PrepAway - Latest Free Exam Questions & Answers

Category: 412-79v8

Exam 412-79v8: EC-Council Certified Security Analyst (ECSA) v8

What is the table name?

A pen tester has extracted a database name by using a blind SQL injection. Now he begins
to test the table inside the database using the below query and finds the table:
http://juggyboy.com/page.aspx?id=1 ; IF (LEN(SELECT TOP 1 NAME from sysobjects
where xtype=’U’)=3) WAITFOR DELAY ’00:00:10′–
http://juggyboy.com/page.aspx?id=1 ; IF (ASCII(lower(substring((SELECT TOP 1 NAME
from sysobjects where xtype=char(85)),1,1)))=101) WAITFOR DELAY ’00:00:10′–
http://juggyboy.com/page.aspx?id=1 ; IF (ASCII(lower(substring((SELECT TOP 1 NAME
from sysobjects where xtype=char(85)),2,1)))=109) WAITFOR DELAY ’00:00:10′–

http://juggyboy.com/page.aspx?id=1 ; IF (ASCII(lower(substring((SELECT TOP 1 NAME
from sysobjects where xtype=char(85)),3,1)))=112) WAITFOR DELAY ’00:00:10’—
What is the table name?

which of the following scanning techniques allow you to determine a port’s state without making a full conne

An external intrusion test and analysis identify security weaknesses and strengths of the
client’s systems and networks as they appear from outside the client’s security perimeter,
usually from the Internet. The goal of an external intrusion test and analysis is to
demonstrate the existence of known vulnerabilities that could be exploited by an external attacker.

During external penetration testing, which of the following scanning techniques allow you to
determine a port’s state without making a full connection to the host?

Which of the following password cracking attacks tries every combination of characters until the password is b

Passwords protect computer resources and files from unauthorized access by malicious
users. Using passwords is the most capable and effective way to protect information and to
increase the security level of a company. Password cracking is the process of recovering
passwords from data that have been stored in or transmitted by a computer system to gain
unauthorized access to a system.

Which of the following password cracking attacks tries every combination of characters until
the password is broken?


Page 1 of 1512345...10...Last »