[2023] 312-49v10 by CHFI v10 Actual Free Exam Practice Test
Free CHFI v10 312-49v10 Exam Question
The EC-Council 312-49v10 Certification Exam is designed to validate the skills and knowledge of professionals in the field of computer hacking forensic investigation. Computer Hacking Forensic Investigator (CHFI-v10) certification is an essential requirement for individuals who want to demonstrate their expertise in the area of computer forensics and investigation. Computer Hacking Forensic Investigator (CHFI-v10) certification exam is known as the Computer Hacking Forensic Investigator (CHFI-v10) Exam, and it is intended for professionals who want to advance their career in the cybersecurity industry.
NEW QUESTION # 359
Which of the following is a MAC-based File Recovery Tool?
- A. VirtualLab
- B. GetDataBack
- C. Smart Undeleter
- D. Cisdem DataRecovery 3
Answer: D
NEW QUESTION # 360
Andie, a network administrator, suspects unusual network services running on a windows system. Which of the following commands should he use to verify unusual network services started on a Windows system?
- A. netmgr
- B. net start
- C. net serv
- D. lusrmgr
Answer: B
NEW QUESTION # 361
What does Locard's Exchange Principle state?
- A. Anyone or anything, entering a crime scene takes something of the scene with them, and leaves something of themselves behind when they leave
- B. Forensic investigators face many challenges during forensics investigation of a digital crime, such as extracting, preserving, and analyzing the digital evidence
- C. Digital evidence must have some characteristics to be disclosed in the court of law
- D. Any information of probative value that is either stored or transmitted in a digital form
Answer: A
NEW QUESTION # 362
Rule 1002 of Federal Rules of Evidence (US) talks about_____
- A. Admissibility of duplicates
- B. Requirement of original
- C. Admissibility of other evidence of contents
- D. Admissibility of original
Answer: B
NEW QUESTION # 363
Jim performed a vulnerability analysis on his network and found no potential problems. He runs another utility that executes exploits against his system to verify the results of the vulnerability test.
The second utility executes five known exploits against his network in which the vulnerability analysis said were not exploitable. What kind of results did Jim receive from his vulnerability analysis?
- A. False positives
- B. True positives
- C. False negatives
- D. True negatives
Answer: C
NEW QUESTION # 364
Why is it a good idea to perform a penetration test from the inside?
- A. To attack a network from a hacker's perspective
- B. It is easier to hack from the inside
- C. Because 70% of attacks are from inside the organization
- D. It is never a good idea to perform a penetration test from the inside
Answer: C
NEW QUESTION # 365
When is it appropriate to use computer forensics?
- A. If a financial institution is burglarized by robbers
- B. If copyright and intellectual property theft/misuse has occurred
- C. If employees do not care for their boss management techniques
- D. If sales drop off for no apparent reason for an extended period of time
Answer: B
NEW QUESTION # 366
One technique for hiding information is to change the file extension from the correct one to the one that might not be noticed by an investigator. For example, changing a .jpg extension to a .doc extension so that a picture file appears to be a document. What can an investigator examine to verify that a file has the correct extension?
- A. The sector map
- B. The file header
- C. The file footer
- D. The File Allocation Table
Answer: B
NEW QUESTION # 367
The MD5 program is used to:
- A. verify that a disk is not altered when you examine it
- B. view graphics files on an evidence drive
- C. wipe magnetic media before recycling it
- D. make directories on an evidence disk
Answer: A
NEW QUESTION # 368
When investigating a wireless attack, what information can be obtained from the DHCP logs?
- A. MAC address of the attacker
- B. IP traffic between the attacker and the victim
- C. If any computers on the network are running in promiscuous mode
- D. The operating system of the attacker and victim computers
Answer: A
NEW QUESTION # 369
Choose the layer in iOS architecture that provides frameworks for iOS app development?
- A. Cocoa Touch
- B. Media services
- C. Core services
- D. Core OS
Answer: C
NEW QUESTION # 370
Company ABC has employed a firewall, IDS, Antivirus, Domain Controller, and SIEM. The company's domain controller goes down. From which system would you begin your investigation?
- A. IDS
- B. Domain Controller
- C. Firewall
- D. SIEM
Answer: D
NEW QUESTION # 371
Why would you need to find out the gateway of a device when investigating a wireless attack?
- A. The gateway will be the IP used to manage the RADIUS server
- B. The gateway will be the IP used to manage the access point
- C. The gateway will be the IP of the proxy server used by the attacker to launch the attack
- D. The gateway will be the IP of the attacker computer
Answer: B
NEW QUESTION # 372
Self-Monitoring, Analysis, and Reporting Technology (SMART) is built into the hard drives to monitor and report system activity. Which of the following is included in the report generated by SMART?
- A. List of running processes
- B. All the states (running and discontinued) associated with the OS
- C. Logs of high temperatures the drive has reached
- D. Power Off time
Answer: C
NEW QUESTION # 373
While analyzing a hard disk, the investigator finds that the file system does not use UEFI-based interface. Which of the following operating systems is present on the hard disk?
- A. Windows 8.1
- B. Windows 10
- C. Windows 7
- D. Windows 8
Answer: C
NEW QUESTION # 374
You are working for a local police department that services a population of 1,000,000 people and you have been given the task of building a computer forensics lab. How many law-enforcement computer investigators should you request to staff the lab?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION # 375
Which of the following Event Correlation Approach checks and compares all the fields systematically and intentionally for positive and negative correlation with each other to determine the correlation across one or multiple fields?
- A. Field-Based Approach
- B. Automated Field Correlation
- C. Rule-Based Approach
- D. Graph-Based Approach
Answer: B
NEW QUESTION # 376
Identify the location of Recycle Bin on a Windows 7 machine that uses NTFS file system to store and retrieve files on the hard disk.
- A. C:\RECYCLED
- B. DriveARECYCLER
- C. DriveARECYCLED
- D. Drive:\$Recycle.Bin
Answer: D
NEW QUESTION # 377
In Windows, prefetching is done to improve system performance. There are two types of prefetching: boot prefetching and application prefetching. During boot prefetching, what does the Cache Manager do?
- A. Checks whether the data is processed
- B. Monitors the first 10 seconds after the process is started
- C. Determines the data associated with value EnablePrefetcher
- D. Checks hard page faults and soft page faults
Answer: A
NEW QUESTION # 378
Which of the following techniques can be used to beat steganography?
- A. Encryption
- B. Cryptanalysis
- C. Decryption
- D. Steganalysis
Answer: D
NEW QUESTION # 379
While working for a prosecutor, what do you think you should do if the evidence you found appears to be exculpatory and is not being released to the defense?
- A. Keep the information of file for later review
- B. Present the evidence to the defense attorney
- C. Bring the information to the attention of the prosecutor, his or her supervisor or finally to the judge
- D. Destroy the evidence
Answer: C
NEW QUESTION # 380
A forensic analyst has been tasked with investigating unusual network activity Inside a retail company's network. Employees complain of not being able to access services, frequent rebooting, and anomalies In log files. The Investigator requested log files from the IT administrator and after carefully reviewing them, he finds the following log entry:
What type of attack was performed on the companies' web application?
- A. Unvalidated input
- B. Directory transversal
- C. Log tampering
- D. SQL injection
Answer: D
NEW QUESTION # 381
......
EC-COUNCIL 312-49v10 Actual Questions and Braindumps: https://certblaster.prep4away.com/EC-COUNCIL-certification/braindumps.312-49v10.ete.file.html