Official Bank 0/204

EC-Council Certified Security Analyst (ECSA) v10 : Penetration Testing (ECSAv10) - EC-Council Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
204 Total Questions
1
Question
A framework for security analysis is composed of a set of instructions, assumptions, and limitations to analyze and solve security concerns and develop threat free applications.

Which of the following frameworks helps an organization in the evaluation of the company’s information security with that of the industrial standards?
Options
A Information System Security Assessment Framework
B Nortell’s Unified Security Framework
C Microsoft Internet Security Framework
D The IBM Security Framework
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
The framework primarily designed to fulfill a methodical and organized way of addressing five threat classes to network and that can be used to access, plan, manage, and maintain secure computers and communication networks is:
Options
A The IBM Security Framework
B Microsoft Internet Security Framework
C Nortells Unified Security Framework
D Bell Labs Network Security Framework
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
A wireless intrusion detection system (WIDS) monitors the radio spectrum for the presence of unauthorized, rogue access points and the use of wireless attack tools. The system monitors the radio spectrum used by wireless LANs, and immediately alerts a systems administrator whenever a rogue access point is detected. Conventionally it is achieved by comparing the MAC address of the participating wireless devices. Which of the following attacks can be detected with the help of wireless intrusion detection system (WIDS)?

Exhibit
Options
A SQL injection
B Man-in-the-middle attack
C Social engineering
D Parameter tampering
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
You are a security analyst performing a penetration tests for a company in the Midwest. After some initial reconnaissance, you discover the IP addresses of some Cisco routers used by the company. You type in the following URL that includes the IP address of one of the routers: http://172.168.4.131/level/99/exec/show/config After typing in this URL, you are presented with the entire configuration file for that router. What have you discovered?
Options
A Cisco IOS Arbitrary Administrative Access Online Vulnerability
B HTML Configuration Arbitrary Administrative Access Vulnerability
C URL Obfuscation Arbitrary Administrative Access Vulnerability
D HTTP Configuration Arbitrary Administrative Access Vulnerability
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Jim performed a vulnerability analysis on his network and found no potential problems. He runs another utility that executes exploits against his system to verify the results of the vulnerability test. The second utility executes five known exploits against his network in which the vulnerability analysis said were not exploitable.

What kind of results did Jim receive from his vulnerability analysis?
Options
A False negatives
B True positives
C True negatives
D False positives
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.