EC-Council 312-50v13 Exam Actual Questions
Certified Ethical Hacker v13 (Page 15 )

Updated On: 31-Jul-2026

While browsing his Facebook feed, Matt sees a picture one of his friends posted with the caption, “Learn more about your friends!”, as well as a number of personal questions. Matt is suspicious and texts his friend, who confirms that he did indeed post it. With assurance that the post is legitimate, Matt responds to the questions on the post. A few days later, Matt’s bank account has been accessed, and the password has been changed.
What most likely happened?

  1. Matt inadvertently provided the answers to his security questions when responding to the post.
  2. Matt inadvertently provided his password when responding to the post.
  3. Matt’s computer was infected with a keylogger.
  4. Matt’s bank account login information was brute forced.

Answer(s): A

Explanation:

A is correct because Matt likely provided answers to security questions embedded in the seemingly innocent Facebook post, which attackers can exploit when they gain access to other accounts.
When engaging with online content that solicits personal information in the form of seemingly benign questions, users expose themselves to social engineering tactics. Security questions are often derived from personal data shared on social platforms, making them easy targets for attackers.
Evaluation of Incorrect Options:
B: Matt inadvertently provided his password when responding to the post. This is unlikely because the context involves answering questions rather than entering credentials. The format of the engagement was not conducive to password entry. C. Matt’s computer was infected with a keylogger.
While this is a plausible concern for data breaches, the timeline and nature of the incident suggest that responding to the post alone, rather than active malicious software, caused the compromise. No evidence of unusual activity or prior signs of infection is mentioned. D. Matt’s bank account login information was brute forced. This scenario assumes Matt’s credentials were exposed to a malicious actor but does not account for the specificity and likelihood of security questions being the direct source of compromise. Brute forcing is less common than exploiting gathered social data.
In conclusion, the primary vulnerability in this scenario arises from users unwittingly providing answers to security questions that can facilitate unauthorized access to their accounts, highlighting the need for greater awareness in social media interactions.
References:
https://www.csoonline.com/article/3203002/social-engineering-how-hackers-use-your-emotions-against-you.html https://www.kaspersky.com/resource-center/definitions/social-engineering https://www.owasp.org/index.php/Social_Engineering


Reference:

References:
https://www.csoonline.com/article/3203002/social-engineering-how-hackers-use-your-emotions-against-you.html https://www.kaspersky.com/resource-center/definitions/social-engineering https://www.owasp.org/index.php/Social_Engineering



Attacker Simon targeted the communication network of an organization and disabled the security controls of NetNTLMv1 by modifying the values of LMCompatibilityLevel, NTLMMinClientSec, and RestrictSendingNTLMTraffic. He then extracted all the non-network logon tokens from all the active processes to masquerade as a legitimate user to launch further attacks.
What is the type of attack performed by Simon?

  1. Combinator attack
  2. Dictionary attack
  3. Rainbow table attack
  4. Internal monologue attack

Answer(s): D

Explanation:

D is correct because Simon's actions reflect a sophisticated form of impersonation utilizing internal credentials while bypassing security mechanisms.
Simon's manipulation of registry settings related to NTLM reflects an advanced internal compromise, leveraging the weaknesses in the authentication protocol rather than brute-force or pre-computed attack methods. By modifying LMCompatibilityLevel , NTLMMinClientSec , and RestrictSendingNTLMTraffic , he effectively downgraded the security level of NTLM, which allowed him to capture non-network logon tokens from active processes. This method enabled Simon to masquerade as a legitimate user, indicating an internal monologue attack, where an attacker exploits valid credentials that have been compromised internally.
Evaluation of Other Options:

A: Combinator attack : This type of attack combines various input terms from different dictionaries to generate potential passwords. It relies on combining known passwords but does not apply to the extraction of logon tokens or internal manipulation of access controls.
B: Dictionary attack : A dictionary attack involves trying numerous passwords or phrases from a pre-arranged list (dictionary) to gain unauthorized access. Simon's strategy did not involve guessing passwords but the usage of exploited token credentials.
C: Rainbow table attack : This attack utilizes precomputed tables for hash values to crack passwords. Simon's method used direct manipulation of authentication tokens instead of hash cracking, making this option irrelevant to the scenario.
By utilizing internal credentials and manipulating security settings, the outlined attack is congruent with internal monologue tactics rather than any form of traditional password attack.
References:
https://www.csoonline.com/article/3235392/network-security-using-ntlm-in-windows.html https://www.sans.org/security-resources/policies/general/pdf/ntlm-authentication-policy https://techcommunity.microsoft.com/t5/security-compliance-insider/ntlm-security-restrictions-and-
deprecation/ba-p/2367818


