EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 541:

    Hampton is the senior security analyst for the city of Columbus in Ohio. His primary responsibility is to ensure that all physical and logical aspects of the city's computer network are secure from all angles. Bill is an IT technician that works with Hampton in the same IT department. Bill's primary responsibility is to keep PC's and servers up to date and to keep track of all the agency laptops that the company owns and lends out to its employees. After Bill setup a wireless network for the agency, Hampton made sure that everything was secure. He instituted encryption, rotating keys, turned off SSID broadcasting, and enabled MAC filtering. According to agency policy, only company laptops are allowed to use the wireless network, so Hampton entered all the MAC addresses for those laptops into the wireless security utility so that only those laptops should be able to access the wireless network.

    Hampton does not keep track of all the laptops, but he is pretty certain that the agency only purchases Dell laptops. Hampton is curious about this because he notices Bill working on a Toshiba laptop one day and saw that he was on the Internet. Instead of jumping to conclusions, Hampton decides to talk to Bill's boss and see if they had purchased a Toshiba laptop instead of the usual Dell. Bill's boss said no, so now Hampton is very curious to see how Bill is accessing the Internet. Hampton does site surveys every couple of days, and has yet to see any outside wireless network signals inside the company's building.

    How was Bill able to get Internet access without using an agency laptop?

    A. Bill spoofed the MAC address of Dell laptop
    B. Bill connected to a Rogue access point
    C. Toshiba and Dell laptops share the same hardware address
    D. Bill brute forced the Mac address ACLs

  • Question 542:

    You just purchased the latest DELL computer, which comes pre-installed with Windows 7, McAfee antivirus software and a host of other applications. You want to connect Ethernet wire to your cable modem and start using the computer immediately. Windows is dangerously insecure when unpacked from the box, and there are a few things that you must do before you use it.

    A. New installation of Windows should be patched by installing the latest service packs and hotfixes
    B. Key applications such as Adobe Acrobat, Macromedia Flash, Java, Winzip etc., must have the latest security patches installed
    C. Install a personal firewall and lock down unused ports from connecting to your computer
    D. Install the latest signatures for Antivirus software
    E. Configure "Windows Update" to automatic
    F. Create a non-admin user with a complex password and logon to this account
    G. You can start using your computer as vendors such as DELL, HP and IBM would have already installed the latest service packs.

  • Question 543:

    BankerFox is a Trojan that is designed to steal users' banking data related to certain banking entities.

    When they access any website of the affected banks through the vulnerable Firefox 3.5 browser, the Trojan is activated and logs the information entered by the user. All the information entered in that website will be logged by the Trojan and

    transmitted to the attacker's machine using covert channel.

    BankerFox does not spread automatically using its own means. It needs an attacking user's intervention in order to reach the affected computer.

    What is the most efficient way an attacker located in remote location to infect this banking Trojan on a victim's machine?

    A. Physical access - the attacker can simply copy a Trojan horse to a victim's hard disk infecting the machine via Firefox add-on extensions
    B. Custom packaging - the attacker can create a custom Trojan horse that mimics the appearance of a program that is unique to that particular computer
    C. Custom packaging - the attacker can create a custom Trojan horse that mimics the appearance of a program that is unique to that particular computer
    D. Custom packaging - the attacker can create a custom Trojan horse that mimics the appearance of a program that is unique to that particular computer
    E. Downloading software from a website? An attacker can offer free software, such as shareware programs and pirated mp3 files

  • Question 544:

    You have successfully gained access to a victim's computer using Windows 2003 Server SMB Vulnerability. Which command will you run to disable auditing from the cmd?

    A. stoplog stoplog ?
    B. EnterPol /nolog
    C. EventViewer o service
    D. auditpol.exe /disable

  • Question 545:

    Your boss Tess King is attempting to modify the parameters of a Web-based application in order to alter the SQL statements that are parsed to retrieve data from the database. What would you call such an attack?

    A. SQL Input attack
    B. SQL Piggybacking attack
    C. SQL Select attack
    D. SQL Injection attack

  • Question 546:

    Which of the following is a protocol that is prone to a man-in-the-middle (MITM) attack and maps a 32-bit address to a 48-bit address?

    A. ICPM
    B. ARP
    C. RARP
    D. ICMP

  • Question 547:

    What is the proper response for a X-MAS scan if the port is closed?

    A. SYN
    B. ACK
    C. FIN
    D. PSH
    E. RST
    F. No response

  • Question 548:

    Diffie-Hellman (DH) groups determine the strength of the key used in the key exchange process. Which of the following is the correct bit size of the Diffie-Hellman (DH) group 5?

    A. 768 bit key
    B. 1025 bit key
    C. 1536 bit key
    D. 2048 bit key

  • Question 549:

    How does a denial-of-service attack work?

    A. A hacker prevents a legitimate user (or group of users) from accessing a service
    B. A hacker uses every character, word, or letter he or she can think of to defeat authentication
    C. A hacker tries to decipher a password by using a system, which subsequently crashes the network
    D. A hacker attempts to imitate a legitimate user by confusing a computer or even another person

  • Question 550:

    If you send a SYN to an open port, what is the correct response?(Choose all correct answers.

    A. SYN
    B. ACK
    C. FIN
    D. PSH

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.