Latest EC0-479 trainning materials
New EC0-479 trainning materials
Exam Number/Code: EC0-479
Questions and Answers:100 Q&As
Updated Time: 2009-09-27
Register for Exam: Prometric/Pearson VUE
Exam Name:EC-Council Certified Security Analyst(ECSA)
The following are the EC0-479 exam questions and answers we get from all of the world company exams vendors include : examsoon EC0-479 exam ,Testinside EC0-479 braindumps, Pass4sure EC0-479 practice exam , Testking EC0-479 study guides, exam4sure trainning materials. after you read the following EC0-479 exam demo questions and answers, you will see the high quanity of the exam
The EC0-479 exam products are designed to maximize your learning productivity and focus only on the important aspects that will help you to pass your EC0-479 test. We will provide you with EC0-479 exam questions and verified answers, that reflect the actual exam. These questions and answers provide you with the experience of taking the EC0-479 actual test. EC0-479 exam guides are not just questions and answers. EC0-479 questions have detailed for every answer, ensuring that you fully understand the questions and the concept behind the questions.
Exam : EC-Council EC0-479
Title : EC-Council Certified Security Analyst (ECSA)
1. You are carrying out the last round of testing for your new website before it goes live. The website has many dynamic pages and connects to a SQL backend that accesses your product inventory in a database. You come across a web security site that recommends inputting the following code into a search field on web pages to check for vulnerabilities:
<script>alert("This is a test.")</script>
When you type this and click on search, you receive a pop-up window that says:
"This is a test."
What is the result of this test?
A. Your website is vulnerable to CSS
B. Your website is not vulnerable
C. Your website is vulnerable to SQL injection
D. Your website is vulnerable to web bugs
Answer: A
2. Simon is a former employee of Trinitron XML Inc. He feels he was wrongly terminated and wants to hack into his former company’s network. Since Simon remembers some of the server names, he attempts to run the axfr and ixfr commands using DIG. What is Simon trying to accomplish here?
A. Send DOS commands to crash the DNS servers
B. Perform DNS poisoning
C. Perform a zone transfer
D. Enumerate all the users in the domain
Answer: C
3. You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers. What type of firewall must you implement to abide by this policy?
A. Packet filtering firewall
B. Circuit-level proxy firewall
C. Application-level proxy firewall
D. Statefull firewall
Answer: D
4. You setup SNMP in multiple offices of your company. Your SNMP software manager is not receiving data from other offices like it is for your main office. You suspect that firewall changes are to blame. What ports should you open for SNMP to work through Firewalls (Select 2)
A. 162
B. 161
C. 163
D. 160
Answer: AB
5. If an attacker’s computer sends an IPID of 31400 to a zombie computer on an open port in IDLE scanning, what will be the response?
A. The zombie will not send a response
B. 31402
C. 31399
D. 31401
Answer: D
6. What will the following command produce on a website login page?
SELECT email, passwd, login_id, full_name
FROM members
WHERE email = ’someone@somehwere.com’; DROP TABLE members; –’
A. Deletes the entire members table
B. Inserts the Error! Reference source not found. email address into the members table
C. Retrieves the password for the first user in the members table
D. This command will not produce anything since the syntax is incorrect
Answer: A
7. Michael works for Kimball Construction Company as senior security analyst. As part of yearly security audit, Michael scans his network for vulnerabilities. Using Nmap, Michael conducts XMAS scan and most of the ports scanned do not give a response. In what state are these ports?
A. Closed
B. Open
C. Stealth
D. Filtered
Answer: B
8. When you are running a vulnerability scan on a network and the IDS cuts off your connection, what type of IDS is being used?
A. Passive IDS
B. Active IDS
C. Progressive IDS
D. NIPS
Answer: B
Free 640-802 Demo Download
Free demo for EC-COUNCIL E-Commerce Architect EC0-479 exam (EC-Council Certified Security Analyst(ECSA)). You can check out the interface, question quality and usability of our practice exams
Free Download 640-802 Exam Pdf Demo
Free Download 640-802 Exam iEngine Demo
No related posts.
Related posts brought to you by Yet Another Related Posts Plugin.