Browse all practice questions for the EC-Council Certified Security Specialist (ECSS) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

EC-Council Certified Security Specialist (ECSS) Practice Test 2026 - Free EC-Council Exam Practice Questions and Study Guide course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Identity Theft is primarily used by attackers to do what?
  • What does SSID stand for?
  • Which statement describes the risk associated with web services integration?
  • Which of the following is NOT listed as an aspect of organizational security?
  • What differentiates a computer worm from a traditional computer virus?
  • Which type of attack involves attackers sending forged control, management, or data frames over a wireless network?
  • Which component is NOT typically part of IDS analysis?
  • Administrative metadata provides information about what?
  • What is incident response?
  • Which backup method is typically offline, requiring the system downtime to perform the backup?
  • Which trend in security involves evasion techniques used by malware researchers?
  • Which layer breaks data into packets (TCP/UDP) for transfers?
  • Which statement best describes a typical consequence of a security misconfiguration?
  • Which of the following is NOT a typical injection type?
  • In security terms, what describes a potential violation of security?
  • Which countermeasure relates to classifying information for access privileges?
  • Which attack aims to intercept confidential information sent over wireless association?
  • In wireless networking, which mechanism encrypts data traveling over the air?
  • Which statement best describes the relationship between IDS and Firewall?
  • Tunneling facilitates what in a network?
  • Where can an IDS be deployed?
  • Which statement about volatile data is true?
  • Which statement about log files is true?
  • Which description best defines Public Key Infrastructure (PKI)?
  • Which term describes deliberately inserting invalid packets to confuse an IDS?
  • Digital evidence is best defined as which of the following?
  • A computer virus is best described as?
  • Which policy type addresses how computers are used within an organization?
  • Which tool analyzes the email header to determine the sender's IP address?
  • Which of the following is not typically considered a major file system?
  • The Host Layer and the Media Layer are described as parts of which reference model?
  • What is firewalking in the context of network security?
  • Which of the following is cited as an example of technical steganography?
  • Which statement best describes Encrypting File System behavior?
  • Which of the following is an example of cyber crime?
  • Which file system type is used to store data on a local disk, as listed among the basic types?
  • Which type of attack is used to steal the identity of Wi‑Fi clients?
  • Which protocol was developed by Netscape and uses certificates for secure transactions?
  • The Three Processes in access control are described as working how?
  • Which of the following is an example of digital evidence that can be gathered?
  • General Indications of Intrusion include which of the following?
  • Which technology is the best example of a WPAN?
  • What is the block size of AES?
  • A well-crafted computer forensics report should be
  • Why is ethical hacking performed?
  • Abuse.net is best described as
  • Which statement best describes Certificate Authorities (CAs)?
  • Which protocol standard is used to encrypt and digitally sign emails with attachments and provides the CIA triad plus non-repudiation?
  • Which statement about cyber crime reporting is true?
  • Which of the following is not listed as a factor when selecting backup media?
  • Which statement about PPTP is correct?
  • Which statement about Windows startup autostart management is true according to the material?
  • Which protocol stands for Secure/Multipurpose Internet Mail Extensions and is used to send digitally signed and encrypted messages?
  • Who is a hacker?
  • TLS is the successor to which protocol?
  • Which type of attack targets weaknesses at the application layer?
  • In the creation of a digital signature, what is typically computed from the message before signing?
  • Point to Point Tunneling Protocol (PPTP) belongs to which group?
  • Which protocol is used with WPA to provide enterprise authentication?
  • IPsec operates at which layer in the network stack?
  • Which term refers to algorithms used to encrypt or decrypt the data?
  • SSH is a protocol used to log onto another computer. What does SSH stand for?
  • Which item is NOT part of AAA?
  • An exploit is best described as?
  • Which is an example of computer-based social engineering?
  • Which is a key advantage of using firewalls?
  • Which elements should incident reporting include?
  • What term means unable to deny the action?
  • H.323 defines protocols to provide what on IP-based networks?
  • For LDAP, which action helps maintain a secure operating environment?
