Exam Details

  • Exam Code
    :412-79V8
  • Exam Name
    :EC-Council Certified Security Analyst (ECSA)
  • Certification
    :ECCouncil Certification
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :200 Q&As
  • Last Updated
    :Apr 18, 2024

EC-COUNCIL ECCouncil Certification 412-79V8 Questions & Answers

  • Question 1:

    Which one of the following is a useful formatting token that takes an int * as an argument, and writes the number of bytes already written, to that location?

    A. "%n"

    B. "%s"

    C. "%p"

    D. "%w"

  • Question 2:

    You have compromised a lower-level administrator account on an Active Directory network of a small company in Dallas, Texas. You discover Domain Controllers through enumeration. You connect to one of the Domain Controllers on port 389 using Idp.exe. What are you trying to accomplish here?

    A. Poison the DNS records with false records

    B. Enumerate MX and A records from DNS

    C. Establish a remote connection to the Domain Controller

    D. Enumerate domain user accounts and built-in groups

  • Question 3:

    Which one of the following tools of trade is an automated, comprehensive penetration testing product for assessing the specific information security threats to an organization?

    A. Sunbelt Network Security Inspector (SNSI)

    B. CORE Impact

    C. Canvas

    D. Microsoft Baseline Security Analyzer (MBSA)

  • Question 4:

    Which one of the following tools of trade is a commercial shellcode and payload generator written in Python by Dave Aitel?

    A. Microsoft Baseline Security Analyzer (MBSA)

    B. CORE Impact

    C. Canvas

    D. Network Security Analysis Tool (NSAT)

  • Question 5:

    Metasploit framework in an open source platform for vulnerability research, development, and penetration testing. Which one of the following metasploit options is used to exploit multiple systems at once?

    A. NinjaDontKill

    B. NinjaHost

    C. RandomNops

    D. EnablePython

  • Question 6:

    Which one of the following log analysis tools is used for analyzing the server's log files?

    A. Performance Analysis of Logs tool

    B. Network Sniffer Interface Test tool

    C. Ka Log Analyzer tool

    D. Event Log Tracker tool

  • Question 7:

    Which one of the following log analysis tools is a Cisco Router Log Format log analyzer and it parses logs, imports them into a SQL database (or its own built-in database), aggregates them, and generates the dynamically filtered reports, all through a web interface?

    A. Event Log Tracker

    B. Sawmill

    C. Syslog Manager

    D. Event Log Explorer

  • Question 8:

    NTP protocol is used to synchronize the system clocks of computers with a remote time server or time source over a network. Which one of the following ports is used by NTP as its transport layer?

    A. TCP port 152

    B. UDP port 177

    C. UDP port 123

    D. TCP port 113

  • Question 9:

    DMZ is a network designed to give the public access to the specific internal resources and you might want to do the same thing for guests visiting organizations without compromising the integrity of the internal resources. In general, attacks on the wireless networks fall into four basic categories. Identify the attacks that fall under Passive attacks category.(Select all that apply)

    A. Wardriving

    B. Spoofing

    C. Sniffing

    D. Network Hijacking

  • Question 10:

    Which one of the following commands is used to search one of more files for a specific pattern and it helps in organizing the firewall log files?

    A. grpck

    B. grep

    C. gpgv

    D. gprn

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 412-79V8 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.