EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 621:

    What is a NULL scan?

    A. A scan in which all flags are turned off
    B. A scan in which certain flags are off
    C. A scan in which all flags are on
    D. A scan in which the packet size is set to zero
    E. A scan with a illegal packet size

  • Question 622:

    RC4 is known to be a good stream generator. RC4 is used within the WEP standard on wireless LAN. WEP is known to be insecure even if we are using a stream cipher that is known to be secured. What is the most likely cause behind this?

    A. There are some flaws in the implementation.
    B. There is no key management.
    C. The IV range is too small.
    D. All of the above.
    E. None of the above.

  • Question 623:

    When creating a security program, which approach would be used if senior management is supporting and enforcing the security policy?

    A. A bottom-up approach
    B. A top-down approach
    C. A senior creation approach
    D. An IT assurance approach

  • Question 624:

    Which Type of scan sends a packets with no flags set? Select the Answer

    A. Open Scan
    B. Null Scan
    C. Xmas Scan
    D. Half-Open Scan

  • Question 625:

    ETHER: Destination address : 0000BA5EBA11 ETHER: Source address :

    An employee wants to defeat detection by a network-based IDS application. He does not want to attack the system containing the IDS application. Which of the following strategies can be used to defeat detection by a network-based IDS application?

    A. Create a SYN flood
    B. Create a network tunnel
    C. Create multiple false positives
    D. Create a ping flood

  • Question 626:

    If a tester is attempting to ping a target that exists but receives no response or a response that states the destination is unreachable, ICMP may be disabled and the network may be using TCP. Which other option could the tester use to get a response from a host using TCP?

    A. Hping
    B. Traceroute
    C. TCP ping
    D. Broadcast ping

  • Question 627:

    Why would an attacker want to perform a scan on port 137?

    A. To discover proxy servers on a network
    B. To disrupt the NetBIOS SMB service on the target host
    C. To check for file and print sharing on Windows systems
    D. To discover information about a target host using NBTSTAT

  • Question 628:

    John is discussing security with Jane. Jane had mentioned to John earlier that she suspects an LKM has been installed on her server. She believes this is the reason that the server has been acting erratically lately. LKM stands for Loadable Kernel Module.

    What does this mean in the context of Linux Security?

    A. Loadable Kernel Modules are a mechanism for adding functionality to a file system without requiring a kernel recompilation.
    B. Loadable Kernel Modules are a mechanism for adding functionality to an operating- system kernel after it has been recompiled and the system rebooted.
    C. Loadable Kernel Modules are a mechanism for adding auditing to an operating-system kernel without requiring a kernel recompilation.
    D. Loadable Kernel Modules are a mechanism for adding functionality to an operating- system kernel without requiring a kernel recompilation.

  • Question 629:

    This method is used to determine the Operating system and version running on a remote target system. What is it called?

    A. Service Degradation
    B. OS Fingerprinting
    C. Manual Target System
    D. Identification Scanning

  • Question 630:

    Which of the following network attacks takes advantage of weaknesses in the fragment reassembly functionality of the TCP/IP protocol stack?

    A. Teardrop
    B. SYN flood
    C. Smurf attack
    D. Ping of death

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.