EC-COUNCIL 412-79 시험 개요:
| 인증 벤더: | EC-Council |
|---|---|
| 시험명: | EC-Council 공인 보안 분석가(ECSA) 시험 412-79 |
| 시험 번호: | 412-79 |
| 자격증 유효 기간: | 3년 |
| 관련 자격증: | 공인 윤리적 해커(CEH) 공인 침투 테스트 전문가(LPT) |
| 시험 형식: | 시나리오 기반 문항, 실습/랩 기반 (버전에 따라 상이), 객관식 문항 |
| 응시료: | USD 550~950 (지역 및 교육 과정 패키지에 따라 상이) |
| 시험 시간: | 240분 |
| 지원 언어: | English |
| 실제 시험 문항 수: | 약 150문항 |
| 합격 점수: | 70% |
| 권장 교육: | CEH 교육 과정 (권장 선수 과정) EC-Council 공식 ECSA 교육 과정 |
| 시험 등록: | EC-Council 공인 인증 포털 EC-Council 응시자 포털 |
| 샘플 문제: | EC-COUNCIL 412-79 샘플 문제 |
| 응시 방법: | 온라인 감독 시험 또는 공인 시험 센터 (지역 및 제공 기관에 따라 상이) |
| 전제 조건: | 권장 사항: 공인 윤리적 해커(CEH) 또는 이에 상응하는 침투 테스트 지식 |
| 공식 요강 URL: | https://www.eccouncil.org/programs/ecsa-certification/ |
EC-COUNCIL 412-79 시험 요강 주제:
| 섹션 | 목표 |
|---|---|
| 침투 테스트 방법론 | - 스캐닝 및 열거
|
| 시스템 해킹 | - 권한 상승 및 접근 제어 우회
|
| 네트워크 공격 | - 스니핑 및 세션 하이재킹
|
| 보고 및 대응 방안 | - 방어 전략
|
| 웹 애플리케이션 보안 | - 웹 취약점
|
| 무선 및 클라우드 보안 | - 무선 공격
|
최신 Certified Ethical Hacker 412-79 무료샘플문제
문제 #1
The IP protocol was designed for use on a wide variety of transmission links. Although the maximum length of an IP datagram is 64K, most transmission links enforce a smaller maximum packet length limit, called a MTU.
The value of the MTU depends on the type of the transmission link. The design of IP accommodates MTU differences by allowing routers to fragment IP datagrams as necessary. The receiving station is responsible for reassembling the fragments back into the original full size IP datagram.
IP fragmentation involves breaking a datagram into a number of pieces that can be reassembled later. The IP source, destination, identification, total length, and fragment offset fields in the IP header, are used for IP fragmentation and reassembly.
The fragment offset is 13 bits and indicates where a fragment belongs in the original IP datagram. This value is a:
A. Multiple of eight bytes
B. Multiple of six bytes
C. Multiple of two bytes
D. Multiple of four bytes
문제 #2
Which one of the following acts makes reputational risk of poor security a reality because it requires public disclosure of any security breach that involves personal information if it is unencrypted or if it is reasonably believed that the information has been acquired by an unauthorized person?
A. USA Patriot Act 2001
B. Gramm-Leach-Bliley Act (GLBA)
C. Sarbanes-Oxley 2002
D. California SB 1386
문제 #3
A firewall's decision to forward or reject traffic in network filtering is dependent upon which of the following?
A. Protocol used
B. Destination address
C. Source address
D. Port numbers
문제 #4
In Linux, /etc/shadow file stores the real password in encrypted format for user's account with added properties associated with the user's password.
In the example of a /etc/shadow file below, what does the bold letter string indicate?
Vivek: $1$fnffc$GteyHdicpGOfffXX40w#5:13064:0:99999:7
A. Maximum number of days the password is valid
B. Number of days the user is warned before the expiration date
C. Minimum number of days required between password changes
D. Last password changed
문제 #5
Timing is an element of port-scanning that can catch one unaware. If scans are taking too long to complete or obvious ports are missing from the scan, various time parameters may need to be adjusted. Which one of the following scanned timing options in NMAP's scan is useful across slow WAN links or to hide the scan?
A. Polite
B. Sneaky
C. Normal
D. Paranoid
질문과 대답:
| 문제 #1 정답: A | 문제 #2 정답: D | 문제 #3 정답: A | 문제 #4 정답: C | 문제 #5 정답: A |














785 개 고객 리뷰
품질과 가치ITCertKR 의 높은 정확도를 보장하는 최고품질의 덤프는 IT인증시험에 대비하여 제작된것으로서 높은 적중율을 자랑하고 있습니다.
테스트 및 승인ITCertKR 의 덤프는 모두 엘리트한 전문가들이 실제시험문제를 분석하여 답을 작성한 만큼 시험문제의 적중률은 아주 높습니다.
쉽게 시험패스ITCertKR의 테스트 엔진을 사용하여 시험을 준비한다는것은 첫 번째 시도에서 인증시험 패스성공을 의미합니다.
주문하기전 체험ITCertKR의 각 제품은 무료 데모를 제공합니다. 구입하기로 결정하기 전에 덤프샘플문제로 덤프품질과 실용성을 검증할수 있습니다.
