EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 401:

    What is the correct command to run Netcat on a server using port 56 that spawns command shell when connected?

    A. nc -port 56 -s cmd.exe
    B. nc -p 56 -p -e shell.exe
    C. nc -r 56 -c cmd.exe
    D. nc -L 56 -t -e cmd.exe

  • Question 402:

    Network Administrator Patricia is doing an audit of the network. Below are some of her findings concerning DNS. Which of these would be a cause for alarm? Select the best answer.

    A. There are two external DNS Servers for Internet domains. Both are AD integrated.
    B. All external DNS is done by an ISP.
    C. Internal AD Integrated DNS servers are using private DNS names that are
    D. unregistered.
    E. Private IP addresses are used on the internal network and are registered with the internal AD integrated DNS server.

  • Question 403:

    You have chosen a 22 character word from the dictionary as your password. How long will it take to crack the password by an attacker?

    A. 16 million years
    B. 5 minutes
    C. 23 days
    D. 200 years

  • Question 404:

    What does the term "Ethical Hacking" mean?

    A. Someone who is hacking for ethical reasons.
    B. Someone who is using his/her skills for ethical reasons.
    C. Someone who is using his/her skills for defensive purposes.
    D. Someone who is using his/her skills for offensive purposes.

  • Question 405:

    Your computer is infected by E-mail tracking and spying Trojan. This Trojan infects the computer with a single file - emos.sys

    Which step would you perform to detect this type of Trojan?

    A. Scan for suspicious startup programs using msconfig
    B. Scan for suspicious network activities using Wireshark
    C. Scan for suspicious device drivers in c:\windows\system32\drivers
    D. Scan for suspicious open ports using netstat

  • Question 406:

    Botnets are networks of compromised computers that are controlled remotely and surreptitiously by one or more cyber criminals. How do cyber criminals infect a victim's computer with bots? (Select 4 answers)

    A. Attackers physically visit every victim's computer to infect them with malicious software
    B. Home computers that have security vulnerabilities are prime targets for botnets
    C. Spammers scan the Internet looking for computers that are unprotected and use these "open-doors" to install malicious software
    D. Attackers use phishing or spam emails that contain links or attachments
    E. Attackers use websites to host the bots utilizing Web Browser vulnerabilities

  • Question 407:

    Which technical characteristic do Ethereal/Wireshark, TCPDump, and Snort have in common?

    A. They are written in Java.
    B. They send alerts to security monitors.
    C. They use the same packet analysis engine.
    D. They use the same packet capture utility.

  • Question 408:

    What do you conclude from the nmap results below? Staring nmap V. 3.10ALPHA0 (www.insecure.org/map/) (The 1592 ports scanned but not shown below are in state: closed) Port State Service 21/tcp open ftp 25/tcp open smtp 80/tcp open http 443/tcp open https Remote operating system guess: Too many signatures match the reliability guess the OS. Nmap run completed ?1 IP address (1 host up) scanned in 91.66 seconds

    A. The system is a Windows Domain Controller.
    B. The system is not firewalled.
    C. The system is not running Linux or Solaris.
    D. The system is not properly patched.

  • Question 409:

    An attacker has successfully compromised a remote computer. Which of the following comes as one of the last steps that should be taken to ensure that the compromise cannot be traced back to the source of the problem?

    A. Install patches
    B. Setup a backdoor
    C. Install a zombie for DDOS
    D. Cover your tracks

  • Question 410:

    Which of the following is a characteristic of Public Key Infrastructure (PKI)?

    A. Public-key cryptosystems are faster than symmetric-key cryptosystems.
    B. Public-key cryptosystems distribute public-keys within digital signatures.
    C. Public-key cryptosystems do not require a secure key distribution channel.
    D. Public-key cryptosystems do not provide technical non-repudiation via digital signatures.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.