very difficult for traditional signature-based antivirus solutions to detect. 'Living off the land' techniques, which abuse legitimate, pre-installed tools like PowerShell, WMI, or registry entries, are a hallmark of fileless malware attacks.

  5. Question 5Advanced

    Cryptography · Perfect Forward Secrecy (PFS)

    A security auditor is reviewing the cryptographic standards for a new application. The application needs to ensure the confidentiality of data in transit. The developers have proposed a plan that involves using a symmetric cipher for bulk data encryption and an asymmetric cipher for key exchange. A primary requirement is that if the server's long-term private key is compromised, past encrypted sessions should not be decipherable. Which cryptographic property must the key exchange mechanism implement to meet this requirement?

    Show answer & explanation

    Correct answer: B

    Perfect Forward Secrecy (PFS) is a property of secure communication protocols where a compromise of long-term keys does not compromise past session keys. PFS is achieved by generating a unique, ephemeral session key for each session. Key exchange protocols like Diffie-Hellman Ephemeral (DHE) or Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) provide PFS. If the server's static private key (used for signing the key exchange) is stolen, it cannot be used to decrypt previously recorded sessions because each session used a different, temporary key that was discarded.

  6. Question 6Intermediate

    Reconnaissance Techniques · Interpreting Nmap Scan Results

    A junior penetration tester is conducting an external assessment. After running an Nmap scan, they present the following output for a single host to their senior team lead. What is the most likely reason that Nmap reported the state of all 1000 scanned ports as 'filtered'?

    Starting Nmap 7.92 ( https://nmap.org ) at 2023-10-27 10:30 EDT
    Nmap scan report for web.targetcorp.com (192.0.2.50)
    Host is up (0.052s latency).
    All 1000 scanned ports on web.targetcorp.com (192.0.2.50) are in ignored states.
    Not showing 1000 filtered tcp ports (no-response)
    
    Nmap done: 1 IP address (1 host up) scanned in 20.50 seconds
    
    Show answer & explanation

    Correct answer: C

    Nmap reports a port as 'filtered' when its probe packets are sent but no response is received. This usually indicates that a firewall, router ACL, or other packet filtering device is silently dropping the packets. An 'open' port would respond with a SYN/ACK, and a 'closed' port would respond with a RST packet. The lack of any response for all scanned ports strongly suggests a firewall is blocking the scan.

  7. Question 7Beginner

    Evading IDS, Firewalls, and Honeypots · Honeypot Types

    A security team is deploying a honeypot to gather threat intelligence on attacks targeting their web infrastructure. They want the honeypot to simulate a real operating system and a full suite of services (e.g., SSH, FTP, HTTP) to engage attackers for an extended period and capture their tools and techniques. Which category of honeypot should they deploy?

    Show answer & explanation

    Correct answer: B

    High-interaction honeypots provide a real, non-emulated environment for attackers to interact with. They run actual operating systems and services, which allows for deep analysis of an attacker's behavior, including capturing their keystrokes, uploaded tools, and TTPs. This is in contrast to low-interaction honeypots, which only emulate services and offer limited engagement, or medium-interaction honeypots, which offer more functionality than low-interaction but still fall short of a real OS.

  8. Question 8Beginner

    Malware Threats · AI-Powered Malware

    A new strain of ransomware has been discovered that utilizes AI to generate highly convincing, personalized phishing emails. It harvests data from a victim's social media and professional profiles to craft messages that are extremely difficult for humans to identify as malicious. This is an example of a threat actor leveraging a malicious AI model similar to which of the following?

    Show answer & explanation

    Correct answer: C

    FraudGPT and WormGPT are examples of malicious AI models, specifically Large Language Models (LLMs), that have been trained without the ethical safeguards of models like ChatGPT. They are designed to assist criminals in activities such as writing malicious code, creating undetectable malware, and crafting sophisticated phishing emails and scam pages. The scenario described is a prime use case for such a tool.

  9. Question 9Advanced

    System Hacking Phases and Attack Techniques · Golden Ticket Attack

    A penetration tester has gained initial access to a Windows domain controller and wants to perform a Golden Ticket attack to gain persistent, high-level access to the entire domain. Which account's NTLM hash is required to create a Golden Ticket?

    Show answer & explanation

    Correct answer: C

    A Golden Ticket is a forged Kerberos Ticket-Granting Ticket (TGT). The TGT is encrypted and signed using the NTLM hash of the krbtgt account, which is a special, disabled account in Active Directory whose sole purpose is to sign and encrypt Kerberos tickets. By obtaining the hash of the krbtgt account, an attacker can use a tool like Mimikatz to forge TGTs for any user, with any group memberships, and for any length of time, granting them ultimate control over the domain.

  10. Question 10Beginner

    Social Engineering · Physical Security Social Engineering

    An ethical hacker is performing a security assessment of a company's physical security controls. The hacker, dressed as a delivery driver, waits by a secure entrance. When an employee badges in and opens the door, the hacker follows them inside before the door closes, without presenting any credentials. This technique is known as:

    Show answer & explanation

    Correct answer: D

    Tailgating is the act of following an authorized person through a secure entryway without their knowledge or consent. This is a common physical security breach. Piggybacking is similar, but it implies the authorized person is aware of and consents to the unauthorized person's entry, which is not the case in this scenario. Impersonation is part of the overall tactic, but tailgating is the specific action of following someone through the door.

Ready for the real thing?

The full 312-50v13 simulator has every exam-style question, timed mode, and instant scoring.