[Jan 03, 2022] Valid 312-49v10 Test Answers & 312-49v10 Exam PDF [Q194-Q218]

Share

[Jan 03, 2022] Valid 312-49v10 Test Answers & 312-49v10 Exam PDF

Valid CHFI v10 312-49v10 Dumps Ensure Your Passing


EC-COUNCIL 312-49v10 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Computer Forensics in Today’s World
  • Investigating Web Attacks
Topic 2
  • Data Acquisition and Duplication
  • Linux and Mac Forensics
Topic 3
  • Defeating Anti-Forensics Techniques
  • Malware Forensics
Topic 4
  • Understanding Hard Disks and File Systems
  • Investigating Email Crimes
Topic 5
  • Computer Forensics Investigation Process
  • Dark Web Forensics
  • Mobile Forensics
Topic 6
  • Database Forensics
  • Network Forensics
  • Windows Forensics

 

NEW QUESTION 194
Which of the following tool can reverse machine code to assembly language?

  • A. PEiD
  • B. RAM Capturer
  • C. Deep Log Analyzer
  • D. IDA Pro

Answer: D

 

NEW QUESTION 195
If a PDA is seized in an investigation while the device is turned on, what would be the proper procedure?

  • A. Remove any memory cards immediately
  • B. Turn off the device immediately
  • C. Remove the battery immediately
  • D. Keep the device powered on

Answer: D

 

NEW QUESTION 196
In General, __________________ Involves the investigation of data that can be retrieved from the hard disk or other disks of a computer by applying scientific methods to retrieve the data.

  • A. Data Recovery
  • B. Disaster Recovery
  • C. Computer Forensics
  • D. Network Forensics

Answer: C

 

NEW QUESTION 197
Which of the following is a federal law enacted in the US to control the ways that financial institutions deal with the private information of individuals?

  • A. HIPAA 1996
  • B. PCI DSS
  • C. GLBA
  • D. SOX

Answer: C

 

NEW QUESTION 198
In Microsoft file structures, sectors are grouped together to form:

  • A. Drives
  • B. Bitstreams
  • C. Partitions
  • D. Clusters

Answer: D

 

NEW QUESTION 199
When performing a forensics analysis, what device is used to prevent the system from recording data on an evidence disk?

  • A. a protocol analyzer
  • B. a disk editor
  • C. a write-blocker
  • D. a firewall

Answer: C

 

NEW QUESTION 200
Sheila is a forensics trainee and is searching for hidden image files on a hard disk. She used a forensic investigation tool to view the media in hexadecimal code for simplifying the search process. Which of the following hex codes should she look for to identify image files?

  • A. d0 0f 11 e0
  • B. 50 41 03 04
  • C. 25 50 44 46
  • D. ff d8 ff

Answer: D

 

NEW QUESTION 201
Ivanovich, a forensics investigator, is trying to extract complete information about running processes from a system. Where should he look apart from the RAM and virtual memory?

  • A. Application data
  • B. Swap space
  • C. Slack space
  • D. Files and documents

Answer: B

 

NEW QUESTION 202
Investigators can use the Type Allocation Code (TAC) to find the model and origin of a mobile device. Where is TAC located in mobile devices?

  • A. Integrated circuit card identifier (ICCID)
  • B. International mobile subscriber identity (IMSI)
  • C. Equipment Identity Register (EIR)
  • D. International Mobile Equipment Identifier (IMEI)

Answer: D

 

NEW QUESTION 203
Madison is on trial for allegedly breaking into her university internal network. The police raided her dorm room and seized all of her computer equipment. Madison lawyer is trying to convince the judge that the seizure was unfounded and baseless. Under which US Amendment is Madison lawyer trying to prove the police violated?

  • A. The 5th Amendment
  • B. The 4th Amendment
  • C. The 10th Amendment
  • D. The 1st Amendment

Answer: B

 

NEW QUESTION 204
Analyze the hex representation of mysql-bin.000013 file in the screenshot below. Which of the following will be an inference from this analysis?

  • A. An attacker with name anonymous_hacker has replaced a user bad_guy in the WordPress database
  • B. A user with username bad_guy has logged into the WordPress web application
  • C. A WordPress user has been created with the username anonymous_hacker
  • D. A WordPress user has been created with the username bad_guy

Answer: D

 

NEW QUESTION 205
At what layer does a cross site scripting attack occur on?

