DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free CEH v13 312-50 Practice Questions & Answers 2026 Part4 | Certified Ethical Hacker

Are you preparing for the EC‐Council CEH 13 certification exam? SPOTO offers the EC‐Council CEH 13 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
What is the role of test automation in security testing?
A. It is an option but it tends to be very expensive
B. It should be used exclusively
C. Test automation is not usable in security due to the complexity of the tests
D. It can accelerate benchmark tests and repeat them with a consistent test setup
View answer
Correct Answer: D
Question #2
Which of the following is the least-likely physical characteristic to be used in biometric control that supports a large company?
A. Iris patterns
B. Voice
C. Height and Weight
D. Fingerprints
View answer
Correct Answer: C
Question #3
What term describes the amount of risk that remains after the vulnerabilities are classified and the countermeasures have been deployed?
A. Residual risk
B. Impact risk
C. Deferred risk
D. Inherent risk
View answer
Correct Answer: A
Question #4
The company ABC recently contracts a new accountant. The accountant will be working with the financial statements. Those financial statements need to be approved by the CFO and then they will be sent to the accountant but the CFO is worried because he wants to be sure that the information sent to the accountant was not modified once he approved it. Which of the following options can be useful to ensure the integrity of the data?
A. The CFO can use a hash algorithm in the document once he approved the financial statements
B. The CFO can use an excel file with a password
C. The financial statements can be sent twice, one by email and the other delivered in USB and the accountant can compare both to be sure is the same document
D. The document can be sent to the accountant using an exclusive USB for that document
View answer
Correct Answer: A
Question #5
You need to deploy a new web-based software package for your organization. The package requires three separate servers and needs to be available on the Internet. What is the recommended architecture in terms of server placement?
A. All three servers need to be placed internally
B. A web server facing the Internet, an application server on the internal network, a database server on the internal network
C. A web server and the database server facing the Internet, an application server on the internal network
D. All three servers need to face the Internet so that they can communicate between themselves
View answer
Correct Answer: B
Question #6
By using a smart card and pin, you are using a two-factor authentication that satisfies
A. omething you have and something you know
B. omething you know and something you are
C. omething you have and something you are
D. omething you are and something you remember
View answer
Correct Answer: A
Question #7
Which of the following viruses tries to hide from anti-virus programs by actively altering and corrupting the chosen service call interruptions when they are being run?
A. Macro virus
B. Stealth/Tunneling virus
C. Cavity virus
D. Polymorphic virus
View answer
Correct Answer: B
Question #8
Which mode of IPSec should you use to assure security and confidentiality of data within the same LAN?
A. ESP transport mode
B. ESP confidential
C. AH permiscuous
D. AH Tunnel mode
View answer
Correct Answer: A
Question #9
What kind of detection techniques is being used in antivirus software that identifies malware by collecting data from multiple protected systems and instead of analyzing files locally it’s made on the provider’s environment?
A. Behavioral based
B. Heuristics based
C. Honeypot based
D. Cloud based
View answer
Correct Answer: D
Question #10
What is the role of test automation in security testing?
A. It is an option but it tends to be very expensive
B. It should be used exclusively
C. Test automation is not usable in security due to the complexity of the tests
D. It can accelerate benchmark tests and repeat them with a consistent test setup
View answer
Correct Answer: D
Question #11
Which results will be returned with the following Google search query? site:target.com – site:Marketing.target.com accounting
A. Results from matches on the site marketing
B. Results matching all words in the query
C. Results for matches on target
D. Results matching “accounting” in domain target
View answer
Correct Answer: D
Question #12
Why is a penetration test considered to be more thorough than vulnerability scan?
A. Vulnerability scans only do host discovery and port scanning by default
B. A penetration test actively exploits vulnerabilities in the targeted infrastructure, while a vulnerability scan does not typically involve active exploitation
C. It is not – a penetration test is often performed by an automated tool, while a vulnerability scan requiresactive engagement
D. The tools used by penetration testers tend to have much more comprehensive vulnerability databases
View answer
Correct Answer: B
Question #13
Session splicing is an IDS evasion technique in which an attacker delivers data in multiple, small sized packets to the target computer, making it very difficult for an IDS to detect the attack signatures. Which tool can be used to perform session splicing attacks?
