Eccouncil

212-82 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 48-question bank.

Provider
Eccouncil
Question bank
48
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for 212-82, a certification listed under Eccouncil. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Eccouncil. The certification credential is issued by Eccouncil, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Thomas, an employee of an organization, is restricted to access specific websites from his office system. He is trying to obtain admin credentials to remove the restrictions. While waiting for an opportunity, he sniffed communication between the administrator and an application server to retrieve the admin credentials. Identify the type of attack performed by Thomas in the above scenario.

    Choose one answer.

    • Vishing
    • Eavesdropping
    • Phishing
    • Dumpster diving
  2. Question 2 · 1

    Rhett, a security professional at an organization, was instructed to deploy an IDS solution on their corporate network to defend against evolving threats. For this purpose, Rhett selected an IDS solution that first creates models for possible intrusions and then compares these models with incoming events to make detection decisions. Identify the detection method employed by the IDS solution in the above scenario.

    Choose one answer.

    • Not-use detection
    • Protocol anomaly detection
    • Anomaly detection
    • Signature recognition
  3. Question 3 · 1

    Richards, a security specialist at an organization, was monitoring an IDS system. While monitoring, he suddenly received an alert of an ongoing intrusion attempt on the organization's network. He immediately averted the malicious actions by implementing the necessary measures. Identify the type of alert generated by the IDS system in the above scenario.

    Choose one answer.

    • True positive
    • True negative
    • False negative
    • False positive
  4. Question 4 · 1

    Karter, a security professional, deployed a honeypot on the organization's network for luring attackers who attempt to breach the network. For this purpose, he configured a type of honeypot that simulates a real OS as well as applications and services of a target network. Furthermore, the honeypot deployed by Karter only responds to preconfigured commands. Identify the type of Honeypot deployed by Karter in the above scenario.

    Choose one answer.

    • Low-interaction honeypot
    • Pure honeypot
    • Medium-interaction honeypot
    • High-interaction honeypot
  5. Question 5 · 1

    An MNC hired Brandon, a network defender, to establish secured VPN communication between the company's remote offices. For this purpose, Brandon employed a VPN topology where all the remote offices communicate with the corporate office but communication between the remote offices is denied. Identify the VPN topology employed by Brandon in the above scenario.

    Choose one answer.

    • Point-to-Point VPN topology
    • Star topology
    • Hub-and-Spoke VPN topology
    • Full-mesh VPN topology
  6. Question 6 · 1

    Mark, a security analyst, was tasked with performing threat hunting to detect imminent threats in an organization's network. He generated a hypothesis based on the observations in the initial step and started the threat hunting process using existing data collected from DNS and proxy logs. Identify the type of threat hunting method employed by Mark in the above scenario.

    Choose one answer.

    • Entity-driven hunting
    • TTP-driven hunting
    • Data-driven hunting
    • Hybrid hunting
  7. Question 7 · 1

    An organization hired a network operations center (NOC) team to protect its IT infrastructure from external attacks. The organization utilized a type of threat intelligence to protect its resources from evolving threats. The threat intelligence helped the NOC team understand how attackers are expected to perform an attack on the organization, identify the information leakage, and determine the attack goals as well as attack vectors. Identify the type of threat intelligence consumed by the organization in the above scenario.

    Choose one answer.

    • Operational threat intelligence
    • Strategic threat intelligence
    • Technical threat intelligence
    • Tactical threat intelligence
  8. Question 8 · 1

    Tristan, a professional penetration tester, was recruited by an organization to test its network infrastructure. The organization wanted to understand its current security posture and its strength in defending against external threats. For this purpose, the organization did not provide any information about their IT infrastructure to Tristan. Thus, Tristan initiated zero-knowledge attacks, with no information or assistance from the organization. Which of the following types of penetration testing has Tristan initiated in the above scenario?

    Choose one answer.

    • Black-box testing
    • White-box testing
    • Gray-box testing
    • Translucent-box testing
  9. Question 9 · 1

    Miguel, a professional hacker, targeted an organization to gain illegitimate access to its critical information. He identified a flaw in the end-point communication that can disclose the target application's data. Which of the following secure application design principles was not met by the application in the above scenario?

    Choose one answer.

    • Secure the weakest link
    • Do not trust user input
    • Exception handling
    • Fault tolerance
  10. Question 10 · 1

    A software company is developing a new software product by following the best practices for secure application development. Dawson, a software analyst, is checking the performance of the application on the client's network to determine whether end users are facing any issues in accessing the application. Which of the following tiers of a secure application development lifecycle involves checking the performance of the application?

    Choose one answer.

    • Development
    • Testing
    • Quality assurance (QA)
    • Staging
  11. Question 11 · 1

    Nicolas, a computer science student, decided to create a guest OS on his laptop for different lab operations. He adopted a virtualization approach in which the guest OS will not be aware that it is running in a virtualized environment. The virtual machine manager (VMM) will directly interact with the computer hardware, translate commands to binary instructions, and forward them to the host OS. Which of the following virtualization approaches has Nicolas adopted in the above scenario?

    Choose one answer.

    • Hardware-assisted virtualization
    • Full virtualization
    • Hybrid virtualization
    • OS-assisted virtualization
  12. Question 12 · 1

    Kayden successfully cracked the final round of interview at an organization. After few days, he received his offer letter through an official company email address. The email stated that the selected candidate should respond within a specified time. Kayden accepted the opportunity and provided e-signature on the offer letter, then replied to the same email address. The company validated the e-signature and added his details to their database. Here, Kayden could not deny company's message, and company could not deny Kayden's signature. Which of the following information security elements was described in the above scenario?

    Choose one answer.

    • Availability
    • Non-repudiation
    • Integrity
    • Confidentiality
  13. Question 13 · 1

    Walker, a security team member at an organization, was instructed to check if a deployed cloud service is working as expected. He performed an independent examination of cloud service controls to verify adherence to standards through a review of objective evidence. Further, Walker evaluated the services provided by the CSP regarding security controls, privacy impact, and performance. Identify the role played by Walker in the above scenario.

    Choose one answer.

    • Cloud auditor
    • Cloud provider
    • Cloud carrier
    • Cloud consumer
  14. Question 14 · 1

    A software company has implemented a wireless technology to track the employees' attendance by recording their in and out timings. Each employee in the company will have an entry card that is embedded with a tag. Whenever an employee enters the office premises, he/she is required to swipe the card at the entrance. The wireless technology uses radio-frequency electromagnetic waves to transfer data for automatic identification and for tracking tags attached to objects. Which of the following technologies has the software company implemented in the above scenario?

    Choose one answer.

    • WiMAX
    • RFID
    • Bluetooth
    • Wi-Fi
  15. Question 15 · 1

    Matias, a network security administrator at an organization, was tasked with the implementation of secure wireless network encryption for their network. For this purpose, Matias employed a security solution that uses 256-bit Galois/Counter Mode Protocol (GCMP-256) to maintain the authenticity and confidentiality of data. Identify the type of wireless encryption used by the security solution employed by Matias in the above scenario.

    Choose one answer.

    • WPA2 encryption
    • WPA3 encryption
    • WEP encryption
    • WPA encryption

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free