Free ECSAv10: EC-Council Certified Security Analyst Exam Questions and Answers
EC-Council Certified Security Analyst is exam ECSAv10, part of EC-Council certification. EC-Council codes run three digits, a hyphen and two more, where the prefix marks the family — 212 for technician level, 312 for the main practitioner range including CEH, 712 for the executive CCISO — and the version is appended to the code rather than changing it. Formats differ sharply: some are four-hour multiple-choice papers, while CPENT is a 24-hour hands-on exam with a written report due within seven days.
Candidates comparing ECSAv10 exam dumps, ExamTopics and other ECSAv10 practice tests use this page for the answers and explanations behind each question. Download the free ECSAv10 PDF, then sit the timed ECSAv10 exam simulation before booking with ECCouncil.
Last updated: October 4, 2026
- Exam code
- ECSAv10
- Provider
- ECCouncil
- Questions in our bank
- 1000+
- Free to read
- First 10, with answers
- Official page
- Official Exam website
- Our test mode duration & pass mark
- 130 mins · 70%
Recommended: Switch to Test Mode to start a practice test that simulates the real exam experience.
Question #1
What is the difference between penetration testing and vulnerability testing?

Correct answer: A
Explanation
Vulnerability testing only enumerates known weaknesses, whereas penetration testing goes further and actively exploits them through in-depth ethical hacking to prove real impact.
Continue with ECSAv10: EC-Council Certified Security Analyst
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in ECSAv10: EC-Council Certified Security Analyst, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #2
Transmission Control Protocol (TCP) is a connection-oriented four layer protocol. It is responsible for breaking messages into segments, re-assembling them at the destination station, and re-sending. Which one of the following protocols does not use the TCP?
Correct answer: A
Explanation
RARP is a link-layer protocol that maps MAC addresses to IP addresses and does not run over TCP, whereas HTTP, SMTP and Telnet are all TCP-based application protocols.
Continue with ECSAv10: EC-Council Certified Security Analyst
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in ECSAv10: EC-Council Certified Security Analyst, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #3
Which one of the following acts makes reputational risk of poor security a reality because it requires public disclosure of any security breach that involves personal information if it is unencrypted or if it is reasonably believed that the information has been acquired by an unauthorized person?
Correct answer: A
Explanation
California SB 1386 was the first breach-notification law, requiring public disclosure when unencrypted personal information is, or is believed to be, acquired by an unauthorized person; SOX, GLBA and the Patriot Act contain no such notification mandate.
Continue with ECSAv10: EC-Council Certified Security Analyst
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in ECSAv10: EC-Council Certified Security Analyst, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #4
The Internet is a giant database where people store some of their most private information on the cloud, trusting that the service provider can keep it all safe. Trojans, Viruses, DoS attacks, website defacement, lost computers, accidental publishing, and more have all been sources of major leaks over the last 15 years. What is the biggest source of data leaks in organizations today?

Correct answer: C
Explanation
Insiders already have authorized access to sensitive data, so rogue employees and insider attacks account for the largest share of organizational data leaks, exceeding external website attacks.
Continue with ECSAv10: EC-Council Certified Security Analyst
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in ECSAv10: EC-Council Certified Security Analyst, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #5
Vulnerability assessment is an examination of the ability of a system or application, including current security procedures and controls, to withstand assault. It recognizes, measures, and classifies security vulnerabilities in a computer system, network, and communication channels. A vulnerability assessment is used to identify weaknesses that could be exploited and predict the effectiveness of additional security measures in protecting information resources from attack. Which of the following vulnerability assessment technique is used to test the web server infrastructure for any misconfiguration and outdated content?

Correct answer: D
Explanation
Application assessment tests the web server infrastructure and its applications for misconfiguration, outdated content and known vulnerabilities; host-based assessment focuses on the operating system and local configuration.
Continue with ECSAv10: EC-Council Certified Security Analyst
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in ECSAv10: EC-Council Certified Security Analyst, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #6
George is the network administrator of a large Internet company on the west coast. Per corporate policy, none of the employees in the company are allowed to use FTP or SFTP programs without obtaining approval from the IT department. Few managers are using SFTP program on their computers. Before talking to his boss, George wants to have some proof of their activity. George wants to use Ethereal to monitor network traffic, but only SFTP traffic to and from his network. What filter should George use in Ethereal?
