EC-COUNCIL 412-79 Exam Overview:
| Certification Vendor: | EC-Council |
| Exam Name: | EC-Council Certified Security Analyst (ECSA) |
| Exam Number: | 412-79 |
| Real Exam Qty: | 150 |
| Certificate Validity Period: | 3 years |
| Exam Price: | USD 450 (varies by region) |
| Exam Format: | Multiple-choice questions, Computer-based exam, Closed book |
| Related Certifications: | Certified Ethical Hacker (CEH) Licensed Penetration Tester (LPT) |
| Passing Score: | 70% |
| Exam Duration: | 240 minutes |
| Available Languages: | English |
| Sample Questions: | EC-COUNCIL 412-79 Sample Questions |
| Exam Way: | Computer-based exam delivered at authorized EC-Council testing centers or via online proctoring depending on region |
| Pre Condition: | Recommended prerequisite is EC-Council Certified Ethical Hacker (CEH) or equivalent knowledge in penetration testing and cybersecurity fundamentals. |
| Official Syllabus URL: | https://www.eccouncil.org/programs/ec-council-certified-security-analyst-ecsa/ |
EC-COUNCIL 412-79 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: Wireless Network Security | - Wireless attacks
|
| Topic 2: Penetration Testing Methodologies | - Information gathering
|
| Topic 3: Cryptography | - Encryption fundamentals
|
| Topic 4: Network Scanning and Enumeration | - Scanning techniques
|
| Topic 5: Malware Threats | - Malware analysis
|
| Topic 6: Web Application Security | - Web security testing
|
| Topic 7: Penetration Testing Reporting | - Reporting and documentation
|
| Topic 8: System Hacking | - Post-exploitation
|
EC-COUNCIL EC-Council Certified Security Analyst (ECSA) Sample Questions:
1. Wireless communication allows networks to extend to places that might otherwise go untouched by the wired networks.
When most people say 'Wireless' these days, they are referring to one of the 802.11 standards.
There are three main 802.11 standards: B, A, and G.
Which one of the following 802.11 types uses DSSS Modulation, splitting the 2.4ghz band into channels?
A) 802.11g
B) 802.11b
C) 802.11-Legacy
D) 802.11n
2. Port numbers are used to keep track of different conversations crossing the network at the same time. Both TCP and UDP use port (socket) numbers to pass information to the upper layers. Port numbers have the assigned ranges.
Port numbers above 1024 are considered which one of the following?
A) Well-known port numbers
B) Dynamically assigned port numbers
C) Unregistered port numbers
D) Statically assigned port numbers
3. In the TCP/IP model, the transport layer is responsible for reliability and flow control from source to the destination. TCP provides the mechanism for flow control by allowing the sending and receiving hosts to communicate. A flow control mechanism avoids the problem with a transmitting host overflowing the buffers in the receiving host.
Which of the following flow control mechanism guarantees reliable delivery of data?
A) Synchronization
B) Sliding Windows
C) Windowing
D) Positive Acknowledgment with Retransmission (PAR)
4. A Blind SQL injection is a type of SQL Injection attack that asks the database true or false questions and determines the answer based on the application response. This attack is often used when the web application is configured to show generic error messages, but has not mitigated the code that is vulnerable to SQL injection.
It is performed when an error message is not received from application while trying to exploit SQL vulnerabilities. The developer's specific message is displayed instead of an error message. So it is quite difficult to find SQL vulnerability in such cases.
A pen tester is trying to extract the database name by using a blind SQL injection. He tests the database using the below query and finally finds the database name.
http://juggyboy.com/page.aspx?id=1;
IF (LEN(DB_NAME())=4) WAITFOR DELAY
'00:00:10'--
http://juggyboy.com/page.aspx?id=1;
IF (ASCII(lower(substring((DB_NAME()),1,1)))=97) WAITFOR DELAY
'00:00:10'--
http://juggyboy.com/page.aspx?id=1;
IF (ASCII(lower(substring((DB_NAME()),2,1)))=98) WAITFOR DELAY
'00:00:10'--
http://juggyboy.com/page.aspx?id=1;
IF (ASCII(lower(substring((DB_NAME()),3,1)))=99) WAITFOR DELAY
'00:00:10'--
http://juggyboy.com/page.aspx?id=1;
IF (ASCII(lower(substring((DB_NAME()),4,1)))=100) WAITFOR DELAY
'00:00:10'--
What is the database name?
A) PQRS
B) ABCD
C) EFGH
D) WXYZ
5. Which of the following scan option is able to identify the SSL services?
A) -sS
B) -sT
C) -sU
D) -sV
Solutions:
| Question # 1 Answer: B | Question # 2 Answer: B | Question # 3 Answer: D | Question # 4 Answer: B | Question # 5 Answer: D |


PDF Version Demo






We are confident about the products and aim to help you pass with ease. In case of failure, we will provide a no hassle full money back guarantee for the purchasing fee.
1038 Customer Reviews
Quality and ValueITbraindumps Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITbraindumps testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITbraindumps offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.