ECCouncil 412-79 - EC-Council Certified Security Analyst (ECSA) Exam

Question #11 (Topic: Topic 1)
What will the following command accomplish?
A. Test ability of a router to handle over-sized packets B. Test the ability of a router to handle fragmented packets C. Test the ability of a WLAN to handle fragmented packets D. Test the ability of a router to handle under-sized packets
Answer: A
Question #12 (Topic: Topic 1)
What are the security risks of running a "repair" installation for Windows XP?
A. There are no security risks when running the "repair" installation for Windows XP B. Pressing Shift+F1 gives the user administrative rights C. Pressing Ctrl+F10 gives the user administrative rights D. Pressing Shift+F10 gives the user administrative rights
Answer: D
Question #13 (Topic: Topic 1)
You are the security analyst working for a private company out of France. Your current
assignment is to obtain credit card information from a Swiss bank owned by that company.
After initial reconnaissance, you discover that the bank security defenses are very strong
and would take too long to penetrate. You decide to get the information by monitoring the
traffic between the bank and one of its subsidiaries in London. After monitoring some of the
traffic, you see a lot of FTP packets traveling back and forth. You want to sniff the traffic
and extract usernames and passwords. What tool could you use to get this information?
A. RaidSniff B. Snort C. Ettercap D. Airsnort
Answer: C
Question #14 (Topic: Topic 1)
George is the network administrator of a large Internet company on the west coast. Per
corporate policy, none of the employees in the company are allowed to use FTP or SFTP
programs without obtaining approval from the IT department. Few managers are using
SFTP program on their computers. Before talking to his boss, George wants to have some
proof of their activity.
George wants to use Ethereal to monitor network traffic, but only SFTP traffic to and from
his network. What filter should George use in Ethereal?
A. net port 22 B. udp port 22 and host 172.16.28.1/24 C. src port 22 and dst port 22 D. src port 23 and dst port 23
Answer: C
Question #15 (Topic: Topic 1)
You are assisting a Department of Defense contract company to become compliant with
the stringent security policies set by the DoD. One such strict rule is that firewalls must only
allow incoming connections that were first initiated by internal computers. What type of
firewall must you implement to abide by this policy?
A. Circuit-level proxy firewall B. Packet filtering firewall C. Application-level proxy firewall D. Statefull firewall
Answer: D
Download Exam
Page: 3 / 47
Total 232 questions