Skip to main content

412-79V8 Real Exam Questions

EC-Council Certified Security Analyst (ECSA)

200 questions available · Page 1 of 20

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Identify the injection attack represented in the diagram below:

  1. A

    XPath Injection Attack

  2. B

    XML Request Attack

  3. C

    XML Injection Attack

  4. D

    Frame Injection Attack

Show answer and explanation

Correct answer: C

Question 2 Single choice

Port numbers are used to keep track of different conversations crossing the network at the same time.
Both TCP and UDP use port (socket) numbers to pass information to the upper layers. Port numbers have the assigned ranges.

Port numbers above 1024 are considered which one of the following?

  1. A

    Dynamically assigned port numbers

  2. B

    Statically assigned port numbers

  3. C

    Well-known port numbers

  4. D

    Unregistered port numbers

Show answer and explanation

Correct answer: A

Question 3 Single choice

The amount of data stored in organizational databases has increased rapidly in recent years due to the rapid advancement of information technologies. A high percentage of these data is sensitive, private and critical to the organizations, their clients and partners.

Therefore, databases are usually installed behind internal firewalls, protected with intrusion detection mechanisms and accessed only by applications. To access a database, users have to connect to one of these applications and submit queries through them to the database. The threat to databases arises when these applications do not behave properly and construct these queries without sanitizing user inputs first.
Identify the injection attack represented in the diagram below:

  1. A

    Frame Injection Attack

  2. B

    LDAP Injection Attack

  3. C

    XPath Injection Attack

  4. D

    SOAP Injection Attack

Show answer and explanation

Correct answer: B

Question 4 Single choice

Which of the following reports provides a summary of the complete pen testing process, its outcomes, and recommendations?

  1. A

    Vulnerability Report

  2. B

    Executive Report

  3. C

    Client-side test Report

  4. D

    Host Report

Show answer and explanation

Correct answer: B

Question 5 Single choice

Which of the following password cracking techniques is used when the attacker has some information about the password?

  1. A

    Hybrid Attack

  2. B

    Dictionary Attack

  3. C

    Syllable Attack

  4. D

    Rule-based Attack

Show answer and explanation

Correct answer: D

Question 6 Single choice

In which of the following IDS evasion techniques does IDS reject the packets that an end system accepts?

  1. A

    IPS evasion technique

  2. B

    IDS evasion technique

  3. C

    UDP evasion technique

  4. D

    TTL evasion technique

Show answer and explanation

Correct answer: D

Question 7 Single choice

Which of the following attacks does a hacker perform in order to obtain UDDI information such as businessEntity, businesService, bindingTemplate, and tModel?

  1. A

    Web Services Footprinting Attack

  2. B

    Service Level Configuration Attacks

  3. C

    URL Tampering Attacks

  4. D

    Inside Attacks

Show answer and explanation

Correct answer: A

Question 8 Single choice

Output modules allow Snort to be much more flexible in the formatting and presentation of output to its users. Snort has 9 output plug-ins that push out data in different formats.

Which one of the following output plug-ins allows alert data to be written in a format easily importable to a database?

  1. A

    unified

  2. B

    csv

  3. C

    alert_unixsock

  4. D

    alert_fast

Show answer and explanation

Correct answer: B

Question 9 Single choice

Transmission control protocol accepts data from a data stream, divides it into chunks, and adds a TCP header creating a TCP segment.
The TCP header is the first 24 bytes of a TCP segment that contains the parameters and state of an end-to-end TCP socket. It is used to track the state of communication between two TCP endpoints.
For a connection to be established or initialized, the two hosts must synchronize. The synchronization requires each side to send its own initial sequence number and to receive a confirmation of exchange in an acknowledgment (ACK) from the other side The below diagram shows the TCP Header format:

How many bits is a acknowledgement number?

  1. A

    16 bits

  2. B

    32 bits

  3. C

    8 bits

  4. D

    24 bits

Show answer and explanation

Correct answer: B

Question 10 Single choice

Which of the following policies helps secure data and protects the privacy of organizational information?

  1. A

    Special-Access Policy

  2. B

    Document retention Policy

  3. C

    Cryptography Policy

  4. D

    Personal Security Policy

Show answer and explanation

Correct answer: C