312-49 Certification - The Ultimate Guide [Updated 2021]
312-49 Practice Exam and Study Guides - Verified By CramPDF
This certification exam measures the individuals’ knowledge of identifying the intruders’ footprints. It also equips the interested candidates with the skills required to collect the relevant proof to indict defaulters in a court of law. Those students who achieve the passing score in EC-Council 312-49 qualify to earn the Computer Hacking Forensic Investigator certificate. The certification you obtain validates your skills in specific security specialization in the domain of computer forensics. The potential applicants for this track will develop the expertise required to function in a range of career paths associated with cybersecurity and other legal professions.
NEW QUESTION 20
One way to identify the presence of hidden partitions on a suspect hard drive is to:One way to identify the presence of hidden partitions on a suspect? hard drive is to:
- A. Examine the FAT and identify hidden partitions by noting an ?in the artition
Type?fieldExamine the FAT and identify hidden partitions by noting an ??in the ?artition
Type?field - B. Add up the total size of all known partitions and compare it to the total size of the hard drive
- C. Examine the LILO and note an ?in the artition Type?fieldExamine the LILO and note an
??in the ?artition Type?field - D. It is not possible to have hidden partitions on a hard drive
Answer: B
NEW QUESTION 21
Why would you need to find out the gateway of a device when investigating a wireless attack?
- A. The gateway will be the IP used to manage the access point
- B. The gateway will be the IP of the proxy server used by the attacker to launch the attack
- C. The gateway will be the IP of the attacker computerThe gateway will be the IP of the attacker? computer
- D. The gateway will be the IP used to manage the RADIUS server
Answer: A
NEW QUESTION 22
You just passed your ECSA exam and are about to start your first consulting job running security audits for a financial institution in Los Angeles. The IT manager of the company you will be working for tries to see if you remember your ECSA class. He asks about the methodology you will be using to test the company's network.
How would you answer?
- A. Google Methodology
- B. IBM Methodology
- C. LPT Methodology
- D. Microsoft Methodology
Answer: C
NEW QUESTION 23
You have been asked to investigate the possibility of computer fraud in the finance department of a company. It is suspected that a staff member has been committing finance fraud by printing cheques that have not been authorized. You have exhaustively searched all data files on a bitmap image of the target computer, but have found no evidence. You suspect the files may not have been saved. What should you examine next in this case?
- A. The metadata
- B. The registry
- C. The recycle bin
- D. The swap file
Answer: D
NEW QUESTION 24
After suspecting a change in MS-Exchange Server storage archive, the investigator has analyzed it. Which of the following components is not an actual part of the archive?
- A. PRIV.EDB
- B. PRIV.STM
- C. PUB.EDB
- D. PUB.STM
Answer: D
NEW QUESTION 25
The offset in a hexadecimal code is:
- A. The 0x at the end of the code
- B. The last byte after the colon
- C. The 0x at the beginning of the code
- D. The first byte after the colon
Answer: C
NEW QUESTION 26
From the following spam mail header, identify the host IP that sent this spam?
From [email protected] [email protected] Tue Nov 27 17:27:11 2001 Received: from viruswall.ie.cuhk.edu.hk (viruswall [137.189.96.52]) by eng.ie.cuhk.edu.hk (8.11.6/8.11.6) with ESMTP id
fAR9RAP23061 for ; Tue, 27 Nov 2001 17:27:10 +0800 (HKT)
Received: from mydomain.com (pcd249020.netvigator.com [203.218.39.20]) by viruswall.ie.cuhk.edu.hk (8.12.1/8.12.1)
with SMTP id fAR9QXwZ018431 for ; Tue, 27 Nov 2001 17:26:36 +0800 (HKT) Message-Id: >[email protected]
From: "china hotel web"
To: "Shlam"
Subject: SHANGHAI (HILTON HOTEL) PACKAGE
Date: Tue, 27 Nov 2001 17:25:58 +0800 MIME-Version: 1.0
X-Priority: 3 X-MSMail-
Priority: Normal
Reply-To: "china hotel web"
- A. 8.12.1.0
- B. 203.218.39.20
- C. 137.189.96.52
- D. 203.218.39.50
Answer: B
NEW QUESTION 27
Which of the following techniques delete the files permanently?
