412-79 Exam Details

  • Exam Code
    :412-79
  • Exam Name
    :EC-Council Certified Security Analyst (ECSA)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :232 Q&As
  • Last Updated
    :Jun 16, 2026

EC-COUNCIL 412-79 Online Questions & Answers

  • Question 1:

    What will the following command produce on a website login page?What will the following command produce on a website? login page?

    SELECT email, passwd, login_id, full_name FROM members WHERE email = '[email protected]'; DROP TABLE members; --'

    A. This command will not produce anything since the syntax is incorrect
    B. Inserts the Error! Reference source not found. email address into the members table
    C. Retrieves the password for the first user in the members table
    D. Deletes the entire members table

  • Question 2:

    Larry is an IT consultant who works for corporations and government agencies. Larry plans on shutting down the city's network using BGP devices and ombies? What type of Penetration Testing is Larry planning to carry out?

    A. Internal Penetration Testing
    B. Firewall Penetration Testing
    C. DoS Penetration Testing
    D. Router Penetration Testing

  • Question 3:

    If an attacker's computer sends an IPID of 31400 to a zombie computer on an open port in IDLE scanning, what will be the response?

    A. 31401
    B. The zombie will not send a response
    C. 31402
    D. 31399

  • Question 4:

    You have been asked to investigate the possibility of computer fraud in the finance department of a company. It is suspected that a staff member has been committing finance fraud by printing cheques that have not been authorizeD. You have exhaustively searched all data files on a bitmap image of the target computer, but have found no evidence. You suspect the files may not have been saveD. What should you examine next in this case?

    A. The registry
    B. Theswapfile
    C. The recycle bin
    D. The metadata

  • Question 5:

    You setup SNMP in multiple offices of your company. Your SNMP software manager is not receiving data from other offices like it is for your main office. You suspect that firewall changes are to blame. What ports should you open for SNMP to work through Firewalls (Select 2)

    A. 162
    B. 160
    C. 161
    D. 163

  • Question 6:

    Why should you note all cable connections for a computer you want to seize as evidence?

    A. to know what outside connections existed
    B. in case other devices were connected
    C. to know what peripheral devices exist
    D. to know what hardware existed

  • Question 7:

    John is using Firewalk to test the security of his Cisco PIX firewall. He is also utilizing a sniffer located on a subnet that resides deep inside his network. After analyzing the sniffer log files, he does not see any of the traffic produced by Firewalk. Why is that?

    A. Firewalk sets all packets with a TTL of zero
    B. Firewalk cannot pass through Cisco firewalls
    C. Firewalk sets all packets with a TTL of one
    D. Firewalk cannot be detected by network sniffers

  • Question 8:

    In Linux, what is the smallest possible shellcode?

    A. 800 bytes
    B. 8 bytes
    C. 80 bytes
    D. 24 bytes

  • Question 9:

    Tyler is setting up a wireless network for his business that he runs out of his home. He has followed all the directions from the ISP as well as the wireless router manual. He does not have any encryption set and the SSID is being broadcast. On his laptop, he can pick up the wireless signal for short periods of time, but then the connection drops and the signal goes away. Eventually the wireless signal shows back up, but drops intermittently. What could be Tyler issue with his home wireless network?

    A. 2.4 Ghz Cordless phones
    B. Satellite television
    C. CB radio
    D. Computers on his wired network

  • Question 10:

    You have used a newly released forensic investigation tool, which doesn t meet the Daubert T est, during a case. The case has ended-up in court. What argument could the defense make to weaken your case?

    A. The tool hasn t been tested by the International Standards Organization (ISO)
    B. Only the local law enforcement should use the tool
    C. The total has not been reviewed and accepted by your peers
    D. You are not certified for using the tool

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 412-79 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.