Exam Details

  • Exam Code
    :EC0-349
  • Exam Name
    :Computer Hacking Forensic Investigator
  • Certification
    :Certified Ethical Hacker
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :304 Q&As
  • Last Updated
    :Apr 28, 2024

EC-COUNCIL Certified Ethical Hacker EC0-349 Questions & Answers

  • Question 1:

    An "idle" system is also referred to as what?

    A. PC not connected to the Internet

    B. Zombie

    C. PC not being used

    D. Bot

  • Question 2:

    Larry is an IT consultant who works for corporations and government agencies. Larry plans on shutting down the city's network using BGP devices and zombies? What type of Penetration Testing is Larry planning to carry out?

    A. Router Penetration Testing

    B. DoS Penetration Testing

    C. Firewall Penetration Testing

    D. Internal Penetration Testing

  • Question 3:

    John and Hillary works at the same department in the company. John wants to find out Hillary's network password so he can take a look at her documents on the file server. He enables Lophtcrack program to sniffing mode. John sends Hillary an email with a link to Error! Reference source not found. What information will he be able to gather from this?

    A. Hillary network username and password hash

    B. The SID of Hillary network account

    C. The SAM file from Hillary computer

    D. The network shares that Hillary has permissions

  • Question 4:

    You work as an IT security auditor hired by a law firm in Boston to test whether you can gain access to sensitive information about the company clients. You have rummaged through their trash and found very little information. You do not want to set off any alarms on their network, so you plan on performing passive foot printing against their Web servers. What tool should you use?

    A. Ping sweep

    B. Nmap

    C. Netcraft

    D. Dig

  • Question 5:

    You are a security analyst performing a penetration tests for a company in the Midwest. After some initial reconnaissance, you discover the IP addresses of some Cisco routers used by the company. You type in the following URL that includes the IP address of one of the routers: http://172.168.4.131/level/99/exec/show/config

    After typing in this URL, you are presented with the entire configuration file for that router. What have you discovered?

    A. HTTP Configuration Arbitrary Administrative Access Vulnerability

    B. HTML Configuration Arbitrary Administrative Access Vulnerability

    C. Cisco IOS Arbitrary Administrative Access Online Vulnerability

    D. URL Obfuscation Arbitrary Administrative Access Vulnerability

  • Question 6:

    What is the following command trying to accomplish?

    A. Verify that UDP port 445 is open for the 192.168.0.0 network

    B. Verify that TCP port 445 is open for the 192.168.0.0 network

    C. Verify that NETBIOS is running for the 192.168.0.0 network

    D. Verify that UDP port 445 is closed for the 192.168.0.0 network

  • Question 7:

    You are the network administrator for a small bank in Dallas, Texas. To ensure network security, you enact a security policy that requires all users to have 14 character passwords. After giving your users 2 weeks notice, you change the Group Policy to force 14 character passwords. A week later you dump the SAM database from the standalone server and run a password-cracking tool against it. Over 99% of the passwords are broken within an hour. Why were these passwords cracked so Quickly?

    A. Passwords of 14 characters or less are broken up into two 7-character hashes

    B. A password Group Policy change takes at least 3 weeks to completely replicate throughout a network

    C. Networks using Active Directory never use SAM databases so the SAM database pulled was empty

    D. The passwords that were cracked are local accounts on the Domain Controller

  • Question 8:

    You are carrying out the last round of testing for your new website before it goes live. The website has many dynamic pages and connects to a SQL backend that accesses your product inventory in a database. You come across a web security site that recommends inputting the following code into a search field on web pages to check for vulnerabilities: When you type this and click on search, you receive a pop-up window that says: "This is a test."

    What is the result of this test?

    A. Your website is vulnerable to CSS

    B. Your website is not vulnerable

    C. Your website is vulnerable to SQL injection

    D. Your website is vulnerable to web bugs

  • Question 9:

    If an attacker's computer sends an IPID of 31400 to a zombie computer on an open port in IDLE scanning, what will be the response?

    A. The zombie will not send a response

    B. 31402

    C. 31399

    D. 31401

  • Question 10:

    Michael works for Kimball Construction Company as senior security analyst. As part of yearly security audit, Michael scans his network for vulnerabilities. Using Nmap, Michael conducts XMAS scan and most of the ports scanned do not give a response. In what state are these ports?

    A. Closed

    B. Open

    C. Stealth

    D. Filtered

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.