EC-COUNCIL EC-Council Certified Security Analyst(ECSA) - EC0-479 Exam Practice Test
What operating system would respond to the following command?


Correct Answer: C
Vote an answer
You work as a penetration tester for Hammond Security Consultants. You are currently working on a contract for the state government of California. Your next step is to initiate a DoS attack on their network. Why would you want to initiate a DoS attack on a system you are testing?
Correct Answer: A
Vote an answer
What is the name of the Standard Linux Command that is also available as windows application that can be used to create bit-stream images?
Correct Answer: C
Vote an answer
You have been asked to investigate after a user has reported a threatening e-mail they have received from an external source. Which of the following are you most interested in when trying to trace the source of the message?
Correct Answer: C
Vote an answer
What method of computer forensics will allow you to trace all ever-established user accounts on a Windows 2000 sever the course of its lifetime?
Correct Answer: C
Vote an answer
To preserve digital evidence, an investigator should ____________________
Correct Answer: B
Vote an answer
The police believe that Mevin Mattew has been obtaining unauthorized access to computers belonging to numerous computer software and computer operating systems manufacturers, cellular telephone manufacturers, Internet Service Providers and Educational Institutions. They also suspect that he has been stealing, copying and misappropriating proprietary computer software belonging to the several victim companies. What is preventing the police from breaking down the suspects door and searching his home and seizing all of his computer equipment if they have not yet obtained a warrant?
Correct Answer: C
Vote an answer
How many characters long is the fixed-length MD5 algorithm checksum of a critical system file?
Correct Answer: A
Vote an answer
When performing a forensics analysis, what device is used to prevent the system from recording data on an evidence disk?
Correct Answer: C
Vote an answer
What should you do when approached by a reporter about a case that you are working on or have worked on?
Correct Answer: D
Vote an answer
In a forensic examination of hard drives for digital evidence, what type of user is most likely to have the most file slack to analyze?
Correct Answer: D
Vote an answer
What type of file is represented by a colon (:) with a name following it in the Master File Table of NTFS disk?
Correct Answer: D
Vote an answer
Melanie was newly assigned to an investigation and asked to make a copy of all the evidence from the compromised system. Melanie did a DOS copy of all the files on the system. What would be the primary reason for you to recommend a disk imaging tool?
Correct Answer: C
Vote an answer