EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 581:

    A newly discovered flaw in a software application would be considered which kind of security vulnerability?

    A. Input validation flaw
    B. HTTP header injection vulnerability
    C. 0-day vulnerability
    D. Time-to-check to time-to-use flaw

  • Question 582:

    An IT security engineer notices that the company's web server is currently being hacked. What should the engineer do next?

    A. Unplug the network connection on the company's web server.
    B. Determine the origin of the attack and launch a counterattack.
    C. Record as much information as possible from the attack.
    D. Perform a system restart on the company's web server.

  • Question 583:

    While performing data validation of web content, a security technician is required to restrict malicious input. Which of the following processes is an efficient way of restricting malicious input?

    A. Validate web content input for query strings.
    B. Validate web content input with scanning tools.
    C. Validate web content input for type, length, and range.
    D. Validate web content input for extraneous queries.

  • Question 584:

    Which of the following statements are true regarding N-tier architecture? (Choose two.)

    A. Each layer must be able to exist on a physically independent system.
    B. The N-tier architecture must have at least one logical layer.
    C. Each layer should exchange information only with the layers above and below it.
    D. When a layer is changed or updated, the other layers must also be recompiled or modified.

  • Question 585:

    While probing an organization you discover that they have a wireless network. From your attempts to connect to the WLAN you determine that they have deployed MAC filtering by using ACL on the access points. What would be the easiest way to circumvent and communicate on the WLAN?

    A. Attempt to crack the WEP key using Airsnort.
    B. Attempt to brute force the access point and update or delete the MAC ACL.
    C. Steel a client computer and use it to access the wireless network.
    D. Sniff traffic if the WLAN and spoof your MAC address to one that you captured.

  • Question 586:

    Several of your co-workers are having a discussion over the etc/passwd file. They are at odds over what types of encryption are used to secure Linux passwords.(Choose all that apply.

    A. Linux passwords can be encrypted with MD5
    B. Linux passwords can be encrypted with SHA
    C. Linux passwords can be encrypted with DES
    D. Linux passwords can be encrypted with Blowfish
    E. Linux passwords are encrypted with asymmetric algrothims

  • Question 587:

    SNMP is a protocol used to query hosts, servers, and devices about performance or health status data. This protocol has long been used by hackers to gather great amount of information about remote hosts. Which of the following features makes this possible? (Choose two)

    A. It used TCP as the underlying protocol.
    B. It uses community string that is transmitted in clear text.
    C. It is susceptible to sniffing.
    D. It is used by all network devices on the market.

  • Question 588:

    A simple compiler technique used by programmers is to add a terminator 'canary word' containing four letters NULL (0x00), CR (0x0d), LF (0x0a) and EOF (0xff) so that most string operations are terminated. If the canary word has been altered when the function returns, and the program responds by emitting an intruder alert into syslog, and then halts what does it indicate?

    A. A buffer overflow attack has been attempted
    B. A buffer overflow attack has already occurred
    C. A firewall has been breached and this is logged
    D. An intrusion detection system has been triggered
    E. The system has crashed

  • Question 589:

    Which type of antenna is used in wireless communication?

    A. Omnidirectional
    B. Parabolic
    C. Uni-directional
    D. Bi-directional

  • Question 590:

    Susan has attached to her company's network. She has managed to synchronize her boss's sessions with that of the file server. She then intercepted his traffic destined for the server, changed it the way she wanted to and then placed it on the server in his home directory. What kind of attack is Susan carrying on?

    A. A sniffing attack
    B. A spoofing attack
    C. A man in the middle attack
    D. A denial of service attack

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.