  • Phase 2 Scanning has the objective to extract information such as IP addresses. Which option reflects this?
  • Which set of terms best indicates the section primarily covering administrative information?
  • Which mechanism allows log files to be sent to a central server for storage?
  • Which cipher rearranges letters of the plaintext to form the ciphertext?
  • What does WPAN stand for?
  • Which port does POP3 listen on by default?
  • Which virus detection method involves verifying file integrity to detect unauthorized changes?
  • Which description matches IP Address Spoofing?
  • Web Application Threats include which type of vulnerabilities?
  • The First FBI Regional Computer Forensic Laboratory was established in which year?
  • Which type of log contains all events logged by programs, as defined by developers?
  • Which IDS is software-based, real-time network intrusion detection system?
  • In Phase 3 Gaining Access, which step is explicitly listed among the actions?
  • Mail Storm refers to
  • What function do beacon frames serve in a Wi‑Fi network?
  • Spamming is defined as sending unsolicited bulk email.
  • Which firewall technology is used to map multiple private addresses to a single public address?
  • Which item is NOT a Data Classification level?
  • Which trend in security refers to malware that targets 64-bit architectures?
  • Which statement is true about Windows log files?
  • Which company developed HFS+ to support Mac OS?
  • Which file system type is designed to store data on a shared disk?
  • Which statement describes the Linux file systems as presented?
  • What are the two modes of attack based on line of attack?
  • Which item is NOT listed as a policy type in the given material?
  • Hidden Manipulation involves which of the following?
  • Which standard is specifically focused on protecting payment card data?
  • OS Logs include which two categories?
  • Which system finds security breaches and manages vulnerabilities?
  • Which process converts encrypted data back into its original form?
  • Which Security Procedure item assigns user privileges as authorized or unauthorized?
  • TLS stands for Transport Layer Security. What is TLS used to achieve?
  • Which IDS is described as a host-based open-source IDS?
  • Which port is used by the SMTP server by default to receive mail?
  • Which action directly supports protection of cookies during transmission?
  • Which statement reflects the focus of technology in information security?
  • Which of the following are VoIP protocols listed?
  • Which component is designed to protect network resources and typically handles traffic between public and private interfaces?
  • Structural metadata describes which aspect of a data object?
  • Which of the following is listed as a security measure for wireless networks?
  • What is the primary purpose of a Trojan?
  • Which Security Procedure item involves analyzing traffic patterns to detect anomalies?
  • What do the scope and limitations of ethical hacking define?
  • Buffer overflow memory vulnerability commonly affects which area of memory?
  • eMailTrackerPro does what?
  • What is the primary function of UrlScan?
  • What is the primary purpose of a digital certificate?
  • Which model has five layers and was developed with protocols that grew up with Internet needs?
  • Voluntary tunneling is defined as what?
  • Which protocol is an extension of PPP used for VPN tunneling?
  • Which option is NOT listed as a technique for bypassing firewalls?
  • What is true about files in the Recycle Bin after you empty it?
  • Which security mechanism provides encryption for data over radio waves in wireless networks?
  • What term refers to data after encryption that is unreadable without the key?
  • Eavesdropping refers to
  • Which practice is the primary defense to prevent injection-type vulnerabilities via user input?
  • Which deployment describes internal LAN VPNs connecting two office LANs via the Internet?
  • Which of the following is a step in the methodology?
  • IP Address Spoofing is best described as what?
  • Which logs contain information about events occurring within an organization's systems and networks?
  • Session sniffing involves which of the following actions?
  • What does 3DES do to increase security?
  • How would you best define a WLAN?
  • Which statement best describes SAN in storage networking?
  • Penetration testing is used to do what?
  • In IDS terms, what describes the situation where the IDS discards packets that the host would normally accept?
  • Which statement about WEP is true?
  • Which type describes mobile data hotspots provided by cellular networks?
  • Social engineering is the art of convincing people to reveal confidential information, especially when they are not aware that it's happening. Which statement best defines social engineering?
  • Which category includes methods such as facial recognition, retina scanning, fingerprinting, and hand geometry?
