ECCouncil 312-50v13 Prüfungsthemen:
| Abschnitt | Gewichtung | Ziele |
|---|---|---|
| Schwachstellenanalyse | 8 % | - Werkzeuge zum Scannen und zur Analyse - Lebenszyklus der Schwachstellenbewertung - Recherche und Datenbanken zu Schwachstellen - Einstufung und Bewertung von Schwachstellen |
| Mobile Betriebssysteme | 4 % | - Angriffsvektoren bei mobilen Geräten - Sicherheit mobiler Geräte - Schwachstellen bei Android und iOS |
| Sicherheit von IoT und OT | 4 % | - Sicherheitsmaßnahmen - Angriffe auf IoT- und OT-Systeme - Architektur und Risiken von IoT/OT-Systemen |
| Dienstverweigerung | 4 % | - Verteidigungsmechanismen - Werkzeuge für DDoS-Angriffe - Grundlagen von DoS- und DDoS-Angriffen - Angriffsmethoden und Botnetze |
| System-Hacking | 8 % | - Beseitigen von Spuren und Protokollen - Aufrechterhalten des Zugriffs - Erhöhung von Zugriffsrechten - Erlangen von Zugriff: Passwortangriffe |
| Angriffe auf Webserver und Webanwendungen | 8 % | - Angriffe auf Webanwendungen: XSS, CSRF - Sicherheitsrisiken bei APIs - Schwachstellen von Webservern - Gegenmaßnahmen zur Websicherheit - SQL-Injektion und Befehlsinjektion |
| Einführung in das ethische Hacken | 5 % | - Methodik des ethischen Hackens - Rechtliche und ethische Vorschriften - Grundbegriffe der Informationssicherheit - Cyber Kill Chain & MITRE ATT&CK |
| Netzwerkscans | 8 % | - Grundlagen des Netzwerkscannens - Scannen über IDS/Firewalls hinweg - KI-gestütztes Scannen - Erkennung von Hosts und Ports - Identifizierung von Diensten und Betriebssystemen - Gegenmaßnahmen zum Scannen |
| Paketaufzeichnung | 5 % | - Gegenmaßnahmen zur Paketaufzeichnung - Werkzeuge und Verfahren zur Paketaufzeichnung - Grundlagen der Paketaufzeichnung - MITM-Angriffe |
| Erfassung und Aufklärung | 7 % | - Grundlagen der Aufklärung - DNS, WHOIS, Netzwerkkartierung - OSINT-Verfahren - Gegenmaßnahmen zur Aufklärung |
| Soziale Manipulation | 6 % | - Identitätsdiebstahl - Grundlagen der sozialen Manipulation - Phishing, Vortäuschung von Identitäten, Köderangriffe - Gegenmaßnahmen und Sensibilisierung |
| Aufzählung von Systeminformationen | 7 % | - Gegenmaßnahmen zur Aufzählung - KI-gestützte Aufzählung - Aufzählung über DNS, SMTP, NFS - Grundlagen der Aufzählung - Aufzählung über NetBIOS, SNMP, LDAP |
| Sitzungsübernahme | 4 % | - Verfahren zur Sitzungsübernahme - Gegenmaßnahmen - Grundlagen der Sitzungsübernahme - Übernahme auf Anwendungs- und Netzwerkebene |
| Umgehung von IDS, Firewalls und Täuschungssystemen | 5 % | - Grundlagen und Erkennung von Täuschungssystemen - IDS, IPS und Firewall-Technologien - Umgehungsmethoden |
| Bedrohungen durch Schadsoftware | 7 % | - Analyse von Schadsoftware und Gegenmaßnahmen - KI-gestützte Schadsoftware - APT und dateilose Schadsoftware - Arten von Schadsoftware: Trojaner, Viren, Würmer |
| Drahtlose Netzwerke | 5 % | - Werkzeuge zum Hacken drahtloser Netzwerke - Bedrohungen und Angriffe im drahtlosen Bereich - Empfehlungen zur Sicherheit - Drahtlose Verschlüsselung: WEP, WPA2, WPA3 |
| Cloud-Computing | 5 % | - Angriffe auf AWS, Azure, GCP - Cloud-Modelle und -Dienste - Sicherheitsrisiken in der Cloud - Empfehlungen zur Cloud-Sicherheit |
| Kryptografie | 5 % | - Anwendung der Kryptografie in der Praxis - Grundlagen und Verfahren der Verschlüsselung - Infrastruktur für öffentliche Schlüssel - Kryptoanalyse und Angriffe |
ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Prüfungsfragen mit Lösungen
1. In the sunlit tech oasis of Phoenix, Arizona, ethical hacker Nadia Patel explores the inner workings of LearnSphere, a US-based e-learning platform serving thousands of students. Tasked with evaluating the application's resource-sharing mechanisms, Nadia crafts HTTP requests to interact with the platform's content delivery endpoint. Her tests uncover a serious flaw: improperly configured access-control headers permit cross-origin requests from unauthorized domains, allowing access to protected course materials. Determined to strengthen the platform, Nadia documents her findings to provide LearnSphere's security team with clear, actionable guidance.
Which vulnerability is Nadia most likely exploiting in LearnSphere's web application?
A) Directory Listing
B) Default Credential Exposure
C) CORS Misconfiguration
D) Verbose Error Messages
2. You are Ethan Brooks, an ethical hacker at Vanguard Security Solutions, hired to perform a wireless penetration test for Pacific Logistics, a shipping company in Seattle, Washington. Your task is to identify all Wi-Fi networks in range without alerting the network administrators. Using a laptop with a Wi-Fi card, you monitor radio channels to detect access points and their BSSiDs without sending any probe requests or injecting data packets. Based on the described method, which Wi-Fi discovery technique are you employing?
A) Active Footprinting
B) Wash Command
C) Passive Footprinting
D) Network Discovery Software
3. What kind of detection techniques is being used in antivirus software that identifies malware by collecting data from multiple protected systems and instead of analyzing files locally it's made on the provider's environment?
A) Heuristics based
B) Cloud based
C) Behavioral based
D) Honeypot based
4. While evaluating a smart card implementation, a security analyst observes that an attacker is measuring fluctuations in power consumption and timing variations during encryption operations on the chip. The attacker uses this information to infer secret keys used within the device. What type of exploitation is being carried out?
A) Observe hardware signals to deduce secrets
B) Force session resets through input flooding
C) Crack hashes using statistical collisions
D) Disrupt control flow to modify instructions
5. In a healthcare organization, the network security team detects unusual network activity, indicating advanced sniffing techniques used by a potential attacker. Upon investigation, it's found that the attacker exploits vulnerabilities in medical imaging protocols to intercept patient data. The security team must identify the specific sniffing technique being used and take action to protect patient privacy. Considering the scenario, which sophisticated sniffing technique poses the greatest challenge for the security team, potentially compromising patient data security?
A) Manipulating radiology report formats to embed patient data within CT scan images.
B) Injecting malicious code into ultrasound machine software to capture patient records.
C) Creating a covert channel within hospital administrative messages for data exfiltration.
D) Exploiting MRI machine firmware vulnerabilities to intercept real-time patient scans.
Fragen und Antworten:
| 1. Frage Antwort: C | 2. Frage Antwort: C | 3. Frage Antwort: B | 4. Frage Antwort: A | 5. Frage Antwort: C |






979 Kundenbewertungen

