ECCouncil 312-50v13 試験概要:
| 認定ベンダー: | EC-Council |
| 試験名: | 認定倫理ハッカー(CEH)試験 |
| 試験番号: | 312-50v13 |
| 出題数: | 125 |
| 受験料: | USD 1,199 |
| 試験時間: | 240 minutes |
| 合格点: | 70% |
| 関連資格: | CEH (Master) |
| 認定の有効期間: | 3年 |
| 対応言語: | 英語 |
| 試験形式: | 多肢選択, ドラッグ&ドロップ, 実技ベースのパフォーマンス試験 |
| サンプル問題: | ECCouncil 312-50v13 サンプル問題 |
| 受験方法: | Pearson VUE試験センターでの対面受験、またはオンライン監督試験(OnVue) |
| 前提条件: | 必須: この分野で2年の実務経験、またはEC-Council公式トレーニングの修了。実務経験のない受験者は、代替としてCEH試験を受験し、USD 100の手数料を伴う試験受験資格申請を提出できます。 |
| 公式シラバスのURL: | https://www.eccouncil.org/certifications/certified-ethical-hacker/ |
ECCouncil 312-50v13 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| 暗号技術とポストエクスプロイト | 13% | - 暗号技術の概念
|
| 列挙 | 15% | - 列挙プロセス
|
| モバイルプラットフォームとIoTへの攻撃 | 7% | - IoTおよびOTへの攻撃
|
| 無線ネットワーク攻撃 | 9% | - 無線ハッキングの手法
|
| システムハッキング | 17% | - システムハッキングツールと対策
|
| マルウェアの脅威 | 8% | - マルウェア分析と配布
|
| スニッフィングと回避 | 10% | - ソーシャルエンジニアリング
|
| クラウドとコンテナへの攻撃 | 10% | - クラウドコンピューティングの概念
|
| 脆弱性分析 | 7% | - 脆弱性評価の概念
|
| 情報セキュリティと倫理的ハッキングの概要 | 6% | - 情報セキュリティの概要
|
| Webアプリケーション攻撃 | 19% | - Webアプリケーションの概念と攻撃
|
| 偵察技術 | 21% | - フットプリンティングと偵察
|
ECCouncil Certified Ethical Hacker Exam (CEHv13) 認定 312-50v13 試験問題:
1. Lewis, a professional hacker, targeted the IoT cameras and devices used by a target venture- capital firm. He used an information-gathering tool to collect information about the IoT devices connected to a network, open ports and services, and the attack surface area. Using this tool, he also generated statistical reports on broad usage patterns and trends. This tool helped Lewis continually monitor every reachable server and device on the Internet, further allowing him to exploit these devices in the network. Which of the following tools was employed by Lewis in the above scenario?
A) Wapiti
B) Lacework
C) NeuVector
D) Censys
2. A U.S.-based online securities trading firm in New York is reviewing its transaction authentication process. The security team confirms that each transaction is processed by first generating a hash of the transaction data. The hash value is then signed using the sender's private key. During verification, the recipient uses the corresponding public key to validate the signature before approving the transaction. The system documentation specifies that the same algorithm supports encryption, digital signatures, and key exchange mechanisms within the organization's secure communications infrastructure. Which encryption algorithm is being used in this implementation?
A) ElGamal
B) RSA
C) Diffie-Hellman
D) DSA
3. In Atlanta, Georgia, ethical hacker James Patel is hired by Southern Retail, a major e-commerce chain, to test the security of their online shopping platform. During his penetration test, James aims to simulate a session hijacking attack by setting up a proxy to intercept HTTP traffic between customers and the platform, log the requests, and perform advanced searches on the captured data to identify session tokens. He needs a lightweight tool specifically designed for security research that can handle these tasks in a controlled environment to demonstrate vulnerabilities to the company's security team. Which tool should James use to perform this session hijacking simulation?
A) Bettercap
B) Caido
C) Hetty
D) Wireshark
4. A certified ethical hacker is conducting a Whois footprinting activity on a specific domain. The individual is leveraging various tools such as Batch IP Converter and Whois Analyzer Pro to retrieve vital details but is unable to gather complete Whois information from the registrar for a particular set of data. As the hacker, what might be the probable data model being utilized by the domain's registrar for storing and looking up Whois information?
A) Thin Whois model with a malfunctioning server
B) Thick Whois model with a malfunctioning server
C) Thin Whois model working correctly
D) Thick Whois model working correctly
5. In Miami, Florida, cybersecurity analyst Laura Bennett is responding to a series of unauthorized access attempts targeting Sunshine Credit Union's online banking platform. She observes unusual network activity that suggests attackers may be intercepting session IDs transmitted over unsecured connections to hijack active user sessions. To prevent further compromise, Laura works with the network team to apply a control that secures session-related communications throughout the entire portal, ensuring sensitive tokens are no longer exposed to interception during user interactions. What countermeasure should Laura implement to prevent session hijacking in this scenario?
A) Do not create sessions for unauthenticated users
B) Implement SSL to encrypt all information in transit via the network
C) Regenerate the session ID after a successful login
D) Use restrictive cache directives such as "Cache-Control: no-cache"
質問と回答:
| 質問 # 1 正解: D | 質問 # 2 正解: B | 質問 # 3 正解: C | 質問 # 4 正解: D | 質問 # 5 正解: B |














1046 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
