EC-COUNCIL EC-Council Certified Security Specialist (ECSSv10) - ECSS 模擬練習
Below are the elements included in the order of volatility for a typical computing system as per the RFC 3227 guidelines for evidence collection and archiving.
l.Archival media
2.Remote logging and monitoring data related to the target system
3.Routing table, process table, kernel statistics, and memory
4.Registers and processor cache
5-Physical configuration and network topology
6.Disk or other storage media
7.Temporary system files
Identify the correct sequence of order of volatility from the most to least volatile for a typical system.
l.Archival media
2.Remote logging and monitoring data related to the target system
3.Routing table, process table, kernel statistics, and memory
4.Registers and processor cache
5-Physical configuration and network topology
6.Disk or other storage media
7.Temporary system files
Identify the correct sequence of order of volatility from the most to least volatile for a typical system.
正解: A
解説: (PassTest メンバーにのみ表示されます)
Kane, an investigation specialist, was appointed to investigate an incident in an organization's network. In this process, Kane executed a command and identified that a network interface is running in the promiscuous mode and is allowing all incoming packets without any restriction.
In the above scenario, which of the following commands did Kane use to check whether the network interface is set to the promiscuous mode?
In the above scenario, which of the following commands did Kane use to check whether the network interface is set to the promiscuous mode?
正解: C
解説: (PassTest メンバーにのみ表示されます)
John, from a remote location, was monitoring his bedridden grandfather's health condition at his home. John has placed a smart wearable ECC on his grandfather's wrist so that he can receive alerts to his mobile phone and can keep a track over his grandfather's health condition periodically.
Which of the following types of loT communication model was demonstrated in the above scenario?
Which of the following types of loT communication model was demonstrated in the above scenario?
正解: C
解説: (PassTest メンバーにのみ表示されます)
Ben, a computer user, applied for a digital certificate. A component of PKI verifies Ben's identity using the credentials provided and passes that request on behalf of Ben to grant the digital certificate.
Which of the following PKI components verified Ben as being legitimate to receive the certificate?
Which of the following PKI components verified Ben as being legitimate to receive the certificate?
正解: C
解説: (PassTest メンバーにのみ表示されます)
Below are the various stages of the virus lifecycle:
1) Replication
2)Detection
3)lncorporation
4)Design
5)Execution of the damage routine
6)Launch
What is the correct sequence of stages involved in the virus lifecycle?
1) Replication
2)Detection
3)lncorporation
4)Design
5)Execution of the damage routine
6)Launch
What is the correct sequence of stages involved in the virus lifecycle?
正解: D
解説: (PassTest メンバーにのみ表示されます)
Sarah was accessing confidential office files from a remote location via her personal computer connected to the public Internet. Accidentally, a malicious file was downloaded onto Sarah's computer without her knowledge. This download might be due to the free Internet access and the absence of network defense solutions.
Identify the Internet access policy demonstrated in the above scenario.
Identify the Internet access policy demonstrated in the above scenario.
正解: C
解説: (PassTest メンバーにのみ表示されます)
Sarah, a forensic investigator, is working on a criminal case. She was provided with all the suspect devices.
Sarah employs an imaging software tool for duplicating the original data from the suspect devices. However, the tool she employed failed to image the data as the suspect version of the drive was very old and incompatible with imaging software. Hence, Sarah used an alternative data acquisition technique and succeeded in imaging the data.
Which of the following types of data acquisition techniques did Sarah employ in the above scenario?
Sarah employs an imaging software tool for duplicating the original data from the suspect devices. However, the tool she employed failed to image the data as the suspect version of the drive was very old and incompatible with imaging software. Hence, Sarah used an alternative data acquisition technique and succeeded in imaging the data.
Which of the following types of data acquisition techniques did Sarah employ in the above scenario?
正解: C
解説: (PassTest メンバーにのみ表示されます)
Bob, a security professional, was recruited by an organization to ensure that application services are being delivered as expected without any delay. To achieve this. Bob decided to maintain different backup servers for the same resources so that if one backup system fails, another will serve the purpose.
Identify the IA principle employed by Bob in the above scenario.
Identify the IA principle employed by Bob in the above scenario.
正解: D
解説: (PassTest メンバーにのみ表示されます)
Kalley, a shopping freak, often visits different e commerce websites from her office system. One day, she received a free software on her mail with the claim that it is loaded with new clothing offers. Tempted by this, Kalley downloaded the malicious software onto her system. The software infected Kalley's system and began spreading the infection to other systems connected to the network.
Identify the threat source through which Kalley unintentionally invited the malware into the network?
Identify the threat source through which Kalley unintentionally invited the malware into the network?
正解: C
解説: (PassTest メンバーにのみ表示されます)
Clark, a digital forensic expert, was assigned to investigate a malicious activity performed on an organization's network. The organization provided Clark with all the information related to the incident. In this process, he assessed the impact of the incident on the organization, reasons for and source of the incident, steps required to tackle the incident, investigating team required to handle the case, investigative procedures, and possible outcome of the forensic process.
Identify the type of analysis performed by Clark in the above scenario.
Identify the type of analysis performed by Clark in the above scenario.
正解: B
解説: (PassTest メンバーにのみ表示されます)