EC-COUNCIL ECSAv8 試験概要:
| 認定ベンダー: | EC-Council |
|---|---|
| 試験名: | EC-Council Certified Security Analyst (ECSA) バージョン8 試験 |
| 試験番号: | ECSA v8 |
| 認定の有効期間: | 3年間 |
| 試験時間: | 240 分 |
| 対応言語: | 英語 |
| 受験料: | 450~950米ドル(地域や受講パッケージにより異なる) |
| 出題数: | 約150問 |
| 試験形式: | シナリオベースの問題, 多肢選択式問題(MCQ) |
| 合格点: | 70% |
| 関連資格: | Licensed Penetration Tester (LPT) Certified Ethical Hacker (CEH) |
| 推奨トレーニング: | ECSA 認定プログラム紹介ページ EC-Council 公式トレーニング(iLearn) |
| 受験申し込み: | EC-Council 公式登録サイト EC-Council 試験ポータル |
| サンプル問題: | EC-COUNCIL ECSAv8 サンプル問題 |
| 受験方法: | オンライン監督付き受験、または公認試験会場での受験(地域によりPearson VUEまたはEC-Councilの試験配信プラットフォームを利用) |
| 前提条件: | ネットワークおよびセキュリティに関する基礎知識を有することが推奨されます。またEC-Councilは、CEH資格の保有または同等の実務経験を強く推奨しています。 |
| 公式シラバスのURL: | https://www.eccouncil.org/programs/ec-council-certified-security-analyst-ecsa/ |
EC-COUNCIL ECSAv8 試験シラバストピック:
| セクション | 目標 |
|---|---|
| トピック 1: ペネトレーションテストの実施サイクル | - 報告書の作成と改善措置の推奨事項 - 情報の収集と偵察活動 - 事前の打ち合わせと実施に関する取り決め - 脆弱性の悪用および侵入後の活動手法 |
| トピック 2: 情報セキュリティ評価の手法 | - リスク分析および脆弱性評価のアプローチ - セキュリティ評価の計画立案と対象範囲の設定 |
| トピック 3: システムへの侵入と権限の昇格 | - パスワードに対する攻撃と解読手法 - 権限を昇格させるための方法 |
| トピック 4: ソーシャルエンジニアリング | - 人的要因を標的とした攻撃経路 - フィッシングおよびなりすましの手法 |
| トピック 5: ネットワークに対する攻撃と防御機構の回避 | - IDS/ファイアウォールを回避するための手法 - データの盗聴およびセッションの乗っ取り |
| トピック 6: Webアプリケーションに対するペネトレーションテスト | - OWASP Top 10に掲載される脆弱性 - SQLインジェクションおよびXSS攻撃 |
| トピック 7: 無線ネットワークおよびモバイル機器への攻撃 | - 無線ネットワークの脆弱性 - モバイルアプリケーションのセキュリティ評価の基礎知識 |
| トピック 8: 報告書の作成と文書化 | - リスクの伝達と改善措置に関するガイダンス - セキュリティ評価報告書の構成 |
| トピック 9: ネットワークのスキャンと情報取得 | - ポートスキャンの手法と使用ツール - 稼働サービスおよびOSの種別判別 |
EC-COUNCIL EC-Council Certified Security Analyst (ECSA) 認定 ECSAv8 試験問題:
問題 #1
Which of the following will not handle routing protocols properly?
A. "Internet-firewall -net architecture"
B. "Internet-firewall/router(edge device)-net architecture"
C. "Internet-router-firewall-net architecture"
D. "Internet-firewall-router-net architecture"
問題 #2
Which of the following password cracking techniques is used when the attacker has some information about the password?
A. Syllable Attack
B. Rule-based Attack
C. Hybrid Attack
D. Dictionary Attack
問題 #3
Identify the injection attack represented in the diagram below:
A. XML Injection Attack
B. Frame Injection Attack
C. XPath Injection Attack
D. XML Request Attack
問題 #4
Which of the following reports provides a summary of the complete pen testing process, its outcomes, and recommendations?
A. Host Report
B. Vulnerability Report
C. Executive Report
D. Client-side test Report
問題 #5
What is a goal of the penetration testing report?
A. The penetration testing report helps you comply with local laws and regulations related to environmental conditions in the organization.
B. The pen testing report helps executive management to make decisions on implementing security controls in the organization and helps the security team implement security controls and patch any flaws discovered during testing.
C. The penetration testing report allows you to increase sales performance by effectively communicating with the internal security team.
D. The penetration testing report allows you to sleep better at night thinking your organization is protected
解説:
| 問題 #1 正解: C | 問題 #2 正解: B | 問題 #3 正解: A | 問題 #4 正解: C | 問題 #5 正解: B |














788 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