Reference:

References:
https://www.csoonline.com/article/3235392/network-security-using-ntlm-in-windows.html https://www.sans.org/security-resources/policies/general/pdf/ntlm-authentication-policy https://techcommunity.microsoft.com/t5/security-compliance-insider/ntlm-security-restrictions-and-
deprecation/ba-p/2367818



Steve, an attacker, created a fake profile on a social media website and sent a request to Stella. Stella was enthralled by Steve’s profile picture and the description given for his profile, and she initiated a conversation with him soon after accepting the request. After a few days, Steve started asking about her company details and eventually gathered all the essential information regarding her company.
What is the social engineering technique Steve employed in the above scenario?

  1. Baiting
  2. Piggybacking
  3. Diversion theft
  4. Honey trap

Answer(s): D

Explanation:

D is correct because the honey trap technique involves using deceptive social interactions to manipulate a target into disclosing sensitive information.
Steve's approach aligns with the honey trap strategy as he created a fabricated persona to engage Stella emotionally and conversationally. This emotional manipulation led her to trust him, which ultimately resulted in the sharing of sensitive company details. The effectiveness of this technique lies in its psychological leverage—by nurturing a relationship, the attacker can lower the guard of the target significantly.
Critique of Other Options:

A: Baiting : This strategy involves enticing the victim with the promise of a benefit (e.g., free downloads) to gain access to information. In this scenario, no tangible bait or offer was used to lure Stella into revealing information.
B: Piggybacking : This refers to gaining unauthorized access to a restricted area by following someone who has legitimate access. In the presented scenario, there was no physical breach; instead, it was a digital and emotional manipulation of trust without direct access.
C: Diversion Theft : This tactic distracts a target to facilitate a theft, generally involving a physical object or access point. Steve's actions focused on gathering information through rapport rather than diverting attention while stealing something tangible.
In conclusion, the honey trap method effectively highlights the psychological aspects of social engineering that Steve exploited, making it the most fitting descriptor of his deceptive strategy.
References:
https://www.sciencedirect.com/science/article/pii/S1877050916311638 https://www.csoonline.com/article/3264976/social-engineering-and-the-art-of-manipulation.html https://www.ibm.com/security/infographic/social-engineering-101


Reference:

References:
https://www.sciencedirect.com/science/article/pii/S1877050916311638 https://www.csoonline.com/article/3264976/social-engineering-and-the-art-of-manipulation.html https://www.ibm.com/security/infographic/social-engineering-101



Hackers often raise the trust level of a phishing message by modeling the email to look similar to the internal email used by the target company. This includes using logos, formatting, and names of the target company. The phishing message will often use the name of the company CEO, President, or Managers. The time a hacker spends performing research to locate this information about a company is known as?

  1. Exploration
  2. Investigation
  3. Reconnaissance
  4. Enumeration

Answer(s): C

Explanation:

C is correct because the time spent researching a target company's internal structure and branding before launching a phishing attack is classified as reconnaissance.
Reconnaissance is the first phase in the attack lifecycle, wherein attackers gather information to inform and enhance their strategies. This phase includes identifying organizational hierarchies, communication styles, and digital infrastructures. In the context of phishing, the insights gained allow attackers to create believable and targeted messages, significantly increasing the likelihood of successful deception (McGuire, 2021).
Evaluation of Incorrect Options:

A: Exploration: This term generally refers to a broader process of inquiry or examination rather than the focused intelligence-gathering context specific to phishing tactics. Exploration lacks the direct correlation with pre-attack research practices.
B: Investigation: While it denotes a thorough examination or inquiry, investigation implies a more formal or legal context, such as law enforcement probing criminal activity. In cybersecurity, this term is less relevant to the proactive research hackers conduct prior to an attack.
D: Enumeration: This describes a specific process of identifying user accounts, services, and vulnerabilities within a system after initial reconnaissance has been conducted. It focuses on active exploitation rather than the preliminary research phase involved in crafting a convincing phishing attempt.
For further reading:
https://www.sans.org/white-papers/37085 https://www.csoonline.com/article/3234198/the-importance-of-reconnaissance-in-cyber-attacks.html https://www.infosecurity-magazine.com/news/stages-cyber-attack-lifecycle-12393/



Attacker Lauren has gained the credentials of an organization’s internal server system, and she was often logging in during irregular times to monitor the network activities. The organization was skeptical about the login times and appointed security professional Robert to determine the issue. Robert analyzed the compromised device to find incident details such as the type of attack, its severity, target, impact, method of propagation, and vulnerabilities exploited.
What is the incident handling and response (IH&R) phase, in which Robert has determined these issues?

