EC0-350 Exam Questions
892 real EC0-350 exam questions with expert-verified answers and explanations. Page 9 of 18.
- Question #406
A hacker searches in Google for filetype:pcf to find Cisco VPN config files. Those files may contain connectivity passwords that can be decoded with which of the following?
- Question #407
Which technical characteristic do Ethereal/Wireshark, TCPDump, and Snort have in common?
- Question #408
A pentester gains acess to a Windows application server and needs to determine the settings of the built-in Windows firewall. Which command would be used?
- Question #409
The following is a sample of output from a penetration tester's machine targeting a machine with the IP address of 192.168.1.106: What is most likely taking place?
- Question #410
A tester is attempting to capture and analyze the traffic on a given network and realizes that the network has several switches. What could be used to successfully sniff the traffi...
- Question #411
A newly discovered flaw in a software application would be considered which kind of security vulnerability?
- Question #412
What are the three types of authentication?
- Question #413
What are the three types of compliance that the Open Source Security Testing Methodology Manual (OSSTMM) recognizes?
- Question #414
While checking the settings on the internet browser, a technician finds that the proxy server settings have been checked and a computer is trying to use itself as a proxy server. W...
- Question #415
Which of the following business challenges could be solved by using a vulnerability scanner?
- Question #416
Which of the following is a hardware requirement that either an IDS/IPS system or a proxy server must have in order to properly function?
- Question #417
If an e-commerce site was put into a live environment and the programmers failed to remove the secret entry point that was used during the application development, what is this sec...
- Question #418
A Certificate Authority (CA) generates a key pair that will be used for encryption and decryption of email. The integrity of the encrypted email is dependent on the security of whi...
- Question #419
Which system consists of a publicly available set of databases that contain domain name registration contact information?
- Question #420
A tester has been hired to do a web application security test. The tester notices that the site is dynamic and must make use of a back end database. In order for the tester to see...
- Question #421
Which set of access control solutions implements two-factor authentication?
- Question #422
What is the name of the international standard that establishes a baseline level of confidence in the security functionality of IT products by providing a set of requirements for e...
- Question #423
Advanced encryption standard is an algorithm used for which of the following?
- Question #424
Which statement best describes a server type under an N-tier architecture?
- Question #425
During a penetration test, a tester finds that the web application being analyzed is vulnerable to Cross Site Scripting (XSS). Which of the following conditions must be met to expl...
- Question #426
Which protocol and port number might be needed in order to send log messages to a log analysis tool that resides behind a firewall?
- Question #427
A certified ethical hacker (CEH) is approached by a friend who believes her husband is cheating. She offers to pay to break into her husband's email account in order to find proof...
- Question #428
A hacker is attempting to see which ports have been left open on a network. Which NMAP switch would the hacker use?
- Question #429
The network administrator for a company is setting up a website with e-commerce capabilities. Packet sniffing is a concern because credit card information will be sent electronical...
- Question #430
Which security control role does encryption meet?
- Question #431
A consultant is hired to do physical penetration testing at a large financial company. In the first day of his assessment, the consultant goes to the company`s building dressed lik...
- Question #432
A pentester is using Metasploit to exploit an FTP server and pivot to a LAN. How will the pentester pivot using Metasploit?
- Question #433
A company has hired a security administrator to maintain and administer Linux and Windows- based systems. Written in the nightly report file is the following. Firewall log files ar...
- Question #434
A hacker is attempting to see which IP addresses are currently active on a network. Which NMAP switch would the hacker use?
- Question #435
At a Windows Server command prompt, which command could be used to list the running services?
- Question #436
Which of the following is optimized for confidential communications, such as bidirectional voice and video?
- Question #437
The use of alert thresholding in an IDS can reduce the volume of repeated alerts, but introduces which of the following vulnerabilities?
- Question #438
Which of the following is considered an acceptable option when managing a risk?
- Question #439
A person approaches a network administrator and wants advice on how to send encrypted email from home. The end user does not want to have to pay for any license fees or manage serv...
- Question #440
__________ is found in all versions of NTFS and is described as the ability to fork file data into existing files without affecting their functionality, size, or display to traditi...
- Question #441
A company is legally liable for the content of email that is sent from its systems, regardless of whether the message was sent for private or business-related purposes. This could...
- Question #442
Paul has just finished setting up his wireless network. He has enabled numerous security features such as changing the default SSID, enabling WPA encryption, and enabling MAC filte...
- Question #443
What two things will happen if a router receives an ICMP packet, which has a TTL value of 1, and the destination host is several hops away? (Select 2 answers)
- Question #444
Which of the following LM hashes represents a password of less than 8 characters?
- Question #445
While investigating a claim of a user downloading illegal material, the investigator goes through the files on the suspect's workstation. He comes across a file that is just called...
- Question #446
Harold is the senior security analyst for a small state agency in New York. He has no other security professionals that work under him, so he has to do all the security-related tas...
- Question #447
Which Windows system tool checks integrity of critical files that has been digitally signed by Microsoft?
- Question #448
Botnets are networks of compromised computers that are controlled remotely and surreptitiously by one or more cyber criminals. How do cyber criminals infect a victim's computer wit...
- Question #449
What is the essential difference between an `Ethical Hacker' and a `Cracker'?
- Question #450
What does the term "Ethical Hacking" mean?
- Question #451
Who is an Ethical Hacker?
- Question #452
What is "Hacktivism"?
- Question #453
Where should a security tester be looking for information that could be used by an attacker against an organization? (Select all that apply)
- Question #454
What are the two basic types of attacks? (Choose two.
- Question #455
User which Federal Statutes does FBI investigate for computer crimes involving e-mail scams and mail fraud?