EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 431:

    Fred is scanning his network to ensure it is as secure as possible. Fred sends a TCP probe packet to a host with a FIN flag and he receives a RST/ACK response. What does this mean?

    A. This response means the port he is scanning is open.
    B. The RST/ACK response means the port Fred is scanning is disabled.
    C. This means the port he is scanning is half open.
    D. This means that the port he is scanning on the host is closed.

  • Question 432:

    What tool can crack Windows SMB passwords simply by listening to network traffic? Select the best answer.

    A. This is not possible
    B. Netbus
    C. NTFSDOS
    D. L0phtcrack

  • Question 433:

    The SNMP Read-Only Community String is like a password. The string is sent along with each SNMP Get-Request and allows (or denies) access to a device. Most network vendors ship their equipment with a default password of "public". This is the so-called "default public community string". How would you keep intruders from getting sensitive information regarding the network devices using SNMP? (Select 2 answers)

    A. Enable SNMPv3 which encrypts username/password authentication
    B. Use your company name as the public community string replacing the default 'public'
    C. Enable IP filtering to limit access to SNMP device
    D. The default configuration provided by device vendors is highly secure and you don't need to change anything

  • Question 434:

    What is the most secure way to mitigate the theft of corporate information from a laptop that was left in a hotel room?

    A. Set a BIOS password.
    B. Encrypt the data on the hard drive.
    C. Use a strong logon password to the operating system.
    D. Back up everything on the laptop and store the backup in a safe place.

  • Question 435:

    Which of the following processes evaluates the adherence of an organization to its stated security policy?

    A. Vulnerability assessment
    B. Penetration testing
    C. Risk assessment
    D. Security auditing

  • Question 436:

    John has a proxy server on his network which caches and filters web access. He shuts down all unnecessary ports and services. Additionally, he has installed a firewall (Cisco PIX) that will not allow users to connect to any outbound ports. Jack, a network user has successfully connected to a remote server on port 80 using netcat. He could in turn drop a shell from the remote machine. Assuming an attacker wants to penetrate John's network, which of the following options is he likely to choose?

    A. Use ClosedVPN
    B. Use Monkey shell
    C. Use reverse shell using FTP protocol
    D. Use HTTPTunnel or Stunnel on port 80 and 443

  • Question 437:

    If a token and 4-digit personal identification number (PIN) are used to access a computer system and the token performs off-line checking for the correct PIN, what type of attack is possible?

    A. Birthday
    B. Brute force
    C. Man-in-the-middle
    D. Smurf

  • Question 438:

    E-mail scams and mail fraud are regulated by which of the following?

    A. 18 U.S.C. par. 1030 Fraud and Related activity in connection with Computers
    B. 18 U.S.C. par. 1029 Fraud and Related activity in connection with Access Devices
    C. 18 U.S.C. par. 1362 Communication Lines, Stations, or Systems
    D. 18 U.S.C. par. 2510 Wire and Electronic Communications Interception and Interception of Oral Communication

  • Question 439:

    Erik notices a big increase in UDP packets sent to port 1026 and 1027 occasionally. He enters the following at the command prompt.

    $ nc -l -p 1026 -u -v

    In response, he sees the following message.

    cell(?(c)????STOPALERT77STOP! WINDOWS REQUIRES IMMEDIATE ATTENTION.

    Windows has found 47 Critical Errors.

    To fix the errors please do the following:

    1.Download Registry Repair from: www.reg-patch.com

    2.Install Registry Repair

    3.Run Registry Repair

    4.Reboot your computer

    FAILURE TO ACT NOW MAY LEAD TO DATA LOSS AND CORRUPTION!

    What would you infer from this alert?

    A. The machine is redirecting traffic to www.reg-patch.com using adware
    B. It is a genuine fault of windows registry and the registry needs to be backed up
    C. An attacker has compromised the machine and backdoored ports 1026 and 1027
    D. It is a messenger spam. Windows creates a listener on one of the low dynamic ports from 1026 to 1029 and the message usually promotes malware disguised as legitimate utilities

  • Question 440:

    Sandra is the security administrator of XYZ.com. One day she notices that the XYZ.com Oracle database server has been compromised and customer information along with financial data has been stolen. The financial loss will be estimated in millions of dollars if the database gets into the hands of competitors. Sandra wants to report this crime to the law enforcement agencies immediately.

    Which organization coordinates computer crime investigations throughout the United States?

    A. NDCA
    B. NICP
    C. CIRP
    D. NPC
    E. CIA

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.