Skip to content

ECSAv10 Certified Security Analyst (ECSA v10) Practice Questions

Prepare for ECSAv10 with more than an answer.

396 questions in the full set20 sample questionsUpdated Jan 26, 2026
Exam fee
$1199 USD
Level
Professional
Valid for
3 years
Domains covered on the exam 13
  1. Penetration Testing Essential Concepts20.72%
  2. Introduction to Penetration Testing Methodologies5.63%
  3. Penetration Testing Scoping and Engagement Methodology5.38%
  4. Open-Source Intelligence (OSINT) Methodology4.8%
  5. Social Engineering Penetration Testing Methodology5.26%
  6. Network Penetration Testing Methodology - External5.84%
  7. Network Penetration Testing Methodology - Internal8.62%
  8. Network Penetration Testing Methodology - Perimeter Devices7.84%
  9. Web Application Penetration Testing Methodology11.3%
  10. Database Penetration Testing Methodology5.1%
  11. Wireless Penetration Testing Methodology9.22%
  12. Cloud Penetration Testing Methodology4.65%
  13. Report Writing and Post Testing Actions5.63%
  1. 1

    James is an attacker who wants to attack XYZ Inc. He has performed reconnaissance over all the publicly available resources of the company and identified the official company website http://xyz.com. He scanned all the pages of the company website to find for any potential vulnerabilities to exploit. Finally, in the user account login page of the company’s website, he found a user login form which consists of several fields that accepts user inputs like username and password. He also found than any non-validated query that is requested can be directly communicated to the active directory and enable unauthorized users to obtain direct access to the databases. Since James knew an employee named Jason from XYZ Inc., he enters a valid username “jason and injects “jason)) in the username field. In the password field, James enters “blah and clicks Submit button. Since the complete URL string entered by James becomes “USER=jason))(PASS=blah)), only the first filter is processed by the Microsoft Active Directory, that is, the query “USER=jason)) is processed. Since this query always stands true, James successfully logs into the user account without a valid password of Jason.

    In the above scenario, identify the type of attack performed by James?

    Show answer details

    Correct answer: B

    B

  2. 2

    An organization has deployed a web application that uses encoding technique before transmitting the data over the Internet. This encoding technique helps the organization to hide the confidential data such as user credentials, email attachments, etc. when in transit. This encoding technique takes 3 bytes of binary data and divides it into four chunks of 6 bits. Each chunk is further encoded into respective printable character.

    Identify the encoding technique employed by the organization?

    Show answer details

    Correct answer: B

    B

  3. 3

    During an internal network audit, you are asked to see if there is any RPC server running on the network and if found, enumerate the associate RPC services.

    Which port would you scan to determine the RPC server and which command will you use to enumerate the RPC services?

    Show answer details

    Correct answer: A

    A

  4. 4

    The penetration testing team of MirTech Inc. identified the presence of various vulnerabilities in the web application coding. They prepared a detailed report addressing to the web developers regarding the findings. In the report, the penetration testing team advised the web developers to avoid the use of dangerous standard library functions. They also informed the web developers that the web application copies the data without checking whether it fits into the target destination memory and is susceptible in supplying the application with large amount of data.

    According to the findings by the penetration testing team, which type of attack was possible on the web application?

    Show answer details

    Correct answer: A

    A

  5. 5

    A penetration tester is attempting to bypass a network firewall that performs stateful packet inspection but does not perform deep packet inspection on DNS traffic. The tester has established a foothold on a compromised machine inside the network. The goal is to exfiltrate a small file containing sensitive data. Which of the following techniques would be most effective for bypassing the firewall under these specific conditions?

    graph TD Attacker[Attacker C2] -- Internet -- FW[Firewall] subgraph Internal Network CompromisedHost[Compromised Host] DNSServer[Internal DNS Server] end FW -- Allows Port 53 --> DNSServer CompromisedHost -- Exfiltration Tunnel --> DNSServer
    Show answer details

    Correct answer: D

    The key condition is that the firewall allows DNS traffic (port 53) and does not perform deep packet inspection on it. This makes DNS tunneling the ideal exfiltration method. The tester can encode the file data into a series of DNS queries (e.g., [encoded_data].c2.attacker.com). These queries are sent from the compromised host to the internal DNS server, which forwards them out through the firewall to the attacker's authoritative DNS server. The firewall sees this as legitimate DNS traffic. The attacker's server receives the queries, decodes the data, and reconstructs the file.

  6. 6

    Irin is a newly joined penetration tester for XYZ Ltd. While joining, as a part of her training, she was instructed about various legal policies and information securities acts by her trainer. During the training, she was informed about a specific information security act related to the conducts and activities like it is illegal to perform DoS attacks on any websites or applications, it is illegal to supply and own hacking tools, it is illegal to access unauthorized computer material, etc.

    To which type of information security act does the above conducts and activities best suit?

    Show answer details

    Correct answer: A

    A

  7. 7

    Adam is an IT administrator for Syncan Ltd. He is designated to perform various IT tasks like setting up new user accounts, managing backup/restores, security authentications and passwords, etc. Whilst performing his tasks, he was asked to employ the latest and most secure authentication protocol to encrypt the passwords of users that are stored in the Microsoft Windows OS-based systems.

    Which of the following authentication protocols should Adam employ in order to achieve the objective?

    Show answer details

    Correct answer: C

    C

  8. 8

    Michael, a Licensed Penetration Tester, wants to create an exact replica of an original website, so he can browse and spend more time analyzing it.

    Which of the following tools will Michael use to perform this task?

    Show answer details

    Correct answer: C

    C

  9. 9

    A hacker initiates so many invalid requests to a cloud network host that the host uses all its resources responding to invalid requests and ignores the legitimate requests.

    Identify the type of attack

    Show answer details

    Correct answer: A

    A

  10. 10

    Thomas is an attacker and he skimmed through the HTML source code of an online shopping website for the presence of any vulnerabilities that he can exploit. He already knows that when a user makes any selection of items in the online shopping webpage, the selection is typically stored as form field values and sent to the application as an HTTP request (GET or POST) after clicking the Submit button. He also knows that some fields related to the selected items are modifiable by the user (like quantity, color, etc.) and some are not (like price). While skimming through the HTML code, he identified that the price field values of the items are present in the HTML code. He modified the price field values of certain items from $200 to $2 in the HTML code and submitted the request successfully to the application.

    Identify the type of attack performed by Thomas on the online shopping website?

    Show answer details

    Correct answer: C

    C

Create an account to continue.