  • Which technologies are commonly associated with firewalls?
  • Which term covers threats due to many devices connected, including data interruption, data modification, data fabrication, and data interception?
  • IrDA is an acronym for which organization?
  • The Digital Signature Standard (DSS) is associated with which family?
  • A digital certificate serves to bind a public key to the identity information by what process?
  • Compulsory tunneling is defined as which statement?
  • Which protocol provides better encryption algorithms and operates at the Internet layer with tunnel and transport modes?
  • Which capability is listed for OS Forensics?
  • Which of the following is listed as an antivirus tool?
  • Phase 4 Maintaining Access includes which approach to ensure return for more information?
  • Which statement about the fragility of digital evidence is true?
  • When was the first international conference held?
  • Two addressing schemes discussed are LAN Addressing (NIC) and Internet Addressing (IP). Which option lists this correctly?
  • Which statement best describes the primary purpose of firewalking?
  • Triple DES (3DES) increases security by applying DES how many times?
  • What term describes data that can be read and understood without any special effort?
  • A common countermeasure to sniffing is to?
  • Which group is commonly targeted by social engineering?
  • Which statement best defines cyber crime?
  • Which of the following is NOT listed as a type of computer security incident?
  • Which is a network security boundary control that monitors and filters traffic?
  • Which statement correctly describes 802.11g?
  • What does ACL stand for in access control?
  • In the TCP/IP model, where do most processes occur?
  • Which of the following is a typical firewall capability?
  • What is the primary reason social engineering is effective?
  • PPTP is primarily associated with which security function according to the notes?
  • What is a Proxy Server?
  • Network forensics is defined as which of the following?
  • Which practice defends against file injection?
  • DoS stands for?
  • In Phase 5 Covering Tracks, which action is described as part of the phase?
  • Which practice helps limit exposure to sniffing?
  • Which term refers to intercepting network traffic to capture data?
  • Which information security principle ensures data remains accurate and unaltered during transmission or storage?
  • IP spoofing is primarily used to achieve what objective?
  • Which of the following is a type of social engineering?
  • Which policy would regulate internet usage within an organization?
  • What does VPN stand for?
  • What is the purpose of a security policy framework in an organization?
  • Which protocol is widely accepted for sending digitally signed and encrypted messages?
  • Which key length is associated with WPA/WPA2/WPA3?
  • Which option best describes a typical impact of a Denial-of-Service attack?
  • Which technique bypasses physical security by following someone into a restricted area?
  • Which of the following is a stage of the virus life cycle?
  • How are incidents categorized in terms of severity?
  • Which VPN protocol is an extension of PPP and encapsulates information?
  • Which artifact is typically stored by a web browser to speed up loading times?
  • Dumpster diving refers to which practice?
  • Which set of file systems is listed as popular Linux file systems in the material?
  • In private key encryption, which statement is true?
  • Which biometric method uses unique patterns of ridges on the fingertips for identification?
  • Which component performs the initial hardware checks in the system boot sequence?
  • Which layer has hardware components connected and includes ISDN, POTS, and Bluetooth as protocols?
  • L2TP stands for?
  • Digital signatures rely on which type of cryptography?
  • Which statement best describes the rules of evidence?
  • Hidden manipulation is most commonly used on which kind of site?
  • Which role is commonly targeted by social engineering?
  • Which biometric method measures the shape and size of the hand for verification?
  • Which protocol is used for session initiation and multi-sessions between computers?
  • What is the primary use of a VPN concentrator as described?
  • During Phase 3 Gaining Access, which action is described as gaining initial access?
  • Which is the highest level in Data Classification?
  • What are the two categories of signs of an incident?
  • Authentication is described as confirming identity. What does this commonly involve?
  • Which statement best describes a good security countermeasure approach?
  • Which of the following describes a disadvantage of 802.11 as noted?
  • Internal threats are motivated by
  • Which statement describes DES?
  • Which statement best describes ethical hacking?
  • Hacktivism is characterized by which of the following?
  • What is decryption?
