EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 571:

    Bret is a web application administrator and has just read that there are a number of surprisingly common web application vulnerabilities that can be exploited by unsophisticated attackers with easily available tools on the Internet. He has also read that when an organization deploys a web application, they invite the world to send HTTP requests. Attacks buried in these requests sail past firewalls, filters, platform hardening, SSL, and IDS without notice because they are inside legal HTTP requests. Bret is determined to weed out vulnerabilities.

    What are some of the common vulnerabilities in web applications that he should be concerned about?

    A. Non-validated parameters, broken access control, broken account and session management, cross-site scripting and buffer overflows are just a few common vulnerabilities
    B. Visible clear text passwords, anonymous user account set as default, missing latest security patch, no firewall filters set and no SSL configured are just a few common vulnerabilities
    C. No SSL configured, anonymous user account set as default, missing latest security patch, no firewall filters set and an inattentive system administrator are just a few common vulnerabilities
    D. No IDS configured, anonymous user account set as default, missing latest security patch, no firewall filters set and visible clear text passwords are just a few common vulnerabilities

  • Question 572:

    Access control is often implemented through the use of MAC address filtering on wireless Access Points. Why is this considered to be a very limited security measure?

    A. Vendors MAC address assignment is published on the Internet.
    B. The MAC address is not a real random number.
    C. The MAC address is broadcasted and can be captured by a sniffer.
    D. The MAC address is used properly only on Macintosh computers.

  • Question 573:

    Which of the following Nmap commands would be used to perform a stack fingerprinting?

    A. Nmap -O -p80
    B. Nmap -hU -Q
    C. Nmap -sT -p
    D. Nmap -u -o -w2
    E. Nmap -sS -0p target

  • Question 574:

    The following excerpt is taken from a honeyput log. The log captures activities across three days. There are several intrusion attempts; however, a few are successful. Study the log given below and answer the following question:

    (Note: The objective of this questions is to test whether the student has learnt about passive OS fingerprinting (which should tell them the OS from log captures): can they tell a SQL injection attack signature; can they infer if a user ID has been created by an attacker and whether they can read plain source ?destination entries from log entries.)

    What can you infer from the above log?

    A. The system is a windows system which is being scanned unsuccessfully.
    B. The system is a web application server compromised through SQL injection.
    C. The system has been compromised and backdoored by the attacker.
    D. The actual IP of the successful attacker is 24.9.255.53.

  • Question 575:

    Paul has just finished setting up his wireless network. He has enabled numerous security features such as changing the default SSID, enabling WPA encryption, and enabling MAC filtering on his wireless router. Paul notices that when he uses his wireless connection, the speed is sometimes 54 Mbps and sometimes it is only 24Mbps or less. Paul connects to his wireless router's management utility and notices that a machine with an unfamiliar name is connected through his wireless connection. Paul checks the router's logs and notices that the unfamiliar machine has the same MAC address as his laptop. What is Paul seeing here?

    A. MAC spoofing
    B. Macof
    C. ARP spoofing
    D. DNS spoofing

  • Question 576:

    You want to carry out session hijacking on a remote server. The server and the client are communicating via TCP after a successful TCP three way handshake. The server has just received packet #120 from the client. The client has a receive window of 200 and the server has a receive window of 250.

    Within what range of sequence numbers should a packet, sent by the client fall in order to be accepted by the server?

    A. 200-250
    B. 121-371
    C. 120-321
    D. 121-231
    E. 120-370

  • Question 577:

    Doug is conducting a port scan of a target network. He knows that his client target network has a web server and that there is a mail server also which is up and running. Doug has been sweeping the network but has not been able to elicit any response from the remote target. Which of the following could be the most likely cause behind this lack of response? Select 4. A. UDP is filtered by a gateway

    B. The packet TTL value is too low and cannot reach the target

    C. The host might be down

    D. The destination network might be down

    E. The TCP windows size does not match

    F. ICMP is filtered by a gateway

    Correct Answer. ABCF

  • Question 578:

    Which of the following countermeasure can specifically protect against both the MAC Flood and MAC Spoofing attacks?

    A. Configure Port Security on the switch
    B. Configure Port Recon on the switch
    C. Configure Switch Mapping
    D. Configure Multiple Recognition on the switch

  • Question 579:

    Bob has set up three web servers on Windows Server 2008 IIS 7.0. Bob has followed all the recommendations for securing the operating system and IIS. These servers are going to run numerous e-commerce websites that are projected to

    bring in thousands of dollars a day. Bob is still concerned about the security of these servers because of the potential for financial loss. Bob has asked his company's firewall administrator to set the firewall to inspect all incoming traffic on

    ports 80 and 443 to ensure that no malicious data is getting into the network.

    Why will this not be possible?

    A. Firewalls cannot inspect traffic coming through port 443
    B. Firewalls can only inspect outbound traffic
    C. Firewalls cannot inspect traffic at all, they can only block or allow certain ports
    D. Firewalls cannot inspect traffic coming through port 80

  • Question 580:

    What does an ICMP (Code 13) message normally indicates?

    A. It indicates that the destination host is unreachable
    B. It indicates to the host that the datagram which triggered the source quench message will need to be re-sent
    C. It indicates that the packet has been administratively dropped in transit
    D. It is a request to the host to cut back the rate at which it is sending traffic to the Internet destination

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.