EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 441:

    Rebecca is a security analyst and knows of a local root exploit that has the ability to enable local users to use available exploits to gain root privileges. This vulnerability exploits a condition in the Linux kernel within the execve() system call. There is no known workaround that exists for this vulnerability. What is the correct action to be taken by Rebecca in this situation as a recommendation to management?

    A. Rebecca should make a recommendation to disable the () system call
    B. Rebecca should make a recommendation to upgrade the Linux kernel promptly
    C. Rebecca should make a recommendation to set all child-process to sleep within the execve()
    D. Rebecca should make a recommendation to hire more system administrators to monitor all child processes to ensure that each child process can't elevate privilege

  • Question 442:

    How do employers protect assets with security policies pertaining to employee surveillance activities?

    A. Employers promote monitoring activities of employees as long as the employees demonstrate trustworthiness.
    B. Employers use informal verbal communication channels to explain employee monitoring activities to employees.
    C. Employers use network surveillance to monitor employee email traffic, network access, and to record employee keystrokes.
    D. Employers provide employees written statements that clearly discuss the boundaries of monitoring activities and consequences.

  • Question 443:

    Bob waits near a secured door, holding a box. He waits until an employee walks up to the secured door and uses the special card in order to access the restricted area of the target company. Just as the employee opens the door, Bob walks up to the employee (still holding the box) and asks the employee to hold the door open so that he can enter. What is the best way to undermine the social engineering activity of tailgating?

    A. Issue special cards to access secure doors at the company and provide a one-time only brief description of use of the special card
    B. Educate and enforce physical security policies of the company to all the employees on a regular basis
    C. Setup a mock video camera next to the special card reader adjacent to the secure door
    D. Post a sign that states, "no tailgating" next to the special card reader adjacent to the secure door

  • Question 444:

    In which part of OSI layer, ARP Poisoning occurs?

    A. Transport Layer
    B. Datalink Layer
    C. Physical Layer
    D. Application layer

  • Question 445:

    To scan a host downstream from a security gateway, Firewalking:

    A. Sends a UDP-based packet that it knows will be blocked by the firewall to determine how specifically the firewall responds to such packets
    B. Uses the TTL function to send packets with a TTL value set to expire one hop past the identified security gateway
    C. Sends an ICMP ''administratively prohibited'' packet to determine if the gateway will drop the packet without comment.
    D. Assesses the security rules that relate to the target system before it sends packets to any hops on the route to the gateway

  • Question 446:

    In this attack, a victim receives an e-mail claiming from PayPal stating that their account has been disabled and confirmation is required before activation. The attackers then scam to collect not one but two credit card numbers, ATM PIN number and other personal details.

    Ignorant users usually fall prey to this scam. Which of the following statement is incorrect related to this attack?

    A. Do not reply to email messages or popup ads asking for personal or financial information
    B. Do not trust telephone numbers in e-mails or popup ads
    C. Review credit card and bank account statements regularly
    D. Antivirus, anti-spyware, and firewall software can very easily detect these type of attacks
    E. Do not send credit card numbers, and personal or financial information via e-mail

  • Question 447:

    In the context of password security: a simple dictionary attack involves loading a dictionary file (a text file full of dictionary words) into a cracking application such as L0phtCrack or John the Ripper, and running it against user accounts located by the application. The larger the word and word fragment selection, the more effective the dictionary attack is. The brute force method is the most inclusive - though slow. Usually, it tries every possible letter and number combination in its automated exploration. If you would use both brute force and dictionary combined together to have variations of words, what would you call such an attack?

    A. Full Blown Attack
    B. Thorough Attack
    C. Hybrid Attack
    D. BruteDict Attack

  • Question 448:

    ViruXine.W32 virus hides their presence by changing the underlying executable code. This Virus code mutates while keeping the original algorithm intact, the code changes itself each time it runs, but the function of the code (its semantics) will not change at all.

    Here is a section of the Virus code:

    What is this technique called?

    A. Polymorphic Virus
    B. Metamorphic Virus
    C. Dravidic Virus
    D. Stealth Virus

  • Question 449:

    John runs a Web server, IDS and firewall on his network. Recently his Web server has been under constant hacking attacks. He looks up the IDS log files and sees no intrusion attempts but the Web server constantly locks up and needs rebooting due to various brute force and buffer overflow attacks but still the IDS alerts no intrusion whatsoever. John becomes suspicious and views the Firewall logs and he notices huge SSL connections constantly hitting his Web server. Hackers have been using the encrypted HTTPS protocol to send exploits to the Web server and that was the reason the IDS did not detect the intrusions. How would John protect his network from these types of attacks?

    A. Install a proxy server and terminate SSL at the proxy
    B. Enable the IDS to filter encrypted HTTPS traffic
    C. Install a hardware SSL "accelerator" and terminate SSL at this layer
    D. Enable the Firewall to filter encrypted HTTPS traffic

  • Question 450:

    What is Cygwin?

    A. Cygwin is a free C++ compiler that runs on Windows
    B. Cygwin is a free Unix subsystem that runs on top of Windows
    C. Cygwin is a free Windows subsystem that runs on top of Linux
    D. Cygwin is a X Windows GUI subsytem that runs on top of Linux GNOME environment

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.