ECSS Sample Questions

ECSS Sample Questions & Answers

Network security fundamentals and identification, authentication, and authorization make up the largest share, alongside ethical-hacking basics like vulnerability assessment and password cracking, and the fundamentals of computer forensics investigation.

Launch the full ECSS simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Ethical Hacking Essentials · Ethical Hacking Fundamentals

    True or False: In the context of the Cyber Kill Chain methodology, the 'Weaponization' phase involves the attacker actively scanning the target's network to find vulnerabilities.

    Show answer & explanation

    Correct answer: B

    This statement is false. The 'Weaponization' phase involves coupling an exploit with a payload (e.g., a remote access trojan) to create a deliverable malicious tool. The act of scanning the target's network to find vulnerabilities occurs during the 'Reconnaissance' and 'Scanning' phases, which precede weaponization.

  2. Question 2Intermediate

    Digital Forensics Essentials · Windows Forensics

    A digital forensics analyst is examining a Windows 10 system and needs to find evidence of files that were recently opened by a user. The user has cleared their browser history and deleted the files from the Recycle Bin. Which of the following artifacts would be the MOST likely place to find residual evidence of recently accessed files and applications?

    Show answer & explanation

    Correct answer: C

    Windows automatically creates LNK (shortcut) files and Jump Lists to track recently opened files and applications for user convenience. These artifacts persist even after files are deleted and history is cleared, providing a valuable timeline of user activity. The Security event log tracks security-related events like logons, the SAM hive stores user password hashes, and the System32 directory contains core system files, not user activity logs.

  3. Question 3Beginner

    Network Defense Essentials · Network Security Fundamentals

    A small e-commerce company wants to ensure the confidentiality and integrity of customer data transmitted between their web server and users' browsers. They also want to provide assurance to customers that they are connected to the legitimate company server. Which network security protocol is essential for achieving these goals?

    Show answer & explanation

    Correct answer: D

    Transport Layer Security (TLS), the protocol that underpins HTTPS, is designed specifically for this purpose. It encrypts data in transit (confidentiality), uses message authentication codes to prevent tampering (integrity), and uses digital certificates to authenticate the server to the client. SSH is for secure remote administration, FTP is insecure for file transfers, and IPsec operates at the network layer, typically for VPNs.

  4. Question 4IntermediateSelect 2

    Ethical Hacking Essentials · Social Engineering Techniques and Countermeasures

    An attacker sends a spear-phishing email to a high-level executive. The email contains a malicious macro in a Word document disguised as an urgent financial report. The executive opens the document, enabling the macro, which then downloads and executes a Remote Access Trojan (RAT). Which two social engineering principles were MOST likely exploited in this attack? (Select TWO).

    Show answer & explanation

    Correct answers: A, D

    The email was disguised as an 'urgent' report, creating a sense of urgency to bypass rational thinking. The attack also leverages authority, as financial reports are typically important and come from authoritative sources, making the executive more likely to comply.

    The email was disguised as an 'urgent' report, creating a sense of urgency to bypass rational thinking. The attack also leverages authority, as financial reports are typically important and come from authoritative sources, making the executive more likely to comply.

  5. Question 5Advanced

    Digital Forensics Essentials · Network Forensics

    A forensic investigator is analyzing network traffic captures (PCAP files) related to a suspected data breach. The investigator observes a large amount of outbound traffic to an unknown IP address, encrypted with TLS. To understand what data might have been exfiltrated, the investigator needs to decrypt this traffic. What essential piece of information is required to decrypt the captured TLS sessions?

    Show answer & explanation

    Correct answer: C

    To decrypt a TLS session captured in a PCAP file (assuming a cipher suite like RSA was used for key exchange), the investigator needs the server's private key. The private key is used to decrypt the pre-master secret exchanged during the TLS handshake, which then allows the investigator's tool (like Wireshark) to derive the symmetric session keys and decrypt the application data. The public key is publicly available and cannot be used for decryption. The session key itself is what needs to be derived.

