Free EC-COUNCIL ECSS Test Practice Test Questions Exam Dumps [Q54-Q74]

Share

Free EC-COUNCIL ECSS Test Practice Test Questions Exam Dumps

Prepare Top EC-COUNCIL ECSS Exam Audio Study Guide Practice Questions Edition

NEW QUESTION # 54
John is working as a network administrator in an MNC company. He was instructed to connect all the remote offices with the corporate office but at the same time deny communication between the remote offices. In this process, he configured a central hub at the corporate head office, through which all branch offices can communicate.
Identify the type of VPN topology implemented by John in the above scenario.

  • A. Star topology
  • B. Hub and spoke topology
  • C. Mesh topology
  • D. Point-to-point topology

Answer: B

Explanation:
In the scenario described, John implemented a hub and spoke topology for the VPN. In this configuration, all remote offices (spokes) connect directly to the central hub (corporate head office). However, communication between the remote offices is denied, ensuring that all traffic flows through the central hub1. This design allows for centralized control and visibility while maintaining resource availability at the hub location. Keep in mind that the central hub becomes a potential single point of failure for VPN tunnels2. References: 2, 1
https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/configuration_examples/bov


NEW QUESTION # 55
Below are the elements included in the order of volatility for a typical computing system as per the RFC 3227 guidelines for evidence collection and archiving.
l.Archival media
2.Remote logging and monitoring data related to the target system
3.Routing table, process table, kernel statistics, and memory
4.Registers and processor cache
5-Physical configuration and network topology
6.Disk or other storage media
7.Temporary system files
Identify the correct sequence of order of volatility from the most to least volatile for a typical system.

  • A. 2->1->4-->3-->6-->5->7
  • B. 7->5- >4->3 ->2 >6 >1
  • C. 4.>3 >7>6.>2-.>5- >l
  • D. 4 >3 >7->l >2 ->5->6

Answer: C

Explanation:
This order correctly reflects the volatility of data from most volatile (disappears quickly) to least volatile (most persistent):
* Registers and processor cache: These contain the CPU's most immediate working data, changing rapidly.
* Routing table, process table, kernel statistics, and memory (RAM): These hold system state information, but can be modified by running processes or events.
* Temporary system files: Designed to be transient, but may persist for some time depending on usage patterns.
* Disk or other storage media: Holds data intended to persist, but is subject to modification.
* Remote logging and monitoring data related to the target system: Often stored off-site, less volatile than local data.
* Physical configuration and network topology: Relatively static information about the system's setup.
* Archival media: Designed for long-term storage, changes to this data are intentional and infrequent.


NEW QUESTION # 56
Which of the following is an example of a worm used in the Linux operating system?

  • A. Sircam
  • B. Ramen
  • C. Love Bug
  • D. Melissa

Answer: B


NEW QUESTION # 57
You work as a Network Security Analyzer. You got a suspicious email while working on a forensic project. Now, you want to know the IP address of the sender so that you can analyze various information such as the actual location, domain information, operating system being used, contact information, etc. of the email sender with the help of various tools and resources. You also want to check whether this email is fake or real. You know that analysis of email headers is a good starting point in such cases. The email header of the suspicious email is given below:

What is the IP address of the sender of this email?

  • A. 209.191.91.180
  • B. 141.1.1.1
  • C. 172.16.10.90
  • D. 216.168.54.25

Answer: D


NEW QUESTION # 58
You work as a system administrator for BlueSkwer.com. You have just finished installing and configuring a new laptop for the CEO. The laptop has Windows 7 operating system. You have just deployed a secure wireless network in the company. Alex, the CEO, wants you to connect his laptop to the wireless network. What will you open to start the process of connecting to a wireless network?

  • A. Network and Sharing Center
  • B. Devices and Printers
  • C. System and Security
  • D. Appearance and Personalization

Answer: A


NEW QUESTION # 59
Which of the following malicious codes is used by a hacker to get control over the system files of a victim?

