EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 521:

    Which of the following business challenges could be solved by using a vulnerability scanner?

    A. Auditors want to discover if all systems are following a standard naming convention.
    B. A web server was compromised and management needs to know if any further systems were compromised.
    C. There is an emergency need to remove administrator access from multiple machines for an employee that quit.
    D. There is a monthly requirement to test corporate compliance with host application usage and security policies.

  • Question 522:

    Which of the following network attacks relies on sending an abnormally large packet size that exceeds TCP/IP specifications?

    A. Ping of death
    B. SYN flooding
    C. TCP hijacking
    D. Smurf attack

  • Question 523:

    One of the most common and the best way of cracking RSA encryption is to begin to derive the two prime numbers, which are used in the RSA PKI mathematical process. If the two numbers p and q are discovered through a _____________ process, then the private key can be derived.

    A. Factorization
    B. Prime Detection
    C. Hashing
    D. Brute-forcing

  • Question 524:

    What is the main advantage that a network-based IDS/IPS system has over a host-based solution?

    A. They do not use host system resources.
    B. They are placed at the boundary, allowing them to inspect all traffic.
    C. They are easier to install and configure.
    D. They will not interfere with user interfaces.

  • Question 525:

    The following script shows a simple SQL injection. The script builds an SQL query by concatenating hard-coded strings together with a string entered by the user:

    The user is prompted to enter the name of a city on a Web form. If she enters Chicago, the query assembled by the script looks similar to the following:

    SELECT * FROM OrdersTable WHERE ShipCity = 'Chicago'

    How will you delete the OrdersTable from the database using SQL Injection?

    A. Chicago'; drop table OrdersTable -
    B. Delete table'blah'; OrdersTable -
    C. EXEC; SELECT * OrdersTable > DROP -
    D. cmdshell'; 'del c:\sql\mydb\OrdersTable' //

  • Question 526:

    SYN Flood is a DOS attack in which an attacker deliberately violates the three-way handshake and opens a large number of half-open TCP connections. The signature of attack for SYN Flood contains:

    A. The source and destination address having the same value
    B. A large number of SYN packets appearing on a network without the corresponding reply packets
    C. The source and destination port numbers having the same value
    D. A large number of SYN packets appearing on a network with the corresponding reply packets

  • Question 527:

    A penetration tester is hired to do a risk assessment of a company's DMZ. The rules of engagement states that the penetration test be done from an external IP address with no prior knowledge of the internal IT systems. What kind of test is being performed?

    A. white box
    B. grey box
    C. red box
    D. black box

  • Question 528:

    You are writing security policy that hardens and prevents Footprinting attempt by Hackers. Which of the following countermeasures will NOT be effective against this attack?

    A. Configure routers to restrict the responses to Footprinting requests
    B. Configure Web Servers to avoid information leakage and disable unwanted protocols
    C. Lock the ports with suitable Firewall configuration
    D. Use an IDS that can be configured to refuse suspicious traffic and pick up Footprinting patterns
    E. Evaluate the information before publishing it on the Website/Intranet
    F. Monitor every employee computer with Spy cameras, keyloggers and spy on them
    G. Perform Footprinting techniques and remove any sensitive information found on DMZ sites
    H. Prevent search engines from caching a Webpage and use anonymous registration services
    I. Disable directory and use split-DNS

  • Question 529:

    Exhibit: You have captured some packets in Ethereal. You want to view only packets sent from 10.0.0.22. What filter will you apply?

    A. ip = 10.0.0.22
    B. ip.src == 10.0.0.22
    C. ip.equals 10.0.0.22
    D. ip.address = 10.0.0.22

  • Question 530:

    Bob has a good understanding of cryptography, having worked with it for many years. Cryptography is used to secure data from specific threats, but it does not secure the application from coding errors. It can provide data privacy; integrity and enable strong authentication but it cannot mitigate programming errors. What is a good example of a programming error that Bob can use to explain to the management how encryption will not address all their security concerns?

    A. Bob can explain that using a weak key management technique is a form of programming error
    B. Bob can explain that using passwords to derive cryptographic keys is a form of a programming error
    C. Bob can explain that a buffer overflow is an example of programming error and it is a common mistake associated with poor programming technique
    D. Bob can explain that a random number generator can be used to derive cryptographic keys but it uses a weak seed value and this is a form of a programming error

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.