412-79 Exam Details

  • Exam Code
    :412-79
  • Exam Name
    :EC-Council Certified Security Analyst (ECSA)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :232 Q&As
  • Last Updated
    :May 29, 2026

EC-COUNCIL 412-79 Online Questions & Answers

  • Question 81:

    Jim performed a vulnerability analysis on his network and found no potential problems. He runs another utility that executes exploits against his system to verify the results of the vulnerability test. The second utility executes five known exploits against his network in which the vulnerability analysis said were not exploitable. What kind of results did Jim receive from his vulnerability analysis?

    A. True negatives
    B. False negatives
    C. False positives
    D. True positives

  • Question 82:

    When performing a forensics analysis, what device is used to prevent the system from recording data on an evidence disk?

    A. a write-blocker
    B. a protocol analyzer
    C. a firewall
    D. a disk editor

  • Question 83:

    With Regard to using an Antivirus scanner during a computer forensics investigation, You should:

    A. Scan the suspect hard drive before beginning an investigation
    B. Never run a scan on your forensics workstation because it could change your systems configuration
    C. Scan your forensics workstation at intervals of no more than once every five minutes during an investigation
    D. Scan your Forensics workstation before beginning an investigation

  • Question 84:

    George is the network administrator of a large Internet company on the west coast. Per corporate policy, none of the employees in the company are allowed to use FTP or SFTP programs without obtaining approval from the IT department. Few managers are using SFTP program on their computers. Before talking to his boss, George wants to have some proof of their activity.

    George wants to use Ethereal to monitor network traffic, but only SFTP traffic to and from his network. What filter should George use in Ethereal?

    A. src port 22 and dst port 22
    B. src port 23 and dst port 23
    C. net port 22
    D. udp port 22 and host 172.16.28.1/24

  • Question 85:

    You are called in to assist the police in an investigation involving a suspected drug dealer. The suspects house was searched by the police after a warrant was obtained and they located a floppy disk in the suspects bedroom. The disk contains several files, but they appear to be password protecteD. What are two common methods used by password cracking software that you can use to obtain the password?

    A. Limited force and library attack
    B. Brute Force and dictionary Attack
    C. Maximum force and thesaurus Attack
    D. Minimum force and appendix Attack

  • Question 86:

    If a suspect computer is located in an area that may have toxic chemicals, you must:

    A. coordinate with the HAZMAT team
    B. determine a way to obtain the suspect computer
    C. assume the suspect machine is contaminated
    D. do not enter alone

  • Question 87:

    You work as an IT security auditor hired by a law firm in Boston to test whether you can gain access to sensitive information about the company clients. You have rummaged through their trash and found very little information. You do not want to set off any alarms on their network, so you plan on performing passive footprinting against their Web servers. What tool should you use?

    A. Nmap
    B. Netcraft
    C. Ping sweep
    D. Dig

  • Question 88:

    You are trying to locate Microsoft Outlook Web Access Default Portal using Google search on the Internet. What search string will you use to locate them?

    A. outlook:"search"
    B. allinurl:"exchange/logon.asp"
    C. locate:"logon page"
    D. intitle:"exchange server"

  • Question 89:

    Area density refers to:

    A. the amount of data per disk
    B. the amount of data per partition
    C. the amount of data per square inch
    D. the amount of data per platter

  • Question 90:

    You are a security analyst performing reconnaissance on a company you will be carrying out a penetration test for. You conduct a search for IT jobs on Dice.com and find the following information for an open position:

    7+ years experience in Windows Server environment 5+ years experience in Exchange 2000/2003 environment Experience with Cisco Pix Firewall, Linksys 1376 router, Oracle 11i and MYOB v3.4 Accounting software are required MCSA desired, MCSE, CEH preferred No Unix/Linux Experience needed

    What is this information posted on the job website considered?

    A. Information vulnerability
    B. Social engineering exploit
    C. Trade secret
    D. Competitive exploit

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 412-79 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.