Certified Security Specialist (ECSS v9) Free Sample Questions

20 free sample questions197 in the full practice test

Try simulator

ECSS Sample Questions

  1. Question 1

    A hospital is redesigning its network to comply with HIPAA regulations, which require stringent protection of Electronic Protected Health Information (ePHI). The security architect has proposed a multi-layered defense strategy. Which of the following sets of controls BEST represents the implementation of a defense-in-depth strategy for protecting ePHI stored on an internal server?

    Answer and explanation

    Correct answer: D

    Defense-in-depth is a strategy that employs multiple layers of security controls to protect assets. The correct option describes four distinct layers: network (segmentation), host (HIDS), data (encryption), and application/user (RBAC). Each of the other options represents only a single layer of security. While valuable, a single control does not constitute a defense-in-depth strategy on its own.

  2. Question 2

    A security analyst is investigating a series of failed login attempts on a critical database server followed by a single successful login from an unrecognized IP address. To determine the scope of the potential breach, the analyst needs to correlate logs from multiple sources. Which security technology is specifically designed to aggregate, correlate, and analyze log data from various network devices and systems to provide a unified view of security events?

    Answer and explanation

    Correct answer: B

    A Security Incident and Event Management (SIEM) system is the core technology for collecting and correlating log data from diverse sources like firewalls, servers, and applications. Its primary function is to provide real-time analysis of security alerts generated by network hardware and applications. NIDS only monitors network traffic, DLP focuses on preventing data exfiltration, and a honeypot is a decoy system.

  3. Question 3

    During a penetration test, an ethical hacker successfully compromises a web server in the company's DMZ. The goal is to pivot from the DMZ to the internal corporate network. The ethical hacker discovers that the compromised web server makes regular database connections to a server on the internal network. Which of the following techniques would be the most effective and stealthy method to establish a foothold in the internal network?

    Answer and explanation

    Correct answer: C

    Tunneling C2 traffic through an already allowed and expected connection (like a database port) is a classic pivoting technique. It is highly effective and stealthy because the traffic appears legitimate to firewalls and basic monitoring systems. A full Nmap scan is extremely noisy and would likely be detected. Sniffing might work, but it's passive and depends on cleartext protocols. A brute-force attack is also noisy and inefficient.

  4. Question 4

    A forensic investigator is tasked with creating a bit-for-bit, forensically sound image of a 1TB hard drive from a suspect's computer. The investigator is concerned about maintaining the integrity of the evidence and being able to prove in court that the acquired image is an exact copy of the original drive. Which of the following is the MOST critical step in the data acquisition process to ensure the integrity of the forensic image?

    Answer and explanation

    Correct answer: C

    Generating and verifying cryptographic hashes is the standard and most critical method to prove that a forensic image is an exact bit-for-bit copy of the original source. A hash is calculated for the source drive before imaging and for the destination image file after imaging. If the hashes match, it provides mathematical proof of integrity. While using a write-blocker is essential to prevent modification and documentation is part of the chain of custody, only hash verification proves the copy is identical.

  5. Question 5

    Multiple answers

    A company is implementing a new wireless network for its corporate office. The security team wants to implement the highest level of security available to protect against common wireless attacks. Which of the following configurations provides the strongest security for the new wireless network? (Select TWO).

    Answer and explanation

    Correct answers: C, E

    WPA3 is the latest and most secure wireless protocol, offering significant improvements over WPA2, including protection against offline dictionary attacks. 802.1X (often used with WPA3-Enterprise) provides robust, individual user authentication via a RADIUS server, which is far more secure than a shared password (PSK).

  6. Question 6

    True or False: In the context of the Cyber Kill Chain methodology, the 'Weaponization' phase involves the attacker actively scanning the target's network to find vulnerabilities.

    Answer and explanation

    Correct answer: B

    This statement is false. The 'Weaponization' phase involves coupling an exploit with a payload (e.g., a remote access trojan) to create a deliverable malicious tool. The act of scanning the target's network to find vulnerabilities occurs during the 'Reconnaissance' and 'Scanning' phases, which precede weaponization.

  7. Question 7

    A digital forensics analyst is examining a Windows 10 system and needs to find evidence of files that were recently opened by a user. The user has cleared their browser history and deleted the files from the Recycle Bin. Which of the following artifacts would be the MOST likely place to find residual evidence of recently accessed files and applications?

    Answer and explanation

    Correct answer: C

    Windows automatically creates LNK (shortcut) files and Jump Lists to track recently opened files and applications for user convenience. These artifacts persist even after files are deleted and history is cleared, providing a valuable timeline of user activity. The Security event log tracks security-related events like logons, the SAM hive stores user password hashes, and the System32 directory contains core system files, not user activity logs.

  8. Question 8

    A small e-commerce company wants to ensure the confidentiality and integrity of customer data transmitted between their web server and users' browsers. They also want to provide assurance to customers that they are connected to the legitimate company server. Which network security protocol is essential for achieving these goals?

    Answer and explanation

    Correct answer: D

    Transport Layer Security (TLS), the protocol that underpins HTTPS, is designed specifically for this purpose. It encrypts data in transit (confidentiality), uses message authentication codes to prevent tampering (integrity), and uses digital certificates to authenticate the server to the client. SSH is for secure remote administration, FTP is insecure for file transfers, and IPsec operates at the network layer, typically for VPNs.

  9. Question 9

    Multiple answers

    An attacker sends a spear-phishing email to a high-level executive. The email contains a malicious macro in a Word document disguised as an urgent financial report. The executive opens the document, enabling the macro, which then downloads and executes a Remote Access Trojan (RAT). Which two social engineering principles were MOST likely exploited in this attack? (Select TWO).

    Answer and explanation

    Correct answers: A, D

    The email was disguised as an 'urgent' report, creating a sense of urgency to bypass rational thinking. The attack also leverages authority, as financial reports are typically important and come from authoritative sources, making the executive more likely to comply.

  10. Question 10

    A forensic investigator is analyzing network traffic captures (PCAP files) related to a suspected data breach. The investigator observes a large amount of outbound traffic to an unknown IP address, encrypted with TLS. To understand what data might have been exfiltrated, the investigator needs to decrypt this traffic. What essential piece of information is required to decrypt the captured TLS sessions?

    Answer and explanation

    Correct answer: C

    To decrypt a TLS session captured in a PCAP file (assuming a cipher suite like RSA was used for key exchange), the investigator needs the server's private key. The private key is used to decrypt the pre-master secret exchanged during the TLS handshake, which then allows the investigator's tool (like Wireshark) to derive the symmetric session keys and decrypt the application data. The public key is publicly available and cannot be used for decryption. The session key itself is what needs to be derived.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 197 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon