Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 132 pages
Exam (elaborations)

EC-Council ECSA Certified Security Analyst Exam | Complete Practice Questions, Answers & Detailed Explanations (2026/2027)

Document preview thumbnail
Preview 4 out of 132 pages

EC-Council ECSA Certified Security Analyst Exam | Complete Practice Questions, Answers & Detailed Explanations (2026/2027)

Content preview

EC-Council ECSA Certified Security Analyst Exam | Complete
Practice Questions, Answers & Detailed Explanations
(2026/2027)


Question 1
What is the primary purpose of defining Rules of Engagement (RoE)
prior to initiating a penetration test?
• A. To outline the specific vulnerability scanners that must be used
by the client's internal team.
• B. To establish legal boundaries, authorized scope, testing
windows, and safety protocols to prevent operational disruption.
• C. To guarantee that 100% of all critical vulnerabilities in the target
infrastructure will be discovered.
• D. To determine the exact financial compensation structure for the
penetration testing vendor.
Correct Answer: B. To establish legal boundaries, authorized scope,
testing windows, and safety protocols to prevent operational disruption.
Detailed Rationale: Rules of Engagement (RoE) define the legal, ethical,
and operational framework for a penetration test. They protect both
the client and the tester by specifying out-of-bounds systems,
emergency contact procedures, and authorized testing hours.
Question 2
During the reconnaissance phase of a penetration test, a security
analyst uses Google Dorking to locate sensitive configuration files

,exposed on a target's web server. Which specific operator is best suited
to search for files with an extension of .config?
• A. site:
• B. filetype:
• C. inurl:
• D. cache:
Correct Answer: B. filetype:
Detailed Rationale: The filetype: operator instructs search engines to
restrict results to files matching a specific extension or format (e.g.,
filetype:config or filetype:pdf), helping analysts discover publicly
indexed configuration files.
Question 3
What is the primary advantage of using a stealth SYN scan (Stealth Scan
/ -sS in Nmap) compared to a full TCP Connect scan (-sT)?
• A. It completes the full three-way handshake, ensuring absolute
reliability over lossy networks.
• B. It avoids logging full connection attempts on many target
operating systems because it tears down the connection via an
RST packet before the handshake is finalized.
• C. It is completely invisible to all modern intrusion detection
systems (IDS) and firewalls.
• D. It requires no elevated privileges (root or administrator access)
to execute.

,Correct Answer: B. It avoids logging full connection attempts on many
target operating systems because it tears down the connection via an
RST packet before the handshake is finalized.
Detailed Rationale: A SYN scan sends a SYN packet and awaits a SYN-
ACK. Upon receiving it, the scanner responds with an RST packet instead
of an ACK, preventing the completion of the 3-way handshake. This
often bypasses basic application-level logging, though modern stateful
firewalls can still detect it.
Question 4
Which Nmap Scripting Engine (NSE) category should a penetration
tester avoid running during a live production assessment if they want to
strictly minimize the risk of causing a denial of service (DoS)?
• A. safe
• B. discovery
• C. intrusive
• D. default
Correct Answer: C. intrusive
Detailed Rationale: The intrusive NSE category contains scripts that are
high-risk, likely to crash services, consume excessive bandwidth, or
cause a denial of service. They should only be run with explicit client
authorization in non-production environments.
Question 5

, An analyst is performing a passive information gathering exercise
against a target organization. Which of the following tools or techniques
is considered passive?
• A. Executing an aggressive Nmap OS fingerprinting scan against
the primary web server.
• B. Querying public certificate transparency logs (e.g., crt.sh) to
identify internal or auxiliary subdomains.
• C. Sending custom TCP packets with invalid flag combinations to
probe firewall rule sets.
• D. Running a directory brute-force tool like Gobuster against the
corporate portal.
Correct Answer: B. Querying public certificate transparency logs (e.g.,
crt.sh) to identify internal or auxiliary subdomains.
Detailed Rationale: Passive reconnaissance involves interacting with
third-party sources or public repositories without directly probing or
sending packets to the target's infrastructure, ensuring complete stealth
from the target's monitoring systems.
Question 6
When analyzing a target network map, an analyst notices that a specific
router responds to ICMP timestamp requests. What security risk does
this information disclosure present?
• A. It allows an attacker to execute remote code execution via
buffer overflow on the router's BIOS.
• B. It leaks system uptime information, which helps attackers infer
whether recent security patches have been applied.

Document information

Uploaded on
August 25, 2026
Number of pages
132
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$19.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CreativeWrites
3.7
(23)
Sold
97
Followers
3
Items
8329
Last sold
3 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions