EC0-350 Exam Details

  • Exam Code
    :EC0-350
  • Exam Name
    :Ethical Hacking And Countermeasures (CEH)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :878 Q&As
  • Last Updated
    :Jul 15, 2026

EC-COUNCIL EC0-350 Online Questions & Answers

  • Question 701:

    Which of the following is a preventive control?

    A. Smart card authentication
    B. Security policy
    C. Audit trail
    D. Continuity of operations plan

  • Question 702:

    You are a Administrator of Windows server. You want to find the port number for POP3. What file would you find the information in and where?

    Select the best answer.

    A. %windir%\\etc\\services
    B. system32\\drivers\\etc\\services
    C. %windir%\\system32\\drivers\\etc\\services
    D. /etc/services
    E. %windir%/system32/drivers/etc/services

  • Question 703:

    Bob, an Administrator at XYZ was furious when he discovered that his buddy Trent, has launched a session hijack attack against his network, and sniffed on his communication, including administrative tasks suck as configuring routers, firewalls, IDS, via Telnet.

    Bob, being an unhappy administrator, seeks your help to assist him in ensuring that attackers such as Trent will not be able to launch a session hijack in XYZ. Based on the above scenario, please choose which would be your corrective measurement actions. (Choose two)

    A. Use encrypted protocols, like those found in the OpenSSH suite.
    B. Implement FAT32 filesystem for faster indexing and improved performance.
    C. Configure the appropriate spoof rules on gateways (internal and external).
    D. Monitor for CRP caches, by using IDS products.

  • Question 704:

    Bank of Timbuktu is a medium-sized, regional financial institution in Timbuktu. The bank has deployed a new Internet-accessible Web application recently. Customers can access their account balances, transfer money between accounts, pay bills and conduct online financial business using a Web browser.

    John Stevens is in charge of information security at Bank of Timbuktu. After one month in production, several customers have complained about the Internet enabled banking application. Strangely, the account balances of many of the bank's customers had been changed! However, money hasn't been removed from the bank; instead, money was transferred between accounts. Given this attack profile, John Stevens reviewed the Web application's logs and found the following entries:

    What kind of attack did the Hacker attempt to carry out at the bank?

    A. Brute force attack in which the Hacker attempted guessing login ID and password from password cracking tools.
    B. The Hacker attempted Session hijacking, in which the Hacker opened an account with the bank, then logged in to receive a session ID, guessed the next ID and took over Jason's session.
    C. The Hacker used a generator module to pass results to the Web server and exploited Web application CGI vulnerability.
    D. The Hacker first attempted logins with suspected user names, then used SQL Injection to gain access to valid bank login IDs.

  • Question 705:

    How do you defend against ARP Poisoning attack? (Select 2 answers)

    A. Enable DHCP Snooping Binding Table
    B. Restrict ARP Duplicates
    C. Enable Dynamic ARP Inspection
    D. Enable MAC snooping Table

  • Question 706:

    What is a primary advantage a hacker gains by using encryption or programs such as Loki?

    A. It allows an easy way to gain administrator rights
    B. It is effective against Windows computers
    C. It slows down the effective response of an IDS
    D. IDS systems are unable to decrypt it
    E. Traffic will not be modified in transit

  • Question 707:

    A security analyst is performing an audit on the network to determine if there are any deviations from the security policies in place. The analyst discovers that a user from the IT department had a dial-out modem installed. Which security policy must the security analyst check to see if dial-out modems are allowed?

    A. Firewall-management policy
    B. Acceptable-use policy
    C. Remote-access policy
    D. Permissive policy

  • Question 708:

    Which is the Novell Netware Packet signature level used to sign all packets ?

    B. 1
    C. 2
    D. 3

  • Question 709:

    What port scanning method involves sending spoofed packets to a target system and then looking for adjustments to the IPID on a zombie system?

    A. Blind Port Scanning
    B. Idle Scanning
    C. Bounce Scanning
    D. Stealth Scanning
    E. UDP Scanning

  • Question 710:

    Bill has successfully executed a buffer overflow against a Windows IIS web server. He has been able to spawn an interactive shell and plans to deface the main web page. He first attempts to use the "echo" command to simply overwrite index.html and remains unsuccessful. He then attempts to delete the page and achieves no progress. Finally, he tries to overwrite it with another page in which also he remains unsuccessful. What is the probable cause of Bill's problem?

    A. You cannot use a buffer overflow to deface a web page
    B. There is a problem with the shell and he needs to run the attack again
    C. The HTML file has permissions of read only
    D. The system is a honeypot

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-350 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.