A. tcpsplice
B. Burp
C. Hydra
D. Whisker
View answer
Correct Answer: D
Question #14
Which of the following tools can be used for passive OS fingerprinting?
A. nmap
B. tcpdump
C. tracert
D. ping
View answer
Correct Answer: B
Question #15
A company’s security policy states that all Web browsers must automatically delete their HTTP browser cookies upon terminating. What sort of security breach is this policy attempting to mitigate?
A. Attempts by attackers to access the user and password information stored in the company’s SQL database
B. Attempts by attackers to access Web sites that trust the Web browser user by stealing the user’s authentication credentials
C. Attempts by attackers to access passwords stored on the user’s computer without the user’s knowledge
D. Attempts by attackers to determine the user’s Web browser usage patterns, including when sites were visited and for how long
View answer
Correct Answer: B
Question #16
The change of a hard drive failure is once every three years. The cost to buy a new hard drive is $300. It will require 10 hours to restore the OS and software to the new hard disk. It will require a further 4 hours to restore the database from the last backup to the new hard disk. The recovery person earns $10/hour. Calculate the SLE, ARO, and ALE. Assume the EF = 1(100%). What is the closest approximate cost of this replacement and recovery operation per year?
A. $1320
B. $440
C. $100
D. $146
View answer
Correct Answer: D
Question #17
A regional healthcare provider in Portland, Oregon, recently migrated its patient scheduling portal to a new cloud platform. Within days, multiple patients reported that when searching online for the clinic ' s appointment system, they were directed to a website that looked identical to the official portal. The fraudulent page appeared prominently in search engine results and prompted users to log in using their patient credentials. The URL closely resembled the legitimate domain name, and no internal DNS servers had been altered within the organization ' s infrastructure. Security analysts later determined that the attacker had created a convincing replica of the portal and manipulated search visibility so that unsuspecting users would voluntarily navigate to the malicious site. Which type of social engineering technique best explains this attack?
A. earch Engine Phishing
B. pear Phishing
C. harming
D. haling
View answer
Correct Answer: A
Question #18
Although FTP traffic is not encrypted by default, which layer 3 protocol would allow for end-to-end encryption of the connection?
A. SFTP
B. Ipsec
C. SSL
D. FTPS
View answer
Correct Answer: B
Question #19
Which Intrusion Detection System is best applicable for large environments where critical assets on the network need extra scrutiny and is ideal for observing sensitive network segments?
A. Honeypots
B. Firewalls
C. Network-based intrusion detection system (NIDS)
D. Host-based intrusion detection system (HIDS)
View answer
Correct Answer: C
Question #20
Which method of password cracking takes the most time and effort?
A. Dictionary attack
B. Shoulder surfing
C. Rainbow tables
D. Brute force
View answer
Correct Answer: D
Question #21
In the field of cryptanalysis, what is meant by a “rubber-hose” attack?
A. Forcing the targeted keystream through a hardware-accelerated device such as an ASIC
B. A backdoor placed into a cryptographic algorithm by its creator
C. Extraction of cryptographic secrets through coercion or torture
D. Attempting to decrypt ciphertext by making logical assumptions about the contents of the original plaintext
View answer
Correct Answer: C
Question #22
Which of the following Linux commands will resolve a domain name into IP address?
A. >host-t a hackeddomain
B. >host-t ns hackeddomain
C. >host -t soa hackeddomain
D. >host -t AXFR hackeddomain
View answer
Correct Answer: A
Question #23
The change of a hard drive failure is once every three years. The cost to buy a new hard drive is $300. It will require 10 hours to restore the OS and software to the new hard disk. It will require a further 4 hours to restore the database from the last backup to the new hard disk. The recovery person earns $10/hour. Calculate the SLE, ARO, and ALE. Assume the EF = 1(100%). What is the closest approximate cost of this replacement and recovery operation per year?
