EC-COUNCIL 412-79 Prüfungsthemen:
| Abschnitt | Ziele |
|---|---|
| Thema 1: Methoden des Penetrationstests | - Informationsbeschaffung
|
| Thema 2: Sicherheit von Webanwendungen | - Angriffe auf Webanwendungen
|
| Thema 3: Kryptografie | - Grundlagen der Verschlüsselung
|
| Thema 4: Berichterstattung zum Penetrationstest | - Berichterstellung und Dokumentation
|
| Thema 5: Sicherheit von Funknetzwerken | - Angriffe auf Funknetzwerke
|
| Thema 6: Netzwerkscan und Aufklärung | - Scanverfahren
|
| Thema 7: Systemangriffe | - Ausnutzung von Schwachstellen
|
| Thema 8: Bedrohungen durch Schadsoftware | - Analyse von Schadsoftware
|
EC-COUNCIL EC-Council Certified Security Analyst (ECSA) 412-79 Prüfungsfragen mit Lösungen
Which one of the following is a supporting tool for 802.11 (wireless) packet injections, it spoofs 802.11 packets to verify whether the access point is valid or not?
- A. WEPCrack
- B. Aircrack
- C. Airpwn
- D. Airsnort
How many possible sequence number combinations are there in TCP/IP protocol?
- A. 1 billion
- B. 32 million
- C. 4 billion
- D. 320 billion
Which of the following reports provides a summary of the complete pen testing process, its outcomes, and recommendations?
- A. Vulnerability Report
- B. Executive Report
- C. Client-side test Report
- D. Host Report
The Web parameter tampering attack is based on the manipulation of parameters exchanged between client and server in order to modify application data, such as user credentials and permissions, price and quantity of products, etc. Usually, this information is stored in cookies, hidden form fields, or URL Query Strings, and is used to increase application functionality and control.
This attack takes advantage of the fact that many programmers rely on hidden or fixed fields (such as a hidden tag in a form or a parameter in a URL) as the only security measure for certain operations. Attackers can easily modify these parameters to bypass the security mechanisms that rely on them.
What is the best way to protect web applications from parameter tampering attacks?
- A. Minimizing the allowable length of parameters
- B. Using an easily guessable hashing algorithm
- C. Applying effective input field filtering parameters
- D. Validating some parameters of the web application
Which of the following is NOT generally included in a quote for penetration testing services?
- A. Type of testers involved
- B. Budget required
- C. Type of testing carried out
- D. Expected timescale required to finish the project






1117 Kundenbewertungen

