ECCouncil 312-50v13 試験概要:
| 認定ベンダー: | EC-Council |
| 試験名: | 認定倫理ハッカー(CEH)試験 |
| 試験番号: | 312-50v13 |
| 合格点: | 70% |
| 関連資格: | CEH (Master) |
| 試験時間: | 240 minutes |
| 対応言語: | 英語 |
| 試験形式: | 多肢選択, ドラッグ&ドロップ, 実技ベースのパフォーマンス試験 |
| 受験料: | USD 1,199 |
| 認定の有効期間: | 3年 |
| 出題数: | 125 |
| サンプル問題: | ECCouncil 312-50v13 サンプル問題 |
| 受験方法: | Pearson VUE試験センターでの対面受験、またはオンライン監督試験(OnVue) |
| 前提条件: | 必須: この分野で2年の実務経験、またはEC-Council公式トレーニングの修了。実務経験のない受験者は、代替としてCEH試験を受験し、USD 100の手数料を伴う試験受験資格申請を提出できます。 |
| 公式シラバスのURL: | https://www.eccouncil.org/certifications/certified-ethical-hacker/ |
ECCouncil 312-50v13 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| トピック 1: 情報セキュリティと倫理的ハッキングの概要 | 6% | - 情報セキュリティの概要
|
| トピック 2: モバイルプラットフォームとIoTへの攻撃 | 7% | - IoTおよびOTへの攻撃
|
| トピック 3: システムハッキング | 17% | - システムハッキングツールと対策
|
| トピック 4: 列挙 | 15% | - 列挙の概念
|
| トピック 5: 無線ネットワーク攻撃 | 9% | - 無線ハッキングの手法
|
| トピック 6: クラウドとコンテナへの攻撃 | 10% | - クラウドへの攻撃とセキュリティ
|
| トピック 7: 暗号技術とポストエクスプロイト | 13% | - 暗号技術の概念
|
| トピック 8: Webアプリケーション攻撃 | 19% | - WebサーバーとWebアプリケーションのハッキング
|
| トピック 9: マルウェアの脅威 | 8% | - マルウェア分析と配布
|
| トピック 10: 偵察技術 | 21% | - ネットワークのスキャン
|
| トピック 11: スニッフィングと回避 | 10% | - ネットワークスニッフィング
|
| トピック 12: 脆弱性分析 | 7% | - 脆弱性評価の概念
|
ECCouncil Certified Ethical Hacker Exam (CEHv13) 認定 312-50v13 試験問題:
1. A penetration tester is tasked with enumerating user accounts and network resources in a highly secured Windows environment where standard methods like SMB null sessions are blocked. The network employs strict firewall rules and intrusion detection systems to prevent unauthorized access. Which technique should the tester use to discreetly gather the required information without triggering security alarms?
A) Exploit a misconfigured LDAP service to perform anonymous searches
B) Conduct a zone transfer by querying the organization's DNS servers
C) Utilize NetBIOS over TCP/IP to list shared resources anonymously
D) Leverage Active Directory Web Services for unauthorized queries
2. During a cybersecurity operation, a CEH professional discovered an unknown Bluetooth Low Energy (BLE) device actively transmitting pairing signals. The professional decided to breach the BLE device using a crackle. The device was seen pairing and exchanging keys, leading to the establishment of a secure connection. However, the professional only managed to capture LL_ENC_REQ and LL_ENC_RSP packets, but not the Long-Term Key (LTK). Which of the following best describes the professional's next course of action?
A) Use the BlueZ tool hcitool inq to reveal more information about the device.
B) Decrypt the pcap data using the -o option.
C) The operation cannot continue without the LTK.
D) Use Btlejacking to hijack the connection.
3. An ethical hacker is hired to conduct a comprehensive network scan of a large organization that strongly suspects potential intrusions into their internal systems. The hacker decides to employ a combination of scanning tools to obtain a detailed understanding of the network. Which sequence of actions would provide the most comprehensive information about the network's status?
A) Begin with NetScanTools Pro for a general network scan, then use Nmap for OS detection and version detection, and finally perform an SYN flooding with Hping3.
B) Initiate with Nmap for a ping sweep, then use Metasploit to scan for open ports and services, and finally use Hping3 to perform remote OS fingerprinting.
C) Start with Hping3 for a UDP scan on random ports, then use Nmap for a version detection scan, and finally use Metasploit to exploit detected vulnerabilities.
D) Use Hping3 for an ICMP ping scan on the entire subnet, then use Nmap for a SYN scan on identified active hosts, and finally use Metasploit to exploit identified vulnerabilities.
4. Dorian is sending a digitally signed email to Poly. With which key is Dorian signing this message and how is Poly validating it?
A) Dorian is signing the message with his public key, and Poly will verify that the message came from Dorian by using Dorian's private key.
B) Dorian is signing the message with Poly's public key, and Poly will verify that the message came from Dorian by using Dorian's public key.
C) Dorian is signing the message with Poly's private key, and Poly will verify that the message came from Dorian by using Dorian's public key.
D) Dorian is signing the message with his private key, and Poly will verify that the message came from Dorian by using Dorian's public key.
5. A multinational organization is implementing a security upgrade for its corporate wireless infrastructure. The current WPA2-Personal configuration relies on a shared passphrase, which the IT team finds difficult to rotate and manage securely across hundreds of employee devices.
To enhance security and scalability, the organization decides to migrate to WPA2-Enterprise. The new setup must allow for centralized control of user authentication, support certificate-based identity verification, and ensure that each authenticated client is assigned a unique session encryption key to prevent key reuse and limit the blast radius of potential breaches. Which component is essential for enabling this centralized, certificate-based authentication with unique key generation per session in a WPA2-Enterprise environment?
A) Opportunistic Wireless Encryption (OWE)
B) Pre-Shared Key (PSK)
C) RADIUS with Extensible Authentication Protocol (EAP)
D) Temporal Key Integrity Protocol (TKIP)
質問と回答:
| 質問 # 1 正解: A | 質問 # 2 正解: C | 質問 # 3 正解: D | 質問 # 4 正解: D | 質問 # 5 正解: C |














1101 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
