EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 461:

    _________ ensures that the enforcement of organizational security policy does not rely on voluntary web application user compliance. It secures information by assigning sensitivity labels on information and comparing this to the level of security a user is operating at.

    A. Mandatory Access Control
    B. Authorized Access Control
    C. Role-based Access Control
    D. Discretionary Access Control

  • Question 462:

    You find the following entries in your web log. Each shows attempted access to either root.exe or cmd.exe. What caused this?

    A. The Morris worm
    B. The PIF virus
    C. Trinoo
    D. Nimda
    E. Code Red
    F. Ping of Death

  • Question 463:

    Vulnerability mapping occurs after which phase of a penetration test?

    A. Host scanning
    B. Passive information gathering
    C. Analysis of host scanning
    D. Network level discovery

  • Question 464:

    Which of the following techniques does a vulnerability scanner use in order to detect a vulnerability on a target service?

    A. Port scanning
    B. Banner grabbing
    C. Injecting arbitrary data
    D. Analyzing service response

  • Question 465:

    Which security strategy requires using several, varying methods to protect IT systems against attacks?

    A. Defense in depth
    B. Three-way handshake
    C. Covert channels
    D. Exponential backoff algorithm

  • Question 466:

    A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should take before enabling the audit feature?

    A. Perform a vulnerability scan of the system.
    B. Determine the impact of enabling the audit feature.
    C. Perform a cost/benefit analysis of the audit feature.
    D. Allocate funds for staffing of audit log review.

  • Question 467:

    While scanning a network you observe that all of the web servers in the DMZ are responding to ACK packets on port 80. What can you infer from this observation?

    A. They are using Windows based web servers.
    B. They are using UNIX based web servers.
    C. They are not using an intrusion detection system.
    D. They are not using a stateful inspection firewall.

  • Question 468:

    You receive an email with the following message:

    Hello Steve,

    We are having technical difficulty in restoring user database record after the recent blackout. Your account data is corrupted. Please logon to the SuperEmailServices.com and change your password.

    http://[email protected]/support/logon.htm

    If you do not reset your password within 7 days, your account will be permanently disabled locking you out from our e-mail services.

    Sincerely,

    Technical Support

    SuperEmailServices

    From this e-mail you suspect that this message was sent by some hacker since you have been using their e-mail services for the last 2 years and they have never sent out an e-mail such as this. You also observe the URL in the message and

    confirm your suspicion about 0xde.0xad.0xbde.0xef which looks like hexadecimal numbers. You immediately enter the following at Windows 2000 command prompt:

    Ping 0xde.0xad.0xbe.0xef

    You get a response with a valid IP address.

    What is the obstructed IP address in the e-mail URL?

    A. 222.173.190.239
    B. 233.34.45.64
    C. 54.23.56.55
    D. 199.223.23.45

  • Question 469:

    Johnny is a member of the hacking group Orpheus1. He is currently working on breaking into the Department of Defense's front end Exchange Server. He was able to get into the server, located in a DMZ, by using an unused service account that had a very weak password that he was able to guess. Johnny wants to crack the administrator password, but does not have a lot of time to crack it. He wants to use a tool that already has the LM hashes computed for all possible permutations of the administrator password.

    What tool would be best used to accomplish this?

    A. SMBCrack
    B. SmurfCrack
    C. PSCrack
    D. RainbowTables

  • Question 470:

    An ethical hacker for a large security research firm performs penetration tests, vulnerability tests, and risk assessments. A friend recently started a company and asks the hacker to perform a penetration test and vulnerability assessment of the new company as a favor. What should the hacker's next step be before starting work on this job?

    A. Start by foot printing the network and mapping out a plan of attack.
    B. Ask the employer for authorization to perform the work outside the company.
    C. Begin the reconnaissance phase with passive information gathering and then move into active information gathering.
    D. Use social engineering techniques on the friend's employees to help identify areas that may be susceptible to attack.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.