最新的 ECSA ECSAv8 免費考試真題:
1. ARP spoofing is a technique whereby an attacker sends fake ("spoofed") Address Resolution Protocol (ARP) messages onto a Local Area Network. Generally, the aim is to associate the attacker's MAC address with the IP address of another host (such as the default gateway), causing any traffic meant for that IP address to be sent to the attacker instead.
ARP spoofing attack is used as an opening for other attacks.
What type of attack would you launch after successfully deploying ARP spoofing?
A) Social Engineering
B) Parameter Filtering
C) Input Validation
D) Session Hijacking
2. Today, most organizations would agree that their most valuable IT assets reside within applications and databases. Most would probably also agree that these are areas that have the weakest levels of security, thus making them the prime target for malicious activity from system administrators, DBAs, contractors, consultants, partners, and customers.
Which of the following flaws refers to an application using poorly written encryption code to securely encrypt and store sensitive data in the database and allows an attacker to steal or modify weakly protected data such as credit card numbers, SSNs, and other authentication credentials?
A) Man-in-the-Middle attack
B) Insecure cryptographic storage attack
C) Hidden field manipulation attack
D) SSI injection attack
3. HTTP protocol specifies that arbitrary binary characters can be passed within the URL by using %xx notation, where 'xx' is the
A) Hex value of the character
B) Decimal value of the character
C) ASCII value of the character
D) Binary value of the character
4. James is testing the ability of his routers to withstand DoS attacks. James sends ICMP ECHO requests to the broadcast address of his network. What type of DoS attack is James testing against his network?
A) Smurf
B) SYN flood
C) Fraggle
D) Trinoo
5. Which type of security policy applies to the below configuration? i)Provides maximum security while allowing known, but necessary, dangers ii)All services are blocked; nothing is allowed iii)Safe and necessary services are enabled individually iv)Non-essential services and procedures that cannot be made safe are NOT allowed v)Everything is logged
A) Paranoid Policy
B) Permissive Policy
C) Prudent Policy
D) Promiscuous Policy
問題與答案:
| 問題 #1 答案: D | 問題 #2 答案: B | 問題 #3 答案: B | 問題 #4 答案: A | 問題 #5 答案: C |

下載最新試用版
1036位客戶反饋
我們對我們的產品非常有信心,所以我們不提供会给客户带去麻煩的產品。








223.142.164.* -
我用這家VCESoft網站的考古題很多套了,是考試前不錯的練習選擇,而且節約了好多時間,比較實用。