Exam Details

  • Exam Code
    :412-79
  • Exam Name
    :EC-Council Certified Security Analyst (ECSA)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :232 Q&As
  • Last Updated
    :Mar 26, 2025

EC-COUNCIL EC-COUNCIL Certifications 412-79 Questions & Answers

  • Question 211:

    You work as a penetration tester for Hammond Security Consultants. You are currently working on a contract for the state government of California. Your next step is to initiate a DoS attack on their network. Why would you want to initiate a DoS attack on a system you are testing?

    A. Use attack as a launching point to penetrate deeper into the network

    B. Demonstrate that no system can be protected against DoS attacks

    C. List weak points on their network

    D. Show outdated equipment so it can be replaced

  • Question 212:

    George is performing security analysis for Hammond and Sons LLC. He is testing security vulnerabilities of their wireless network. He plans on remaining as "stealthy" as possible during the scan. Why would a scanner like Nessus is not recommended in this situation?

    A. Nessus is too loud

    B. There are no ways of performing a "stealthy" wireless scan

    C. Nessus cannot perform wireless testing

    D. Nessus is not a network scanner

  • Question 213:

    Jim performed a vulnerability analysis on his network and found no potential problems. He runs another utility that executes exploits against his system to verify the results of the vulnerability test. The second utility executes five known exploits against his network in which the vulnerability analysis said were not exploitable. What kind of results did Jim receive from his vulnerability analysis?

    A. True negatives

    B. False negatives

    C. False positives

    D. True positives

  • Question 214:

    In a virtual test environment, Michael is testing the strength and security of BGP using multiple routers to mimic the backbone of the Internet. This project will help him write his doctoral thesis on "bringing down the Internet". Without sniffing the traffic between the routers, Michael sends millions of RESET packets to the routers in an attempt to shut one or all of them down. After a few hours, one of the routers finally shuts itself down. What will the other routers communicate between themselves?

    A. More RESET packets to the affected router to get it to power back up

    B. RESTART packets to the affected router to get it to power back up

    C. The change in the routing fabric to bypass the affected router

    D. STOP packets to all other routers warning of where the attack originated

  • Question 215:

    What is the following command trying to accomplish?

    A. Verify that NETBIOS is running for the 192.168.0.0 network

    B. Verify that TCP port 445 is open for the 192.168.0.0 network

    C. Verify that UDP port 445 is open for the 192.168.0.0 network

    D. Verify that UDP port 445 is closed for the 192.168.0.0 network

  • Question 216:

    Your company uses Cisco routers exclusively throughout the network. After securing the routers to the best of your knowledge, an outside security firm is brought in to assess the network security. Although they found very few issues, they were able to enumerate the model, OS version, and capabilities for all your Cisco routers with very little effort. Which feature will you disable to eliminate the ability to enumerate this information on your Cisco routers?

    A. Simple Network Management Protocol

    B. Broadcast System Protocol

    C. Cisco Discovery Protocol

    D. Border Gateway Protocol

  • Question 217:

    You are running known exploits against your network to test for possible vulnerabilities. To test the strength of your virus software, you load a test network to mimic your production network. Your software successfully blocks some simple macro and encrypted viruses. You decide to really test the software by using virus code where the code rewrites itself entirely and the signatures change from child to child, but the functionality stays the same. What type of virus is this that you are testing?

    A. Metamorphic

    B. Oligomorhic

    C. Polymorphic

    D. Transmorphic

  • Question 218:

    You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers. What type of firewall must you implement to abide by this policy?

    A. Circuit-level proxy firewall

    B. Packet filtering firewall

    C. Application-level proxy firewall

    D. Statefull firewall

  • Question 219:

    George is the network administrator of a large Internet company on the west coast. Per corporate policy, none of the employees in the company are allowed to use FTP or SFTP programs without obtaining approval from the IT department. Few managers are using SFTP program on their computers. Before talking to his boss, George wants to have some proof of their activity.

    George wants to use Ethereal to monitor network traffic, but only SFTP traffic to and from his network. What filter should George use in Ethereal?

    A. net port 22

    B. udp port 22 and host 172.16.28.1/24

    C. src port 22 and dst port 22

    D. src port 23 and dst port 23

  • Question 220:

    What are the security risks of running a "repair" installation for Windows XP?

    A. There are no security risks when running the "repair" installation for Windows XP

    B. Pressing Shift+F1 gives the user administrative rights

    C. Pressing Ctrl+F10 gives the user administrative rights

    D. Pressing Shift+F10 gives the user administrative rights

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 412-79 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.