EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 681:

    Bob has been hired to perform a penetration test on XYZ.com. He begins by looking at IP address ranges owned by the company and details of domain name registration. He then goes to News Groups and financial web sites to see if they

    are leaking any sensitive information of have any technical details online.

    Within the context of penetration testing methodology, what phase is Bob involved with?

    A. Passive information gathering
    B. Active information gathering
    C. Attack phase
    D. Vulnerability Mapping

  • Question 682:

    NTP allows you to set the clocks on your systems very accurately, to within 100ms and sometimes-even 10ms. Knowing the exact time is extremely important for enterprise security. Various security protocols depend on an accurate source of time information in order to prevent "playback" attacks. These protocols tag their communications with the current time, to prevent attackers from replaying the same communications, e.g., a login/password interaction or even an entire communication, at a later date. One can circumvent this tagging, if the clock can be set back to the time the communication was recorded. An attacker attempts to try corrupting the clocks on devices on your network. You run Wireshark to detect the NTP traffic to see if there are any irregularities on the network. What port number you should enable in Wireshark display filter to view NTP packets?

    A. TCP Port 124
    B. UDP Port 125
    C. UDP Port 123
    D. TCP Port 126

  • Question 683:

    What technique is used to perform a Connection Stream Parameter Pollution (CSPP) attack?

    A. Injecting parameters into a connection string using semicolons as a separator
    B. Inserting malicious Javascript code into input parameters
    C. Setting a user's session identifier (SID) to an explicit known value
    D. Adding multiple parameters with the same name in HTTP requests

  • Question 684:

    Trojan horse attacks pose one of the most serious threats to computer security. The image below shows different ways a Trojan can get into a system. Which are the easiest and most convincing ways to infect a computer?

    A. IRC (Internet Relay Chat)
    B. Legitimate "shrink-wrapped" software packaged by a disgruntled employee
    C. NetBIOS (File Sharing)
    D. Downloading files, games and screensavers from Internet sites

  • Question 685:

    Which Open Web Application Security Project (OWASP) implements a web application full of known vulnerabilities?

    A. WebBugs
    B. WebGoat
    C. VULN_HTML
    D. WebScarab

  • Question 686:

    Your lab partner is trying to find out more information about a competitors web site. The site has a .com extension. She has decided to use some online whois tools and look in one of the regional Internet registrys. Which one would you suggest she looks in first?

    A. LACNIC
    B. ARIN
    C. APNIC
    D. RIPE
    E. AfriNIC

  • Question 687:

    What are two things that are possible when scanning UDP ports? (Choose two.

    A. A reset will be returned
    B. An ICMP message will be returned
    C. The four-way handshake will not be completed
    D. An RFC 1294 message will be returned
    E. Nothing

  • Question 688:

    This attack uses social engineering techniques to trick users into accessing a fake Web site and divulging personal information. Attackers send a legitimate-looking e-mail asking users to update their information on the company's Web site, but the URLs in the e-mail actually point to a false Web site.

    A. Wiresharp attack
    B. Switch and bait attack
    C. Phishing attack
    D. Man-in-the-Middle attack

  • Question 689:

    If an attacker's computer sends an IPID of 24333 to a zombie (Idle Scanning) computer on a closed port, what will be the response?

    A. The zombie computer will respond with an IPID of 24334.
    B. The zombie computer will respond with an IPID of 24333.
    C. The zombie computer will not send a response.
    D. The zombie computer will respond with an IPID of 24335.

  • Question 690:

    Which of the following techniques can be used to mitigate the risk of an on-site attacker from connecting to an unused network port and gaining full access to the network? (Choose three.)

    A. Port Security
    B. IPSec Encryption
    C. Network Admission Control (NAC)
    D. 802.1q Port Based Authentication
    E. 802.1x Port Based Authentication
    F. Intrusion Detection System (IDS)

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.