EC-COUNCIL EC-Council Certified Security Analyst (ECSA) V10 Sample Questions:
1. By default, the TFTP server listens on UDP port 69. Which of the following utility reports the port status of target TCP and UDP ports on a local or a remote computer and is used to troubleshoot TCP/IP connectivity issues?
A) PortQry
B) Tracert
C) Netstat
D) Telnet
2. You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers.
What type of firewall must you implement to abide by this policy?
A) Application-level proxy firewall
B) Circuit-level proxy firewall
C) Packet filtering firewall
D) Statefull firewall
3. Identify the injection attack represented in the diagram below:
A) XML Injection Attack
B) Frame Injection Attack
C) XPath Injection Attack
D) XML Request Attack
4. The first and foremost step for a penetration test is information gathering. The main objective of this test is to gather information about the target system which can be used in a malicious manner to gain access to the target systems.
Which of the following information gathering terminologies refers to gathering information through social engineering on-site visits, face-to-face interviews, and direct questionnaires?
A) Open Source or Passive Information Gathering
B) Active Information Gathering
C) Pseudonymous Information Gathering
D) Anonymous Information Gathering
5. Which of the following policy forbids everything with strict restrictions on all usage of the company systems and network?
A) Information-Protection Po
B) Paranoid Policy
C) Promiscuous Policy
D) Prudent Policy
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: D | Question # 3 Answer: A | Question # 4 Answer: B | Question # 5 Answer: B |
We're so confident of our products that we provide no hassle product exchange.


By Dinah

