412-79 Exam Details

  • Exam Code
    :412-79
  • Exam Name
    :EC-Council Certified Security Analyst (ECSA)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :232 Q&As
  • Last Updated
    :May 29, 2026

EC-COUNCIL 412-79 Online Questions & Answers

  • Question 121:

    John and Hillary works at the same department in the company. John wants to find out Hillary's network password so he can take a look at her documents on the file server. He enables Lophtcrack program to sniffing mode. John sends Hillary an email with a link to Error! Reference source not found.

    What information will he be able to gather from this?

    A. The SAM file from Hillary computer
    B. Hillary network username and password hash
    C. The SID of Hillary network account
    D. The network shares that Hillary has permissions

  • Question 122:

    You are a computer forensics investigator working with local police department and you are called to assist in an investigation of threatening emails. The complainant has printer out 27 email messages from the suspect and gives the printouts to you. You inform her that you will need to examine her computer because you need access to the ______________ in order to track the emails back to the suspect.

    A. Routing Table
    B. Firewall log
    C. Configuration files
    D. Email Header

  • Question 123:

    You are working in the security Department of law firm. One of the attorneys asks you about the topic of sending fake email because he has a client who has been charged with doing just that. His client alleges that he is innocent and that there is no way for a fake email to actually be sent. You inform the attorney that his client is mistaken and that fake email is possibility and that you can prove it. You return to your desk and craft a fake email to the attorney that appears to come from his boss. What port do you send the email to on the company SMTP server?

    A. 10
    B. 25
    C. 110
    D. 135

  • Question 124:

    What is kept in the following directory? HKLM\SECURITY\Policy\Secrets

    A. Service account passwords in plain text
    B. Cached password hashes for the past 20 users
    C. IAS account names and passwords
    D. Local store PKI Kerberos certificates

  • Question 125:

    What is the advantage in encrypting the communication between the agent and the monitor in an Intrusion Detection System?

    A. Encryption of agent communications will conceal the presence of the agents
    B. Alerts are sent to the monitor when a potential intrusion is detected
    C. An intruder could intercept and delete data or alerts and the intrusion can go undetected
    D. The monitor will know if counterfeit messages are being generated because they will not be encrypted

  • Question 126:

    You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers. What type of firewall must you implement to abide by this policy?

    A. Circuit-level proxy firewall
    B. Packet filtering firewall
    C. Application-level proxy firewall
    D. Statefull firewall

  • Question 127:

    When using Windows acquisitions tools to acquire digital evidence, it is important to use a well- tested hardware write-blocking device to:

    A. Automate Collection from image files
    B. Avoiding copying data from the boot partition
    C. Acquire data from host-protected area on a disk
    D. Prevent Contamination to the evidence drive

  • Question 128:

    E-mail logs contain which of the following information to help you in your investigation? (Select up to 4) A. user account that was used to send the account

    B. attachments sent with the e-mail message
    C. unique message identifier
    D. contents of the e-mail message
    E. date and time the message was sent

  • Question 129:

    If you discover a criminal act while investigating a corporate policy abuse, it becomes a public- sector investigation and should be referred to law enforcement?

    A. true
    B. false

  • Question 130:

    When cataloging digital evidence, the primary goal is to:

    A. Make bit-stream images of all hard drives
    B. Preserve evidence integrity
    C. Not remove the evidence from the scene
    D. Not allow the computer to be turned off

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 412-79 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.