EC-COUNCIL 412-79v10 試験概要:
| 認定ベンダー: | EC-Council |
| 試験名: | EC-Council Certified Security Analyst (ECSA) バージョン10 |
| 試験番号: | 412-79v10 |
| 受験料: | USD $999(標準バウチャー;地域・パッケージにより変動あり) |
| 関連資格: | Certified Ethical Hacker (CEH) ECSA Practical LPT (Licensed Penetration Tester) |
| 対応言語: | 英語 |
| 出題数: | 150 |
| 合格点: | 70% |
| 試験時間: | 240 minutes |
| 認定の有効期間: | 3年間 |
| 試験形式: | 多肢選択式問題(MCQ) |
| 推奨トレーニング: | ECSA v10 公式トレーニング ECSA 受験者向けハンドブック |
| 受験申し込み: | ECC 試験ポータル EC-Council 資格認定ポータル |
| サンプル問題: | EC-COUNCIL 412-79v10 サンプル問題 |
| 受験方法: | オンライン監督付き受験、またはEC-Council認定試験会場での受験 |
| 前提条件: | 推奨受験資格:CEH資格または同等の実務経験を有すること;実技試験の受験資格を得るには事前にペネトレーションテストの報告書を提出する必要があります |
| 公式シラバスのURL: | https://cert.eccouncil.org/exam-ecsa.html |
EC-COUNCIL 412-79v10 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| トピック 1: 外部ネットワーク向けペネトレーションテスト手法 | 12.0% | - 偵察、スキャン、情報列挙 - 脆弱性評価と悪用手法 |
| トピック 2: 内部ネットワーク向けペネトレーションテスト手法 | 11.5% | - 権限昇格とネットワーク内移動 - 内部インフラストラクチャの評価 |
| トピック 3: クラウド環境向けペネトレーションテスト手法 | 5.5% | - クラウドサービスの形態とセキュリティ制御機構 - AWS/Azureにおけるセキュリティ評価 |
| トピック 4: Webアプリケーション向けペネトレーションテスト手法 | 13.0% | - 認証機能、セッション管理、入力値検証の不備 - OWASP Top 10に記載された脆弱性 |
| トピック 5: ペネトレーションテストの基礎概念 | 7.5% | - 関連規格、法令、コンプライアンス - ペネトレーションテストの基本原則 |
| トピック 6: ペネトレーションテストの範囲設定と実施規程 | 5.4% | - 法的・契約上の考慮事項 - 試験範囲と実施ルールの定義 |
| トピック 7: 無線ネットワーク向けペネトレーションテスト手法 | 6.0% | - 無線ネットワークへの攻撃と対策 - 802.11プロトコルと暗号化の不備 |
| トピック 8: 報告書作成と試験後の対応業務 | 8.0% | - 改善措置の提案 - 体系的なペネトレーションテスト報告書の作成 |
| トピック 9: ペネトレーションテスト手法の概要 | 5.6% | - 手法のフレームワーク - ペネトレーションテストの実施サイクル |
| トピック 10: 境界デバイス向けペネトレーションテスト手法 | 7.0% | - ファイアウォール、IDS/IPS、ルーター、スイッチ |
| トピック 11: ソーシャルエンジニアリングによるペネトレーションテスト手法 | 7.2% | - 人的要因・技術的要因を利用した攻撃 - 対策とリスク評価 |
| トピック 12: データベース向けペネトレーションテスト手法 | 6.5% | - データベースの構造と脆弱性 - SQLインジェクションと悪用手法 |
| トピック 13: 公開情報収集(OSINT)の手法 | 4.8% | - 情報収集の技術 - OSINT用ツールと自動化手法 |
EC-COUNCIL EC-Council Certified Security Analyst (ECSA) V10 認定 412-79v10 試験問題:
1. Which one of the following Snort logger mode commands is associated to run a binary log file through Snort in sniffer mode to dump the packets to the screen?
A) ./snort -l ./log -b
B) ./snort -dev -l ./log
C) ./snort -dvr packet.log icmp
D) ./snort -dv -r packet.log
2. War Driving is the act of moving around a specific area, mapping the population of wireless access points for statistical purposes. These statistics are then used to raise awareness of the security problems associated with these types of networks.
Which one of the following is a Linux based program that exploits the weak IV (Initialization Vector) problem documented with static WEP?
A) Aircrack
B) Airpwn
C) Airsnort
D) WEPCrack
3. Which of the following password hashing algorithms is used in the NTLMv2 authentication mechanism?
A) DES (ECB mode)
B) MD5
C) AES
D) RC5
4. What sort of vulnerability assessment approach starts by building an inventory of protocols found on the machine?
A) Inference-based Assessment
B) Service-based Assessment Solutions
C) Tree-based Assessment
D) Product-based Assessment Solutions
5. Wireshark is a network analyzer. It reads packets from the network, decodes them, and presents them in an easy-to-understand format. Which one of the following is the command-line version of Wireshark, which can be used to capture the live packets from the wire or to read the saved capture files?
A) Tshark
B) Tcpdump
C) Idl2wrs
D) Capinfos
質問と回答:
| 質問 # 1 正解: D | 質問 # 2 正解: C | 質問 # 3 正解: B | 質問 # 4 正解: A | 質問 # 5 正解: D |














719 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
