Free EC0-479 Exam Braindumps (page: 3)

Page 2 of 26

You are carrying out the last round of testing for your new website before it goes live. The website has many dynamic pages and connects to a SQL backend that accesses your product inventory in a database. You come across a web security site that recommends inputting the following code into a search field on web pages to check for vulnerabilities:

<script>alert("This is a test.")</script>

When you type this and click on search, you receive a pop-up window that says:

"This is a test."

What is the result of this test?

  1. Your website is vulnerable to CSS
  2. Your website is not vulnerable
  3. Your website is vulnerable to SQL injection
  4. Your website is vulnerable to web bugs

Answer(s): A



If an attacker's computer sends an IPID of 31400 to a zombie computer on an open port in IDLE scanning, what will be the response?

  1. The zombie will not send a response
  2. 31402
  3. 31399
  4. 31401

Answer(s): D



Michael works for Kimball Construction Company as senior security analyst, As part of yearly security audit, Michael scans his network for vulnerabilities. Using Nmap, Michael conducts XMAS scan and most of the ports scanned do not give a response. In what state are these ports?

  1. Closed
  2. Open
  3. Stealth
  4. Filtered

Answer(s): B



You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers.
What type of firewall must you implement to abide by this policy?

  1. Packet filtering firewall
  2. Circuit-level proxy firewall
  3. Application-level proxy firewall
  4. Statefull firewall

Answer(s): D






Post your Comments and Discuss EC-Council EC0-479 exam with other Community members:

EC0-479 Discussions & Posts