EC-COUNCIL 412-79v10 試験概要:
| 認定ベンダー: | EC-COUNCIL |
|---|---|
| 試験名: | EC-Council Certified Security Analyst (ECSA) V10 |
| 試験番号: | 412-79v10 |
| 合格点: | 70% |
| 試験時間: | 240 分 |
| 関連資格: | Certified Ethical Hacker (CEH) |
| 試験形式: | 選択式問題 (MCQ), 実技ペネトレーションテストレポートの提出(認定資格要件としての事前受験要件) |
| 受験料: | 公式価格は地域や受験方法によって異なります(通常、公式コースとセットの場合はトレーニングおよびバウチャーでUSD $850〜$1000以上) |
| 認定の有効期間: | 3年間(更新には継続教育が必要) |
| 出題数: | 150 |
| 対応言語: | English |
| サンプル問題: | EC-COUNCIL 412-79v10 サンプル問題 |
| 受験方法: | EC-COUNCIL試験ポータルを介したオンライン監視付き試験、または認定テストセンターでの受験。 |
| 前提条件: | EC-COUNCIL公式トレーニングの修了または同等の実務経験。選択式試験の受験前に、承認されたペネトレーションテストレポートを提出すること。 |
| 公式シラバスのURL: | https://www.eccouncil.org/train-certify/courses/ec-council-certified-security-analyst/ |
EC-COUNCIL 412-79v10 試験シラバストピック:
| セクション | 目標 |
|---|---|
| ペネトレーションテストのコア概念 | - ペネトレーションテストの手法 - ペネトレーションテストの基礎 |
| ソーシャルエンジニアリングとネットワークペネトレーション | - ソーシャルエンジニアリングペネトレーションテスト - ネットワークペネトレーションテスト(外部/内部) - 境界デバイスのアセスメント |
| アプリケーションおよび高度なテスト手法 | - 無線およびクラウドペネトレーションテスト - Webアプリケーションペネトレーションテスト - データベースペネトレーションテスト |
| ペネトレーションテストのエンゲージメントとスコープ設定 | - エンゲージメント計画と交戦規定(Rules of Engagement) - スコープ設定と偵察(OSINT) |
| レポート作成とテスト後のアクション | - エンゲージメント後の分析と推奨事項 - プロフェッショナルなペネトレーションテストレポートの作成 |
EC-COUNCIL EC-Council Certified Security Analyst (ECSA) V10 認定 412-79v10 試験問題:
問題 #1
Metasploit framework in an open source platform for vulnerability research, development, and penetration testing. Which one of the following metasploit options is used to exploit multiple systems at once?
A. NinjaHost
B. NinjaDontKill
C. RandomNops
D. EnablePython
問題 #2
From where can clues about the underlying application environment can be collected?
A. From file types and directories
B. From executable file
C. From the extension of the file
D. From source code
問題 #3
The objective of this act was to protect consumers personal financial information held by financial institutions and their service providers.
A. HIPAA
B. California SB 1386a
C. Gramm-Leach-Bliley Act
D. Sarbanes-Oxley 2002
問題 #4
NTP protocol is used to synchronize the system clocks of computers with a remote time server or time source over a network. Which one of the following ports is used by NTP as its transport layer?
A. TCP port 152
B. UDP port 177
C. TCP port 113
D. UDP port 123
問題 #5
Julia is a senior security analyst for Berber Consulting group. She is currently working on a contract for a small accounting firm in Florida. They have given her permission to perform social engineering attacks on the company to see if their in-house training did any good. Julia calls the main number for the accounting firm and talks to the receptionist. Julia says that she is an IT technician from the company's main office in Iowa.
She states that she needs the receptionist's network username and password to troubleshoot a problem they are having. Julia says that Bill Hammond, the CEO of the company, requested this information. After hearing the name of the CEO, the receptionist gave Julia all the information she asked for.
What principal of social engineering did Julia use?
A. Scarcity
B. Reciprocation
C. Friendship/Liking
D. Social Validation
解説:
| 問題 #1 正解: B | 問題 #2 正解: C | 問題 #3 正解: C | 問題 #4 正解: D | 問題 #5 正解: B |














1248 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
