Free 412-79v10: EC-Council Certified Security Analyst (ECSA) V10 Exam Questions and Answers
196 verified practice questions for 412-79v10.
The first 10 questions on this page are free to read, answers included — no account and no card. A plan opens the rest of the bank, the full timed practice test and your weak-topic reporting.
Last updated: September 19, 2026
- Exam code
- 412-79v10
- Provider
- ECCouncil
- Questions in our bank
- 1000+
- Free to read
- First 10, with answers
- Our test mode duration & pass mark
- 130 mins · 70%
- Verified answers
- Reviewed weekly
Recommended: Switch to Test Mode to start a practice test that simulates the real exam experience.
Question #1
An external intrusion test and analysis identify security weaknesses and strengths of the client's systems and networks as they appear from outside the client's security perimeter, usually from the Internet. The goal of an external intrusion test and analysis is to demonstrate the existence of known vulnerabilities that could be exploited by an external attacker. During external penetration testing, which of the following scanning techniques allow you to determine a port’s state without making a full connection to the host?
Please select an optionIncorrectCorrect answer: B
A SYN scan sends SYN and reads the SYN/ACK or RST without completing the three-way handshake.
Was this answer correct?Question #2
A WHERE clause in SQL specifies that a SQL Data Manipulation Language (DML) statement should only affect rows that meet specified criteria. The criteria are expressed in the form of predicates. WHERE clauses are not mandatory clauses of SQL DML statements, but can be used to limit the number of rows affected by a SQL DML statement or returned by a query. A pen tester is trying to gain access to a database by inserting exploited query statements with a WHERE clause. The pen tester wants to retrieve all the entries from the database using the WHERE clause from a particular table (e.g. StudentTable). What query does he need to write to retrieve the information?
Please select an optionIncorrectCorrect answer: C
The always-true condition '' or '1'='1' makes the WHERE clause match every row; the other statements use invalid SQL verbs.
Was this answer correct?Question #3
What will the following URL produce in an unpatched IIS Web Server?
Please select an optionIncorrectCorrect answer: D
Was this answer correct?Question #4
Firewall is an IP packet filter that enforces the filtering and security policies to the flowing network traffic. Using firewalls in IPv6 is still the best way of protection from low level attacks at the network and transport layers. Which one of the following cannot handle routing protocols properly?
Please select an optionIncorrectCorrect answer: B
With no router, an Internet-firewall-net architecture leaves the firewall unable to handle routing protocols properly.
Was this answer correct?Question #5
The IP protocol was designed for use on a wide variety of transmission links. Although the maximum length of an IP datagram is 64K, most transmission links enforce a smaller maximum packet length limit, called a MTU. The value of the MTU depends on the type of the transmission link. The design of IP accommodates MTU differences by allowing routers to fragment IP datagrams as necessary. The receiving station is responsible for reassembling the fragments back into the original full size IP datagram. IP fragmentation involves breaking a datagram into a number of pieces that can be reassembled later. The IP source, destination, identification, total length, and fragment offset fields in the IP header, are used for IP fragmentation and reassembly. The fragment offset is 13 bits and indicates where a fragment belongs in the original IP datagram. This value is a:
Please select an optionIncorrectCorrect answer: C
The 13-bit fragment offset is expressed in 8-byte units so it can address the full 65535-byte datagram.
Was this answer correct?Question #6
Which one of the following acts related to the information security in the US fix the responsibility of management for establishing and maintaining an adequate internal control structure and procedures for financial reporting?
Please select an optionIncorrectCorrect answer: B
Section 404 of Sarbanes-Oxley makes management responsible for adequate internal controls over financial reporting.
Was this answer correct?Question #7
In a virtual test environment, Michael is testing the strength and security of BGP using multiple routers to mimic the backbone of the Internet. This project will help him write his doctoral thesis on "bringing down the Internet". Without sniffing the traffic between the routers, Michael sends millions of RESET packets to the routers in an attempt to shut one or all of them down. After a few hours, one of the routers finally shuts itself down. What will the other routers communicate between themselves?
Please select an optionIncorrectCorrect answer: C
BGP routers converge on a new topology and advertise routes that bypass the failed router.
