Exam Details

  • Exam Code
    :ECSS
  • Exam Name
    :EC-Council Certified Security Specialist (ECSS) v10
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :337 Q&As
  • Last Updated
    :Mar 24, 2025

EC-COUNCIL EC-COUNCIL Certifications ECSS Questions & Answers

  • Question 301:

    John works as a Network Security Administrator for NetPerfect Inc. The manager of the company has told John that the company's phone bill has increased drastically. John suspects that the company's phone system has been cracked by a malicious hacker. Which attack is used by malicious hackers to crack the phone system?

    A. Sequence++ attack

    B. Phreaking

    C. Man-in-the-middle attack

    D. War dialing

  • Question 302:

    You work as a professional Computer Hacking Forensic Investigator for DataEnet Inc. You want to investigate e-mail information of an employee of the company. The suspected employee is using an online e-mail system such as Hotmail or Yahoo. Which of the following folders on the local computer will you review to accomplish the task?

    Each correct answer represents a complete solution. Choose all that apply.

    A. Download folder

    B. History folder

    C. Temporary Internet Folder

    D. Cookies folder

  • Question 303:

    Victor works as a professional Ethical Hacker for SecureEnet Inc. He has been assigned a job to test an image, in which some secret information is hidden, using Steganography. Victor performs the following techniques to accomplish the task:

    1.

    Smoothening and decreasing contrast by averaging the pixels of the area where significant color transitions occurs.

    2.

    Reducing noise by adjusting color and averaging pixel value.

    3.

    Sharpening, Rotating, Resampling, and Softening the image. Which of the following Steganography attacks is Victor using?

    A. Steg-Only Attack

    B. Chosen-Stego Attack

    C. Active Attacks

    D. Stegdetect Attack

  • Question 304:

    Which of the following Linux rootkits is installed via stolen SSH keys?

    A. Phalanx2

    B. Beastkit

    C. Adore

    D. Linux.Ramen

  • Question 305:

    Which of the following is a set of exclusive rights granted by a state to an inventor or his assignee for a fixed period of time in exchange for the disclosure of an invention?

    A. Snooping

    B. Copyright

    C. Utility model

    D. Patent

  • Question 306:

    Jason works as a System Administrator for Passguide Inc. The company has a Windows-based network. Sam, an employee of the company, accidentally changes some of the applications and system settings. He complains to Jason that his

    system is not working properly. To troubleshoot the problem, Jason diagnoses the internals of his computer and observes that some changes have been made in Sam's computer registry. To rectify the issue, Jason has to restore the registry.

    Which of the following utilities can Jason use to accomplish the task?

    Each correct answer represents a complete solution. Choose all that apply.

    A. Reg.exe

    B. Resplendent registrar

    C. EventCombMT

    D. Regedit.exe

  • Question 307:

    Maria works as a Desktop Technician for PassGuide Inc. She has received an e-mail from the MN

    Compensation Office with the following message:

    Dear Sir/Madam,

    My name is Edgar Rena, the director of compensation here at the MN Compensation Office in Chicago. We receive so many complaints about fraudulent activities that have been taking place in your region for the past few years. Due to the

    high volume loss of money, the MN compensation department has had an agreement with the appropriate authority to compensate each victim with a sum of USD$500,000.00.

    You were selected among the list of people to be paid this sum. To avoid any imperative mood by intending scammers, your payment has been transmuted into an International bank draft which can be cashed at any local bank in your

    country.

    Please fill the below details and send it to our secretary for your compensation bank draft.

    Full name:

    Address:

    Tel:

    Fill and Send to:

    Dr. Michael Brown

    MN Compensation Office, IL

    Tel: +1-866-233-8434

    Email: [email protected]

    Further instructions shall be given to you by our secretary as soon as you contact him. To avoid losing your compensation, you are requested to pay the sum of $350 for Insurance Premium to our secretary.

    Thanks and God bless.

    If Maria replies to this mail, which of the following attacks may she become vulnerable to?

    A. Phishing attack

    B. SYN attack

    C. CookieMonster attack

    D. Mail bombing

  • Question 308:

    Victor works as a network administrator for DataSecu Inc. He uses a dual firewall Demilitarized Zone (DMZ) to insulate the rest of the network from the portions that is available to the Internet. Which of the following security threats may occur if DMZ protocol attacks are performed? Each correct answer represents a complete solution. Choose all that apply.

    A. The attacker can exploit any protocol used to go into the internal network or intranet of thecompany.

    B. The attacker can gain access to the Web server in a DMZ and exploit the database.

    C. The attacker can perform a Zero Day attack by delivering a malicious payload that is not a part of the intrusion detection/prevention systems guarding the network.

    D. The attacker managing to break the first firewall defense can access the internal network without breaking the second firewall if it is different.

  • Question 309:

    Which of the following proxy servers is also referred to as transparent proxies or forced proxies?

    A. Intercepting proxy server

    B. Anonymous proxy server

    C. Reverse proxy server

    D. Tunneling proxy server

  • Question 310:

    Which of the following security policies will you implement to keep safe your data when you connect your Laptop to the office network over IEEE 802.11 WLANs?

    Each correct answer represents a complete solution. Choose two.

    A. Using a protocol analyzer on your Laptop to monitor for risks.

    B. Using an IPSec enabled VPN for remote connectivity.

    C. Using portscanner like nmap in your network.

    D. Using personal firewall software on your Laptop.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your ECSS exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.