  • A. Multipartite virus
  • B. Worm
  • C. Macro virus
  • D. Trojan

Answer: D


NEW QUESTION # 60
A ________ attack is designed to bring loss of network connectivity and services by consuming the bandwidth of a user's network.

  • A. Denial of Service (DoS)
  • B. Brute force
  • C. Man-in-the-middle
  • D. Dictionary

Answer: A


NEW QUESTION # 61
John, a professional penetration tester, was hired by an organization for conducting a penetration test on their IT infrastructure. He was assigned the task of identifying risks, rather than finding vulnerabilities. In this process, he defined the goal before initiating the penetration test and performed multiple parallel processes to achieve the goal.
Identify the type of penetration assessment performed by John in the above scenario.

  • A. Objective-oriented penetration testing approach
  • B. Adversarial goal based assessment
  • C. Red team oriented penetration testing approach
  • D. Compliance oriented penetration testing approach

Answer: A

Explanation:
* In the scenario described, John's approach aligns with objective-oriented penetration testing. In this method, the tester defines specific goals or objectives before initiating the penetration test. The focus is on identifying risks related to achieving those objectives rather than merely finding vulnerabilities. By performing multiple parallel processes to achieve the defined goal, John is following an objective-oriented approach.
* References: 12
https://www.synopsys.com/glossary/what-is-red-teaming.html


NEW QUESTION # 62
What does CSIRT stand for?

  • A. Computer Security Incident Response Team
  • B. Chief Security Incident Response Team
  • C. Computer Security Information Response Team
  • D. Chief Security Information Response Team

Answer: A


NEW QUESTION # 63
Which of the following programs is used to identify unknown open ports on a computer system?

  • A. TCPView
  • B. Keylogger
  • C. Ethereal
  • D. Fport

Answer: D


NEW QUESTION # 64
Which of the following protocols is used the most by web servers?

  • A. ORG
  • B. COM
  • C. HTTP
  • D. FTP

Answer: C


NEW QUESTION # 65
Which of the following statements are TRUE about Demilitarized zone (DMZ)?
Each correct answer represents a complete solution. Choose all that apply.

  • A. In a DMZ configuration, most computers on the LAN run behind a firewall connected to a public network like the Internet.
  • B. The purpose of a DMZ is to add an additional layer of security to the Local Area Network of an organization.
  • C. Hosts in the DMZ have full connectivity to specific hosts in the internal network.
  • D. Demilitarized zone is a physical or logical sub-network that contains and exposes external services of an organization to a larger un-trusted network.

Answer: A,B,D


NEW QUESTION # 66
John works as a professional Ethical Hacker. He has been assigned the project of testing the security of www.we-are-secure.com. John notices that the We-are-secure network is vulnerable to a man-in-the-middle attack since the key exchange process of the cryptographic algorithm it is using does not authenticate participants. Which of the following cryptographic algorithms is being used by the We-are-secure server?

  • A. Blowfish
  • B. Twofish
  • C. Diffie-Hellman
  • D. RSA

Answer: C


NEW QUESTION # 67
Andrew, a bachelor student of Faulkner University, creates a gmail account. He uses 'Faulkner' as the password for the gmail account. After a few days, he starts receiving a lot of e-mails stating that his gmail account has been hacked. He also finds that some of his important mails have been deleted by someone. Which of the following methods has the attacker used to crack Andrew's password?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Rainbow attack
  • B. Buffer-overflow attack
  • C. Brute force attack
  • D. Denial-of-service (DoS) attack
  • E. Password guessing
  • F. Social engineering
  • G. Zero-day attack
  • H. Dictionary-based attack

Answer: A,C,E,F,H


NEW QUESTION # 68
Andrew works as a Forensic Investigator for PassGuide Inc. The company has a Windows-based environment. The company's employees use Microsoft Outlook Express as their e-mail client program. E-mails of some employees have been deleted due to a virus attack on the network. Andrew is therefore assigned the task to recover the deleted mails. Which of the following tools can Andrew use to accomplish the task?
Each correct answer represents a complete solution. Choose two.

