EC-Council EC0-479 Exam Questions
EC0-479 EC-Council Certified Security Analyst (ECSA) (Page 3 )

Updated On: 21-Feb-2026

If an attacker's computer sends an IPID of 31400 to a zombie computer on an open port in IDLE scanning, what will be the response?

  1. The zombie will not send a response
  2. 31402
  3. 31399
  4. 31401

Answer(s): D



Michael works for Kimball Construction Company as senior security analyst, As part of yearly security audit, Michael scans his network for vulnerabilities. Using Nmap, Michael conducts XMAS scan and most of the ports scanned do not give a response. In what state are these ports?

  1. Closed
  2. Open
  3. Stealth
  4. Filtered

Answer(s): B



You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers.
What type of firewall must you implement to abide by this policy?

  1. Packet filtering firewall
  2. Circuit-level proxy firewall
  3. Application-level proxy firewall
  4. Statefull firewall

Answer(s): D



Jessica works as systems administrator for a large electronics firm. She wants to scan her network quickly to detect live hosts by using ICMP ECHO Requests.
What type of scan is Jessica going to perform?

  1. Tracert
  2. Smurf scan
  3. Ping trace
  4. ICMP ping sweep

Answer(s): D



You work as an IT security auditor hired by a law firm in Boston to test whether you can gain access to sensitive information about the company clients. You have rummaged through their trash and found very little information. You do not want to set off any alarms on their network, so you plan on performing passive footprinting against their Web servers.
What tool should you use?

  1. Ping sweep
  2. Nmap
  3. Netcraft
  4. Dig

Answer(s): C






Post your Comments and Discuss EC-Council EC0-479 exam dumps with other Community members:

Join the EC0-479 Discussion