ECCouncil ECSAv10 - EC-Council Certified Security Analyst Exam

Question #11 (Topic: Topic 1)
Sandra, a wireless network auditor, discovered her client is using WEP. To prove the point that the WEP encryption is very weak, she wants to decrypt some WEP
packets. She successfully captured the WEP data packets, but could not reach the content as the data is encrypted.
Which of the following will help Sandra decrypt the data packets without knowing the key?
A. Fragmentation Attack B. Chopchop Attack C. ARP Poisoning Attack D. Packet injection Attack
Answer: B
Question #12 (Topic: Topic 1)
Peter, a disgruntled ex-employee of Zapmaky Solutions Ltd., is trying to jeopardize the companyג€™s website http://zapmaky.com. He conducted the port scan of the
website by using the Nmap tool to extract the information about open ports and their corresponding services. While performing the scan, he recognized that some
of his requests are being blocked by the firewall deployed by the IT personnel of Zapmaky and he wants to bypass the same. For evading the firewall, he wanted
to employ the stealth scanning technique which is an incomplete TCP three-way handshake method that can effectively bypass the firewall rules and logging
mechanisms.
Which if the following Nmap commands should Peter execute to perform stealth scanning?
A. nmap -sT -v zapmaky.com B. nmap -T4 -A -v zapmaky.com C. nmap -sX -T4 -A -v zapmaky.com D. nmap -sN -A zapmaky.com
Answer: A
Question #13 (Topic: Topic 1)
Richard, a penetration tester was asked to assess a web application. During the assessment, he discovered a file upload field where users can upload their profile
pictures. While scanning the page for vulnerabilities, Richard found a file upload exploit on the website. Richard wants to test the web application by uploading a
malicious PHP shell, but the web page denied the file upload. Trying to get around the security, Richard added the ג€˜jpgג€™ extension to the end of the file. The new
[1]
successfully upload the PHP shell.
Which of the following techniques has Richard implemented to upload the PHP shell?
A. Session stealing B. Cookie tampering C. Cross site scripting D. Parameter tampering
Answer: D
Question #14 (Topic: Topic 1)
Richard is working on a web app pen testing assignment for one of his clients. After preliminary information, gathering and vulnerability scanning Richard runs the
SQLMAP tool to extract the database information.
Which of the following commands will give Richard an output as shown in the screenshot?
[ECCouncil-ECSAv10-1.0/xmlfile-8_1.png]
A. sqlmap ג€"url http://quennhotel.com/about.aspx?name=1 ג€"D queenhotel --tables B. sqlmap ג€"url http://quennhotel.com/about.aspx?name=1 ג€"dbs C. sqlmap ג€"url http://quennhotel.com/about.aspx?name=1 ג€"D queenhotel ג€"T --columns D. sqlmap ג€"url http://quennhotel.com/about.aspx?name=1 ג€"database queenhotel ג€"tables
Answer: A
Question #15 (Topic: Topic 1)
Identify the PRGA from the following screenshot:
[ECCouncil-ECSAv10-1.0/xmlfile-9_1.png]
A. replay_src-0124-161120.cap B. fragment-0124-161129.xor C. 0505 933f af2f 740e D. 0842 0201 000f b5ab cd9d 0014 6c7e 4080
Answer: A
Download Exam
Page: 3 / 30
Total 150 questions