10 free EC-Council 212-82 CCT practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 125 questions. Work through them, then open each answer to check your reasoning.
Get all 125 questions (US$39) · Download these 10 as a PDF
Question 1
Thomas, an employee of an organization, is restricted to access specific websites from his office system. He is trying to obtain admin credentials to remove the restrictions. While waiting for an opportunity, he sniffed communication between the administrator and an application server to retrieve the admin credentials.
Identify the type of attack performed by Thomas in the above scenario.
Show answer and explanation
Correct answer: B. Eavesdropping
Eavesdropping is the unauthorized interception and listening to private communications. Thomas sniffed network communication between the administrator and application server to capture admin credentials, which is a classic eavesdropping attack. The attacker passively monitored traffic without the knowledge or consent of the communicating parties to obtain sensitive information.
Why the other options are wrong
- A. Vishing is a voice-based social engineering attack conducted over the telephone, not network sniffing.
- C. Phishing involves deceptive emails or messages attempting to trick users into revealing credentials, not network traffic interception.
- D. Dumpster diving is physical retrieval of discarded materials containing sensitive information, not network-based eavesdropping.
Question 2
Kayden successfully cracked the final round of interview at an organization. After few days, he received his offer letter through an official company email address. The email stated that the selected candidate should respond within a specified time. Kayden accepted the opportunity and provided e-signature on the offer letter, then replied to the same email address. The company validated the e-signature and added his details to their database. Here, Kayden could not deny company's message, and company could not deny Kayden's signature.
Which of the following information security elements was described in the above scenario?
Show answer and explanation
Correct answer: B. Non-repudiation
Non-repudiation ensures that neither party can deny their involvement in a transaction. In this scenario, Kayden cannot deny sending his e-signature and acceptance because it was validated and recorded, and the company cannot deny sending the offer letter because it came from an official email address that was validated. This mutual inability to deny participation is the defining characteristic of non-repudiation.
Why the other options are wrong
- A. Availability refers to ensuring data and services are accessible when needed, not relevant to this authentication scenario.
- C. Integrity ensures data is not altered or corrupted, but the focus here is on proving authenticity of actions, not data modification prevention.
- D. Confidentiality protects information from unauthorized disclosure, which is not the primary concern in this offer letter exchange.
Question 3
Sam, a software engineer, visited an organization to give a demonstration on a software tool that helps in business development. The administrator at the organization created a least privileged account on a system and allocated that system to Sam for the demonstration. Using this account, Sam can only access the files that are required for the demonstration and cannot open any other file in the system.
Which of the following type of accounts the organization has given to Sam in the above scenario?
Show answer and explanation
Correct answer: B. Guest account
A guest account is a temporary account created for temporary or external users with minimal privileges. The organization created a least privileged account for Sam, an external visitor, allowing access only to demonstration-related files. This temporary, restricted access profile is characteristic of a guest account designed for short-term external use.
Why the other options are wrong
- A. Service accounts are created for running background services and applications, not for human users attending demonstrations.
- C. User accounts are standard employee accounts typically with broader permissions than a least privileged demonstration account.
- D. Administrator accounts have full system privileges, directly contradicting the least privileged access described.
Question 4
Myles, a security professional at an organization, provided laptops for all the employees to carry out the business processes from remote locations. While installing necessary applications required for the business, Myles has also installed antivirus software on each laptop following the company's policy to detect and protect the machines from external malicious events over the Internet.
Identify the PCI-DSS requirement followed by Myles in the above scenario.
Show answer and explanation
Correct answer: C. PCI-DSS requirement no 5.1
PCI-DSS requirement 5.1 mandates deploying anti-virus software on all systems commonly affected by malicious software, and requirement 5 as a whole covers protecting systems against malware. Myles installed antivirus on every employee laptop so the machines can detect and be protected from malicious events originating over the Internet, which is exactly what requirement 5.1 calls for. All of the 1.3.x requirements sit under requirement 1, which deals with firewall and router configuration, not endpoint malware protection.
Why the other options are wrong
- A. PCI-DSS requirement 1.3.2 restricts inbound Internet traffic to IP addresses within the DMZ, which is a firewall control rather than antivirus deployment.
- B. PCI-DSS requirement 1.3.5 permits only established connections into the network, a stateful firewall rule that has nothing to do with endpoint antivirus.
- D. PCI-DSS requirement 1.3.1 requires implementing a DMZ to limit inbound traffic to authorized publicly accessible services, not installing antivirus software.
Question 5
Ashton is working as a security specialist in SoftEight Tech. He was instructed by the management to strengthen the Internet access policy. For this purpose, he implemented a type of Internet access policy that forbids everything and imposes strict restrictions on all company computers, whether it is system or network usage.
Identify the type of Internet access policy implemented by Ashton in the above scenario.
Show answer and explanation
Correct answer: A. Paranoid policy
A paranoid policy is the most restrictive Internet access policy: it forbids everything and places severe restrictions on all company system and network usage, to the point that Internet use is effectively blocked. Ashton's implementation of a policy that forbids everything and imposes strict restrictions on every company computer matches the paranoid model exactly.