  1. Incident triage
  2. Preparation
  3. Incident recording and assignment
  4. Eradication

Answer(s): A

Explanation:

A is correct because incident triage entails the categorization, assessment, and prioritization of incidents based on their severity, impact, and the exploited vulnerabilities, which is precisely what Robert conducted.
Incident triage is a critical phase in incident handling and response as it enables security professionals to prioritize incidents efficiently and address them appropriately. In this scenario, Robert assessed various dimensions of the incident, notably identifying the attack type, severity, targets, impacts, propagation methods, and vulnerabilities exploited. This comprehensive evaluation is essential for determining subsequent response actions, thus aligning with standard triage objectives in security incident management.
Evaluation of Other Options:
Preparation: This phase involves establishing and maintaining readiness for potential incidents through training, creating response plans, and defining roles. Robert was not in the preparatory phase; he was actively analyzing an already occurring incident.
Incident recording and assignment: This phase typically focuses on logging the incident details and assigning responsibilities for further investigation or response.
While documentation may occur during triage, Robert's primary activity was the assessment and prioritization of the incident, rather than merely recording or delegating.
Eradication: This phase involves eliminating the cause of the incident and recovering affected systems. Robert's actions were diagnostic and preemptive regarding remediation rather than focusing on eradication strategies, which would occur later in the incident response process.
Thus, Robert’s in-depth analysis confirms that he was engaged in the incident triage phase, crucial for timely and effective incident management.
References:
https://www.isc2.org/Certifications/Cybersecurity https://www.sans.org/white-papers/39099/ https://www.nist.gov/publications/nist-special-publication-800-61-rev-2-computer-security-incident-handling-guide


Reference:

References:
https://www.isc2.org/Certifications/Cybersecurity https://www.sans.org/white-papers/39099/ https://www.nist.gov/publications/nist-special-publication-800-61-rev-2-computer-security-incident-handling-guide



At what stage of the cyber kill chain theory model does data exfiltration occur?

  1. Weaponization
  2. Actions on objectives
  3. Command and control
  4. Installation

Answer(s): B

Explanation:

B is correct because data exfiltration is the culmination of the adversary's objectives, taking place during the
Actions on Objectives phase of the cyber kill chain.
In the cyber kill chain model, the Actions on Objectives phase is specifically characterized by an attacker executing their primary goal, which often involves retrieving sensitive data or disrupting operations. Data exfiltration signifies the successful completion of prior stages—reconnaissance, weaponization, delivery, exploitation, installation, and command and control—where the attacker has established access and control over the target environment. This sets the stage for effective data extraction, marking it as an endpoint of adversarial intent and operational execution.
In contrast, the remaining options do not accurately reflect the point of data exfiltration.

A: Weaponization : This stage involves the creation of malicious payloads tailored for delivery. It is primarily focused on preparing the attack rather than executing any objectives. Data extraction cannot occur if the malicious tool is still being developed.
C: Command and Control : While this phase entails establishing a communication channel with compromised systems, it is still preparatory. Command and Control facilitates ongoing access; however, it does not entail the actual extraction of data, which occurs later when the intruder is executing their goals.
D: Installation : This stage refers to compromising the target environment and establishing tools for persistence.
While crucial, it does not involve the execution of data retrieval, thereby serving as a setup rather than an endpoint.
In summary, the Actions on Objectives stage is where data exfiltration concretely occurs, representing the endpoint of the cyber kill chain for the intruder's operational goals.
References:
https://www.csoonline.com/article/3240496/the-cyber-kill-chain-and-how-to-defend-against-it.html https://www.forbes.com/sites/bernardmarr/2018/11/21/the-cyber-kill-chain-what-you-need-to-know-to-protect-your-business/ https://www.sans.org/blog/understanding-the-cyber-kill-chain/


Reference:

References:
https://www.csoonline.com/article/3240496/the-cyber-kill-chain-and-how-to-defend-against-it.html https://www.forbes.com/sites/bernardmarr/2018/11/21/the-cyber-kill-chain-what-you-need-to-know-to-protect-your-business/ https://www.sans.org/blog/understanding-the-cyber-kill-chain/



Johnson, an attacker, performed online research for the contact details of reputed cybersecurity firms. He found the contact number of sibertech.org and dialed the number, claiming himself to represent a technical support team from a vendor. He warned that a specific server is about to be compromised and requested sibertech.org to follow the provided instructions. Consequently, he prompted the victim to execute unusual commands and install malicious files, which were then used to collect and pass critical information to Johnson’s machine.
What is the social engineering technique Steve employed in the above scenario?