Was this answer correct?Question #8
Simon is a former employee of Trinitron XML Inc. He feels he was wrongly terminated and wants to hack into his former company's network. Since Simon remembers some of the server names, he attempts to run the AXFR and IXFR commands using DIG. What is Simon trying to accomplish here?
Please select an optionIncorrectCorrect answer: D
AXFR and IXFR are full and incremental zone transfer requests, used to dump DNS zone records.
Was this answer correct?Question #9
Which of the following pen testing reports provides detailed information about all the tasks performed during penetration testing?
Please select an optionIncorrectCorrect answer: B
The activity report records every task carried out during the engagement and is the most detailed operational document. Client-side, host and vulnerability reports cover narrower scopes or findings only.
Was this answer correct?Question #10
In the context of penetration testing, what does blue teaming mean?
Please select an optionIncorrectCorrect answer: A
Blue teaming is testing performed with the knowledge and consent of the organization's IT staff.
Was this answer correct?
Continue with 412-79v10: EC-Council Certified Security Analyst (ECSA) V10
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in 412-79v10: EC-Council Certified Security Analyst (ECSA) V10, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Other ECCouncil certifications
- 312-49v10: Computer Hacking Forensic Investigator (opens in a new tab)
- 312-50v11: Certified Ethical Hacker v11 Exam (opens in a new tab)
- 312-50v12: Certified Ethical Hacker v12 Exam (opens in a new tab)
- 712-50: EC-Council Certified CISO (opens in a new tab)
- 312-50: CEH Certified Ethical Hacker (312-50v9) (opens in a new tab)
- 312-50v13: Certified Ethical Hacker v13 (opens in a new tab)
Reviews
★★★★★
This platform is a lifesaver. The practice questions and explanations are so detailed. It’s the best study tool I’ve ever used.
Hannah Smith
USA
★★★★★
I highly recommend Exam Practice. The feedback after each test helped me improve significantly, and I passed my exams easily.
Oscar Nyström
Sweden
★★★★★
Exam Practice is worth every penny. The mock exams are realistic, and the feedback helped me focus on key areas.
Amit Sharma
India
FAQ
Learn More: https://cert.eccouncil.org/
- Q1: What are EC-Council Certification Exams?
- A: EC-Council Certification Exams validate your expertise in various aspects of cybersecurity, including ethical hacking, network security, and forensic investigation. These certifications demonstrate your proficiency in identifying, preventing, and mitigating cyber threats.
- Q2: Why should I pursue EC-Council Certification?
- A: EC-Council Certification enhances your professional credibility, showcasing your skills and knowledge in cybersecurity. This can lead to better job opportunities, higher salaries, and career advancement in the IT and cybersecurity industries.
- Q3: What are the benefits of EC-Council Certification?
- A: Benefits include recognition as a certified cybersecurity professional, improved job performance, access to exclusive resources, continuing education opportunities, and staying current with the latest cybersecurity trends and best practices.
- Q4: Who should take EC-Council Certification Exams?
- A: IT professionals, security analysts, ethical hackers, network administrators, and anyone involved in protecting and securing information systems should consider these certifications to validate their expertise and advance their careers.
- Q5: What types of EC-Council Certification Exams are available?
- A: EC-Council offers various certification paths, including:
- Q6: How do I prepare for EC-Council Certification Exams?
- A: Preparation can include official EC-Council training courses, study guides, practice exams, online tutorials, and hands-on experience in cybersecurity practices.
- Q7: Where can I take EC-Council Certification Exams?
- A: EC-Council Certification Exams can be taken at authorized Pearson VUE testing centers worldwide or online, providing flexibility to fit your schedule and location.
- Q8: How do EC-Council Certifications impact my career?
- A: EC-Council Certifications significantly boost your career by demonstrating your expertise to employers, making you a more competitive candidate for advanced roles and promotions in cybersecurity and IT.
- Q9: Are there any prerequisites for EC-Council Certification Exams?
- A: Some exams may have prerequisites, such as foundational knowledge or prior certifications. Check the specific requirements for each certification path on the EC-Council website.
- Q10: How often do I need to recertify for EC-Council Certifications?
- A: EC-Council Certifications typically require recertification every three years to ensure that certified professionals stay updated with the latest cybersecurity technologies and industry practices.