- A. Artifact Wiping
- B. Data Hiding
- C. Steganography
- D. Trail obfuscation
Answer: A
NEW QUESTION 28
Pagefile.sys is a virtual memory file used to expand the physical memory of a computer. Select the registry path for the page file:
- A. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\System Management
- B. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
- C. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Device Management
- D. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
\PrefetchParameters
Answer: B
NEW QUESTION 29
Centralized binary logging is a process in which many websites write binary and unformatted log data to a single log file. What extension should the investigator look to find its log file?
- A. .ibl
- B. .txt
- C. .log
- D. .cbl
Answer: A
NEW QUESTION 30
You are called in to assist the police in an investigation involving a suspected drug dealer.
The police searched the suspect house after aYou are called in to assist the police in an investigation involving a suspected drug dealer. The police searched the suspect? house after a warrant was obtained and they located a floppy disk in the suspect bedroom. The disk contains several files, but they appear to be passwordwarrant was obtained and they located a floppy disk in the suspect? bedroom. The disk contains several files, but they appear to be password protected. What are two common methods used by password cracking software that you could use to obtain the password?
- A. Brute force and dictionary attack
- B. Limited force and library attack
- C. Minimum force and appendix attack
- D. Maximum force and thesaurus attack
Answer: A
NEW QUESTION 31
A suspect is accused of violating the acceptable use of computing resources, as he has visited adult websites and downloaded images. The investigator wants to demonstrate that the suspect did indeed visit these sites.
However, the suspect has cleared the search history and emptied the cookie cache. Moreover, he has removed any images he might have downloaded. What can the investigator do to prove the violation?
- A. Approach the websites for evidence
- B. Check the Windows registry for connection data (you may or may not recover)
- C. Seek the help of co-workers who are eye-witnesses
- D. Image the disk and try to recover deleted files
Answer: D
NEW QUESTION 32
In handling computer-related incidents, which IT role should be responsible for recovery, containment, and prevention to constituents?
- A. Security Administrator
- B. Director of Information Technology
- C. Director of Administration
- D. Network Administrator
Answer: D
NEW QUESTION 33
What is an investigator looking for in the rp.log file stored in a system running on Windows 10 operating system?
- A. Automatically created restore points
- B. System CheckPoints required for restoring
- C. Restore point functions
- D. Restore point interval
Answer: B
NEW QUESTION 34
Which of the following tool can reverse machine code to assembly language?
- A. PEiD
- B. RAM Capturer
- C. Deep Log Analyzer
- D. IDA Pro
Answer: D
NEW QUESTION 35
Which of the following files stores information about local Dropbox installation and account, email IDs linked with the account, current version/build for the local application, the host_id, and local path information?
- A. filecache.db
- B. host.db
- C. sigstore.db
- D. config.db
Answer: D
NEW QUESTION 36
You work as an IT security auditor hired by a law firm in Boston to test whether you can gain access to sensitive information about the company clients. You have rummaged through their trash and found very little information. You do not want to set off any alarms on their network, so you plan on performing passive foot printing against their Web servers. What tool should you use?
- A. Nmap
- B. Netcraft
- C. Dig
- D. Ping sweep
Answer: B
NEW QUESTION 37
Jack Smith is a forensics investigator who works for Mason Computer Investigation
Services. He is investigating a computer that was infected by Ramen Virus.
He runs the netstat command on the machine to see its current connections. In the following screenshot, what do the 0.0.0.0 IP addresses signify?
- A. Those connections are in closed/waiting modeThose connections are in closed/waiting modeThose connections are in closed/waiting mode
- B. Those connections are in listening modeThose connections are in listening modeThose connections are in listening mode
- C. Those connections are established Those connections are established Those connections are established
- D. Those connections are in timed out/waiting mode Those connections are in timed out/waiting mode Those connections are in timed out/waiting mode
Answer: B
NEW QUESTION 38
You are called by an author who is writing a book and he wants to know how long the copyright for his book will last after he has the book published?
- A. copyrights last forever
- B. the life of the author
- C. 70 years
- D. the life of the author plus 70 years
Answer: D
NEW QUESTION 39
......
Ultimate Guide to the 312-49 - Latest Edition Available Now: https://www.crampdf.com/312-49-exam-prep-dumps.html