Skip to main content

EC0-479 Real Exam Questions

EC-Council Certified Security Analyst(ECSA)

232 questions available · Page 1 of 24

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

____________________ is simply the application of Computer Investigation and analysis techniques in the interests of determining potential legal evidence.

  1. A

    Network Forensics

  2. B

    Computer Forensics

  3. C

    Incident Response

  4. D

    Event Reaction

Show answer and explanation

Correct answer: B

Question 2 Single choice

You just passed your ECSA exam and are about to start your first consulting job running security audits for a financial institution in Los Angeles. The IT manager of the company you will be working for tries to see if you remember your ECSA class. He asks about the methodology you will be using to test the company's network.

How would you answer?

  1. A

    IBM Methodology

  2. B

    LPT Methodology

  3. C

    Google Methodology

  4. D

    Microsoft Methodology

Show answer and explanation

Correct answer: B

Question 3 Single choice

Windows identifies which application to open a file with by examining which of the following?

  1. A

    The File extension

  2. B

    The file attributes

  3. C

    The file Signature at the end of the file

  4. D

    The file signature at the beginning of the file

Show answer and explanation

Correct answer: A

Question 4 Single choice

You are working as an investigator for a corporation and you have just received instructions from your manager to assist in the collection of 15 hard drives that are part of an ongoing investigation. Your job is to complete the required evidence custody forms to properly document each piece of evidence as it is collected by other members of your team. Your manager instructs you to complete one multi-evidence form for the entire case and a single-evidence form for each hard drive.

How will these forms be stored to help preserve the chain of custody of the case?

  1. A

    All forms should be placed in an approved secure container because they are now primary evidence in the case.

  2. B

    The multi-evidence form should be placed in the report file and the single-evidence forms should be kept with each hard drive in an approved secure container.

  3. C

    The multi-evidence form should be placed in an approved secure container with the hard drives and the single-evidence forms should be placed in the report file.

  4. D

    All forms should be placed in the report file because they are now primary evidence in the case.

Show answer and explanation

Correct answer: B

Question 5 Single choice

What is the following command trying to accomplish?

  1. A

    Verify that NETBIOS is running for the 192.168.0.0 network

  2. B

    Verify that TCP port 445 is open for the 192.168.0.0 network

  3. C

    Verify that UDP port 445 is open for the 192.168.0.0 network

  4. D

    Verify that UDP port 445 is closed for the 192.168.0.0 network

Show answer and explanation

Correct answer: C

Question 6 Single choice

You work as an IT security auditor hired by a law firm in Boston to test whether you can gain access to sensitive information about the company's clients. You have rummaged through their trash and found very little information. You do not want to set off any alarms on their network, so you plan on performing passive footprinting against their Web servers.

What tool should you use?

  1. A

    Ping sweep

  2. B

    Netcraft

  3. C

    Dig

  4. D

    Nmap

Show answer and explanation

Correct answer: B

Question 7 Single choice

If a suspect computer is located in an area that may have toxic chemicals, you must:

  1. A

    coordinate with the HAZMAT team

  2. B

    determine a way to obtain the suspect computer

  3. C

    assume the suspect machine is contaminated

  4. D

    do not enter alone

Show answer and explanation

Correct answer: A

Question 8 Single choice

What is the advantage in encrypting the communication between the agent and the monitor in an Intrusion Detection System?

  1. A

    Encryption of agent communications will conceal the presence of the agents

  2. B

    Alerts are sent to the monitor when a potential intrusion is detected

  3. C

    An intruder could intercept and delete data or alerts and the intrusion can go undetected

  4. D

    The monitor will know if counterfeit messages are being generated because they will not be encrypted

Show answer and explanation

Correct answer: D

Question 9 Single choice

What does ICMP Type 3/Code 13 mean?

  1. A

    Host Unreachable

  2. B

    Port Unreachable

  3. C

    Protocol Unreachable

  4. D

    Administratively Blocked

Show answer and explanation

Correct answer: D

Question 10 Single choice

Software firewalls work at which layer of the OSI model?

  1. A

    Data Link

  2. B

    Network

  3. C

    Transport

  4. D

    Application

Show answer and explanation

Correct answer: A