Skip to content

ECSS Practice Questions

Prepare for ECSS with more than an answer.

197 questions in the full set20 sample questionsUpdated Jan 26, 2026
Exam fee
$250 USD
Level
Entry-Level
Valid for
3 years
Domains covered on the exam 3
  1. Network Defense Essentials36%
  2. Ethical Hacking Essentials33%
  3. Digital Forensics Essentials31%
  1. 1

    True or False: When conducting a forensic investigation of a live Linux system, the first step should always be to power down the machine to preserve the state of the hard disk.

    Show answer details

    Correct answer: B

    This statement is false. Powering down a live system immediately destroys all volatile data stored in RAM, such as running processes, network connections, active user sessions, and encryption keys. The correct procedure for live forensics is to follow the order of volatility, collecting the most volatile data (RAM, CPU cache) first before moving on to less volatile data (hard disk) and eventually powering down the system.

  2. 2

    A security architect is designing a network for a new branch office. The design requires that guest wireless traffic be completely isolated from the corporate network and have direct, filtered access to the internet. The corporate wireless network needs to enforce strong user authentication and provide access to internal resources. Which of the following is the BEST way to configure the wireless access points to meet these requirements?

    Show answer details

    Correct answer: B

    The best practice for isolating traffic is to use Virtual LANs (VLANs). By creating two separate SSIDs and mapping each to a different VLAN, the traffic is logically separated at Layer 2. The guest VLAN can then be routed directly to the internet through a firewall, while the corporate VLAN can be routed to internal resources with appropriate security policies. This provides robust segmentation that cannot be easily bypassed.

  3. 3

    A security auditor is reviewing a web application's code and discovers the following SQL query being executed:

    String query = "SELECT * FROM users WHERE username = '" + userName + "' AND password = '" + password + "';";

    What vulnerability is present in this code, and what is a potential consequence?

    Show answer details

    Correct answer: B

    The code is directly concatenating user-supplied input (userName and password) into a SQL query. This is a classic SQL Injection vulnerability. An attacker could provide a specially crafted input, such as ' OR '1'='1, to alter the query's logic, potentially bypassing authentication. The proper way to prevent this is by using parameterized queries (prepared statements).

  4. 4

    An incident response team is investigating a malware infection on a user's workstation. They have performed a static analysis of the malicious executable, but need to understand its behavior when it runs. They decide to execute the malware in a controlled environment to observe its interactions with the file system, registry, and network. What is this process called?

    Show answer details

    Correct answer: C

    Dynamic malware analysis involves running the malware in a safe, isolated environment (a sandbox) to observe its behavior in real-time. This allows analysts to see what files it creates, what registry keys it modifies, and what network connections it attempts to make. This is contrasted with static analysis, which involves examining the code without executing it.

  5. 5

    Case Study:

    A regional bank, 'SecureTrust Bank,' is updating its network security architecture to better protect customer data and comply with financial regulations. The current architecture is flat, with all servers, workstations, and critical systems residing on the same large subnet. The security team has identified this as a major risk, as a single compromised workstation could lead to an attacker moving laterally to the core banking servers without restriction.

    The bank's requirements are to segment the network into distinct security zones, control traffic flow between these zones with granular policies, and implement a centralized monitoring solution to detect anomalous activity. The new design must isolate the core banking systems, the public-facing web servers, and the corporate user workstations into separate zones. The solution must be highly available and support stateful inspection.

    Which of the following architectural designs BEST meets SecureTrust Bank's requirements?

    graph TD subgraph Legend direction LR FW((Firewall)) WS[Workstations] WEB[Web Servers] CBS[(Core Banking)] end Internet --> FW_A[Firewall] FW_A --> WEB_A[Web Servers] WEB_A --> CBS_A[(Core Banking)] FW_A --> WS_A[Workstations] WS_A --> CBS_A

    Show answer details

    Correct answer: B

    This design directly addresses all requirements. Using an HA pair of NGFWs provides high availability and stateful inspection. Creating separate zones (DMZ, Core, Corporate) achieves the required segmentation. The NGFWs provide the capability for granular policy enforcement between zones, which is more robust than simple ACLs. While VLANs with ACLs provide some segmentation, they lack the stateful inspection and advanced threat detection capabilities of an NGFW. A single firewall is a single point of failure. Host-based firewalls are important but do not provide network-level segmentation and control.

