EC-COUNCIL 312-92 시험 개요:
| 인증 벤더: | EC-Council |
|---|---|
| 시험명: | EC-Council Certified Secure Programmer v2 (ECSP v2) 시험 |
| 시험 번호: | 312-92 |
| 시험 형식: | 객관식 문제 |
| 관련 자격증: | ECSA (EC-Council Certified Security Analyst) CEH (Certified Ethical Hacker) |
| 시험 시간: | 120분 |
| 자격증 유효 기간: | 3년 |
| 지원 언어: | English |
| 권장 교육: | EC-Council 공식 ECSP v2 교육 과정 |
| 시험 등록: | EC-Council 공식 자격증 포털 |
| 샘플 문제: | EC-COUNCIL 312-92 샘플 문제 |
| 응시 방법: | 온라인 감독 시험 또는 공인 시험 센터(지역에 따라 EC-Council VUE/EC-Council 플랫폼 이용) |
| 전제 조건: | 권장 사항: 기본 프로그래밍 지식 및 소프트웨어 개발 개념에 대한 이해 |
| 공식 요강 URL: | https://www.eccouncil.org/programs/certified-secure-programmer-ecsp/ |
EC-COUNCIL 312-92 시험 요강 주제:
| 섹션 | 목표 |
|---|---|
| 주제 1: 암호화 및 데이터 보호 | - 암호화 알고리즘 및 해시 처리 - 안전한 키 관리 |
| 주제 2: 일반적인 소프트웨어 취약점 | - 주입 공격 (SQL, 명령어, 코드 주입) - 버퍼 오버플로우 및 메모리 손상 - 교차 사이트 스크립팅(XSS) 및 웹 취약점 |
| 주제 3: 안전한 소프트웨어 개발 기초 | - 소프트웨어 개발 수명 주기(SDLC) 보안 통합 - 안전한 코딩 원칙 및 모범 사례 |
| 주제 4: 안전한 웹 애플리케이션 개발 | - 세션 관리 및 인증 보안 - 입력값 검증 및 출력 인코딩 |
| 주제 5: 안전한 데이터베이스 프로그래밍 | - SQL 주입 방지 기법 - 안전한 데이터베이스 접근 제어 |
| 주제 6: 코드 검토 및 보안 테스트 | - 안전한 코드 검토 방법론 - 정적 및 동적 애플리케이션 보안 테스트 |
최신 ECSP 312-92 무료샘플문제
문제 #1
Gregory is a system administrator who oversees 15 Mac OS X servers for his company.
Three of his servers are at remote sites, but they still need to replicate and communicate with the servers at the main office. Gregory wants to use SSL to protect the LDAP traffic between all servers for security. For this to work properly, what port must be opened on the firewalls so that the SSL LDAP traffic can pass through?
A. 636
B. 22
C. 139
D. 443
문제 #2
Kevin wants to use an SSL certificate from his Mac OS X server so that he can send and receive encrypted email. What would Kevin accomplish by typing in the following command?
certtool c k=/Users/root/Library/Keychains/certkc
A. Copy the root certificate of the server to the file "certkc"
B. Import encryption key into the file "certkc"
C. Remove any unnecessary permissions on the file "certkc"
D. Create keychain called "certkc"
문제 #3
What type of problem or error will result from the following statement?
void f2b(void * arg, size_t len)
{
char buffer[100];
long val = ...;
long *ptr = ...;
extern void (*f)();
memcpy(buff, arg, len);
*ptr = val;
f();
return;
}
A. Sign error
B. Virtual pointer smashing
C. Pointer subterfuge
D. Heap smashing
문제 #4
What type of problem will result if the following statement is used?
int main()
{
short int a;
unsigned short int=b32768;
a=b;
printf( " a = %d", a);
b=65535;
a=b;
printf( " a = %d", a);
}
A. Sign error
B. Pointer subterfuge
C. Truncation
D. Function-pointer clobbering
문제 #5
What security package is implemented with the following code?
dwStatus = DsMakSpn
(
"ldap",
"MyServer.Mydomain.com",
NULL,
0,
NULL,
&pcSpnLength,
pszSpn
);
rpcStatus = RpcServerRegisterAuthInfo
(
psz
RPC_C_AUTHN_GSS_NEGOTIATE,
NULL,
NULL
);
A. SSPI
B. Diffie-Hellman encryption
C. SMDT
D. Repurposing
질문과 대답:
| 문제 #1 정답: A | 문제 #2 정답: D | 문제 #3 정답: C | 문제 #4 정답: C | 문제 #5 정답: B |














1118 개 고객 리뷰
품질과 가치ITCertKR 의 높은 정확도를 보장하는 최고품질의 덤프는 IT인증시험에 대비하여 제작된것으로서 높은 적중율을 자랑하고 있습니다.
테스트 및 승인ITCertKR 의 덤프는 모두 엘리트한 전문가들이 실제시험문제를 분석하여 답을 작성한 만큼 시험문제의 적중률은 아주 높습니다.
쉽게 시험패스ITCertKR의 테스트 엔진을 사용하여 시험을 준비한다는것은 첫 번째 시도에서 인증시험 패스성공을 의미합니다.
주문하기전 체험ITCertKR의 각 제품은 무료 데모를 제공합니다. 구입하기로 결정하기 전에 덤프샘플문제로 덤프품질과 실용성을 검증할수 있습니다.
