Free ECSS sample questions
Real questions from the Certified Security Specialist (ECSS v9) practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
A security analyst is investigating a series of failed login attempts on a critical database server followed by a single successful login from an unrecognized IP address. To determine the scope of the potential breach, the analyst needs to correlate logs from multiple sources. Which security technology is specifically designed to aggregate, correlate, and analyze log data from various network devices and systems to provide a unified view of security events?
During a penetration test, an ethical hacker successfully compromises a web server in the company's DMZ. The goal is to pivot from the DMZ to the internal corporate network. The ethical hacker discovers that the compromised web server makes regular database connections to a server on the internal network. Which of the following techniques would be the most effective and stealthy method to establish a foothold in the internal network?
A forensic investigator is tasked with creating a bit-for-bit, forensically sound image of a 1TB hard drive from a suspect's computer. The investigator is concerned about maintaining the integrity of the evidence and being able to prove in court that the acquired image is an exact copy of the original drive. Which of the following is the MOST critical step in the data acquisition process to ensure the integrity of the forensic image?
A company is implementing a new wireless network for its corporate office. The security team wants to implement the highest level of security available to protect against common wireless attacks. Which of the following configurations provides the strongest security for the new wireless network? (Select TWO).
True or False: In the context of the Cyber Kill Chain methodology, the 'Weaponization' phase involves the attacker actively scanning the target's network to find vulnerabilities.
A digital forensics analyst is examining a Windows 10 system and needs to find evidence of files that were recently opened by a user. The user has cleared their browser history and deleted the files from the Recycle Bin. Which of the following artifacts would be the MOST likely place to find residual evidence of recently accessed files and applications?
A small e-commerce company wants to ensure the confidentiality and integrity of customer data transmitted between their web server and users' browsers. They also want to provide assurance to customers that they are connected to the legitimate company server. Which network security protocol is essential for achieving these goals?
An attacker sends a spear-phishing email to a high-level executive. The email contains a malicious macro in a Word document disguised as an urgent financial report. The executive opens the document, enabling the macro, which then downloads and executes a Remote Access Trojan (RAT). Which two social engineering principles were MOST likely exploited in this attack? (Select TWO).
A forensic investigator is analyzing network traffic captures (PCAP files) related to a suspected data breach. The investigator observes a large amount of outbound traffic to an unknown IP address, encrypted with TLS. To understand what data might have been exfiltrated, the investigator needs to decrypt this traffic. What essential piece of information is required to decrypt the captured TLS sessions?
10 more free samples are waiting
Create a free account to unlock the whole ECSS sample bank, or get full access to all 197 practice questions in the simulator.