EC-COUNCIL 412-79v10 Exam Overview:
| Certification Vendor: | EC-Council |
| Exam Name: | EC-Council Certified Security Analyst (ECSA) Version 10 |
| Exam Number: | 412-79v10 |
| Certificate Validity Period: | 3 years |
| Exam Price: | USD $999 (standard voucher; varies by region/package) |
| Related Certifications: | Certified Ethical Hacker (CEH) ECSA Practical LPT (Licensed Penetration Tester) |
| Exam Format: | Multiple Choice Questions (MCQ) |
| Available Languages: | English |
| Passing Score: | 70% |
| Exam Duration: | 240 minutes |
| Real Exam Qty: | 150 |
| Recommended Training: | Official ECSA v10 Training ECSA Candidate Handbook |
| Exam Registration: | EC-Council Certification Portal ECC Exam Portal |
| Sample Questions: | EC-COUNCIL 412-79v10 Sample Questions |
| Exam Way: | Online proctored or onsite at EC-Council authorized test centers |
| Pre Condition: | Recommended: CEH certification or equivalent industry experience; must submit a penetration testing report before practical exam eligibility |
| Official Syllabus URL: | https://cert.eccouncil.org/exam-ecsa.html |
EC-COUNCIL 412-79v10 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Perimeter Devices Penetration Testing Methodology | 7.0% | - Firewalls, IDS/IPS, routers, switches |
| Topic 2: Introduction to Penetration Testing Methodologies | 5.6% | - Penetration testing lifecycle - Methodology frameworks |
| Topic 3: Social Engineering Penetration Testing Methodology | 7.2% | - Human-based and technology-based attacks - Countermeasures and assessment |
| Topic 4: Penetration Testing Essential Concepts | 7.5% | - Fundamentals of penetration testing - Standards, laws, and compliance |
| Topic 5: Penetration Testing Scoping and Engagement Methodology | 5.4% | - Legal and contractual considerations - Defining scope and rules of engagement |
| Topic 6: Web Application Penetration Testing Methodology | 13.0% | - Authentication, session, input validation flaws - OWASP Top 10 vulnerabilities |
| Topic 7: Report Writing and Post-Testing Actions | 8.0% | - Structured penetration test report - Remediation recommendations |
| Topic 8: Internal Network Penetration Testing Methodology | 11.5% | - Privilege escalation and lateral movement - Internal infrastructure assessment |
| Topic 9: Database Penetration Testing Methodology | 6.5% | - Database architecture and vulnerabilities - SQL injection and exploitation |
| Topic 10: External Network Penetration Testing Methodology | 12.0% | - Reconnaissance, scanning, enumeration - Vulnerability assessment and exploitation |
| Topic 11: Cloud Penetration Testing Methodology | 5.5% | - Cloud service models and security controls - AWS/Azure/Azure security assessment |
| Topic 12: Open-Source Intelligence (OSINT) Methodology | 4.8% | - Information gathering techniques - OSINT tools and automation |
| Topic 13: Wireless Penetration Testing Methodology | 6.0% | - 802.11 protocols and encryption flaws - Wireless attacks and mitigation |
EC-COUNCIL EC-Council Certified Security Analyst (ECSA) V10 Sample Questions:
1. Identify the framework that comprises of five levels to guide agency assessment of their security programs and assist in prioritizing efforts for improvement:
A) Nortells Unified Security Framework
B) Microsoft Internet Security Framework
C) Federal Information Technology Security Assessment Framework
D) Information System Security Assessment Framework (ISSAF)
2. Why is a legal agreement important to have before launching a penetration test?
A) Allows you to perform a penetration test without the knowledge and consent of the organization's upper management
B) It establishes the legality of the penetration test by documenting the scope of the project and the consent of the company.
C) Guarantees your consultant fees
D) It is important to ensure that the target organization has implemented mandatory security policies
3. After attending a CEH security seminar, you make a list of changes you would like to perform on your network to increase its security. One of the first things you change is to switch the Restrict Anonymous setting from 0 to 1 on your servers. This, as you were told, would prevent anonymous users from establishing a null session on the server.
Using User info tool mentioned at the seminar, you succeed in establishing a null session with one of the servers. Why is that?
A) Restrict Anonymous must be set to "3" for complete security
B) There is no way to always prevent an anonymous null session from establishing
C) Restrict Anonymous must be set to "2" for complete security
D) Restrict Anonymous must be set to "10" for complete security
4. As a security analyst you setup a false survey website that will require users to create a username and a strong password. You send the link to all the employees of the company. What information will you be able to gather?
A) The MAC address of the employees' computers
B) The employees network usernames and passwords
C) Bank account numbers and the corresponding routing numbers
D) The IP address of the employees computers
5. In a virtual test environment, Michael is testing the strength and security of BGP using multiple routers to mimic the backbone of the Internet. This project will help him write his doctoral thesis on "bringing down the Internet".
Without sniffing the traffic between the routers, Michael sends millions of RESET packets to the routers in an attempt to shut one or all of them down. After a few hours, one of the routers finally shuts itself down.
What will the other routers communicate between themselves?
A) STOP packets to all other routers warning of where the attack originated
B) RESTART packets to the affected router to get it to power back up
C) The change in the routing fabric to bypass the affected router
D) More RESET packets to the affected router to get it to power back up
Solutions:
| Question # 1 Answer: C | Question # 2 Answer: B | Question # 3 Answer: C | Question # 4 Answer: D | Question # 5 Answer: C |

We're so confident of our products that we provide no hassle product exchange.


By Laura