Correct answer: C
Explanation
SFTP runs over SSH on TCP port 22, so filtering on source and destination port 22 isolates that traffic. Port 23 is Telnet and SFTP does not use UDP.
Continue with ECSAv10: EC-Council Certified Security Analyst
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in ECSAv10: EC-Council Certified Security Analyst, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #7
The IP protocol was designed for use on a wide variety of transmission links. Although the maximum length of an IP datagram is 64K, most transmission links enforce a smaller maximum packet length limit, called a MTU. The value of the MTU depends on the type of the transmission link. The design of IP accommodates MTU differences by allowing routers to fragment IP datagrams as necessary. The receiving station is responsible for reassembling the fragments back into the original full size IP datagram. IP fragmentation involves breaking a datagram into a number of pieces that can be reassembled later. The IP source, destination, identification, total length, and fragment offset fields in the IP header, are used for IP fragmentation and reassembly. The fragment offset is 13 bits and indicates where a fragment belongs in the original IP datagram. This value is a:

Correct answer: C
Explanation
The 13-bit fragment offset is expressed in 8-byte units so it can address the full 65535-byte datagram.
Continue with ECSAv10: EC-Council Certified Security Analyst
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in ECSAv10: EC-Council Certified Security Analyst, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #8
Which of the following contents of a pen testing project plan addresses the strengths, weaknesses, opportunities, and threats involved in the project?
Correct answer: D
Explanation
The assumptions section of the pen testing project plan records the strengths, weaknesses, opportunities and threats (SWOT) assumed about the project; goals and objectives state what is to be achieved.
Continue with ECSAv10: EC-Council Certified Security Analyst
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in ECSAv10: EC-Council Certified Security Analyst, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #9
You work as a penetration tester for Hammond Security Consultants. You are currently working on a contract for the state government of California. Your next step is to initiate a DoS attack on their network. Why would you want to initiate a DoS attack on a system you are testing?
Correct answer: C
Explanation
A DoS test during a penetration test is meant to identify weak points, i.e. which systems fail under load or are not protected, so the client can strengthen them.
Continue with ECSAv10: EC-Council Certified Security Analyst
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in ECSAv10: EC-Council Certified Security Analyst, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #10
Which one of the following tools of trade is an automated, comprehensive penetration testing product for assessing the specific information security threats to an organization?
Correct answer: B
Explanation
CORE Impact is a commercial automated penetration testing product used to assess an organization's specific information security threats. SNSI and MBSA are vulnerability scanners rather than comprehensive penetration testing suites.
Continue with ECSAv10: EC-Council Certified Security Analyst
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in ECSAv10: EC-Council Certified Security Analyst, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Discussion
Explain your reasoning, not just the letterOther ECCouncil certifications
- 312-49v10: Computer Hacking Forensic Investigator (opens in a new tab)
- 312-50v11: Certified Ethical Hacker v11 Exam (opens in a new tab)
- 312-50v12: Certified Ethical Hacker v12 Exam (opens in a new tab)
- 712-50: EC-Council Certified CISO (opens in a new tab)
- 312-50: CEH Certified Ethical Hacker (312-50v9) (opens in a new tab)
- 312-50v13: Certified Ethical Hacker v13 (opens in a new tab)
- 212-89: EC-Council Certified Incident Handler (opens in a new tab)
- 312-39: Certified SOC Analyst (opens in a new tab)
- 312-49v9: ECCouncil Computer Hacking Forensic Investigator (V9) (opens in a new tab)
- 312-38: Certified Network Defender (opens in a new tab)
- 312-85: Certified Threat Intelligence Analyst (opens in a new tab)
- 412-79v8: EC-Council Certified Security Analyst (opens in a new tab)
Reviews
Write a review★★★★★
Exam Practice is worth every penny. The mock exams are realistic, and the feedback helped me focus on key areas.
