EC-COUNCIL EC-Council Certified Security Analyst (ECSA) v10 : Penetration Testing - ECSAv10 Exam Practice Test
Which one of the following 802.11 types uses either FHSS or DSSS for modulation?
Correct Answer: A
Vote an answer
Which one of the following is a supporting tool for 802.11 (wireless) packet injections, it spoofs 802.11 packets to verify whether the access point is valid or not?
Correct Answer: B
Vote an answer
What are the scanning techniques that are used to bypass firewall rules and logging mechanisms and disguise themselves as usual network traffic?
Correct Answer: A
Vote an answer
What sort of vulnerability assessment approach starts by building an inventory of protocols found on the machine?
Correct Answer: D
Vote an answer
Which of the following acts related to information security in the US establish that the management of an organization is responsible for establishing and maintaining an adequate internal control structure and procedures for financial reporting?
Correct Answer: B
Vote an answer
Which of the following is not a characteristic of a firewall?
Correct Answer: A
Vote an answer
Internet Control Message Protocol (ICMP) messages occur in many situations, such as whenever a datagram cannot reach the destination or the gateway does not have the buffering capacity to forward a datagram.
Each ICMP message contains three fields: type, code, and checksum. Different types of Internet Control Message Protocols (ICMPs) are identified by a TYPE field.
If the destination is not reachable, which one of the following are generated?
Each ICMP message contains three fields: type, code, and checksum. Different types of Internet Control Message Protocols (ICMPs) are identified by a TYPE field.
If the destination is not reachable, which one of the following are generated?
Correct Answer: A
Vote an answer
The first phase of the penetration testing plan is to develop the scope of the project in consultation with the client. Pen testing test components depend on the client's operating environment, threat perception, security and compliance requirements, ROE, and budget.
Various components need to be considered for testing while developing the scope of the project.

Which of the following is NOT a pen testing component to be tested?
Various components need to be considered for testing while developing the scope of the project.

Which of the following is NOT a pen testing component to be tested?
Correct Answer: A
Vote an answer
Which one of the following tools of trade is a commercial shellcode and payload generator written in Python by Dave Aitel?
Correct Answer: A
Vote an answer
Which type of vulnerability assessment tool provides security to the IT system by testing for vulnerabilities in the applications and operation system?
Correct Answer: D
Vote an answer
