EC-COUNCIL 412-79 試験概要:
| 認定ベンダー: | EC-Council |
| 試験名: | EC-Council Certified Security Analyst (ECSA) |
| 試験番号: | 412-79 |
| 合格点: | 70% |
| 出題数: | 150 |
| 試験形式: | 多肢選択式, コンピュータベース試験 (CBT), クローズドブック(資料持ち込み不可) |
| 受験料: | USD 450 (地域により異なります) |
| 認定の有効期間: | 3年間 |
| 試験時間: | 240 minutes |
| 対応言語: | English |
| 関連資格: | Certified Ethical Hacker (CEH) Licensed Penetration Tester (LPT) |
| サンプル問題: | EC-COUNCIL 412-79 サンプル問題 |
| 受験方法: | 認定されたEC-Councilテストセンターでのコンピュータベース試験(CBT)、または地域によってはオンラインプロクター経由での受験となります。 |
| 前提条件: | 推奨される前提条件は、EC-Council Certified Ethical Hacker (CEH) またはペネトレーションテストおよびサイバーセキュリティの基礎に関する同等の知識です。 |
| 公式シラバスのURL: | https://www.eccouncil.org/programs/ec-council-certified-security-analyst-ecsa/ |
EC-COUNCIL 412-79 試験シラバストピック:
| セクション | 目標 |
|---|---|
| トピック 1: マルウェアの脅威 | - マルウェア解析
|
| トピック 2: ペネトレーションテストの手法 | - 情報収集
|
| トピック 3: 無線ネットワークセキュリティ | - 無線攻撃
|
| トピック 4: システムハッキング | - エクスプロイト技術
|
| トピック 5: ペネトレーションテストのレポート作成 | - レポート作成とドキュメント化
|
| トピック 6: ネットワークスキャンと列挙 | - 列挙
|
| トピック 7: Webアプリケーションセキュリティ | - Webセキュリティテスト
|
| トピック 8: 暗号技術 | - 暗号化の基礎
|
EC-COUNCIL EC-Council Certified Security Analyst (ECSA) 認定 412-79 試験問題:
1. An attacker injects malicious query strings in user input fields to bypass web service authentication mechanisms and to access back-end databases. Which of the following attacks is this?
A) Frame Injection Attack
B) XPath Injection Attack
C) LDAP Injection Attack
D) SOAP Injection Attack
2. Identify the transition mechanism to deploy IPv6 on the IPv4 network from the following diagram.
A) Dual Stacks
B) Tunneling
C) Translation
D) Encapsulation
3. A man enters a PIN number at an ATM machine, being unaware that the person next to him was watching.
Which of the following social engineering techniques refers to this type of information theft?
A) Vishing
B) Phishing
C) Insider Accomplice
D) Shoulder surfing
4. Identify the framework that comprises of five levels to guide agency assessment of their security programs and assist in prioritizing efforts for improvement:
A) Information System Security Assessment Framework (ISSAF)
B) Microsoft Internet Security Framework
C) Nortells Unified Security Framework
D) Federal Information Technology Security Assessment Framework
5. Which of the following external pen testing tests reveals information on price, usernames and passwords, sessions, URL characters, special instructors, encryption used, and web page behaviors?
A) Examine Server Side Includes (SSI)
B) Examine E-commerce and Payment Gateways Handled by the Web Server
C) Check for Directory Consistency and Page Naming Syntax of the Web Pages
D) Examine Hidden Fields
質問と回答:
| 質問 # 1 正解: D | 質問 # 2 正解: B | 質問 # 3 正解: D | 質問 # 4 正解: D | 質問 # 5 正解: D |














1556 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
