ECCouncil ECSAv8 - EC-Council Certified Security Analyst (ECSA) Exam

Question #11 (Topic: )
Which of the following approaches to vulnerability assessment relies on the administrator
providing baseline of system configuration and then scanning continuously without
incorporating any information found at the time of scanning?
[ECCouncil-ECSAv8-10.3/ECCouncil-ECSAv8-7_2.png]
A. Service-based Assessment Solutions B. Product-based Assessment Solutions C. Tree-based Assessment D. Inference-based Assessment
Answer: C
Question #12 (Topic: )
Which of the following password cracking techniques is used when the attacker has some
information about the password?
A. Hybrid Attack B. Dictionary Attack C. Syllable Attack D. Rule-based Attack
Answer: D
Question #13 (Topic: )
Information gathering is performed to:
i) Collect basic information about the target company and its network
ii) Determine the operating system used, platforms running, web server versions, etc.
iii) Find vulnerabilities and exploits
[ECCouncil-ECSAv8-10.3/ECCouncil-ECSAv8-9_2.png]
Which of the following pen testing tests yields information about a companys technology
infrastructure?
A. Searching for web page posting patterns B. Analyzing the link popularity of the company’s website C. Searching for trade association directories D. Searching for a company’s job postings
Answer: D
Question #14 (Topic: )
Which of the following shields Internet users from artificial DNS data, such as a deceptive
or mischievous address instead of the genuine address that was requested?
A. DNSSEC B. Firewall C. Packet filtering D. IPSec
Answer: A
Question #15 (Topic: )
A directory traversal (or path traversal) consists in exploiting insufficient security
validation/sanitization of user-supplied input file names, so that characters representing
"traverse to parent directory" are passed through to the file APIs.
The goal of this attack is to order an application to access a computer file that is not
intended to be accessible. This attack exploits a lack of security (the software is acting
exactly as it is supposed to) as opposed to exploiting a bug in the code.
[ECCouncil-ECSAv8-10.3/ECCouncil-ECSAv8-10_2.png]
To perform a directory traversal attack, which sequence does a pen tester need to follow to
manipulate variables of reference files?
A. dot-dot-slash (../) sequence B. Denial-of-Service sequence C. Brute force sequence D. SQL Injection sequence
Answer: A
Download Exam
Page: 3 / 40
Total 200 questions