Skip to main content

412-79 Real Exam Questions

EC-Council Certified Security Analyst (ECSA)

232 questions available · Page 1 of 24

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

When investigating a potential e-mail crime, what is your first step in the investigation?

  1. A

    Trace the IP address to its origin

  2. B

    Write a report

  3. C

    Determine whether a crime was actually committed

  4. D

    Recover the evidence

Show answer and explanation

Correct answer: A

Question 2 Single choice

You are working on a thesis for your doctorate degree in Computer Science. Your thesis is based on HTML, DHTML, and other web-based languages and how they have evolved over the years. You navigate to archive.org and view the HTML code of news.com. You then navigate to the current news.com website and copy over the source code. While searching through the code, you come across something abnormal:

<img src=http://coolwebsearch.com/ads/pixel.news.com width=1 height=1 border=0>

What have you found?

  1. A

    Trojan.downloader

  2. B

    Blind bug

  3. C

    Web bug

  4. D

    CGI code

Show answer and explanation

Correct answer: C

Question 3 Multiple choice

E-mail logs contain which of the following information to help you in your investigation? (Select up to 4)

  1. A

    user account that was used to send the account

  2. B

    attachments sent with the e-mail message

  3. C

    unique message identifier

  4. D

    contents of the e-mail message

  5. E

    date and time the message was sent

Show answer and explanation

Correct answers: A, C, D, E

Question 4 Single choice

You are using DriveSpy, a forensic tool and want to copy 150 sectors where the starting sector is 1709 on the primary hard drive.

Which of the following formats correctly specifies these sectors?

  1. A

    0:1000, 150

  2. B

    0:1709, 150

  3. C

    1:1709, 150

  4. D

    0:1709-1858

Show answer and explanation

Correct answer: B

Question 5 Single choice

Why is it a good idea to perform a penetration test from the inside?

  1. A

    It is easier to hack from the inside

  2. B

    It is never a good idea to perform a penetration test from the inside

  3. C

    To attack a network from a hacker's perspective

  4. D

    Because 70% of attacks are from inside the organization

Show answer and explanation

Correct answer: D

Question 6 Single choice

What will the following URL produce in an unpatched IIS Web Server?

  1. A

    Execute a buffer flow in the C: drive of the web server

  2. B

    Insert a Trojan horse into the C: drive of the web server

  3. C

    Directory listing of the C:\windows\system32 folder on the web server

  4. D

    Directory listing of C: drive on the web server

Show answer and explanation

Correct answer: D

Question 7 Single choice

During the course of a corporate investigation, you find that an Employee is committing a crime.
Can the Employer file a criminal complain with Police?

  1. A

    Yes, and all evidence can be turned over to the police

  2. B

    Yes, but only if you turn the evidence over to a federal law enforcement agency

  3. C

    No, because the investigation was conducted without following standard police procedures

  4. D

    No, because the investigation was conducted without warrant

Show answer and explanation

Correct answer: A

Question 8 Single choice

When investigating a Windows System, it is important to view the contents of the page or swap file because:

  1. A

    Windows stores all of the systems configuration information in this file

  2. B

    This is file that windows use to communicate directly with Registry

  3. C

    A Large volume of data can exist within the swap file of which the computer user has no knowledge

  4. D

    This is the file that windows use to store the history of the last 100 commands that were run from the

    command line

Show answer and explanation

Correct answer: C

Question 9 Single choice

What is the advantage in encrypting the communication between the agent and the monitor in an Intrusion Detection System?

  1. A

    Encryption of agent communications will conceal the presence of the agents

  2. B

    Alerts are sent to the monitor when a potential intrusion is detected

  3. C

    An intruder could intercept and delete data or alerts and the intrusion can go undetected

  4. D

    The monitor will know if counterfeit messages are being generated because they will not be encrypted

Show answer and explanation

Correct answer: D

Question 10 Single choice

What binary coding is used most often for e-mail purposes?

  1. A

    MIME

  2. B

    Uuencode

  3. C

    IMAP

  4. D

    SMTP

Show answer and explanation

Correct answer: A