EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 501:

    Exhibit:

    Based on the following extract from the log of a compromised machine, what is the hacker really trying to steal?

    A. har.txt
    B. SAM file
    C. wwwroot
    D. Repair file

  • Question 502:

    Virus Scrubbers and other malware detection program can only detect items that they are aware of. Which of the following tools would allow you to detect unauthorized changes or modifications of binary files on your system by unknown malware?

    A. System integrity verification tools
    B. Anti-Virus Software
    C. A properly configured gateway
    D. There is no way of finding out until a new updated signature file is released

  • Question 503:

    A botnet can be managed through which of the following?

    A. IRC
    B. E-Mail
    C. Linkedin and Facebook
    D. A vulnerable FTP server

  • Question 504:

    June, a security analyst, understands that a polymorphic virus has the ability to mutate and can change its known viral signature and hide from signature-based antivirus programs. Can June use an antivirus program in this case and would it be effective against a polymorphic virus?

    A. Yes. June can use an antivirus program since it compares the parity bit of executable files to the database of known check sum counts and it is effective on a polymorphic virus
    B. Yes. June can use an antivirus program since it compares the signatures of executable files to the database of known viral signatures and it is very effective against a polymorphic virus
    C. No. June can't use an antivirus program since it compares the signatures of executable files to the database of known viral signatures and in the case the polymorphic viruses cannot be detected by a signature-based anti-virus program
    D. No. June can't use an antivirus program since it compares the size of executable files to the database of known viral signatures and it is effective on a polymorphic virus

  • Question 505:

    The use of alert thresholding in an IDS can reduce the volume of repeated alerts, but introduces which of the following vulnerabilities?

    A. An attacker, working slowly enough, can evade detection by the IDS.
    B. Network packets are dropped if the volume exceeds the threshold.
    C. Thresholding interferes with the IDS' ability to reassemble fragmented packets.
    D. The IDS will not distinguish among packets originating from different sources.

  • Question 506:

    Most NIDS systems operate in layer 2 of the OSI model. These systems feed raw traffic into a detection engine and rely on the pattern matching and/or statistical analysis to determine what is malicious. Packets are not processed by the host's TCP/IP stack allowing the NIDS to analyze traffic the host would otherwise discard. Which of the following tools allows an attacker to intentionally craft packets to confuse pattern-matching NIDS systems, while still being correctly assembled by the host TCP/IP stack to render the attack payload?

    A. Defrag
    B. Tcpfrag
    C. Tcpdump
    D. Fragroute

  • Question 507:

    A network security administrator is worried about potential man-in-the-middle attacks when users access a corporate web site from their workstations. Which of the following is the best remediation against this type of attack?

    A. Implementing server-side PKI certificates for all connections
    B. Mandating only client-side PKI certificates for all connections
    C. Requiring client and server PKI certificates for all connections
    D. Requiring strong authentication for all DNS queries

  • Question 508:

    John is using a special tool on his Linux platform that has a database containing signatures to be able to detect hundreds of vulnerabilities in UNIX, Windows, and commonly used web CGI/ASPX scripts. Moreover, the database detects DDoS

    zombies and Trojans as well.

    What would be the name of this tool?

    A. hping2
    B. nessus
    C. nmap
    D. make

  • Question 509:

    Null sessions are un-authenticated connections (not using a username or password.) to an NT or 2000 system. Which TCP and UDP ports must you filter to check null sessions on your network?

    A. 137 and 139
    B. 137 and 443
    C. 139 and 443
    D. 139 and 445

  • Question 510:

    Which of the following is a common Service Oriented Architecture (SOA) vulnerability?

    A. Cross-site scripting
    B. SQL injection
    C. VPath injection
    D. XML denial of service issues

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.