  1. Diversion theft
  2. Quid pro quo
  3. Elicitation
  4. Phishing

Answer(s): B

Explanation:

B is correct because Johnson utilized the quid pro quo technique by offering technical support in exchange for sensitive information from the target.
In social engineering, quid pro quo involves a promise of a benefit in return for sensitive information or actions.
Johnson posed as a member of a technical support team, creating the illusion of urgency and necessity, thus coercing the victim into executing harmful commands. This manipulative tactic effectively leveraged trust and authority, driving the victim to comply with potentially harmful instructions under the guise of assistance.
Evaluation of Other Options:

A: Diversion theft: This involves redirecting a victim’s resources or assets with deceptive tactics. Johnson's approach did not involve diverting physical assets but was focused on manipulating the victim's actions through false pretenses, making this option incorrect for the context of this scenario.
C: Elicitation: Elicitation refers to extracting information indirectly, often in a conversational manner. Johnson's strategy was more aggressive and deceptive, seeking to create a false sense of security rather than subtly extracting information without the target's awareness. Therefore, this option does not align with the overt manipulation exhibited.
D: Phishing: Phishing typically involves deceptive emails or messages to mislead victims into revealing personal information.
While Johnson's actions could exhibit phishing traits, they were more directly engaging and interactive, distinguishing them from the typical phishing model which is often asynchronous and less personal.
For further reading on social engineering techniques, consult the following resources:
https://www.gartner.com/en/information-technology/glossary/social-engineering https://www.csoonline.com/article/3441593/social-engineering-how-attacks-work-and-how-to-protect-your-business.html https://www.infosecurity-magazine.com/opinions/social-engineering-techniques-what-you-need-know/



An organization decided to harden its security against web-application and web-server attacks. John, a security personnel in the organization, employed a security scanner to automate web-application security testing and to guard the organization's web infrastructure against web-application threats. Using that tool, he also wants to detect XSS, directory transversal problems, fault injection, SQL injection, attempts to execute commands, and several other attacks.
Which of the following security scanners will help John perform the above task?

  1. AlienVault® OSSIMTM
  2. Syhunt Hybrid
  3. Saleae Logic Analyzer
  4. Cisco ASA

Answer(s): B

Explanation:

B is correct because Syhunt Hybrid is specifically designed for web application security testing, making it suitable for detecting various vulnerabilities such as XSS, SQL injection, and more.
Syhunt Hybrid provides comprehensive scanning capabilities that focus on the nuances of web applications, thereby ensuring that John can effectively monitor and identify multiple forms of attacks prevalent in web infrastructures. It supports automated testing, which enhances efficiency and accuracy in vulnerability detection, particularly for web applications that are often targeted due to their accessible nature. The scanner employs signature-based, heuristic, and dynamic analysis methods, allowing John to mitigate the risks through real-time vulnerabilities assessment and remediation suggestions.
Evaluation of other options:

A: AlienVault® OSSIM™: This is a Security Information and Event Management (SIEM) solution, primarily focused on log management and threat detection across various systems, rather than specialized scanning for web applications. Although capable of monitoring overall security, it does not perform the targeted vulnerability assessment required for web application security testing.
C: Saleae Logic Analyzer: This tool is intended for hardware debugging and analysis of electronic signals. It does not pertain to web application scanning or vulnerability assessment, making it entirely irrelevant for John's needs focused on web-based threats.
D: Cisco ASA: While this is a robust firewall and security appliance that provides broad network security, its primary function is to manage and control network traffic rather than conducting specialized web application security assessments. As such, it lacks the specific vulnerability scanning capabilities for issues like XSS and SQL injection.
References:
1. https://www.syhunt.com/hybrid 2. https://www.alienvault.com/products/ossim 3. https://www.cisco.com/c/en/us/products/security/asa-firepower-services/index.html


Reference:

References:
1. https://www.syhunt.com/hybrid 2. https://www.alienvault.com/products/ossim 3. https://www.cisco.com/c/en/us/products/security/asa-firepower-services/index.html



Viewing page 15 of 133
Viewing questions 71 - 75 out of 1065 questions


Post your Comments and Discuss EC-Council 312-50v13 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!