ECCouncil 312-50v13 考試概覽:
| 認證廠商: | EC-Council |
|---|---|
| 考試名稱: | 認證道德駭客(CEH)考試 |
| 考試代碼: | 312-50v13 |
| 考試形式: | 拖放題, 選擇題, 實作表現型題目 |
| 考試時間: | 240 分鐘 |
| 實際考試題數: | 125 |
| 及格分數: | 70% |
| 證照有效期限: | 3年 |
| 相關認證: | CEH (Master) |
| 考試費用: | USD 1,199 |
| 支援語言: | English |
| 範例考題: | ECCouncil 312-50v13 範例考題 |
| 考試方式: | 可於Pearson VUE考場實地應考,或透過線上監考系統(OnVue)應考 |
| 必備條件: | 必要條件:具備2年相關領域工作經驗,或完成EC-Council官方培訓課程。若無相關經驗,亦可先報考CEH考試,並提交資格審核申請及繳交USD 100審核費用。 |
| 官方大綱網址: | https://www.eccouncil.org/certifications/certified-ethical-hacker/ |
ECCouncil 312-50v13 考試大綱主題:
| 章節 | 權重 | 目標 |
|---|---|---|
| 主題 1: 弱點分析 | 7% | - 弱點評估概念
|
| 主題 2: 無線網路攻擊 | 9% | - 無線網路入侵方法論
|
| 主題 3: 雲端與容器技術攻擊 | 10% | - 雲端運算概念
|
| 主題 4: 惡意程式威脅 | 8% | - 惡意程式及其類型
|
| 主題 5: 網頁應用程式攻擊 | 19% | - 網頁伺服器與網頁應用程式入侵
|
| 主題 6: 資訊安全與道德駭客概論 | 6% | - 資訊安全概論
|
| 主題 7: 列舉探查 | 15% | - 列舉探查概念
|
| 主題 8: 封包側錄與防禦繞過 | 10% | - 網路防禦繞過
|
| 主題 9: 系統入侵 | 17% | - 系統入侵方法論
|
| 主題 10: 偵查蒐集技術 | 21% | - 資訊足跡探查與偵查蒐集
|
| 主題 11: 行動平台與物聯網攻擊 | 7% | - 物聯網與工業控制系統攻擊
|
| 主題 12: 密碼學與入侵後行動 | 13% | - 密碼學概念
|
最新的 CEH v13 312-50v13 免費考試真題:
問題 #1
A penetration tester reviews an API and discovers that changing a numeric object identifier allows access to another user's records without additional authorization checks. Which vulnerability BEST describes this issue?
A. Insecure Direct Object Reference (IDOR)
B. XML Injection
C. HTTP Request Smuggling
D. Clickjacking
問題 #2
During a red team assessment at a retail bank in New York, ethical hacker Aisha launches a flood of TCP connection initiation packets against the bank's online portal. The target accepts each initial handshake packet but never receives the final ACK to complete the three-way handshake, exhausting the server's backlog of half-open connections and preventing legitimate users from establishing new sessions. Which type of DoS attack is Aisha most likely simulating?
A. SYN Flood Attack
B. TCP SACK Panic
C. ACK Flood
D. RST Attack
問題 #3
Following reports of inconsistent IP-to-MAC mappings on an internal access switch at a manufacturing company in Detroit, Michigan, the network security team enabled additional validation controls. Soon afterward, the switch began automatically discarding certain ARP replies that did not match previously recorded IP address assignments. Log entries indicated that packets were being denied due to validation failures tied to existing address-to-port mappings learned earlier from legitimate host configuration traffic. Which switch-level security feature is most likely responsible for enforcing this ARP validation behavior?
A. Configuring BPDU Guard to protect spanning-tree topology
B. Activating Dynamic ARP Inspection to validate ARP packets
C. Displaying the DHCP Snooping binding table for verification
D. Enabling DHCP Snooping to track address assignments
問題 #4
At a biomedical analytics firm in Raleigh, North Carolina, security consultant Marcus Ellison was reviewing exposed services on a legacy Linux host located in a screened subnet. While mapping available services, he observed that the machine was responding to time synchronization queries from multiple internal systems.
Curious whether the service might reveal additional intelligence, Marcus issued targeted queries against the time service and received responses that exposed internal client addresses and system identifiers interacting with it. The information provided unexpected visibility into internal network structure without requiring authentication.
From the available options, what enumeration technique is illustrated in this scenario?
A. NFS Enumeration
B. SNMP Enumeration
C. NetBIOS Enumeration
D. NTP Enumeration
問題 #5
During a red team exercise at a technology consulting firm in San Francisco, analyst Evelyn deploys a malicious payload disguised within a software update installer. When the target runs the installer, the main application functions normally, but behind the scenes, additional malware components are silently placed on the system without the user's knowledge. These hidden components later activate to establish remote access for the red team. Which technique was most likely used to deliver the hidden malware?
A. Downloader
B. Injector
C. Dropper
D. Wrapper
問題與答案:
| 問題 #1 答案: A | 問題 #2 答案: A | 問題 #3 答案: B | 問題 #4 答案: D | 問題 #5 答案: D |

下載最新試用版
1312位客戶反饋
我們對我們的產品非常有信心,所以我們不提供会给客户带去麻煩的產品。








123.194.160.* -
之前幾個月我非常擔心我的 312-50v13 考試。有一天,我的朋友推薦 VCESoft 学习材料给我,我发现這網站的学习材料非常适合我。最终我选择了使用它,它帮助我獲得了更好的表现。