  • A. Data Link
  • B. Session
  • C. Presentation
  • D. Application

Answer: D

 

NEW QUESTION 206
What is the location of the binary files required for the functioning of the OS in a Linux system?

  • A. /root
  • B. /bin
  • C. /sbin
  • D. /run

Answer: B

 

NEW QUESTION 207
Billy, a computer forensics expert, has recovered a large number of DBX files during the forensic investigation of a laptop. Which of the following email clients can he use to analyze the DBX files?

  • A. Microsoft Outlook
  • B. Eudora
  • C. Mozilla Thunderbird
  • D. Microsoft Outlook Express

Answer: D

 

NEW QUESTION 208
Smith, an employee of a reputed forensic investigation firm, has been hired by a private organization to investigate a laptop that is suspected to be involved in the hacking of the organization's DC server. Smith wants to find all the values typed into the Run box in the Start menu. Which of the following registry keys will Smith check to find the above information?

  • A. TypedURLs key
  • B. RunMRU key
  • C. UserAssist Key
  • D. MountedDevices key

Answer: B

 

NEW QUESTION 209
Tasklist command displays a list of applications and services with their Process ID (PID) for all tasks running on either a local or a remote computer. Which of the following tasklist commands provides information about the listed processes, including the image name, PID, name, and number of the session for the process?

  • A. tasklist /s
  • B. tasklist /v
  • C. tasklist /u
  • D. tasklist /p

Answer: B

 

NEW QUESTION 210
If you plan to startup a suspect's computer, you must modify the ___________ to ensure that you do not contaminate or alter data on the suspect's hard drive by booting to the hard drive.

  • A. CMOS
  • B. Scandisk utility
  • C. deltree command
  • D. Boot.sys

Answer: D

 

NEW QUESTION 211
What stage of the incident handling process involves reporting events?

  • A. Containment
  • B. Follow-up
  • C. Identification
  • D. Recovery

Answer: C

 

NEW QUESTION 212
If you discover a criminal act while investigating a corporate policy abuse, it becomes a publicsector investigation and should be referred to law enforcement?

  • A. true
  • B. false

Answer: A

 

NEW QUESTION 213
Travis, a computer forensics investigator, is finishing up a case he has been working on for over a month involving copyright infringement and embezzlement. His last task is to prepare an investigative report for the president of the company he has been working for. Travis must submit a hard copy and an electronic copy to this president. In what electronic format should Travis send this report?

  • A. TIFF-8
  • B. PDF
  • C. DOC
  • D. WPD

Answer: B

 

NEW QUESTION 214
What type of attack occurs when an attacker can force a router to stop forwarding packets by flooding the router with many open connections simultaneously so that all the hosts behind the router are effectively disabled?

  • A. digital attack
  • B. physical attack
  • C. denial of service
  • D. ARP redirect

Answer: C

 

NEW QUESTION 215
An on-site incident response team is called to investigate an alleged case of computer tampering within their company. Before proceeding with the investigation, the CEO informs them that the incident will be classified as low level. How long will the team have to respond to the incident?

  • A. Four hours
  • B. Two working days
  • C. Immediately
  • D. One working day

Answer: D

 

NEW QUESTION 216
Heather, a computer forensics investigator, is assisting a group of investigators working on a large computer fraud case involving over 20 people. These 20 people, working in different offices, allegedly siphoned off money from many different client accounts. Heather responsibility is to find out how the accused people communicated between each other. She has searched their email and their computers and has not found any useful evidence. Heather then finds some possibly useful evidence under the desk of one of the accused.
In an envelope she finds a piece of plastic with numerous holes cut out of it. Heather then finds the same exact piece of plastic with holes at many of the other accused peoples desks. Heather believes that the 20 people involved in the case were using a cipher to send secret messages in between each other. What type of cipher was used by the accused in this case?

  • A. Grill cipher
  • B. Text semagram
  • C. Visual semagram
  • D. Null cipher

Answer: A

 

NEW QUESTION 217
How many possible sequence number combinations are there in TCP/IP protocol?

  • A. 4 billion
  • B. 1 billion
  • C. 320 billion
  • D. 32 million

Answer: A

 

NEW QUESTION 218
......

312-49v10 Dumps Real Exam Questions Test Engine Dumps Training: https://www.exam4tests.com/312-49v10-valid-braindumps.html

312-49v10 exam dumps and online Test Engine: https://drive.google.com/open?id=19QDXzydM6oLj7FbNzj9-l7pngIWB44p7