EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 651:

    A Certificate Authority (CA) generates a key pair that will be used for encryption and decryption of email. The integrity of the encrypted email is dependent on the security of which of the following?

    A. Public key
    B. Private key
    C. Modulus length
    D. Email server certificate

  • Question 652:

    SOAP services use which technology to format information?

    A. SATA
    B. PCI
    C. XML
    D. ISDN

  • Question 653:

    You are the security administrator of Jaco Banking Systems located in Boston. You are setting up e-banking website (http://www.ejacobank.com) authentication system. Instead of issuing banking customer with a single password, you give them a printed list of 100 unique passwords. Each time the customer needs to log into the e-banking system website, the customer enters the next password on the list. If someone sees them type the password using shoulder surfing, MiTM or keyloggers, then no damage is done because the password will not be accepted a second time. Once the list of 100 passwords is almost finished, the system automatically sends out a new password list by encrypted e-mail to the customer.

    You are confident that this security implementation will protect the customer from password abuse.

    Two months later, a group of hackers called "HackJihad" found a way to access the one- time password list issued to customers of Jaco Banking Systems. The hackers set up a fake website (http://www.e-jacobank.com) and used phishing attacks to direct ignorant customers to it. The fake website asked users for their e-banking username and password, and the next unused entry from their one-time password sheet. The hackers collected 200 customer's username/passwords this way. They transferred money from the customer's bank account to various offshore accounts.

    Your decision of password policy implementation has cost the bank with USD 925, 000 to hackers. You immediately shut down the e-banking website while figuring out the next best security solution

    What effective security solution will you recommend in this case?

    A. Implement Biometrics based password authentication system. Record the customers face image to the authentication database
    B. Configure your firewall to block logon attempts of more than three wrong tries
    C. Enable a complex password policy of 20 characters and ask the user to change the password immediately after they logon and do not store password histories
    D. Implement RSA SecureID based authentication system

  • Question 654:

    Which of the following are advantages of adopting a Single Sign On (SSO) system? (Choose two.)

    A. A reduction in password fatigue for users because they do not need to know multiple passwords when accessing multiple applications
    B. A reduction in network and application monitoring since all recording will be completed at the SSO system
    C. A reduction in system administration overhead since any user login problems can be resolved at the SSO system
    D. A reduction in overall risk to the system since network and application attacks can only happen at the SSO point

  • Question 655:

    Which statement best describes a server type under an N-tier architecture?

    A. A group of servers at a specific layer
    B. A single server with a specific role
    C. A group of servers with a unique role
    D. A single server at a specific layer

  • Question 656:

    A penetration tester is conducting a port scan on a specific host. The tester found several ports opened that were confusing in concluding the Operating System (OS) version installed. Considering the NMAP result below, which of the

    following is likely to be installed on the target machine by the OS?

    Starting NMAP 5.21 at 2011-03-15 11:06

    NMAP scan report for 172.16.40.65

    Host is up (1.00s latency).

    Not shown: 993 closed ports

    PORT STATE SERVICE

    21/tcp open ftp

    23/tcp open telnet

    80/tcp open http

    139/tcp open netbios-ssn

    515/tcp open

    631/tcp open ipp 9100/tcp open MAC Address: 00:00:48:0D:EE:89

    A. The host is likely a Windows machine.
    B. The host is likely a Linux machine.
    C. The host is likely a router.
    D. The host is likely a printer.

  • Question 657:

    Harold is the senior security analyst for a small state agency in New York. He has no other security professionals that work under him, so he has to do all the security-related tasks for the agency. Coming from a computer hardware background, Harold does not have a lot of experience with security methodologies and technologies, but he was the only one who applied for the position. Harold is currently trying to run a Sniffer on the agency's network to get an idea of what kind of traffic is being passed around, but the program he is using does not seem to be capturing anything. He pours through the Sniffer's manual, but cannot find anything that directly relates to his problem. Harold decides to ask the network administrator if he has any thoughts on the problem. Harold is told that the Sniffer was not working because the agency's network is a switched network, which cannot be sniffed by some programs without some tweaking. What technique could Harold use to sniff his agency's switched network?

    A. ARP spoof the default gateway
    B. Conduct MiTM against the switch
    C. Launch smurf attack against the switch
    D. Flood the switch with ICMP packets

  • Question 658:

    A covert channel is a channel that

    A. transfers information over, within a computer system, or network that is outside of the security policy.
    B. transfers information over, within a computer system, or network that is within the security policy.
    C. transfers information via a communication path within a computer system, or network for transfer of data.
    D. transfers information over, within a computer system, or network that is encrypted.

  • Question 659:

    Which command line switch would be used in NMAP to perform operating system detection?

    A. -OS
    B. -sO
    C. -sP
    D. -O

  • Question 660:

    Sandra has been actively scanning the client network on which she is doing a vulnerability assessment test. While conducting a port scan she notices open ports in the range of 135 to 139. What protocol is most likely to be listening on those ports?

    A. Finger
    B. FTP
    C. Samba
    D. SMB

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.