EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 551:

    Carl has successfully compromised a web server from behind a firewall by exploiting a vulnerability in the web server program. He wants to proceed by installing a backdoor program. However, he is aware that not all inbound ports on the firewall are in the open state.

    From the list given below, identify the port that is most likely to be open and allowed to reach the server that Carl has just compromised.

    A. 53
    B. 110
    C. 25
    D. 69

  • Question 552:

    You have the SOA presented below in your Zone. Your secondary servers have not been able to contact your primary server to synchronize information. How long will the secondary servers attempt to contact the primary server before it considers that zone is dead and stops responding to queries?

    collegae.edu.SOA, cikkye.edu ipad.college.edu. (200302028 3600 3600 604800 3600)

    A. One day
    B. One hour
    C. One week
    D. One month

  • Question 553:

    What port number is used by LDAP protocol?

    A. 110
    B. 389
    C. 464
    D. 445

  • Question 554:

    During a wireless penetration test, a tester detects an access point using WPA2 encryption. Which of the following attacks should be used to obtain the key?

    A. The tester must capture the WPA2 authentication handshake and then crack it.
    B. The tester must use the tool inSSIDer to crack it using the ESSID of the network.
    C. The tester cannot crack WPA2 because it is in full compliance with the IEEE 802.11i standard.
    D. The tester must change the MAC address of the wireless network card and then use the AirTraf tool to obtain the key.

  • Question 555:

    ____________ will let you assume a users identity at a dynamically generated web page or site.

    A. SQL attack
    B. Injection attack
    C. Cross site scripting
    D. The shell attack
    E. Winzapper

  • Question 556:

    Choose one of the following pseudo codes to describe this statement:

    "If we have written 200 characters to the buffer variable, the stack should stop because it cannot hold any more data."

    A. If (I > 200) then exit (1)
    B. If (I < 200) then exit (1)
    C. If (I
    D. If (I >= 200) then exit (1)

  • Question 557:

    Switches maintain a CAM Table that maps individual MAC addresses on the network to physical ports on the switch.

    In MAC flooding attack, a switch is fed with many Ethernet frames, each containing different source MAC addresses, by the attacker. Switches have a limited memory for mapping various MAC addresses to physical ports. What happens when the CAM table becomes full?

    A. Switch then acts as hub by broadcasting packets to all machines on the network
    B. The CAM overflow table will cause the switch to crash causing Denial of Service
    C. The switch replaces outgoing frame switch factory default MAC address of FF:FF:FF:FF:FF:FF
    D. Every packet is dropped and the switch sends out SNMP alerts to the IDS port

  • Question 558:

    WWW wanderers or spiders are programs that traverse many pages in the World Wide Web by recursively retrieving linked pages. Search engines like Google, frequently spider web pages for indexing. How will you stop web spiders from crawling certain directories on your website?

    A. Place robots.txt file in the root of your website with listing of directories that you don't want to be crawled
    B. Place authentication on root directories that will prevent crawling from these spiders
    C. Enable SSL on the restricted directories which will block these spiders from crawling
    D. Place "HTTP:NO CRAWL" on the html pages that you don't want the crawlers to index

  • Question 559:

    Which of the following statement correctly defines ICMP Flood Attack? (Select 2 answers)

    A. Bogus ECHO reply packets are flooded on the network spoofing the IP and MAC address
    B. The ICMP packets signal the victim system to reply and the combination of traffic saturates the bandwidth of the victim's network
    C. ECHO packets are flooded on the network saturating the bandwidth of the subnet causing denial of service
    D. A DDoS ICMP flood attack occurs when the zombies send large volumes of ICMP_ECHO_REPLY packets to the victim system.

  • Question 560:

    Which of the following lists are valid data-gathering activities associated with a risk assessment?

    A. Threat identification, vulnerability identification, control analysis
    B. Threat identification, response identification, mitigation identification
    C. Attack profile, defense profile, loss profile
    D. System profile, vulnerability identification, security determination

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.