  • Buffer overflow occurs when a buffer has been overrun in which memory area?
  • Which statement best defines the type of wireless network that extends a wired network?
  • SAN stands for what category of storage device?
  • Steganography is defined as which of the following?
  • Which statement about infrared-based wireless networks is presented in the material?
  • Which logs record data from network and host-based security software?
  • What is a common limitation of firewalls?
  • Which statement about non-volatile data is true?
  • What is the primary purpose of System Integrity Verifiers (SIV)?
  • In the NFTS architecture chain, which component comes directly after the Master Boot Record?
  • False Positive Generation occurs when the IDS generates an alarm under which condition?
  • Which organization established a forensic lab in 1932?
  • Which item is listed as an unethical use of steganography?
  • Which statement correctly describes OS logs' security-related information?
  • Which statement reflects Increasing Awareness in digital forensics?
  • Which layer provides users access to a network?
  • Which layer makes the data legible in the Application Layer and is not implemented?
  • Which protocol enables users to log on to another computer over the network and must be installed on the remote host?
  • A multi-homed firewall is characterized by having how many interfaces?
  • Denial of Service Attacks are categorized under which broader category?
  • Which statement best describes a challenge of digital evidence?
  • Which algorithms are used behind WPA, WPA2, and WPA3?
  • Which type of file system is designed for storing files on a network file share?
  • External threats originate from where?
  • Which type of information is lost when power is lost?
  • Which protocol is listed under the Physical Layer?
  • What is the primary purpose of incident response?
  • Email Spoofing is
  • Three Processes are Identification, Authentication, and Authorization. What is the correct sequence?
  • Which term is used for mapping wireless networks by traveling with a wireless-sniffing device in a vehicle?
  • OS logs record which of the following?
  • Which concept is commonly associated with enabling authentication, authorization, and accounting for remote-access VPNs?
  • Which standard is commonly associated with the Data Link Layer?
  • Which term describes a sign that occurs before an incident, such as port scanning?
  • Which steps are part of investigating a computer crime?
  • Digest Authentication is described as more secure because what property is used?
  • In the context of injection flaws, attackers are trying to do what?
  • Which of the following is a stage of the virus life cycle?
  • Which term means verifying credentials?
  • Which item is listed as a type of attack that targets vulnerabilities at the application layer?
  • OSSEC is described as which of the following?
  • RSA is best described as?
  • How many layers does the TCP/IP model have?
  • In wireless networking, SSID stands for which term?
  • What does AAA stand for?
  • What is the primary purpose of a Secure Hash Algorithm (SHA)?
  • In information security, which concept is traditionally emphasized as protecting data from unauthorized disclosure?
  • Which tool is a password cracker commonly used in security assessments?
  • Which is a primary role of a firewall?
  • Buffer Overflow is described as the most effective hack because why?
  • Which option is a family of standards for information security management systems?
  • Which statement about RC4, RC5, and RC6 is accurate?
  • Port scanning is used to identify which ports are open. What does this typically help determine?
  • Which statement describes public-key (asymmetric) encryption?
  • What best describes a vulnerability in information security?
  • MD5 processes a variable-length message into a fixed-length output of how many bits?
  • Which attack vector involves malicious software designed to disrupt operations or gain unauthorized access?
  • How many layers does the OSI model have?
  • What is a primary goal of forensic readiness?
  • In file system terminology, what is a cluster best described as?
  • Which statement characterizes 802.11g?
  • Which countermeasure uses a second factor to verify identity?
  • Sguil is built by network security analysts for network security analysts. Which option best describes Sguil?
  • Which type of information remains unchanged when a system is shut down or loses power?
  • Which statement reflects a limitation of firewalls?
  • In Phase 4 Maintaining Access, which action is described to ensure future access?
  • IPsec is commonly used for what in VPNs?
  • Which sequence correctly lists the four sections of a forensic report?
  • What does WTLS stand for?
  • Which statement best describes 802.11 as noted?
  • Hacking is best described as?
  • Which concept involves thinking like an adversary to improve security?
  • Which file system is described as being used as the primary file system in Macintosh?