  6. 6

    A hospital is redesigning its network to comply with HIPAA regulations, which require stringent protection of Electronic Protected Health Information (ePHI). The security architect has proposed a multi-layered defense strategy. Which of the following sets of controls BEST represents the implementation of a defense-in-depth strategy for protecting ePHI stored on an internal server?

    Show answer details

    Correct answer: D

    Defense-in-depth is a strategy that employs multiple layers of security controls to protect assets. The correct option describes four distinct layers: network (segmentation), host (HIDS), data (encryption), and application/user (RBAC). Each of the other options represents only a single layer of security. While valuable, a single control does not constitute a defense-in-depth strategy on its own.

  7. 7

    A security analyst is investigating a series of failed login attempts on a critical database server followed by a single successful login from an unrecognized IP address. To determine the scope of the potential breach, the analyst needs to correlate logs from multiple sources. Which security technology is specifically designed to aggregate, correlate, and analyze log data from various network devices and systems to provide a unified view of security events?

    Show answer details

    Correct answer: B

    A Security Incident and Event Management (SIEM) system is the core technology for collecting and correlating log data from diverse sources like firewalls, servers, and applications. Its primary function is to provide real-time analysis of security alerts generated by network hardware and applications. NIDS only monitors network traffic, DLP focuses on preventing data exfiltration, and a honeypot is a decoy system.

  8. 8

    During a penetration test, an ethical hacker successfully compromises a web server in the company's DMZ. The goal is to pivot from the DMZ to the internal corporate network. The ethical hacker discovers that the compromised web server makes regular database connections to a server on the internal network. Which of the following techniques would be the most effective and stealthy method to establish a foothold in the internal network?

    Show answer details

    Correct answer: C

    Tunneling C2 traffic through an already allowed and expected connection (like a database port) is a classic pivoting technique. It is highly effective and stealthy because the traffic appears legitimate to firewalls and basic monitoring systems. A full Nmap scan is extremely noisy and would likely be detected. Sniffing might work, but it's passive and depends on cleartext protocols. A brute-force attack is also noisy and inefficient.

  9. 9

    A forensic investigator is tasked with creating a bit-for-bit, forensically sound image of a 1TB hard drive from a suspect's computer. The investigator is concerned about maintaining the integrity of the evidence and being able to prove in court that the acquired image is an exact copy of the original drive. Which of the following is the MOST critical step in the data acquisition process to ensure the integrity of the forensic image?

    Show answer details

    Correct answer: C

    Generating and verifying cryptographic hashes is the standard and most critical method to prove that a forensic image is an exact bit-for-bit copy of the original source. A hash is calculated for the source drive before imaging and for the destination image file after imaging. If the hashes match, it provides mathematical proof of integrity. While using a write-blocker is essential to prevent modification and documentation is part of the chain of custody, only hash verification proves the copy is identical.

  10. 10

    A company is implementing a new wireless network for its corporate office. The security team wants to implement the highest level of security available to protect against common wireless attacks. Which of the following configurations provides the strongest security for the new wireless network? (Select TWO).

    Show answer details

    Correct answer: C, E

    WPA3 is the latest and most secure wireless protocol, offering significant improvements over WPA2, including protection against offline dictionary attacks. 802.1X (often used with WPA3-Enterprise) provides robust, individual user authentication via a RADIUS server, which is far more secure than a shared password (PSK).

    WPA3 is the latest and most secure wireless protocol, offering significant improvements over WPA2, including protection against offline dictionary attacks. 802.1X (often used with WPA3-Enterprise) provides robust, individual user authentication via a RADIUS server, which is far more secure than a shared password (PSK).

Create an account to continue.