ECCouncil 312-50v13日本語 Exam Overview:
| Certification Vendor: | EC-Council |
| Exam Name: | Certified Ethical Hacker (CEH) Exam |
| Exam Number: | 312-50v13 |
| Available Languages: | English |
| Exam Price: | USD 1,199 |
| Passing Score: | 70% |
| Exam Format: | Multiple Choice, Drag & Drop, Hands-on Performance Based |
| Related Certifications: | CEH (Master) |
| Exam Duration: | 240 minutes |
| Real Exam Qty: | 125 |
| Certificate Validity Period: | 3 years |
| Sample Questions: | ECCouncil 312-50v13日本語 Sample Questions |
| Exam Way: | In-person at Pearson VUE testing centers or Online Proctored (OnVue) |
| Pre Condition: | Mandatory: 2 years of work experience in the domain OR completion of an EC-Council official training. For candidates without experience, an alternative is to take the CEH exam and submit an exam eligibility application with USD 100 fee. |
| Official Syllabus URL: | https://www.eccouncil.org/certifications/certified-ethical-hacker/ |
ECCouncil 312-50v13日本語 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Cloud and Container Attacks | 10% | - Cloud Computing Concepts
|
| Topic 2: Wireless Network Attacks | 9% | - Wireless Network Concepts
|
| Topic 3: Web Application Attacks | 19% | - Web Application Concepts and Attacks
|
| Topic 4: Malware Threats | 8% | - Malware Analysis and Distribution
|
| Topic 5: Vulnerability Analysis | 7% | - Vulnerability Assessment Concepts
|
| Topic 6: System Hacking | 17% | - System Hacking Methodologies
|
| Topic 7: Enumeration | 15% | - Enumeration Process
|
| Topic 8: Sniffing and Evasion | 10% | - Social Engineering
|
| Topic 9: Cryptography and Post-Exploitation | 13% | - Post-Exploitation Techniques
|
| Topic 10: Information Security and Ethical Hacking Overview | 6% | - Ethical Hacking Overview
|
| Topic 11: Reconnaissance Techniques | 21% | - Scanning Networks
|
| Topic 12: Mobile Platform and IoT Attacks | 7% | - IoT and OT Attacks
|
ECCouncil Certified Ethical Hacker Exam (CEHv13) (312-50v13日本語版) Sample Questions:
1. マイアミに拠点を置く仮想通貨取引所の倫理的ハッカーであるリアムは、最近発生したユーザーによるデジタル資産の二重支払いの報告を受け、同社のブロックチェーンネットワークのセキュリティを評価している。彼の調査により、攻撃者がネットワークの計算リソースを大幅に制御し、トランザクションの検証を操作できたことが明らかになった。リアムは、ブロックチェーンはビットコインのような公開台帳であり、誰でも許可なくトランザクションデータにアクセスできると指摘している。分析の結果、攻撃者がネットワークの計算リソースの大部分を制御し、トランザクション履歴を書き換えることができた可能性が高いことが判明した。取引所の防御を強化するために、リアムはどのブロックチェーン攻撃を特定すべきだろうか?
A) 攻撃力51%
B) エクリプスアタック
C) フィニーアタック
D) DeFiサンドイッチ攻撃
2. セキュリティアナリストとして、攻撃者がネットワークに侵入した事件を調査しています。ログファイルを最初に調べたところ、ネットワーク上の様々なポートに大量のTCP SYNパケットが送信されているにもかかわらず、対応するACKパケットが一切送信されていないことに気づきました。攻撃者はどのようなスキャン手法を用いたと考えられますか?
A) 攻撃者はSYN/ACKスキャンを使用してファイアウォールを騙し、パケットを通過させました。
B) 攻撃者はXMASスキャンを使用して、ネットワーク上の開いているポートと閉じているポートを特定しました。
C) 攻撃者はTCP Connectスキャンを使用して、ターゲットとの完全なTCP接続を確立しました。
D) 攻撃者は、SYN スキャン(ハーフオープン スキャンとも呼ばれる)を使用しました。これは、SYN パケットを送信し、SYN/ACK 応答を待つというものです。
3. ローマはセキュリティチームの一員です。彼女は組織の内部ネットワークを差し迫った脅威から保護する任務を負っています。この任務を遂行するために、ローマは脅威インテリジェンスをデジタル形式でセキュリティデバイスに入力し、組織のネットワークに侵入する悪意のある送受信トラフィックをブロックおよび識別しました。ローマは内部ネットワークを保護するために、どのような種類の脅威インテリジェンスを使用していますか?
A) 戦略的脅威インテリジェンス
B) 運用上の脅威インテリジェンス
C) 戦術的脅威インテリジェンス
D) 技術的脅威インテリジェンス
4. ジェイコブは組織でシステム管理者として働いています。彼はモバイルアプリケーションのソースコードを抽出し、アプリケーションを逆アセンブルして設計上の欠陥を分析したいと考えています。この手法を用いて、アプリケーションのバグを修正し、潜在的な脆弱性を発見し、攻撃に対する防御戦略を改善したいと考えています。上記のシナリオにおいて、ジェイコブがモバイルアプリケーションのセキュリティを向上させるために使用する手法は何でしょうか?
A) 脱獄
B) アプリのサンドボックス化
C) リバースエンジニアリング
D) 社会工学
5. Windowsエンドポイントが、認証情報ダンプツールに関するアラートを生成します。どの資産が標的となっていますか?
A) ログ
B) 入手可能性
C) ネットワーク
D) 資格情報
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: D | Question # 3 Answer: D | Question # 4 Answer: C | Question # 5 Answer: D |


PDF Version Demo






We are confident about the products and aim to help you pass with ease. In case of failure, we will provide a no hassle full money back guarantee for the purchasing fee.
0 Customer Reviews
Quality and ValueITbraindumps Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITbraindumps testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITbraindumps offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.