EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 511:

    Liza has forgotten her password to an online bookstore. The web application asks her to key in her email so that they can send her the password. Liza enters her email [email protected]'. The application displays server error. What is wrong with the web application?

    A. The email is not valid
    B. User input is not sanitized
    C. The web server may be down
    D. The ISP connection is not reliable

  • Question 512:

    Which of the following Trojans would be considered 'Botnet Command Control Center'?

    A. YouKill DOOM
    B. Damen Rock
    C. Poison Ivy
    D. Matten Kit

  • Question 513:

    A hacker is attempting to see which IP addresses are currently active on a network. Which NMAP switch would the hacker use?

    A. -sO
    B. -sP
    C. -sS
    D. -sU

  • Question 514:

    A tester has been using the msadc.pl attack script to execute arbitrary commands on a Windows NT4 web server. While it is effective, the tester finds it tedious to perform extended functions. On further research, the tester come across a perl script that runs the following msadc functions:system("perl msadc.pl -h $host -C \"echo open $your >testfile\"");

    Which exploit is indicated by this script?

    A. A buffer overflow exploit
    B. A chained exploit
    C. A SQL injection exploit
    D. A denial of service exploit

  • Question 515:

    Cyber Criminals have long employed the tactic of masking their true identity. In IP spoofing, an attacker gains unauthorized access to a computer or a network by making it appear that a malicious message has come from a trusted machine, by "spoofing" the IP address of that machine.

    How would you detect IP spoofing?

    A. Check the IPID of the spoofed packet and compare it with TLC checksum. If the numbers match then it is spoofed packet
    B. Probe a SYN Scan on the claimed host and look for a response SYN/FIN packet, if the connection completes then it is a spoofed packet
    C. Turn on 'Enable Spoofed IP Detection' in Wireshark, you will see a flag tick if the packet is spoofed
    D. Sending a packet to the claimed host will result in a reply. If the TTL in the reply is not the same as the packet being checked then it is a spoofed packet

  • Question 516:

    Blane is a security analyst for a law firm. One of the lawyers needs to send out an email to a client but he wants to know if the email is forwarded on to any other recipients. The client is explicitly asked not to re-send the email since that would be a violation of the lawyer's and client's agreement for this particular case. What can Blane use to accomplish this?

    A. He can use a split-DNS service to ensure the email is not forwarded on.
    B. A service such as HTTrack would accomplish this.
    C. Blane could use MetaGoofil tracking tool.
    D. Blane can use a service such as ReadNotify tracking tool.

  • Question 517:

    You may be able to identify the IP addresses and machine names for the firewall, and the names of internal mail servers by:

    A. Sending a mail message to a valid address on the target network, and examining the header information generated by the IMAP servers
    B. Examining the SMTP header information generated by using the x command parameter of DIG
    C. Examining the SMTP header information generated in response to an e-mail message sent to an invalid address
    D. Sending a mail message to an invalid address on the target network, and examining the header information generated by the POP servers

  • Question 518:

    Harold just got home from working at Henderson LLC where he works as an IT technician. He was able to get off early because they were not too busy. When he walks into his home office, he notices his teenage daughter on the computer, apparently chatting with someone online. As soon as she hears Harold enter the room, she closes all her windows and tries to act like she was playing a game. When Harold asks her what she was doing, she acts very nervous and does not give him a straight answer. Harold is very concerned because he does not want his daughter to fall victim to online predators and the sort. Harold doesn't necessarily want to install any programs that will restrict the sites his daughter goes to, because he doesn't want to alert her to his trying to figure out what she is doing. Harold wants to use some kind of program that will track her activities online, and send Harold an email of her activity once a day so he can see what she has been up to. What kind of software could Harold use to accomplish this?

    A. Install hardware Keylogger on her computer
    B. Install screen capturing Spyware on her computer
    C. Enable Remote Desktop on her computer
    D. Install VNC on her computer

  • Question 519:

    Attacking well-known system defaults is one of the most common hacker attacks. Most software is shipped with a default configuration that makes it easy to install and setup the application. You should change the default settings to secure the system.

    Which of the following is NOT an example of default installation?

    A. Many systems come with default user accounts with well-known passwords that administrators forget to change
    B. Often, the default location of installation files can be exploited which allows a hacker to retrieve a file from the system
    C. Many software packages come with "samples" that can be exploited, such as the sample programs on IIS web services
    D. Enabling firewall and anti-virus software on the local system

  • Question 520:

    Consider the following code:

    URL:http://www.certified.com/search.pl?

    text=

    If an attacker can trick a victim user to click a link like this, and the Web application does not validate input, then the victim's browser will pop up an alert showing the users current set of cookies. An attacker can do much more damage,

    including stealing passwords, resetting your home page, or redirecting the user to another Web site.

    What is the countermeasure against XSS scripting?

    A. Create an IP access list and restrict connections based on port number
    B. Replace "" characters with "and l t;" and "and g t;" using server scripts
    C. Disable Javascript in IE and Firefox browsers
    D. Connect to the server using HTTPS protocol instead of HTTP

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.