  • Recover My Email is best described as
  • Which protocol is described as a secure connection to transfer information and uses certificates to authenticate the server?
  • What does SIV stand for?
  • Which term describes monitoring that finds events after they have occurred?
  • In NFTS architecture, which component loads the operating system after the boot sector?
  • Snort is described as which of the following?
  • Which email security solution uses its own digital certificates?
  • Mail Bomb is best described as
  • Web 2.0 technologies are described as database driven.
  • What is a hash function used for in the context of digital signatures?
  • Which statement best describes Computer Forensics?
  • IPsec provides two encryption modes: Tunnel mode and Transport mode. Which option reflects that statement?
  • How many levels are in Data Classification?
  • Impersonation on social networking sites includes activities?
  • What is the primary purpose of a VPN?
  • Webserver Attacks are mostly due to what?
  • Protocol Anomaly Detection: Models are built on TCP/IP protocols using their specs.
  • Phishing is a form of which security threat?
  • What is a Screened Subnet (DMZ) used for in network security?
  • Which tools are mentioned for managing autostart locations?
  • Which statement about MD5 is accurate?
  • SSL stands for Secure Socket Layer. What is SSL primarily used for?
  • Which backup type saves all data regardless of previous backups?
  • Which statement describes a phase that is NOT part of the Hacking Cycle?
  • The Mirai botnet attack targeted which type of devices?
  • ARP Spoofing is associated with which protocol?
  • Which port does IMAP listen on by default?
  • Protected resources should be mapped to which handler?
  • Which service is responsible for sending out mail?
  • General Indications of Intrusion consist of which of the following?
  • Which is described as a host-based open-source IDS?
  • Steganography is often demonstrated by hiding data in which of the following media?
  • Which of the following is a potential risk of frequent false positives in an IDS?
  • A Multi-homed Firewall is configured with multiple network interfaces. Which description best fits it?
  • What describes a Web Services Attack?
  • PKI is best described as which of the following in security architectures?
  • What are common antenna configurations in wireless systems?
  • Which statement best describes an insider attack?
  • Which FAT version range is supported according to the material?
  • What is the effect of a false positive in an intrusion detection system?
  • Which description applies to symmetric key encryption?
  • Bluetooth is an example of which type of wireless technology?
  • Which statement best describes the relationship between VPN and the Internet?
  • What key lengths does WEP use according to the source material?
  • In the context of MAX Security for wireless LAN, which measure is suggested?
  • Authorization is defined as what?
  • Which of the following is listed as a common target among social engineering scenarios?
  • TCP session hijacking occurs when a hacker takes over what?
  • Which option is a major standard family for information security management systems?
  • Recuva is a tool used for what?
  • Which term describes the range of authentication factors including single, two, or multi-factor approaches?
  • What is EventLog Analyzer primarily used for?
  • Which protocol transfers data packets as UDP messages for authentication, authorization, and accounting?
  • Web Applications are described as providing what?
  • Which process makes data difficult to read without appropriate knowledge?
  • A Trojan is best described as
  • Which boot loader enables booting of multiple operating systems on a Linux system?
  • What term describes actions to detect and prevent unauthorized access of a network?
  • Which utility is cited as a method to retrieve Windows event records?
  • IDS stands for which of the following?
  • Technical Steganography is best described as which of the following?
  • Which trend in security includes techniques for evading detection by malware researchers?
  • Which combination of techniques is commonly used by IDS for detection?
  • Which detects intrusion based on fixed behavioral characteristics of the users and components in a computer system?
  • When selecting backup media, which factors are considered?
  • Web Service Attacks are associated with which type of vulnerability?
  • Digital evidence can be found in which of the following?
  • Which category includes facial recognition, retina scanning, fingerprinting, and hand geometry as verification methods?
  • IKE is used in Cisco IPSec standards and provides what?
  • What term refers to the set of rules for communication, including a protocol stack?
  • Enumeration information is typically gathered to reveal which of the following?
  • Windows log files are categorized into which three types?
