EC-Council ECSAV8 Exam Questions
EC-Council Certified Security Analyst (ECSA) (Page 3 )

Updated On: 21-Feb-2026

Why is a legal agreement important to have before launching a penetration test?

  1. Guarantees your consultant fees
  2. Allows you to perform a penetration test without the knowledge and consent of the organization's upper management
  3. It establishes the legality of the penetration test by documenting the scope of the project and the consent of the company.
  4. It is important to ensure that the target organization has implemented mandatory security policies

Answer(s): C



A security policy is a document or set of documents that describes, at a high level, the security controls that will be implemented by the company. Which one of the following policies forbids everything and restricts usage of company computers, whether it is system usage or network usage?

  1. Paranoid Policy
  2. Prudent Policy
  3. Promiscuous Policy
  4. Information-Protection Policy

Answer(s): A



Which of the following protocol’s traffic is captured by using the filter tcp.port==3389 in the Wireshark tool?

  1. Reverse Gossip Transport Protocol (RGTP)
  2. Real-time Transport Protocol (RTP)
  3. Remote Desktop Protocol (RDP)
  4. Session Initiation Protocol (SIP)

Answer(s): C


Reference:

http://wiki.wireshark.org/RDP



In the context of penetration testing, what does blue teaming mean?

  1. A penetration test performed with the knowledge and consent of the organization's IT staff
  2. It is the most expensive and most widely used
  3. It may be conducted with or without warning
  4. A penetration test performed without the knowledge of the organization's IT staff but with permission from upper management

Answer(s): A


Reference:

https://www.sypriselectronics.com/information-security/cyber-security-solutions/computer-network-defense/



James is testing the ability of his routers to withstand DoS attacks. James sends ICMP ECHO requests to the broadcast address of his network. What type of DoS attack is James testing against his network?

  1. Smurf
  2. Trinoo
  3. Fraggle
  4. SYN flood

Answer(s): A






Post your Comments and Discuss EC-Council ECSAV8 exam dumps with other Community members:

Join the ECSAV8 Discussion