EC-COUNCIL · 312-50v13 CEH v13

EC-Council 312-50v13 CEH v13 Exam Practice Questions

1,049 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 1,049 questions in this pack

Question 1

In this form of encryption algorithm, every individual block contains 64-bit data, and three keys are used, where each key consists of 56 bits. Which is this encryption algorithm?

  1. IDEA
  2. Triple Data Encryption Standard
  3. AES
  4. MD5 encryption algorithm
Show answer and explanation

Correct answer: B. Triple Data Encryption Standard

Triple Data Encryption Standard (3DES) is characterized by using three 56-bit keys and operating on 64-bit blocks of data. It applies the DES algorithm three times to each block, making it the only option that matches all specified criteria: three keys of 56 bits each and 64-bit data blocks.

Why the other options are wrong

  • A. IDEA uses 128-bit keys and 64-bit blocks, not three 56-bit keys.
  • C. AES uses 128, 192, or 256-bit keys and operates on 128-bit blocks, not 64-bit blocks.
  • D. MD5 is a hash function, not a block cipher, and does not use keys in the traditional encryption sense.

Question 2

John is investigating web-application firewall logs and observers that someone is attempting to inject the following: What type of attack is this?

Exhibit for question 2

  1. SQL injection
  2. Buffer overflow
  3. CSRF
  4. XSS
Show answer and explanation

Correct answer: B. Buffer overflow

The code snippet shows a character buffer of size 10 being assigned the value 'a', which appears to be demonstrating a buffer overflow vulnerability. Buffer overflow attacks occur when data is written beyond the allocated memory boundaries of a buffer, potentially overwriting adjacent memory and causing program crashes, unauthorized code execution, or privilege escalation. This is a classic example of how buffer overflow vulnerabilities are exploited in C/C++ programs.

Why the other options are wrong

  • A. SQL injection targets database queries with malicious SQL code, not memory buffers.
  • C. CSRF (Cross-Site Request Forgery) is a web attack involving unauthorized requests, unrelated to buffer memory.
  • D. XSS (Cross-Site Scripting) involves injecting malicious scripts into web pages, not exploiting memory buffers.

Question 3

John, a professional hacker, performs a network attack on a renowned organization and gains unauthorized access to the target network. He remains in the network without being detected for a long time and obtains sensitive information without sabotaging the organization. Which of the following attack techniques is used by John?

  1. Insider threat
  2. Diversion theft
  3. Spear-phishing sites
  4. Advanced persistent threat ✅Correct Answer: D, Advanced persistent threat An Advanced Persistent Threat (APT) involves unauthorized access, long undetected presence, and theft of sensitive data without disrupting operations. John's stealthy long-term presence and information theft without sabotage match an APT.
Show answer and explanation

Answer and explanation for question 3

See all 10 free questions Get the full pack, US$39

1,049 practice questions for EC-Council CEH v13 (312-50v13), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 1,049 questions, the largest question bank available for the CEH v13 exam
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A failed CEH v13 attempt costs a US$500 retake voucher, on top of the US$950 to 1,199 you already spent on the first attempt. This pack is US$39, paid once, and refunded if you fail.

Try 10 questions free before you buy.

Last updated September 2026 · 1,049 questions

What makes the CEH v13 hard

EC-Council does not offer free retakes or partial credit, and the passing score shifts between 60% and 85% depending on the difficulty of your specific question pool, so you will not know your cut score until after you finish.

CEH v13 covers 20 modules. That breadth is the main challenge: you need to know something about everything, from social engineering and cryptography to cloud security, IoT hacking, and the AI-powered attack techniques added in this version. Most candidates who fail do not fail one topic; they get spread too thin across the ones they deprioritised.

1,049 practice questions for the CEH v13, the largest question bank available anywhere for this exam.

About the exam

The Certified Ethical Hacker (CEH) is EC-Council’s flagship ethical hacking certification and the most widely recognised penetration testing credential globally. It validates the ability to think like an attacker across the full hacking methodology, from reconnaissance and scanning through exploitation, post-exploitation and covering tracks. CEH v13 is the current version, updated to include AI-powered attack techniques, AI-driven defensive tools, cloud security hacking, IoT attack vectors, and operational technology hacking. It is mapped to the U.S. DoD and recognised across more than 45 cybersecurity job roles. Two years of information security experience is required for the self-study pathway; candidates without it must complete official EC-Council training.

Exam domains (20 modules)

  • Introduction to ethical hacking
  • Footprinting and reconnaissance
  • Scanning networks
  • Enumeration
  • Vulnerability analysis
  • System hacking
  • Malware threats
  • Sniffing
  • Social engineering
  • Denial of service
  • Session hijacking
  • Evading IDS, firewalls and honeypots
  • Hacking web servers
  • Hacking web applications
  • SQL injection
  • Hacking wireless networks
  • Hacking mobile platforms
  • IoT and OT hacking
  • Cloud computing
  • Cryptography

125 questions, 4 hours, pass mark 60 to 85% (variable by exam form), EC-Council Exam Centre or Pearson VUE, valid for three years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the EC-Council 312-50v13 CEH v13 pack?

1,049 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.