  6. Question 6Intermediate

    Network Defense Essentials · Mobile Device Security

    A company is adopting a 'Bring Your Own Device' (BYOD) policy but is concerned about corporate data security on employee-owned devices. They want to ensure that corporate applications and data are isolated from personal apps and data, and that they can selectively wipe only the corporate data if a device is lost or an employee leaves the company. Which mobile security solution BEST meets these requirements?

    Show answer & explanation

    Correct answer: B

    Mobile Application Management (MAM) with containerization is the ideal solution for BYOD scenarios. It creates a secure, encrypted container on the device that isolates corporate apps and data. This allows the company to enforce policies (like copy-paste restrictions) and perform a selective wipe of only the container without affecting the user's personal data. Full MDM gives control over the entire device, which is often too intrusive for BYOD. Geofencing restricts functionality by location, and a VPN only secures the connection.

  7. Question 7Beginner

    Ethical Hacking Essentials · Password Cracking Techniques and Countermeasures

    A penetration tester is attempting to crack a password hash obtained from a Linux /etc/shadow file. The tester has a powerful GPU and a large wordlist. Which of the following tools is specifically designed to leverage the power of GPUs for high-speed password cracking and would be the most efficient choice?

    Show answer & explanation

    Correct answer: D

    Hashcat is a world-renowned password recovery tool that is highly optimized for GPU-based cracking, making it significantly faster than CPU-based tools for this task. While John the Ripper can crack passwords (and has some GPU support), Hashcat is generally considered the superior tool for leveraging GPU power. Nmap is a network scanner, and Metasploit is an exploitation framework.

  8. Question 8Beginner

    Digital Forensics Essentials · Defeating Anti-forensics Techniques

    A forensic analyst is investigating a case of intellectual property theft. The suspect is believed to have hidden stolen design documents inside seemingly innocuous image files that were then emailed out of the company. What anti-forensics technique has the suspect likely used?

    Show answer & explanation

    Correct answer: B

    Steganography is the practice of concealing a file, message, image, or video within another file, message, image, or video. Hiding documents inside image files is a classic example of steganography. Encryption scrambles data but doesn't hide its existence. Data wiping securely erases data, and trail obfuscation involves altering logs to hide activities.

  9. Question 9Advanced

    Network Defense Essentials · Cryptography and PKI

    A security team is configuring a Public Key Infrastructure (PKI) for their organization. An employee attempts to access a secure internal website, and their browser receives the website's digital certificate. The browser needs to verify that the certificate has not been revoked by the Certificate Authority (CA). Which mechanism provides the MOST efficient, real-time method for checking a certificate's revocation status?

    Show answer & explanation

    Correct answer: B

    The Online Certificate Status Protocol (OCSP) is designed to provide real-time revocation status for a single certificate without requiring the client to download a potentially large list. The browser sends a query to an OCSP responder and gets a direct, signed response of 'good', 'revoked', or 'unknown'. A CRL is a list of all revoked certificates that must be downloaded and parsed, which can be slow and is not real-time (it's only as current as its last publication). OCSP Stapling is an optimization of OCSP but OCSP is the underlying protocol. Key escrow relates to key recovery, not revocation status.

  10. Question 10Beginner

    Ethical Hacking Essentials · Web Application Attacks and Countermeasures

    An attacker is targeting a web application's login form. Instead of trying to guess passwords for a known username, the attacker uses a list of common passwords and tries each one against a large list of usernames. What is this type of attack called?

    Show answer & explanation

    Correct answer: C

    This technique is known as password spraying. It is a 'low-and-slow' method where an attacker tries one or a few common passwords against many different accounts. This helps to avoid account lockouts that would typically occur if many incorrect passwords were tried against a single account (a standard brute-force or dictionary attack).

Ready for the real thing?

The full ECSS simulator has every exam-style question, timed mode, and instant scoring.

Go to the ECSS simulator →