EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 301:

    Exhibit:

    You are conducting pen-test against a company's website using SQL Injection techniques. You enter "anuthing or 1=1-" in the username filed of an authentication form. This is the output returned from the server.

    What is the next step you should do?

    A. Identify the user context of the web application by running_ http://www.example.com/order/include_rsa_asp?pressReleaseID=5 AND USER_NAME() = `dbo'
    B. Identify the database and table name by running: http://www.example.com/order/include_rsa.asp?pressReleaseID=5 AND ascii(lower(substring((SELECT TOP 1 name FROM sysobjects WHERE xtype='U'), 1))) > 109
    C. Format the C: drive and delete the database by running: http://www.example.com/order/include_rsa.asp?pressReleaseID=5 AND xp_cmdshell `format c: /q /yes `; drop database myDB; -
    D. Reboot the web server by running: http://www.example.com/order/include_rsa.asp?pressReleaseID=5 AND xp_cmdshell `iisreset eboot'; -

  • Question 302:

    You have just installed a new Linux file server at your office. This server is going to be used by several individuals in the organization, and unauthorized personnel must not be able to modify any data. What kind of program can you use to track changes to files on the server?

    A. Network Based IDS (NIDS)
    B. Personal Firewall
    C. System Integrity Verifier (SIV)
    D. Linux IP Chains

  • Question 303:

    You are the security administrator for a large network. You want to prevent attackers from running any sort of traceroute into your DMZ and discover the internal structure of publicly accessible areas of the network. How can you achieve this?

    A. Block ICMP at the firewall.
    C. Both A and
    D. There is no way to completely block doing a trace route into this area.

  • Question 304:

    After studying the following log entries, what is the attacker ultimately trying to achieve as inferred from the log sequence?

    1.mkdir -p /etc/X11/applnk/Internet/.etc

    2.mkdir -p /etc/X11/applnk/Internet/.etcpasswd

    3.touch -acmr /etc/passwd /etc/X11/applnk/Internet/.etcpasswd

    4.touch -acmr /etc /etc/X11/applnk/Internet/.etc

    5.passwd nobody -d

    6./usr/sbin/adduser dns -d/bin -u 0 -g 0 -s/bin/bash

    7.passwd dns -d

    8.touch -acmr /etc/X11/applnk/Internet/.etcpasswd /etc/passwd

    9.

    touch -acmr /etc/X11/applnk/Internet/.etc /etc

    A. Change password of user nobody
    B. Extract information from a local directory
    C. Change the files Modification Access Creation times
    D. Download rootkits and passwords into a new directory

  • Question 305:

    What do Trinoo, TFN2k, WinTrinoo, T-Sight, and Stracheldraht have in common?

    A. All are hacking tools developed by the legion of doom
    B. All are tools that can be used not only by hackers, but also security personnel
    C. All are DDOS tools
    D. All are tools that are only effective against Windows
    E. All are tools that are only effective against Linux

  • Question 306:

    In TCP communications there are 8 flags; FIN, SYN, RST, PSH, ACK, URG, ECE, CWR. These flags have decimal numbers assigned to them: FIN = 1 SYN = 2 RST = 4 PSH = 8 ACK = 16 URG = 32 ECE = 64 CWR = 128 Jason is the security administrator of ASPEN Communications. He analyzes some traffic using Wireshark and has enabled the following filters.

    What is Jason trying to accomplish here?

    A. SYN, FIN, URG and PSH
    B. SYN, SYN/ACK, ACK
    C. RST, PSH/URG, FIN
    D. ACK, ACK, SYN, URG

  • Question 307:

    When Jason moves a file via NFS over the company's network, you want to grab a copy of it by sniffing. Which of the following tool accomplishes this?

    A. macof
    B. webspy
    C. filesnarf
    D. nfscopy

  • Question 308:

    Exhibit:

    Given the following extract from the snort log on a honeypot, what do you infer from the attack?

    A. A new port was opened
    B. A new user id was created
    C. The exploit was successful
    D. The exploit was not successful

  • Question 309:

    What information should an IT system analysis provide to the risk assessor?

    A. Management buy-in
    B. Threat statement
    C. Security architecture
    D. Impact analysis

  • Question 310:

    In keeping with the best practices of layered security, where are the best places to place intrusion detection/intrusion prevention systems? (Choose two.)

    A. HID/HIP (Host-based Intrusion Detection/Host-based Intrusion Prevention)
    B. NID/NIP (Node-based Intrusion Detection/Node-based Intrusion Prevention)
    C. NID/NIP (Network-based Intrusion Detection/Network-based Intrusion Prevention)
    D. CID/CIP (Computer-based Intrusion Detection/Computer-based Intrusion Prevention)

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.