EC-COUNCIL 312-49v10 Exam Prep Guide: Prep guide for the 312-49v10 Exam
2024 New Preparation Guide of EC-COUNCIL 312-49v10 Exam
NEW QUESTION # 412
Why is it still possible to recover files that have been emptied from the Recycle Bin on a Windows computer?
- A. The data will reside in the L2 cache on a Windows computer until it is manually deleted
- B. The data is still present until the original location of the file is used
- C. The data is moved to the Restore directory and is kept there indefinitely
- D. It is not possible to recover data that has been emptied from the Recycle Bin
Answer: B
NEW QUESTION # 413
Buffer overflow vulnerabilities, of web applications, occurs when the application fails to guard its buffer properly and allows writing beyond its maximum size. Thus, it overwrites the _________. There are multiple forms of buffer overflow, including a Heap Buffer Overflow and a Format String Attack.
- A. Adjacent buffer locations
- B. Adjacent bit blocks
- C. Adjacent string locations
- D. Adjacent memory locations
Answer: D
NEW QUESTION # 414
This organization maintains a database of hash signatures for known software.
- A. American National standards Institute
- B. International Standards Organization
- C. National Software Reference Library
- D. Institute of Electrical and Electronics Engineers
Answer: C
NEW QUESTION # 415
Which password cracking technique uses every possible combination of character sets?
- A. Rule-based attack
- B. Dictionary attack
- C. Brute force attack
- D. Rainbow table attack
Answer: C
NEW QUESTION # 416
Which of the following tools will help the investigator to analyze web server logs?
- A. Deep Log Analyzer
- B. Deep Log Monitor
- C. XRY LOGICAL
- D. LanWhois
Answer: A
NEW QUESTION # 417
Which of the following malware targets Android mobile devices and installs a backdoor that remotely installs applications from an attacker-controlled server?
- A. XcodeGhost
- B. Unflod
- C. Felix
- D. xHelper
Answer: B
NEW QUESTION # 418
Which US law does the interstate or international transportation and receiving of child pornography fall under?
- A. §18. U.S.C 2252
- B. §18. U.S.C. 1466A
- C. §18. U.S.C 252
- D. §18. U.S.C 146A
Answer: A
NEW QUESTION # 419
Which of the following stages in a Linux boot process involve initialization of the system's hardware?
- A. BootROM Stage
- B. Bootloader Stage
- C. Kernel Stage
- D. BIOS Stage
Answer: D
NEW QUESTION # 420
Ron, a computer forensics expert, is investigating a case involving corporate espionage. He has recovered several mobile computing devices from the crime scene. One of the evidence that Ron possesses is a mobile phone from Nokia that was left in ON condition. Ron needs to recover the IMEI number of the device to establish the identity of the device owner. Which of the following key combinations can he use to recover the IMEI number?
- A. #*06*#
- B. *IMEI#
- C. #06#*
- D. *#06#
Answer: A
NEW QUESTION # 421
You are a computer forensics investigator working with local police department and you are called to assist in an investigation of threatening emails. The complainant has printer out 27 email messages from the suspect and gives the printouts to you. You inform her that you will need to examine her computer because you need access to the _________________________ in order to track the emails back to the suspect.
- A. Firewall log
- B. Email Header
- C. Routing Table
- D. Configuration files
Answer: B
NEW QUESTION # 422
Which of the following is an iOS Jailbreaking tool?
- A. Kingo Android ROOT
- B. One Click Root
- C. Redsn0w
- D. Towelroot
Answer: C
NEW QUESTION # 423
When setting up a wireless network with multiple access points, why is it important to set each access point on a different channel?
- A. Multiple access points can be set up on the same channel without any issues
- B. So that the access points will work on different frequencies
- C. Avoid cross talk
- D. Avoid over-saturation of wireless signals
Answer: C
NEW QUESTION # 424
Which rule requires an original recording to be provided to prove the content of a recording?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
NEW QUESTION # 425
The Recycle Bin exists as a metaphor for throwing files away, but it also allows a user to retrieve and restore files. Once the file is moved to the recycle bin, a record is added to the log file that exists in the Recycle Bin. Which of the following files contains records that correspond to each deleted file in the Recycle Bin?
- A. INFO1
- B. INFO2
- C. LOGINFO2
- D. LOGINFO1
Answer: C
NEW QUESTION # 426
You are contracted to work as a computer forensics investigator for a regional bank that has four 30 TB storage area networks that store customer data.
What method would be most efficient for you to acquire digital evidence from this network?
- A. make a bit-stream disk-to-image file
- B. make a bit-stream disk-to-disk file
- C. create a sparse data copy of a folder or file
- D. create a compressed copy of the file with DoubleSpace
Answer: A
NEW QUESTION # 427
What feature of Windows is the following command trying to utilize?
- A. White space
- B. ADS
- C. Slack file
- D. AFS
Answer: B
NEW QUESTION # 428
Which of the following files contains the traces of the applications installed, run, or uninstalled from a system?
- A. Image Files
- B. Virtual Files
- C. Prefetch Files
- D. Shortcut Files
Answer: D
NEW QUESTION # 429
The ____________________ refers to handing over the results of private investigations to the authorities because of indications of criminal activity.
- A. Locard Exchange Principle
- B. Silver-Platter Doctrine
- C. Clark Standard
- D. Kelly Policy
Answer: B
NEW QUESTION # 430
Which command can provide the investigators with details of all the loaded modules on a Linux-based system?
- A. plist mod -a
- B. list modules -a
- C. lsmod
- D. lsof -m
Answer: C
NEW QUESTION # 431
A forensic examiner is examining a Windows system seized from a crime scene. During the examination of a suspect file, he discovered that the file is password protected. He tried guessing the password using the suspect's available information but without any success. Which of the following tool can help the investigator to solve this issue?
- A. Cain & Abel
- B. Recuva
- C. Colasoft's Capsa
- D. Xplico
Answer: A
NEW QUESTION # 432
......
EC-COUNCIL 312-49v10 certification exam, also known as the Computer Hacking Forensic Investigator (CHFI-v10), is an industry-recognized certification for professionals who are interested in working in the field of computer forensics. Computer Hacking Forensic Investigator (CHFI-v10) certification exam is designed to equip candidates with the necessary skills and knowledge to identify, collect, and analyze evidence from computer systems, networks, and digital devices.
Latest Questions 312-49v10 Guide to Prepare Free Practice Tests: https://certblaster.prep4away.com/EC-COUNCIL-certification/braindumps.312-49v10.ete.file.html