EC0-350 Exam Questions
892 real EC0-350 exam questions with expert-verified answers and explanations. Page 5 of 18.
- Question #206
Which type of scan measures a person's external features through a digital video camera?
- Question #207
In order to show improvement of security over time, what must be developed?
- Question #208
In the software security development life cyle process, threat modeling occurs in which phase?
- Question #209
Which of the following items of a computer system will an anti-virus program scan for viruses?
- Question #210
Which of the following can take an arbitrary length of input and produce a message digest output of 160 bit?
- Question #211
A computer science student needs to fill some information into a secured Adobe PDF job application that was received from a prospective employer. Instead of requesting a new docume...
- Question #212
A hacker, who posed as a heating and air conditioning specialist, was able to install a sniffer program in a switched environment network. Which attack could the hacker use to snif...
- Question #213
Which of the following conditions must be given to allow a tester to exploit a Cross-Site Request Forgery (CSRF) vulnerable web application?
- Question #214
During a wireless penetration test, a tester detects an access point using WPA2 encryption. Which of the following attacks should be used to obtain the key?
- Question #215
Which tool is used to automate SQL injections and exploit a database by forcing a given web application to connect to another database controlled by a hacker?
- Question #216
A security analyst is performing an audit on the network to determine if there are any deviations from the security policies in place. The analyst discovers that a user from the IT...
- Question #217
A company is using Windows Server 2003 for its Active Directory (AD). What is the most efficient way to crack the passwords for the AD users?
- Question #218
When an alert rule is matched in a network-based IDS like snort, the IDS does which of the following?
- Question #219
Passive reconnaissance involves collecting information through which of the following?
- Question #220
During a penetration test, the tester conducts an ACK scan using NMAP against the external interface of the DMZ firewall. NMAP reports that port 80 is unfiltered. Based on this res...
- Question #221
What is the main reason the use of a stored biometric is vulnerable to an attack?
- Question #222
Which of the following types of firewall inspects only header information in network traffic?
- Question #223
An attacker sniffs encrypted traffic from the network and is subsequently able to decrypt it. The attacker can now use which cryptanalytic technique to attempt to discover the encr...
- Question #224
Low humidity in a data center can cause which of the following problems?
- Question #225
Which of the following describes a component of Public Key Infrastructure (PKI) where a copy of a private key is stored to provide third-party access and to facilitate recovery ope...
- Question #226
Which tool would be used to collect wireless packet data?
- Question #227
Which of the following processes evaluates the adherence of an organization to its stated security policy?
- Question #228
Which of the following statements are true regarding N-tier architecture? (Choose two.)
- Question #229
Some passwords are stored using specialized encryption algorithms known as hashes. Why is this an appropriate method?
- Question #230
What is the main disadvantage of the scripting languages as opposed to compiled programming languages?
- Question #231
Which of the following are password cracking tools? (Choose three.)
- Question #232
Which of the following techniques can be used to mitigate the risk of an on-site attacker from connecting to an unused network port and gaining full access to the network? (Choose...
- Question #233
When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing?
- Question #234
Which type of antenna is used in wireless communication?
- Question #235
Employees in a company are no longer able to access Internet web sites on their computers. The network administrator is able to successfully ping IP address of web servers on the I...
- Question #236
Which initial procedure should an ethical hacker perform after being brought into an organization?
- Question #237
Which of the following guidelines or standards is associated with the credit card industry?
- Question #238
An attacker has captured a target file that is encrypted with public key cryptography. Which of the attacks below is likely to be used to crack the target file?
- Question #239
Which tool can be used to silently copy files from USB devices?
- Question #240
How can a rootkit bypass Windows 7 operating system's kernel mode, code signing policy?
- Question #241
A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should...
- Question #242
A consultant has been hired by the V.P. of a large financial organization to assess the company's security posture. During the security testing, the consultant comes across child p...
- Question #243
How is sniffing broadly categorized?
- Question #244
An engineer is learning to write exploits in C++ and is using the exploit tool Backtrack. The engineer wants to compile the newest C++ exploit and name it calc.exe. Which command w...
- Question #245
A computer technician is using a new version of a word processing software package when it is discovered that a special sequence of characters causes the entire computer to crash....
- Question #246
What is the most secure way to mitigate the theft of corporate information from a laptop that was left in a hotel room?
- Question #247
The intrusion detection system at a software development company suddenly generates multiple alerts regarding attacks against the company's external webserver, VPN concentrator, an...
- Question #248
A corporation hired an ethical hacker to test if it is possible to obtain users' login credentials using methods other than social engineering. Access to offices and to a network n...
- Question #249
Which of the following scanning tools is specifically designed to find potential exploits in Microsoft Windows products?
- Question #250
Which of the statements concerning proxy firewalls is correct?
- Question #251
Which of the following is an example of two factor authentication?
- Question #252
A security consultant is trying to bid on a large contract that involves penetration testing and reporting. The company accepting bids wants proof of work so the consultant prints...
- Question #253
A penetration tester is conducting a port scan on a specific host. The tester found several ports opened that were confusing in concluding the Operating System (OS) version install...
- Question #254
What is the outcome of the comm"nc -l -p 2222 | nc 10.1.0.43 1234"?
- Question #255
For messages sent through an insecure channel, a properly implemented digital signature gives the receiver reason to believe the message was sent by the claimed sender. While using...