  • A. FINALeMAIL
  • B. R-mail
  • C. eMailTrackerPro
  • D. EventCombMT

Answer: A,B


NEW QUESTION # 69
Adam works as a Computer Hacking Forensic Investigator for a garment company in the United States. A project has been assigned to him to investigate a case of a disloyal employee who is suspected of stealing design of the garments, which belongs to the company and selling those garments of the same design under different brand name. Adam investigated that the company does not have any policy related to the copy of design of the garments. He also investigated that the trademark under which the employee is selling the garments is almost identical to the original trademark of the company. On the grounds of which of the following laws can the employee be prosecuted?

  • A. Espionage law
  • B. Cyber law
  • C. Copyright law
  • D. Trademark law

Answer: D


NEW QUESTION # 70
Which of the following proxy servers is placed anonymously between the client and remote server and handles all of the traffic from the client?

  • A. Forced proxy server
  • B. Caching proxy server
  • C. Open proxy server
  • D. Web proxy server

Answer: A


NEW QUESTION # 71
Clark, a security professional, was instructed to monitor and continue the backup functions without interrupting the system or application services. In this process, Clark implemented a backup mechanism that dynamically backups the data even If the system or application resources are being used.
Which of the following types of backup mechanisms has Clark implemented in the above scenario?

  • A. Hot backup
  • B. Cold backup
  • C. Offline backup
  • D. Full backup

Answer: A

Explanation:
* Clark has implemented a hot backup mechanism. Hot backups allow data to be backed up while the system or application resources are actively being used, ensuring continuous availability without interruption.
* References: EC-Council Certified Security Specialist (E|CSS) documents and study guide12.


NEW QUESTION # 72
Below are the various steps involved in forensic readiness planning.
l.Keep an incident response team ready to review the incident and preserve the evidence.
2.Create a process for documenting the procedure.
3.ldentify the potential evidence required for an incident.
4.Determine the sources of evidence.
5.Establish a legal advisory board to guide the investigation process.
6.ldentify if the incident requires full or formal investigation.
7.Establish a policy for securely handling and storing the collected evidence.
8.Define a policy that determines the pathway to legally extract electronic evidence with minimal disruption.
Identify the correct sequence of steps involved in forensic readiness planning.

  • A. 1 >2 >3 >4 -5 >6 >7 >8
  • B. 2..>3->l->4->6->5->7->8
  • C. 3 >1. >4 >S >8 >2 >6 >7
  • D. 3 >4 >8 >7 >6 >2 >5 >1

Answer: D

Explanation:
Let's break down the steps involved in forensic readiness planning and identify the correct sequence:
* Keep an incident response team ready to review the incident and preserve the evidence.
* Create a process for documenting the procedure.
* Identify the potential evidence required for an incident.
* Determine the sources of evidence.
* Establish a legal advisory board to guide the investigation process.
* Identify if the incident requires full or formal investigation.
* Establish a policy for securely handling and storing the collected evidence.
* Define a policy that determines the pathway to legally extract electronic evidence with minimal disruption.


NEW QUESTION # 73
Which of the following statements best describes a certification authority?

  • A. A certification authority is a type of encryption that uses a public key and a private key pair fordata encryption.
  • B. A certification authority is an entity that issues digital certificates for use by other parties.
  • C. A certification authority is a type of encryption that uses a single key to encrypt and decryp t data.
  • D. A certification authority is a technique to authenticate digital documents by using computercryptography.

Answer: B


NEW QUESTION # 74
......


EC-COUNCIL ECSS (EC-Council Certified Security Specialist Practice Test) Exam is a certification exam designed to test an individual's knowledge and expertise in the field of cybersecurity. EC-Council Certified Security Specialist (ECSSv10) certification is highly respected in the industry and is recognized globally. ECSS exam covers a wide range of topics, including network security, cryptography, and ethical hacking.

 

Go to ECSS Questions - Try ECSS dumps pdf: https://pass4sure.actual4dump.com/EC-COUNCIL/ECSS-actualtests-dumps.html