ECCouncil 312-50v13日本語 Exam Overview:
| Certification Vendor: | EC-Council |
| Exam Name: | Certified Ethical Hacker Version 13 |
| Exam Number: | 312-50v13 |
| Exam Duration: | 240 minutes |
| Passing Score: | 60% - 85% (varies by exam form, ~70% typical) |
| Exam Format: | Multiple Choice Questions, Scenario-based Questions |
| Related Certifications: | CEH Practical CEH Master ECSA LPT |
| Real Exam Qty: | 125 |
| Available Languages: | English, Japanese, Portuguese, Spanish |
| Exam Price: | $450 USD |
| Certificate Validity Period: | 3 years |
| Recommended Training: | Official CEH v13 Training |
| Exam Registration: | EC-Council Exam Portal Pearson VUE |
| Sample Questions: | ECCouncil 312-50v13日本語 Sample Questions |
| Exam Way: | Online remote proctored or onsite at Pearson VUE test centers |
| Pre Condition: | No mandatory prerequisites; recommended basic knowledge of networking, IT, or security concepts |
| Official Syllabus URL: | https://www.eccouncil.org/train-certify/certified-ethical-hacker-cehv13-usa-new/ |
ECCouncil 312-50v13日本語 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Cryptography | 5% | - Encryption Concepts & Algorithms - Cryptography in Practice - Public Key Infrastructure - Cryptanalysis & Attacks |
| Topic 2: Denial-of-Service | 4% | - DDoS Tools - Defense Mechanisms - Attack Techniques & Botnets - DoS & DDoS Concepts |
| Topic 3: Session Hijacking | 4% | - Application & Network Level Hijacking - Session Hijacking Concepts - Countermeasures - Hijacking Techniques |
| Topic 4: Web Server & Application Attacks | 8% | - Web Server Vulnerabilities - Web Application Attacks: XSS, CSRF - API Security Risks - Web Security Countermeasures - SQL Injection & Command Injection |
| Topic 5: Evading IDS, Firewalls, and Honeypots | 5% | - IDS, IPS, Firewall Technologies - Evasion Techniques - Honeypot Concepts & Detection |
| Topic 6: Enumeration | 7% | - NetBIOS, SNMP, LDAP Enumeration - AI-Driven Enumeration - Enumeration Countermeasures - DNS, SMTP, NFS Enumeration - Enumeration Concepts |
| Topic 7: Vulnerability Analysis | 8% | - Vulnerability Classification & Scoring - Vulnerability Assessment Lifecycle - Scanning & Analysis Tools - Vulnerability Research & Databases |
| Topic 8: System Hacking | 8% | - Gaining Access: Password Attacks - Privilege Escalation - Clearing Tracks & Logs - Maintaining Access |
| Topic 9: Footprinting and Reconnaissance | 7% | - DNS, WHOIS, Network Mapping - Reconnaissance Countermeasures - Reconnaissance Concepts - OSINT Techniques |
| Topic 10: Cloud Computing | 5% | - Cloud Models & Services - Cloud Security Best Practices - Cloud Security Risks - AWS, Azure, GCP Attacks |
| Topic 11: Mobile Platforms | 4% | - Mobile Device Security - Android & iOS Vulnerabilities - Mobile Attack Vectors |
| Topic 12: IoT & OT Security | 4% | - Attacks on IoT & OT Systems - Security Controls - IoT/OT Architecture & Risks |
| Topic 13: Social Engineering | 6% | - Identity Theft - Social Engineering Concepts - Countermeasures & Awareness - Phishing, Pretexting, Baiting |
| Topic 14: Introduction to Ethical Hacking | 5% | - Ethical Hacking Methodology - Cyber Kill Chain & MITRE ATT&CK - Information Security Concepts - Legal and Ethical Compliance |
| Topic 15: Malware Threats | 7% | - Malware Types: Trojans, Viruses, Worms - Malware Analysis & Countermeasures - APT & Fileless Malware - AI-Powered Malware |
| Topic 16: Wireless Networks | 5% | - Wireless Hacking Tools - Wireless Encryption: WEP, WPA2, WPA3 - Security Best Practices - Wireless Threats & Attacks |
| Topic 17: Scanning Networks | 8% | - Service & OS Fingerprinting - Scanning Beyond IDS/Firewall - Host & Port Discovery - AI-Assisted Scanning - Network Scanning Basics - Scanning Countermeasures |
| Topic 18: Sniffing | 5% | - Sniffing Tools & Techniques - Packet Sniffing Concepts - Sniffing Countermeasures - MITM Attacks |
ECCouncil Certified Ethical Hacker Exam (CEHv13) (312-50v13日本語版) Sample Questions:
1. 建物のドアを車両が突き破るのを防ぐセキュリティ機能はどれですか?
A) ボラード
B) マントラップ
C) 回転式改札機
D) 受付係
2. 倫理的ハッカーとして、あなたはアプリケーションのSQLインジェクション脆弱性をテストするよう依頼されました。テストの過程で、脆弱性があると思われる入力フィールドを発見しました。しかし、バックエンドのデータベースは不明であり、通常のSQLインジェクション手法では有用な情報を得ることができませんでした。次に、どの高度なSQLインジェクション手法を適用すべきでしょうか?
A) ユニオンベースSQLインジェクション
B) 時間ベースのブラインドSQLインジェクション
C) エラーベースのSQLインジェクション
D) コンテンツベースのブラインドSQLインジェクション
3. 侵入テスト担当者が、信頼できないユーザー入力を適切な出力エンコーディングなしでHTMLページに直接反映するアプリケーションを特定しました。最も可能性が高い脆弱性はどれですか?
A) コマンドインジェクション
B) SQLインジェクション
C) LDAPインジェクション
D) クロスサイトスクリプティング(XSS)
4. 企業内部ネットワークのステルス評価中に、攻撃者はホスト間の通信がスイッチングされ、一般的なARPポイズニング手法から保護されているサブネットにアクセスします。攻撃者はトラフィックを傍受しながら、ターゲットシステム(ホストB)がARP要求への応答を断続的に遅延させていることに気づきます。攻撃者はこの機会を捉え、ターゲットのIPアドレスを自身のMACアドレスにマッピングする偽のARP応答を作成し、正規の応答が到着する前に送信します。時間が経つにつれて、攻撃者は、特にこれらのARP応答の遅延中に、本来ホストB宛てのパケットが時折自身のシステムに到着することに気づきます。スイッチのCAMテーブルは、正規のホストが自身を再び主張するまでの間、ターゲットのIPアドレスを攻撃者のMACアドレスとポートに一時的に関連付けているようです。攻撃者はどのような種類のスニッフィング攻撃を行っているのでしょうか?
A) タイミングベースのARPスプーフィングによるスイッチポートの盗用
B) スイッチングネットワーク上でのパッシブスニッフィング
C) 重複IP競合解決攻撃
D) 中間者攻撃(MiTM)傍受のためのARPポイズニング
5. ニコラスは、公開システムにゼロデイ脆弱性と思われる脆弱性を発見しました。彼はそのシステムの所有者にメールを送信し、問題点と脆弱性から身を守る方法を説明しました。また、マイクロソフトにもメールを送信し、彼らのシステムが晒されている問題について知らせました。ニコラスはどのようなタイプのハッカーでしょうか?
A) 赤い帽子
B) グレーの帽子
C) 黒い帽子
D) 白い帽子
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: B | Question # 3 Answer: D | Question # 4 Answer: A | Question # 5 Answer: D |
We're so confident of our products that we provide no hassle product exchange.


By Pearl

