EC-COUNCIL ECSAv8 Prüfungsthemen:
| Abschnitt | Ziele |
|---|---|
| Thema 1: Berichterstellung und Dokumentation | - Aufbau von Berichten zur Sicherheitsbewertung - Kommunikation von Risiken und Anleitung zur Behebung von Schwachstellen |
| Thema 2: Methoden zur Bewertung der Informationssicherheit | - Ansätze zur Risikoanalyse und Schwachstellenbewertung - Planung und Festlegung des Umfangs von Sicherheitsbewertungen |
| Thema 3: Systemzugriff und Erhöhung von Zugriffsrechten | - Verfahren zum Angriff und Knacken von Passwörtern - Methoden zur Erhöhung von Zugriffsrechten |
| Thema 4: Netzwerkscan und Ermittlung von Merkmalen | - Verfahren und Werkzeuge zum Scannen von Ports - Ermittlung von Merkmalen von Diensten und Betriebssystemen |
| Thema 5: Penetrationstests für Webanwendungen | - OWASP Top 10-Schwachstellen - SQL-Injektionen und XSS-Angriffe |
| Thema 6: Angriffe auf drahtlose Netze und mobile Geräte | - Grundlagen der Sicherheitsprüfung mobiler Anwendungen - Schwachstellen drahtloser Netzwerke |
| Thema 7: Netzwerkangriffe und Umgehung von Sicherheitsmaßnahmen | - Abhören von Datenverkehr und Übernahme von Sitzungen - Techniken zur Umgehung von IDS und Firewalls |
| Thema 8: Soziale Manipulation | - Techniken des Phishings und der Identitätsvorspiegelung - Auf den Menschen ausgerichtete Angriffswege |
| Thema 9: Lebenszyklus von Penetrationstests | - Berichterstellung und Empfehlungen zur Behebung von Schwachstellen - Informationssammlung und Aufklärung - Exploitation und Techniken nach dem Zugriff - Vorgespräche und Durchführungsregeln |
EC-COUNCIL EC-Council Certified Security Analyst (ECSA) ECSAv8 Prüfungsfragen mit Lösungen
Which of the following is the objective of Gramm-Leach-Bliley Act?
- A. To ease the transfer of financial information between institutions and banks
- B. To certify the accuracy of the reported financial statement
- C. To set a new or enhanced standards for all U.S. public company boards, management and public accounting firms
- D. To protect the confidentiality, integrity, and availability of data
Antwort: D 🗳️
Erklärung: (Nur für DeutschPrüfung-Mitglieder sichtbar)
A pen tester has extracted a database name by using a blind SQL injection. Now he begins to test the table inside the database using the below query and finds the table:
http://juggyboy.com/page.aspx?id=1; IF (LEN(SELECT TOP 1 NAME from sysobjects where xtype='U')=3) WAITFOR DELAY '00:00:10'--
http://juggyboy.com/page.aspx?id=1; IF (ASCII(lower(substring((SELECT TOP 1 NAME from sysobjects where xtype=char(85)),1,1)))=101) WAITFOR DELAY '00:00:10'--
http://juggyboy.com/page.aspx?id=1; IF (ASCII(lower(substring((SELECT TOP 1 NAME from sysobjects where xtype=char(85)),2,1)))=109) WAITFOR DELAY '00:00:10'--
http://juggyboy.com/page.aspx?id=1; IF (ASCII(lower(substring((SELECT TOP 1 NAME from sysobjects where xtype=char(85)),3,1)))=112) WAITFOR DELAY '00:00:10'-
What is the table name?
- A. CTS
- B. QRT
- C. EMP
- D. ABC
Antwort: C 🗳️
Identify the data security measure which defines a principle or state that ensures that an action or transaction cannot be denied.
- A. Authorization
- B. Non-Repudiation
- C. Availability
- D. Integrity
Antwort: B 🗳️
Erklärung: (Nur für DeutschPrüfung-Mitglieder sichtbar)
Which type of security policy applies to the below configuration? i)Provides maximum security while allowing known, but necessary, dangers ii)All services are blocked; nothing is allowed iii)Safe and necessary services are enabled individually iv)Non-essential services and procedures that cannot be made safe are NOT allowed v)Everything is logged
- A. Permissive Policy
- B. Promiscuous Policy
- C. Paranoid Policy
- D. Prudent Policy
Antwort: D 🗳️
Which of the following defines the details of services to be provided for the client's organization and the list of services required for performing the test in the organization?
- A. Requirement list
- B. Quotation
- C. Report
- D. Draft
Antwort: B 🗳️






985 Kundenbewertungen

