EC-COUNCIL EC0-350 試験概要:
| 認定ベンダー: | EC-COUNCIL |
| 試験名: | エシカルハッキングと対抗策 (Certified Ethical Hacker v8) |
| 試験番号: | EC0-350 |
| 認定の有効期間: | 3年間 |
| 関連資格: | CEH (Certified Ethical Hacker) CEH Practical CEH Master |
| 試験形式: | 選択式 |
| 試験時間: | 240 minutes |
| 対応言語: | English |
| 出題数: | 125 |
| 受験料: | 地域によって異なります(通常、バウチャー価格は約650米ドル) |
| 合格点: | 70% |
| サンプル問題: | EC-COUNCIL EC0-350 サンプル問題 |
| 受験方法: | Pearson VUEまたはEC-COUNCILポータルでのコンピュータベース試験(CBT)。試験会場またはオンラインでの監視付き試験。 |
| 前提条件: | 情報セキュリティにおける2年間の実務経験または関連するトレーニングを推奨。EC-COUNCIL公式トレーニングの受講、または承認された受験資格申請が必要。 |
| 公式シラバスのURL: | https://www.eccouncil.org/train-certify/certified-ethical-hacker-ceh/ |
EC-COUNCIL EC0-350 試験シラバストピック:
| セクション | 目標 |
|---|---|
| ネットワークスキャン | |
| システムハッキング | |
| セッションハイジャック | |
| スニッフィング | |
| ソーシャルエンジニアリング | |
| ワイヤレスネットワークとモバイルプラットフォームのハッキング | |
| エシカルハッキング入門 | |
| マルウェアの脅威 | |
| サービス拒否(DoS) | |
| Webサーバーとアプリケーションのハッキング | |
| フットプリンティングと偵察 | |
| 脆弱性分析 | |
| 列挙 | |
| IDS、ファイアウォール、ハニーポットの回避 | |
| 暗号技術 |
EC-COUNCIL Ethical hacking and countermeasures 認定 EC0-350 試験問題:
1. One advantage of an application-level firewall is the ability to
A) filter specific commands, such as http:post.
B) filter packets at the network level.
C) retain state information for each packet.
D) monitor tcp handshaking.
2. A security analyst in an insurance company is assigned to test a new web application that will be used by clients to help them choose and apply for an insurance plan. The analyst discovers that the application is developed in ASP scripting language and it uses MSSQL as a database backend. The analyst locates the application's search form and introduces the following code in the search input fielD.
IMG SRC=vbscript:msgbox("Vulnerable");> originalAttribute="SRC" originalPath="vbscript:msgbox("Vulnerable");>" When the analyst submits the form, the browser returns a pop-up window that says "Vulnerable".
Which web applications vulnerability did the analyst discover?
A) Cross-site request forgery
B) Cross-site scripting
C) Command injection
D) SQL injection
3. If a competitor wants to cause damage to your organization, steal critical secrets, or put you out of business, they just have to find a job opening, prepare someone to pass the interview, have that person hired, and they will be in the organization.
How would you prevent such type of attacks?
A) Hire the people through third-party job agencies who will vet them for you
B) Conduct thorough background checks before you engage them
C) Investigate their social networking profiles
D) It is impossible to block these attacks
4. Pandora is used to attack __________ network operating systems.
A) UNIX
B) Windows
C) Netware
D) MAC OS
E) Linux
5. The programmers on your team are analyzing the free, open source software being used to run FTP services on a server in your organization. They notice that there is excessive number of functions in the source code that might lead to buffer overflow. These C++ functions do not check bounds. Identify the line in the source code that might lead to buffer overflow?
A) 17B.17
B) 35E.35
C) 32D.32
D) 9A.9
E) 20C.20
質問と回答:
| 質問 # 1 正解: A | 質問 # 2 正解: B | 質問 # 3 正解: B | 質問 # 4 正解: C | 質問 # 5 正解: A |














843 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