A. $1320
B. $440
C. $100
D. $146
View answer
Correct Answer: D
Question #24
While using your bank’s online servicing you notice the following string in the URL bar: “http://www.MyPersonalBank.com/account?id=368940911028389&Damount=10980&Camount=21”You observe that if you modify the Damount&Camount values and submit the request, that data on the web page reflect the changes.Which type of vulnerability is present on this site?
A. Cookie Tampering
B. SQL Injection
C. Web Parameter Tampering
D. XSS Reflection
View answer
Correct Answer: C
Question #25
Which results will be returned with the following Google search query? site:target.com – site:Marketing.target.com accounting
A. Results from matches on the site marketing
B. Results matching all words in the query
C. Results for matches on target
D. Results matching “accounting” in domain target
View answer
Correct Answer: D
Question #26
You are the Network Admin, and you get a complaint that some of the websites are no longer accessible. You try to ping the servers and find them to be reachable. Then you type the IP address and then you try on the browser, and find it to be accessible. But they are not accessible when you try using the URL.What may be the problem?
A. Traffic is Blocked on UDP Port 53
B. Traffic is Blocked on TCP Port 80
C. Traffic is Blocked on TCP Port 54
D. Traffic is Blocked on UDP Port 80
View answer
Correct Answer: A
Question #27
Which of the following tools is used to detect wireless LANs using the 802.11a/b/g/n WLAN standards on a Linux platform?
A. Kismet
B. Abel
C. Netstumbler
D. Nessus
View answer
Correct Answer: A
Question #28
Which system consists of a publicly available set of databases that contain domain name registration contact information?
A. WHOIS
B. CAPTCHA
C. IANA
D. IETF
View answer
Correct Answer: A
Question #29
Todd has been asked by the security officer to purchase a counter-based authentication system. Which of the following best describes this type of system?
A. A biometric system that bases authentication decisions on behavioral attributes
B. A biometric system that bases authentication decisions on physical attributes
C. An authentication system that creates one-time passwords that are encrypted with secret keys
D. An authentication system that uses passphrases that are converted into virtual passwords
View answer
Correct Answer: C
Question #30
A large mobile telephony and data network operator has a data center that houses network elements. These are essentially large computers running on Linux. The perimeter of the data center is secured with firewalls and IPS systems.What is the best security policy concerning this setup?
A. Network elements must be hardened with user ids and strong passwords
B. As long as the physical access to the network elements is restricted, there is no need for additional measures
C. There is no need for specific security measures on the network elements as long as firewalls and IPS systems exist
D. The operator knows that attacks and down time are inevitable and should have a backup site
View answer
Correct Answer: A
Question #31
During a red team engagement at a law firm in Dallas, ethical hacker Sarah connects a compromised workstation to a core switch. Within minutes, the switch begins experiencing instability, and multiple VLANs report traffic leakage across isolated departments. Sarah observes that her machine is now receiving packets not originally destined for it, giving her visibility into multiple active sessions. Logs show the switch ' s CAM table was overwhelmed during the attack.Which sniffing technique did Sarah most likely use?
A. RP Poisoning
B. NS Poisoning
C. LAN Hopping
D. AC Flooding
View answer
Correct Answer: D
Question #32
Which of the following programming languages is most susceptible to buffer overflow attacks, due to its lack of a built-in bounds checking mechanism?Code:#include intmain(){____________char buffer[8];strcpy(buffer, ““11111111111111111111111111111””);} Output: Segmentation fault
A. C#
B. Python
C. Java
D. C++
View answer
Correct Answer: D
Question #33
Peter is surfing the internet looking for information about DX Company. Which hacking process is Peter doing?
A. Scanning
B. Footprinting
C. Enumeration
D. System Hacking
View answer
Correct Answer: B
Question #34
You need to deploy a new web-based software package for your organization. The package requires three separate servers and needs to be available on the Internet. What is the recommended architecture in terms of server placement?
