EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 361:

    In the OSI model, where does PPTP encryption take place?

    A. Transport layer
    B. Application layer
    C. Data link layer
    D. Network layer

  • Question 362:

    Syslog is a standard for logging program messages. It allows separation of the software that generates messages from the system that stores them and the software that reports and analyzes them. It also provides devices, which would otherwise be unable to communicate a means to notify administrators of problems or performance.

    What default port Syslog daemon listens on?

    A. 242
    B. 312
    C. 416
    D. 514

  • Question 363:

    Because UDP is a connectionless protocol: (Select 2)

    A. UDP recvfrom() and write() scanning will yield reliable results
    B. It can only be used for Connect scans
    C. It can only be used for SYN scans
    D. There is no guarantee that the UDP packets will arrive at their destination
    E. ICMP port unreachable messages may not be returned successfully

  • Question 364:

    To what does "message repudiation" refer to what concept in the realm of email security?

    A. Message repudiation means a user can validate which mail server or servers a message was passed through.
    B. Message repudiation means a user can claim damages for a mail message that damaged their reputation.
    C. Message repudiation means a recipient can be sure that a message was sent from a particular person.
    D. Message repudiation means a recipient can be sure that a message was sent from a certain host.
    E. Message repudiation means a sender can claim they did not actually send a particular message.

  • Question 365:

    A Network Administrator was recently promoted to Chief Security Officer at a local university. One of employee's new responsibilities is to manage the implementation of an RFID card access system to a new server room on campus. The server room will house student enrollment information that is securely backed up to an off-site location.

    During a meeting with an outside consultant, the Chief Security Officer explains that he is concerned that the existing security controls have not been designed properly. Currently, the Network Administrator is responsible for approving and issuing RFID card access to the server room, as well as reviewing the electronic access logs on a weekly basis.

    Which of the following is an issue with the situation?

    A. Segregation of duties
    B. Undue influence
    C. Lack of experience
    D. Inadequate disaster recovery plan

  • Question 366:

    Clive has been monitoring his IDS and sees that there are a huge number of ICMP Echo Reply packets that are being received on the external gateway interface. Further inspection reveals that they are not responses from the internal hosts'

    requests but simply responses coming from the Internet.

    What could be the most likely cause?

    A. Someone has spoofed Clive's IP address while doing a smurf attack.
    B. Someone has spoofed Clive's IP address while doing a land attack.
    C. Someone has spoofed Clive's IP address while doing a fraggle attack.
    D. Someone has spoofed Clive's IP address while doing a DoS attack.

  • Question 367:

    Steve scans the network for SNMP enabled devices. Which port number Steve should scan?

    A. 150
    B. 161
    C. 169
    D. 69

  • Question 368:

    What is one thing a tester can do to ensure that the software is trusted and is not changing or tampering with critical data on the back end of a system it is loaded on?

    A. Proper testing
    B. Secure coding principles
    C. Systems security and architecture review
    D. Analysis of interrupts within the software

  • Question 369:

    In TCP communications there are 8 flags; FIN, SYN, RST, PSH, ACK, URG, ECE, CWR. These flags have decimal numbers assigned to them: FIN = 1 SYN = 2 RST = 4 PSH = 8 ACK = 16 URG = 32 ECE = 64 CWR =128 Example: To calculate SYN/ACK flag decimal value, add 2 (which is the decimal value of the SYN flag) to 16 (which is the decimal value of the ACK flag), so the result would be 18. Based on the above calculation, what is the decimal value for XMAS scan?

    A. 23
    B. 24
    C. 41
    D. 64

  • Question 370:

    Which DNS resource record can indicate how long any "DNS poisoning" could last?

    A. MX
    B. SOA
    C. NS
    D. TIMEOUT

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.