Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

All 312-50v13 Test Inside ECCouncil Questions

Page: 7 / 60
Total 797 questions

Certified Ethical Hacker Exam (CEHv13) Questions and Answers

Question 25

As part of a passive reconnaissance engagement for a university research network, you are tasked with mapping potential administrative exposure points across .edu domains. Your objective is to identify web pages that might allow privileged backend access, such as misconfigured administrative interfaces, using only publicly indexed information. To ensure efficiency and compliance, you decide to use advanced Google search operators to refine your search results. Your goal is to locate URLs across educational domains that may contain restricted backend functionality.

Which of the following search strings would most effectively support this goal?

Options:

A.

site:.edu filetype:pdf intitle: " admin "

B.

intitle: " admin login " site:.edu

C.

site:.edu inurl:admin

D.

inanchor: " backend access " site:.edu

Question 26

Which of the following tools can be used for passive OS fingerprinting?

Options:

A.

nmap

B.

ping

C.

tcpdump

D.

tracert

Question 27

A penetration tester is assessing a company ' s executive team for vulnerability to sophisticated social engineering attacks by impersonating a trusted vendor and leveraging internal communications. What is the most effective social engineering technique to obtain sensitive executive credentials without being detected?

Options:

A.

Develop a fake social media profile to connect with executives and request private information

B.

Conduct a phone call posing as the CEO to request immediate password changes

C.

Create a targeted spear-phishing email that references recent internal projects and requests credential verification

D.

Send a mass phishing email with a malicious link disguised as a company-wide update

Question 28

An attacker impersonates a technician and gains physical access to restricted areas. What tactic is this?

Options:

A.

Help desk impersonation

B.

Dumpster diving

C.

Remote tech support scam

D.

Physical impersonation (Tailgating/Impersonation)

Page: 7 / 60
Total 797 questions