EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 601:

    What does black box testing mean?

    A. You have full knowledge of the environment
    B. You have no knowledge of the environment
    C. You have partial knowledge of the environment

  • Question 602:

    You are conducting a port scan on a subnet that has ICMP blocked. You have discovered 23 live systems and after scanning each of them you notice that they all show port 21 in closed state.

    What should be the next logical step that should be performed?

    A. Connect to open ports to discover applications.
    B. Perform a ping sweep to identify any additional systems that might be up.
    C. Perform a SYN scan on port 21 to identify any additional systems that might be up.
    D. Rescan every computer to verify the results.

  • Question 603:

    Ivan is auditing a corporate website. Using Winhex, he alters a cookie as shown below.

    Before Alteration: Cookie: lang=en-us; ADMIN=no; y=1 ; time=10:30GMT ;

    After Alteration: Cookie: lang=en-us; ADMIN=yes; y=1 ; time=12:30GMT ;

    What attack is being depicted here?

    A. Cookie Stealing
    B. Session Hijacking
    C. Cross Site Scripting
    D. Parameter Manipulation

  • Question 604:

    War dialing is a very old attack and depicted in movies that were made years ago. Why would a modem security tester consider using such an old technique?

    A. It is cool, and if it works in the movies it must work in real life.
    B. It allows circumvention of protection mechanisms by being on the internal network.
    C. It allows circumvention of the company PBX.
    D. A good security tester would not use such a derelict technique.

  • Question 605:

    You have initiated an active operating system fingerprinting attempt with nmap against a target system:

    What operating system is the target host running based on the open ports shown above?

    A. Windows XP
    B. Windows 98 SE
    C. Windows NT4 Server
    D. Windows 2000 Server

  • Question 606:

    A tester is attempting to capture and analyze the traffic on a given network and realizes that the network has several switches. What could be used to successfully sniff the traffic on this switched network? (Choose three.)

    A. ARP spoofing
    B. MAC duplication
    C. MAC flooding
    D. SYN flood
    E. Reverse smurf attack
    F. ARP broadcasting

  • Question 607:

    In this type of Man-in-the-Middle attack, packets and authentication tokens are captured using a sniffer. Once the relevant information is extracted, the tokens are placed back on the network to gain access.

    A. Token Injection Replay attacks
    B. Shoulder surfing attack
    C. Rainbow and Hash generation attack
    D. Dumpster diving attack

  • Question 608:

    "Testing the network using the same methodologies and tools employed by attackers" Identify the correct terminology that defines the above statement.

    A. Vulnerability Scanning
    B. Penetration Testing
    C. Security Policy Implementation
    D. Designing Network Security

  • Question 609:

    In Trojan terminology, what is a covert channel?

    A. A channel that transfers information within a computer system or network in a way that violates the security policy
    B. A legitimate communication path within a computer system or network for transfer of data
    C. It is a kernel operation that hides boot processes and services to mask detection
    D. It is Reverse tunneling technique that uses HTTPS protocol instead of HTTP protocol to establish connections

  • Question 610:

    Which of the following examples best represents a logical or technical control?

    A. Security tokens
    B. Heating and air conditioning
    C. Smoke and fire alarms
    D. Corporate security policy

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.