A. All three servers need to be placed internally
B. A web server facing the Internet, an application server on the internal network, a database server on the internal network
C. A web server and the database server facing the Internet, an application server on the internal network
D. All three servers need to face the Internet so that they can communicate between themselves
View answer
Correct Answer: B
Question #35
Granite Ridge Technologies in New Jersey is preparing to formalize its information security governance model. Executive leadership requires adoption of an internationally recognized framework that ensures confidentiality, integrity, and availability of information while enabling the organization to systematically identify, assess, and manage information security risks. The framework must also support compliance with regulatory and contractual obligations and demonstrate commitment to stakeholders.Which standard best fulfills these requirements?
A. SO/IEC 27002:2022
B. SO/IEC 27701:2019
C. SO/IEC 27001:2022
D. SO/IEC 27005:2022
View answer
Correct Answer: C
Question #36
As a Certified Ethical Hacker, you were contracted by a private firm to conduct an external security assessment through penetration testing.What document describes the specifics of the testing, the associated violations, and essentially protects both the organization’s interest and your liabilities as a tester?
A. Service Level Agreement
B. Project Scope
C. Rules of Engagement
D. Non-Disclosure Agreement
View answer
Correct Answer: C
Question #37
A large mobile telephony and data network operator has a data center that houses network elements. These are essentially large computers running on Linux. The perimeter of the data center is secured with firewalls and IPS systems.What is the best security policy concerning this setup?
A. Network elements must be hardened with user ids and strong passwords
B. As long as the physical access to the network elements is restricted, there is no need for additional measures
C. There is no need for specific security measures on the network elements as long as firewalls and IPS systems exist
D. The operator knows that attacks and down time are inevitable and should have a backup site
View answer
Correct Answer: A
Question #38
An attacker has installed a RAT on a host. The attacker wants to ensure that when a user attempts to go to "www.MyPersonalBank.com", the user is directed to a phishing site.Which file does the attacker need to modify?
A. Boot
B. Sudoers
C. Networks
D. Hosts
View answer
Correct Answer: D
Question #39
What is correct about digital signatures?
A. A digital signature cannot be moved from one signed document to another because it is the hash of the original document encrypted with the private key of the signing party
B. Digital signatures may be used in different documents of the same type
C. A digital signature cannot be moved from one signed document to another because it is a plain hash of the document content
D. Digital signatures are issued once for each user and can be used everywhere until they expire
View answer
Correct Answer: A
Question #40
What does a firewall check to prevent particular ports and applications from getting packets into an organization?
A. Transport layer port numbers and application layer headers
B. Presentation layer headers and the session layer port numbers
C. Network layer headers and the session layer port numbers
D. Application layer port numbers and the transport layer headers
View answer
Correct Answer: A
Question #41
Bob received this text message on his mobile phone: “Hello, this is Scott Smelby from the Yahoo Bank. Kindly contact me for a vital transaction on: scottsmelby@yahoo.com”. Which statement below is true?
A. This is a scam as everybody can get a @yahoo address, not the Yahoo customer service employees
B. This is a scam because Bob does not know Scott
C. Bob should write to scottmelby@yahoo
D. This is probably a legitimate message as it comes from a respectable organization
View answer
Correct Answer: A
Question #42
Which of the following is a low-tech way of gaining unauthorized access to systems?
A. Social Engineering
B. Eavesdropping
C. Scanning
D. Sniffing
View answer
Correct Answer: A
Question #43
When you are getting information about a web server, it is very important to know the HTTP Methods (GET, POST, HEAD, PUT, DELETE, TRACE) that are available because there are two critical methods (PUT and DELETE). PUT can upload a file to the server and DELETE can delete a file from the server. You can detect all these methods (GET, POST, HEAD, PUT, DELETE, TRACE) using NMAP script engine. What Nmap script will help you with this task?
A. http-methods
B. http enum
C. http-headers
D. http-git
View answer
Correct Answer: A

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us