412-79 Exam Details

  • Exam Code
    :412-79
  • Exam Name
    :EC-Council Certified Security Analyst (ECSA)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :232 Q&As
  • Last Updated
    :May 29, 2026

EC-COUNCIL 412-79 Online Questions & Answers

  • Question 141:

    A suspect is accused of violating the acceptable use of computing resources, as he has visited adult websites and downloaded images. The investigator wants to demonstrate that the suspect did indeed visit these sites. However, the suspect has cleared the search history and emptied the cookie cache. Moreover, he has removed any images he might have downloadeD. What can the investigator do to prove the violation? Choose the most feasible option.

    A. Image the disk and try to recover deleted files
    B. Seek the help of co-workers who are eye-witnesses
    C. Check the Windows registry for connection data (You may or may not recover)
    D. Approach the websites for evidence

  • Question 142:

    In Microsoft file structures, sectors are grouped together to form:

    A. Clusters
    B. Drives
    C. Bitstreams
    D. Partitions

  • Question 143:

    The MD5 program is used to:

    A. wipe magnetic media before recycling it
    B. make directories on a evidence disk
    C. view graphics files on an evidence drive
    D. verify that a disk is not altered when you examine it

  • Question 144:

    A (n) ____________ is one that s performed by a computer program rather than the attacker manually performing the steps in the attack sequence.

    A. blackout attack
    B. automated attack
    C. distributed attack
    D. central processing attack

  • Question 145:

    You are assisting in the investigation of a possible Web Server Hack. The company who called you stated that customers reported to them that whenever they entered the web address of the company in their browser, what they received was a porno graphic web site. The company checked the web server and nothing appears wrong. When you type in the IP address of the web site in your browser everything appears normal. What is the name of the attack that affects the DNS cache of the name resolution servers, resulting in those servers directing users to the wrong web site?

    A. ARP Poisoning
    B. DNS Poisoning
    C. HTTP redirect attack
    D. IP Spoofing

  • Question 146:

    Your company's network just finished going through a SAS 70 audit. This audit reported that overall, your network is secure, but there are some areas that needs improvement. The major area was SNMP security. The audit company recommended turning off SNMP, but that is not an option since you have so many remote nodes to keep track of. What step could you take to help secure SNMP on your network?

    A. Change the default community string names
    B. Block all internal MAC address from using SNMP
    C. Block access to UDP port 171
    D. Block access to TCP port 171

  • Question 147:

    In General, ______________ Involves the investigation of data that can be retrieved from the hard disk or other disks of a computer by applying scientific methods to retrieve the datA.

    A. Network Forensics
    B. Data Recovery
    C. Disaster Recovery
    D. Computer Forensics

  • Question 148:

    What are the security risks of running a "repair" installation for Windows XP?

    A. Pressing Shift+F10 gives the user administrative rights
    B. Pressing Ctrl+F10 gives the user administrative rights
    C. There are no security risks when running the "repair" installation for Windows XP
    D. Pressing Shift+F1 gives the user administrative rights

  • Question 149:

    Harold wants to set up a firewall on his network but is not sure which one would be the most appropriate. He knows he needs to allow FTP traffic to one of the servers on his network, but he wants to only allow FTP-PUT. Which firewall would be most appropriate for Harold? needs?

    A. Application-level proxy firewall
    B. Data link layer firewall
    C. Packet filtering firewall
    D. Circuit-level proxy firewall

  • Question 150:

    Jason has set up a honeypot environment by creating a DMZ that has no physical or logical access to his production network. In this honeypot, he has placed a server running Windows Active Directory. He has also placed a Web server in the DMZ that services a number of web pages that offer visitors a chance to download sensitive information by clicking on a button. A week later, Jason finds in his network logs how an intruder accessed the honeypot and downloaded sensitive information. Jason uses the logs to try and prosecute the intruder for stealing sensitive corporate information. Why will this not be viable?

    A. Intruding into a honeypot is not illegal
    B. Entrapment
    C. Intruding into a DMZ is not illegal
    D. Enticement

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 412-79 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.