EC-COUNCIL 412-79 Exam Overview:
| Certification Vendor: | EC-Council |
|---|---|
| Exam Name: | EC-Council Certified Security Analyst (ECSA) Exam 412-79 |
| Exam Number: | 412-79 |
| Certificate Validity Period: | 3 years |
| Exam Duration: | 240 minutes |
| Related Certifications: | Licensed Penetration Tester (LPT) Certified Ethical Hacker (CEH) |
| Available Languages: | English |
| Exam Format: | Scenario-based Questions, Practical / Lab-based (depending on version), Multiple Choice Questions |
| Exam Price: | USD 550–950 (varies by region and training bundle) |
| Real Exam Qty: | Approximately 150 |
| Passing Score: | 70% |
| Recommended Training: | EC-Council Official ECSA Training CEH Training Path (Recommended prerequisite) |
| Exam Registration: | EC-Council Candidate Portal EC-Council Official Certification Portal |
| Sample Questions: | EC-COUNCIL 412-79 Sample Questions |
| Exam Way: | Online proctored exam or authorized testing center (varies by region and provider) |
| Pre Condition: | Recommended: Certified Ethical Hacker (CEH) or equivalent penetration testing knowledge |
| Official Syllabus URL: | https://www.eccouncil.org/programs/ecsa-certification/ |
EC-COUNCIL 412-79 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Wireless and Cloud Security | - Cloud Security Fundamentals
|
| Web Application Security | - Web Vulnerabilities
|
| System Hacking | - Malware Threats
|
| Reporting and Countermeasures | - Penetration Testing Reports
|
| Network Attacks | - Denial of Service Attacks
|
| Penetration Testing Methodology | - Information Gathering & Reconnaissance
|
EC-COUNCIL EC-Council Certified Security Analyst (ECSA) Sample Questions:
Question 1
Which of the following pen testing reports provides detailed information about all the tasks performed during penetration testing?
A. Host Report
B. Activity Report
C. Vulnerability Report
D. Client-Side Test Report
Question 2
This is a group of people hired to give details of the vulnerabilities present in the system found after a penetration test. They are elite and extremely competent penetration testers and intrusion analysts. This team prepares a report on the vulnerabilities in the system, attack methods, and how to defend against them.
What is this team called?
A. Lion team
B. Tiger team
C. Gorilla team
D. Blue team
Question 3
John, a penetration tester, was asked for a document that defines the project, specifies goals, objectives, deadlines, the resources required, and the approach of the project. Which of the following includes all of these requirements?
A. Penetration testing project scope report
B. Penetration testing project plan
C. Penetration testing schedule plan
D. Penetration testing software project management plan
Question 4
Variables are used to define parameters for detection, specifically those of your local network and/or specific servers or ports for inclusion or exclusion in rules. These are simple substitution variables set with the var keyword. Which one of the following operator is used to define meta-variables?
A. "#"
B. "?"
C. "*"
D. "$"
Question 5
TCP/IP model is a framework for the Internet Protocol suite of computer network protocols that defines the communication in an IP-based network. It provides end-to-end connectivity specifying how data should be formatted, addressed, transmitted, routed and received at the destination. This functionality has been organized into four abstraction layers which are used to sort all related protocols according to the scope of networking involved.
Which of the following TCP/IP layers selects the best path through the network for packets to travel?
A. Network Access layer
B. Internet layer
C. Transport layer
D. Application layer
Solutions:
| Question 1 Answer: D | Question 2 Answer: B | Question 3 Answer: B | Question 4 Answer: D | Question 5 Answer: B |

We're so confident of our products that we provide no hassle product exchange.


By Bernice


