EC-COUNCIL EC-Council Certified Security Analyst (ECSA) Sample Questions:
1. One needs to run "Scan Server Configuration" tool to allow a remote connection to Nessus from the remote Nessus clients. This tool allows the port and bound interface of the Nessus daemon to be configured. By default, the Nessus daemon listens to connections on which one of the following?
A) Localhost (127.0.0.1) and port 1241
B) Localhost (127.0.0.1) and port 1246
C) Localhost (127.0.0.1) and port 1240
D) Localhost (127.0.0.0) and port 1243
2. Today, most organizations would agree that their most valuable IT assets reside within applications and databases. Most would probably also agree that these are areas that have the weakest levels of security, thus making them the prime target for malicious activity from system administrators, DBAs, contractors, consultants, partners, and customers.
Which of the following flaws refers to an application using poorly written encryption code to securely encrypt and store sensitive data in the database and allows an attacker to steal or modify weakly protected data such as credit card numbers, SSNs, and other authentication credentials?
A) Man-in-the-Middle attack
B) Hidden field manipulation attack
C) Insecure cryptographic storage attack
D) SSI injection attack
3. Firewall and DMZ architectures are characterized according to its design. Which one of the following architectures is used when routers have better high-bandwidth data stream handling capacity?
A) "Inside Versus Outside" Architecture
B) Strong Screened-Subnet Architecture
C) "Three-Homed Firewall" DMZ Architecture
D) Weak Screened Subnet Architecture
4. Which of the following pen testing reports provides detailed information about all the tasks performed during penetration testing?
A) Client-Side Test Report
B) Host Report
C) Activity Report
D) Vulnerability Report
5. A security policy is a document or set of documents that describes, at a high level, the security controls that will be implemented by the company. Which one of the following policies forbids everything and restricts usage of company computers, whether it is system usage or network usage?
A) Information-Protection Policy
B) Paranoid Policy
C) Promiscuous Policy
D) Prudent Policy
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: C | Question # 3 Answer: D | Question # 4 Answer: A | Question # 5 Answer: B |
We're so confident of our products that we provide no hassle product exchange.


By Sandy

