EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 481:

    A pentester gains acess to a Windows application server and needs to determine the settings of the built-in Windows firewall. Which command would be used?

    A. Netsh firewall show config
    B. WMIC firewall show config
    C. Net firewall show config
    D. Ipconfig firewall show config

  • Question 482:

    During a penetration test, the tester conducts an ACK scan using NMAP against the external interface of the DMZ firewall. NMAP reports that port 80 is unfiltered. Based on this response, which type of packet inspection is the firewall conducting?

    A. Host
    B. Stateful
    C. Stateless
    D. Application

  • Question 483:

    Which of the following describes the characteristics of a Boot Sector Virus?

    A. Moves the MBR to another location on the RAM and copies itself to the original location of the MBR
    B. Moves the MBR to another location on the hard disk and copies itself to the original location of the MBR
    C. Modifies directory table entries so that directory entries point to the virus code instead of the actual program
    D. Overwrites the original MBR and only executes the new virus code

  • Question 484:

    A hacker, who posed as a heating and air conditioning specialist, was able to install a sniffer program in a switched environment network. Which attack could the hacker use to sniff all of the packets in the network?

    A. Fraggle
    B. MAC Flood
    C. Smurf
    D. Tear Drop

  • Question 485:

    While attempting to discover the remote operating system on the target computer, you receive the following results from an nmap scan:

    Remote operating system guess: Too many signatures match to reliably guess the OS.

    Nmap run completed -- 1 IP address (1 host up) scanned in 277.483 seconds

    What should be your next step to identify the OS?

    A. Perform a firewalk with that system as the target IP
    B. Perform a tcp traceroute to the system using port 53
    C. Run an nmap scan with the -v-v option to give a better output
    D. Connect to the active services and review the banner information

  • Question 486:

    Joe the Hacker breaks into XYZ's Linux system and plants a wiretap program in order to sniff passwords and user accounts off the wire. The wiretap program is embedded as a Trojan horse in one of the network utilities. Joe is worried that network administrator might detect the wiretap program by querying the interfaces to see if they are running in promiscuous mode.

    What can Joe do to hide the wiretap program from being detected by ifconfig command?

    A. Block output to the console whenever the user runs ifconfig command by running screen capture utiliyu
    B. Run the wiretap program in stealth mode from being detected by the ifconfig command.
    C. Replace original ifconfig utility with the rootkit version of ifconfig hiding Promiscuous information being displayed on the console.
    D. You cannot disable Promiscuous mode detection on Linux systems.

  • Question 487:

    Which of the following statements would NOT be a proper definition for a Trojan Horse?

    A. An authorized program that has been designed to capture keyboard keystroke while the user is unaware of such activity being performed
    B. An unauthorized program contained within a legitimate program. This unauthorized program performs functions unknown (and probably unwanted) by the user
    C. A legitimate program that has been altered by the placement of unauthorized code within it; this code performs functions unknown (and probably unwanted) by the user
    D. Any program that appears to perform a desirable and necessary function but that (because of unauthorized code within it that is unknown to the user) performs functions unknown (and definitely unwanted) by the user

  • Question 488:

    A Security Engineer at a medium-sized accounting firm has been tasked with discovering how much information can be obtained from the firm's public facing web servers. The engineer decides to start by using netcat to port 80. The engineer receives this output: HTTP/1.1 200 OK Server: Microsoft-IIS/6 Expires: Tue, 17 Jan 2011 01:41:33 GMT DatE. Mon, 16 Jan 2011 01:41:33 GMT Content-TypE. text/html Accept-Ranges: bytes Last-ModifieD. Wed, 28 Dec 2010 15:32:21 GMT ETaG. "b0aac0542e25c31:89d" Content-Length: 7369 Which of the following is an example of what the engineer performed?

    A. Cross-site scripting
    B. Banner grabbing
    C. SQL injection
    D. Whois database query

  • Question 489:

    During a penetration test, a tester finds a target that is running MS SQL 2000 with default credentials. The tester assumes that the service is running with Local System account. How can this weakness be exploited to access the system?

    A. Using the Metasploit psexec module setting the SA / Admin credential
    B. Invoking the stored procedure xp_shell to spawn a Windows command shell
    C. Invoking the stored procedure cmd_shell to spawn a Windows command shell
    D. Invoking the stored procedure xp_cmdshell to spawn a Windows command shell

  • Question 490:

    What type of session hijacking attack is shown in the exhibit?

    A. Cross-site scripting Attack
    B. SQL Injection Attack
    C. Token sniffing Attack
    D. Session Fixation Attack

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.