  • Phase 1 - Reconnaissance: What is attacker seeking to do?
  • Which technique is a form of human-based social engineering?
  • Enumeration is defined as what in network security terms?
  • Identification is defined as a way of proving genuineness of the user. Which term describes this?
  • Which protocol secures a connection to transfer information and uses digital certs to authenticate the server?
  • Which layer establishes and manages communication sessions between hosts?
  • Which of the following is a valid log category for security software?
  • Which term means only authorized users?
  • Which area runs applications and user processes outside the kernel, providing the environment in which most software operates?
  • What does the ClearPageFileAtShutdown setting instruct the operating system to do?
  • Which term means not disclosed to unauthorized users?
  • IPsec is described as a set of protocols devised by which organization?
  • Which term means legitimate users have access?
  • Which is the initial stage in the digital evidence examination process?
  • Which VPN protocol uses IPsec to encrypt information?
  • What does VPN stand for?
  • Which Security Procedure item counters Man-in-the-Middle attacks?
  • Which of the following is a non-electric attack method used to obtain information?
  • Cookie Snooping is primarily used for what purpose?
  • Which statement best describes data integrity?
  • What does AP stand for in networking?
  • Internal threats originate from where?
  • Which of the following is a major file system?
  • Which is NOT a characteristic of digital evidence?
  • Default passwords are typically supplied by whom?
  • Which tool is used to access and manage the Windows Registry?
  • What is the process of identifying the systems, open ports, and services running in a network called?
  • Which backup method is described as Nearline?
  • Which organization sets Wi-Fi standards?
  • Which practice is best described as social engineering?
  • Kerberos is an authentication protocol that provides which credential to an authority?
  • Which layer establishes paths for data transfer and uses routers and IP addresses?
  • Which concept describes the overall goal of preventing unauthorized access to networks?
  • Which statement best defines Forensic Science?
  • What is the process called when an attacker confuses an intrusion detection system by forcing it to read invalid packets?
  • Which cipher replaces blocks of plaintext with ciphertext?
  • Which biometric method analyzes facial features for identity verification?
  • Which option best describes what incident reporting should include?
  • DisableLastAccess relates to modifying last access tracking using which Windows components?
  • Denial-of-Service Attack is defined as which of the following?
  • Which description applies to asymmetric key encryption?
  • In denial-of-service attacks, which form is described as the most common?
  • What does 'IP Address in Place of URL' refer to?
  • What does WEP stand for in wireless security?
  • Which statement accurately describes Residual Data?
  • Which protocol is used for session establishment between computers, especially for initiating calls?
  • Why do switches help reduce sniffing?
  • Which action is the appropriate countermeasure for directory traversal vulnerabilities?
  • Which field derives its name from Greek words kryptos and graphia and involves converting data into scrambled code?
  • Which statement best describes steganography?
  • AAA stands for?
  • Which statement about RC4 is true?
  • Which category listed among the file system types includes systems designed for specialized tasks?
  • Which of the following is NOT listed as a steganography cover medium?
  • Digest Authentication is described as more secure because the password is what?
  • Which describes a rogue access point attack?
  • Which level corresponds to Proprietary information?
  • DES uses a key of what size?
  • Which email encryption tool uses its own digital certificates rather than CA-issued ones?
  • Which tool is a UNIX program used to listen to ARP replies?
  • Obfuscating is used to accomplish which of the following?
  • Which term describes two categories of tunneling protocols based on how tunnels are established?
  • Zero Day is best described as?
  • A file system is primarily used to store data in which way?
  • Which of the following is listed as a wireless security protocol?
  • Which category of wireless threats aims to penetrate a network by evading WLAN access control measures?
  • L2TP operates at which layer of the OSI model as described?
  • Which file system is described as the New Technology File System?
  • Validation Authorities (VAs) are responsible for what in the PKI ecosystem?
  • Which algorithm is known as the Advanced Encryption Standard?
  • Where is an IDS typically deployed?
  • Which statement best describes encryption?
  • What does FAT stand for?
  • Which of the following is NOT listed as a type of authentication?