Amit SharmaVerified buyer
★★★★★
I highly recommend Exam Practice. The feedback after each test helped me improve significantly, and I passed my exams easily.
Oscar NyströmVerified buyer
★★★★★
This platform is a lifesaver. The practice questions and explanations are so detailed. It’s the best study tool I’ve ever used.
Hannah SmithVerified buyer
FAQ
Learn More: https://cert.eccouncil.org/
- Q1: What is the ECSAv10: EC-Council Certified Security Analyst exam?
- A: ECSAv10: EC-Council Certified Security Analyst is a ECCouncil certification exam. Judging by the questions in our bank, it concentrates on nessus, datagram, vulnerability, penetration and george.
- Q2: What topics does the ECSAv10: EC-Council Certified Security Analyst exam cover?
- A: Questions in our ECSAv10: EC-Council Certified Security Analyst bank cluster around nessus, datagram, vulnerability, penetration, george, 64bit, ICMP and fragment. Working through the full set is the quickest way to find which of these you are weakest on.
- Q3: How should I prepare for ECSAv10: EC-Council Certified Security Analyst?
- A: Work through the ECSAv10: EC-Council Certified Security Analyst practice questions here, checking your answer on each one, then sit the practice test to rehearse the exam under timed conditions before the real thing.
- Q4: Are these real ECSAv10: EC-Council Certified Security Analyst exam questions?
- A: They are drawn from officially released past questions and from community members who have sat ECSAv10: EC-Council Certified Security Analyst. Answers are verified and updated weekly.
- Q5: Where do I register for the ECSAv10: EC-Council Certified Security Analyst exam?
- A: Register through ECCouncil directly at https://cert.eccouncil.org/. Exampractice is not affiliated with ECCouncil and does not administer the exam.
- Q6: Is there a free ECSAv10: EC-Council Certified Security Analyst sample?
- A: Yes. Every ECSAv10: EC-Council Certified Security Analyst page shows a free sample of real questions. Upgrading opens the full bank and the practice test.
- Q7: What are EC-Council Certification Exams?
- A: EC-Council Certification Exams validate your expertise in various aspects of cybersecurity, including ethical hacking, network security, and forensic investigation. These certifications demonstrate your proficiency in identifying, preventing, and mitigating cyber threats.
- Q8: Why should I pursue EC-Council Certification?
- A: EC-Council Certification enhances your professional credibility, showcasing your skills and knowledge in cybersecurity. This can lead to better job opportunities, higher salaries, and career advancement in the IT and cybersecurity industries.
- Q9: What are the benefits of EC-Council Certification?
- A: Benefits include recognition as a certified cybersecurity professional, improved job performance, access to exclusive resources, continuing education opportunities, and staying current with the latest cybersecurity trends and best practices.
- Q10: Who should take EC-Council Certification Exams?
- A: IT professionals, security analysts, ethical hackers, network administrators, and anyone involved in protecting and securing information systems should consider these certifications to validate their expertise and advance their careers.
- Q11: What types of EC-Council Certification Exams are available?
- A: EC-Council offers various certification paths, including:
- Q12: How do I prepare for EC-Council Certification Exams?
- A: Preparation can include official EC-Council training courses, study guides, practice exams, online tutorials, and hands-on experience in cybersecurity practices.
- Q13: Where can I take EC-Council Certification Exams?
- A: EC-Council Certification Exams can be taken at authorized Pearson VUE testing centers worldwide or online, providing flexibility to fit your schedule and location.
- Q14: How do EC-Council Certifications impact my career?
- A: EC-Council Certifications significantly boost your career by demonstrating your expertise to employers, making you a more competitive candidate for advanced roles and promotions in cybersecurity and IT.
- Q15: Are there any prerequisites for EC-Council Certification Exams?
- A: Some exams may have prerequisites, such as foundational knowledge or prior certifications. Check the specific requirements for each certification path on the EC-Council website.
- Q16: How often do I need to recertify for EC-Council Certifications?
- A: EC-Council Certifications typically require recertification every three years to ensure that certified professionals stay updated with the latest cybersecurity technologies and industry practices.



