Testpassport

 sales@testpassport.jp

下記はEC-Council ECSAv10試験問題集は実際の試験問題のバージョンの一部です。 ECSA ECSAv10問題集 は実際の試験問題バージョンには204問になります。すべての実際の試験問題は、勉強者が最初の試みで成功することを保証できます。ECSAv10問題集の実際の試験問題でEC-Council試験に不合格になった場合、全額で支払い手数料の払い戻しを受けられます。実際の試験問題をトレーニングしたいでしょうか? では、トレーニングしましょう!

 ECSAv10フルバージョンを入手

問題#1

Alisa is a Network Security Manager at Aidos Cyber Security. During a regular network audit, she sent specially crafted ICMP packet fragments with different offset values into the network, causing a system crash.
Which attack Alisa is trying to perform?

A. Ping-of-death attack
B. Fraggle attack
C. Session hijacking
D. Smurf attack

問題#2

The penetration testing team of MirTech Inc. identified the presence of various vulnerabilities in the web application coding. They prepared a detailed report addressing to the web developers regarding the findings. In the report, the penetration testing team advised the web developers to avoid the use of dangerous standard library functions. They also informed the web developers that the web application copies the data without checking whether it fits into the target destination memory and is susceptible in supplying the application with large amount of data.
According to the findings by the penetration testing team, which type of attack was possible on the web application?

A. Buffer overflow
B. SQL injection
C. Cross-site scripting
D. Denial-of-service

問題#3

During an internal network audit, you are asked to see if there is any RPC server running on the network and if found, enumerate the associate RPC services.
Which port would you scan to determine the RPC server and which command will you use to enumerate the RPC services?

A. Port 111, rpcinfo
B. Port 111, rpcenum
C. Port 145, rpcinfo
D. Port 145, rpcenum

問題#4

An organization has deployed a web application that uses encoding technique before transmitting the data over the Internet. This encoding technique helps the organization to hide the confidential data such as user credentials, email attachments, etc. when in transit. This encoding technique takes 3 bytes of binary data and divides it into four chunks of 6 bits. Each chunk is further encoded into respective printable character.
Identify the encoding technique employed by the organization?

A. Unicode encoding
B. Base64 encoding
C. URL encoding
D. HTMS encoding

問題#5

James is an attacker who wants to attack XYZ Inc. He has performed reconnaissance over all the publicly available resources of the company and identified the official company website http://xyz.com. He scanned all the pages of the company website to find for any potential vulnerabilities to exploit. Finally, in the user account login page of the company’s website, he found a user login form which consists of several fields that accepts user inputs like username and password. He also found than any non-validated query that is requested can be directly communicated to the active directory and enable unauthorized users to obtain direct access to the databases. Since James knew an employee named Jason from XYZ Inc., he enters a valid username “jason” and injects “jason)(&))” in the username field. In the password field, James enters “blah” and clicks Submit button. Since the complete URL string entered by James becomes “(& (USER=jason)(&))(PASS=blah)),” only the first filter is processed by the Microsoft Active Directory, that is, the query “(&(USER=jason)(&))” is processed. Since this query always stands true, James successfully logs into the user account without a valid password of Jason.
In the above scenario, identify the type of attack performed by James?

A. LDAP injection attack
B. HTML embedding attack
C. Shell injection attack
D. File injection attack

試験コード: ECSAv10問題数量: 204 Q&As更新時間:  2022-09-23

  ECSAv10フルバージョンを入手