Why the other options are wrong
- B. A prudent policy blocks all services by default and then individually enables only those that are necessary and considered safe, with all activity logged, so it is restrictive but not a blanket prohibition.
- C. A permissive policy is wide open by default and blocks only known dangerous services or attacks, which is the opposite of the scenario.
- D. A promiscuous policy places no restrictions at all on Internet or resource usage, contradicting the strict restrictions described.
Question 6
Zion belongs to a category of employees who are responsible for implementing and managing the physical security equipment installed around the facility. He was instructed by the management to check the functionality of equipment related to physical security.
Identify the designation of Zion.
Show answer and explanation
Correct answer: D. Safety officer
In EC-Council's breakdown of physical security personnel, the safety officer is the role charged with implementing and managing the physical security equipment installed around the facility and verifying that it functions correctly. Zion's task of checking the functionality of physical security equipment places him squarely in the safety officer role.
Why the other options are wrong
- A. A supervisor oversees the security staff and enforces adherence to security procedures rather than installing, managing and testing the equipment itself.
- B. A chief information security officer sets information security strategy, budget and policy at an executive level and does not perform equipment functionality checks.
- C. A guard provides physical presence, access screening and surveillance monitoring, not implementation and maintenance of the security equipment.
Question 7
In an organization, all the servers and database systems are guarded in a sealed room with a single entry point. The entrance is protected with a physical lock system that requires typing a sequence of numbers and letters by using a rotating dial that intermingles with several other rotating discs.
Which of the following types of physical locks is used by the organization in the above scenario?
Show answer and explanation
Correct answer: B. Combination locks
A combination lock requires inputting a correct sequence of numbers and letters using rotating dials or similar mechanical mechanisms. The scenario describes a rotating dial system that intermingles with several other rotating discs to create a sequence, which is the defining mechanism of a combination lock that operates without electronic components.
Why the other options are wrong
- A. Digital locks use electronic keypads or biometric systems, not mechanical rotating dials.
- C. Mechanical locks include padlocks and keyed locks but not combination locks with rotating dials.
- D. Electromagnetic locks use electrical current to secure doors and are activated electronically, not through dial rotation.
Question 8
Lorenzo, a security professional in an MNC, was instructed to establish centralized authentication, authorization, and accounting for remote-access servers. For this purpose, he implemented a protocol that is based on the client-server model and works at the transport layer of the OSI model.
Identify the remote authentication protocol employed by Lorenzo in the above scenario.
Show answer and explanation
Correct answer: B. RADIUS
RADIUS (Remote Authentication Dial-In User Service) is a protocol based on the clien-erver model operating at the transport layer (Layer 4) of the OSI model. It provides centralized authentication, authorization, and accounting (AAA) for remote access servers, making it the standard choice for managing remote user access in enterprise networks.
Why the other options are wrong
- A. SNMPv3 is a network management protocol used for monitoring and managing network devices, not for user authentication.
- C. POP3S is a secure version of the Post Office Protocol for email retrieval, not for remote access authentication.
- D. IMAPS is a secure version of the Internet Message Access Protocol for email, not for establishing remote access authentication.
Question 9
Malachi, a security professional, implemented a firewall in his organization to trace incoming and outgoing traffic. He deployed a firewall that works at the session layer of the OSI model and monitors the TCP handshake between hosts to determine whether a requested session is legitimate.
Identify the firewall technology implemented by Malachi in the above scenario.
Show answer and explanation
Correct answer: B. Circuit-level gateways
Circuit-level gateways operate at the session layer (Layer 5) of the OSI model and monitor TCP/UDP handshakes to determine session legitimacy before allowing data transmission. They validate the connection establishment process itself rather than inspecting packet contents, making them ideal for tracing and validating session initiation between hosts.
Why the other options are wrong
- A. Next-generation firewalls operate at higher layers and perform deep packet inspection, not specifically session-layer handshake monitoring.
- C. Network address translation modifies IP addresses for routing purposes and does not monitor TCP handshakes or validate session legitimacy.
- D. Packet filtering operates at Layer 3-4 and examines individual packets based on headers, not session establishment patterns.
Question 10
Rhett, a security professional at an organization, was instructed to deploy an IDS solution on their corporate network to defend against evolving threats. For this purpose, Rhett selected an IDS solution that first creates models for possible intrusions and then compares these models with incoming events to make detection decisions.
Identify the detection method employed by the IDS solution in the above scenario.
Show answer and explanation
Correct answer: D. Signature recognition
Signature recognition, also called misuse detection, works by first building models of possible intrusions and then comparing incoming events against those models to reach a detection decision. That is precisely the process Rhett's IDS follows, so the detection method is signature recognition. Anomaly-based approaches work the other way round, profiling normal activity and alerting on deviations from that baseline.
Why the other options are wrong
- A. Not-use detection is the alternate name for anomaly detection, which profiles normal system and user behavior instead of modeling intrusions.
- B. Protocol anomaly detection flags traffic that violates the specifications and expected structure of a protocol, not events matched against intrusion models.
- C. Anomaly detection builds a baseline of normal behavior and reports deviations from it, the reverse of modeling possible intrusions and matching events to them.
That was 10 of 125.
The full EC-Council 212-82 CCT pack has all 125 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
