ECCouncil 312-50v13日本語 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Introduction to Ethical Hacking | 5% | - Legal and Ethical Compliance - Ethical Hacking Methodology - Information Security Concepts - Cyber Kill Chain & MITRE ATT&CK |
| Wireless Networks | 5% | - Security Best Practices - Wireless Encryption: WEP, WPA2, WPA3 - Wireless Hacking Tools - Wireless Threats & Attacks |
| Footprinting and Reconnaissance | 7% | - DNS, WHOIS, Network Mapping - Reconnaissance Countermeasures - Reconnaissance Concepts - OSINT Techniques |
| System Hacking | 8% | - Privilege Escalation - Maintaining Access - Gaining Access: Password Attacks - Clearing Tracks & Logs |
| Malware Threats | 7% | - APT & Fileless Malware - AI-Powered Malware - Malware Types: Trojans, Viruses, Worms - Malware Analysis & Countermeasures |
| Session Hijacking | 4% | - Application & Network Level Hijacking - Countermeasures - Hijacking Techniques - Session Hijacking Concepts |
| Mobile Platforms | 4% | - Android & iOS Vulnerabilities - Mobile Device Security - Mobile Attack Vectors |
| Cloud Computing | 5% | - AWS, Azure, GCP Attacks - Cloud Security Risks - Cloud Security Best Practices - Cloud Models & Services |
| Web Server & Application Attacks | 8% | - SQL Injection & Command Injection - Web Server Vulnerabilities - Web Security Countermeasures - API Security Risks - Web Application Attacks: XSS, CSRF |
| Scanning Networks | 8% | - Network Scanning Basics - Service & OS Fingerprinting - AI-Assisted Scanning - Scanning Countermeasures - Host & Port Discovery - Scanning Beyond IDS/Firewall |
| Evading IDS, Firewalls, and Honeypots | 5% | - Honeypot Concepts & Detection - IDS, IPS, Firewall Technologies - Evasion Techniques |
| Denial-of-Service | 4% | - Attack Techniques & Botnets - DoS & DDoS Concepts - Defense Mechanisms - DDoS Tools |
| Sniffing | 5% | - Sniffing Tools & Techniques - MITM Attacks - Sniffing Countermeasures - Packet Sniffing Concepts |
| Cryptography | 5% | - Public Key Infrastructure - Cryptography in Practice - Encryption Concepts & Algorithms - Cryptanalysis & Attacks |
| IoT & OT Security | 4% | - Attacks on IoT & OT Systems - Security Controls - IoT/OT Architecture & Risks |
| Social Engineering | 6% | - Phishing, Pretexting, Baiting - Social Engineering Concepts - Countermeasures & Awareness - Identity Theft |
| Enumeration | 7% | - AI-Driven Enumeration - Enumeration Countermeasures - Enumeration Concepts - DNS, SMTP, NFS Enumeration - NetBIOS, SNMP, LDAP Enumeration |
| Vulnerability Analysis | 8% | - Vulnerability Research & Databases - Vulnerability Classification & Scoring - Vulnerability Assessment Lifecycle - Scanning & Analysis Tools |
ECCouncil Certified Ethical Hacker Exam (CEHv13) (312-50v13日本語版) Sample Questions:
1. シアトルのパシフィック・トラスト銀行で侵入テストを実施中、倫理的ハッカーのミア・チェンは、顧客の取引データをホストしているサーバーがハニーポットである可能性を疑います。調査のため、彼女は細工したクエリを繰り返し送信し、システムの応答速度を観察します。すると、応答速度が他の本番サーバーよりも一貫して速く、均一であることが分かり、この環境が攻撃者を誘い込むように設計されているのではないかと疑念を抱きます。ミアは、サーバーがハニーポットかどうかを判断するために、どの手法を最も利用している可能性が高いでしょうか?
A) システム構成とメタデータの分析
B) ランニングサービスの指紋認証
C) MACアドレスの解析
D) 応答時間の分析
2. 侵入テスト担当者が、URLパラメータの入力検証が不適切であるために、Webアプリケーションがローカルファイルインクルージョン(LFI)の脆弱性を抱えていることを発見しました。この脆弱性を悪用するために、テスト担当者はどのようなアプローチを取るべきでしょうか?
A) 管理者ログインページに対して総当たり攻撃を行い、アクセス権を取得する
B) ディレクトリトラバーサルを使用して、/etc/passwd などのサーバー上の機密ファイルにアクセスします。
C) URLに悪意のあるスクリプトを挿入してクロスサイトスクリプティング(XSS)攻撃を実行する
D) SQLコマンドをURLパラメータに挿入して、データベースの脆弱性をテストします。
3. シカゴのホライゾン・ファイナンシャル・サービスで忙しい月曜日の朝、経理アシスタントのクララ・グエンは、会社のIT部門から送られたように見えるメールを受け取りました。クララ宛てのメールには、彼女の経理チームでの役割が記されており、緊急の対応が必要な重大なシステム脆弱性に関する警告が書かれていました。メールには、社内ポータルに似たログインページへのリンクが含まれており、アカウント停止を回避するために認証情報を更新するよう促されていました。メールの送信元アドレスは正規のアドレスのように見えましたが、クララはドメイン名にわずかなスペルミスがあることに気付きました。
クララに対してどのようなソーシャルエンジニアリングの手法が試みられているのでしょうか?
A) フィッシング
B) なりすまし
C) 対価
D) スピアフィッシング
4. 認定倫理的ハッカー(CEH)がターゲットネットワークを分析しています。そのために、Nmapを使用してIDLE/IPIDヘッダースキャンを実行することにしました。ネットワーク分析の結果、IDLEスキャンを実行した後にIPID番号が2増加していることがわかりました。この情報に基づいて、CEHはターゲットネットワークについてどのような結論を導き出すことができるでしょうか?
A) 対象ネットワークにはファイアウォールが存在しません
B) 対象ネットワーク上のポートが閉じられています
C) 対象ネットワークのポートが開いています
D) 対象ネットワークにステートフルファイアウォールが存在する
5. ソフトウェア開発者のカルビンは、手動操作なしでウェブページのコンテンツを自動生成する機能を使用しており、この機能はSSIディレクティブと統合されています。この機能はリモートユーザー入力を受け付けてページ上で使用するため、開発されたウェブアプリケーションに脆弱性が生じます。ハッカーはこの機能を悪用し、悪意のあるSSIディレクティブを入力値として渡すことで、サーバーファイルの変更や削除などの悪意のある活動を実行できます。カルビンのウェブアプリケーションは、どのような種類のインジェクション攻撃に対して脆弱でしょうか?
A) CRLF注射
B) サーバーサイドにはインジェクションが含まれています
C) サーバーサイドテンプレートインジェクション
D) サーバーサイドJSインジェクション
Solutions:
| Question # 1 Answer: D | Question # 2 Answer: B | Question # 3 Answer: D | Question # 4 Answer: D | Question # 5 Answer: B |














0 Customer Reviews
Quality and ValueITCertKing Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITCertKing testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITCertKing offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.