  • Which of the following is a countermeasure for ARP spoofing?
  • H.323 supports which type of communication?
  • Which statement about password cracking is true?
  • What practice is recommended for LDAP security?
  • Which term refers to data consistency?
  • In steganography, hidden information is commonly embedded in what type of media?
  • Which physical layers are defined by the 802.11 standard?
  • Which biometric method uses unique patterns in the retina for verification?
  • Which countermeasure is commonly used to deter social engineering?
  • AutoRuns is described as having what characteristic regarding startup locations?
  • Which of the following is a benefit of forensic readiness?
  • Which area contains the core operating system components and device drivers that interact directly with hardware?
  • What is a defining feature of a block cipher?
  • Which groups are commonly involved as cyber criminals?
  • Which of the following describes typical IDS characteristics?
  • Which of the following is NOT listed as a stage in the virus life cycle?
  • Which term describes a storage device that provides network-attached data storage accessible over Ethernet?
  • Which statement about DMZ (Screened Subnet) is true?
  • Protocol Anomaly Detection models are built on TCP/IP protocols using their specs?
  • Which term is also known as misuse detection?
  • Which targeted phishing technique is aimed at executives or high-level targets?
  • CART stands for which of the following?
  • Which items are listed as Information as a Business Asset?
  • In the evolution of computer forensics, which event occurred earliest?
  • Trojan Horse is best described as which of the following?
  • Which backup method is performed while the system remains online and accessible?
  • PKI is described as what in security architectures?
  • PPTP stands for?
  • What is an operational advantage of deploying firewalls?
  • Which term refers to announcements generated by services in response to access attempts?
  • In the simplified OSI layering, which layer is described as the Media Layer, explaining how packets move from one point to another?
  • What is sniffing in networking?
  • Which statement about VPN security is accurate?
  • Which organizations typically deal with computer security incidents?
  • What does War Chalking refer to?
  • Impersonation on social networks involves activities?
  • Which is a typical function of a firewall?
  • Which algorithm is NOT part of the SHA family?
  • In Phase 2 Scanning, which tool is listed for extracting information such as IP addresses?
  • Injection Flaws include which types of injection?
  • Which statement about Windows Event Logs is noted in the material?
  • In the simplified OSI layering, which layer is described as the Host Layer, describing what's happening at the end device?
  • Which statement best describes VPN via SSH and PPP in the notes?
  • Which statement BEST describes a data policy?
  • Which type of network is most commonly found in homes?
  • Which of the following is NOT listed as a type of social engineering?
  • Which statement best describes public key encryption?
  • What is a recommended action to fix security misconfiguration?
  • Which of the following is a VPN protocol mentioned in the secure network protocols?
  • Which statement describes private key encryption?
  • Which transmission means is commonly used by viruses?
  • Afflib is best described as?
  • Which describes Denial of Service Attacks?
  • Which protocol was developed by Netscape and is the foundation for secure web transactions?
  • Which of the following is a limitation of intrusion detection systems?
  • Metadata is defined as which of the following?
  • For cookie or session poisoning, which practice is recommended?
  • Which statement about SSID is true?
  • What does a stream cipher do?
  • Which of the following is a common type of hacker?
  • Which statement accurately lists all five Data Classification levels?
  • MD5 has been replaced by SHA3.
  • What does HTTPS stand for?
  • Which capability is part of OS forensics?
  • The Hacking Cycle includes which sets of phases?
  • Which item is a type of attack listed under Types of Attacks?
  • In a data backup strategy, which action helps ensure recoverability after a failure?
  • Which security technologies are mentioned for wireless security?
  • Which of the following is NOT a type of metadata?
  • What are Anonymous Website Surfing Sites?
  • Which statement describes the CIA triangle restrictions in information security?
  • Which countermeasure addresses insufficient transport layer protection?
  • Which layer encodes and decodes data packets into bits and has two sub-layers?
  • IOCE stands for which organization?
  • How many sub-layers does the Data Link Layer have?
  • L2TP operates at which layer?
  • Which of the following is a layer in the TCP/IP model?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy