4.3/5 - (3 votes)

EC-COUNCIL 312-49v10 Practice Verified Answers – Pass Your Exams For Sure! [2023]

Valid Way To Pass CHFI v10’s 312-49v10 Exam

Q106. “In exceptional circumstances, where a person finds it necessary to access original data held on a computer or on storage media, that person must be competent to do so and be able to explain his/her actions and the impact of those actions on the evidence, in the court.” Which ACPO principle states this?

 
 
 
 

Q107. Steve received a mail that seemed to have come from her bank. The mail has instructions for Steve to click on a link and provide information to avoid the suspension of her account. The link in the mail redirected her to a form asking for details such as name, phone number, date of birth, credit card number or PIN, CW code, SNNs, and email address. On a closer look, Steve realized that the URL of the form in not the same as that of her bank’s. Identify the type of external attack performed by the attacker In the above scenario?

 
 
 
 

Q108. You are running through a series of tests on your network to check for any security vulnerabilities.
After normal working hours, you initiate a DoS attack against your external firewall. The firewall Quickly freezes up and becomes unusable. You then initiate an FTP connection from an external IP into your internal network. The connection is successful even though you have FTP blocked at the external firewall. What has happened?

 
 
 
 

Q109. Which of the following network attacks refers to sending huge volumes of email to an address in an attempt to overflow the mailbox or overwhelm the server where the email address is hosted so as to cause a denial-of-service attack?

 
 
 
 

Q110. What is the extension used by Windows OS for shortcut files present on the machine?

 
 
 
 

Q111. Which code does the FAT file system use to mark the file as deleted?

 
 
 
 

Q112. Office documents (Word, Excel, PowerPoint) contain a code that allows tracking the MAC, or unique identifier, of the machine that created the document. What is that code called?

 
 
 
 

Q113. Which of the following options will help users to enable or disable the last access time on a system running Windows 10 OS?

 
 
 
 

Q114. Which part of the Windows Registry contains the user’s password file?

 
 
 
 

Q115. Melanie was newly assigned to an investigation and asked to make a copy of all the evidence from the compromised system. Melanie did a DOS copy of all the files on the system. What would be the primary reason for you to recommend a disk imaging tool?

 
 
 
 

Q116. Edgar is part of the FBI’s forensic media and malware analysis team; he Is analyzing a current malware and Is conducting a thorough examination of the suspect system, network, and other connected devices. Edgar’s approach Is to execute the malware code to know how It Interacts with the host system and Its Impacts on It. He is also using a virtual machine and a sandbox environment.
What type of malware analysis is Edgar performing?

 
 
 
 

Q117. Which of the following tool enables a user to reset his/her lost admin password in a Windows system?

 
 
 
 

Q118. What is the role of Alloc.c in Apache core?

 
 
 
 

Q119. An “idle” system is also referred to as what?

 
 
 
 

Q120. You are working as an investigator for a corporation and you have just received instructions from your manager to assist in the collection of 15 hard drives that are part of an ongoing investigation.
Your job is to complete the required evidence custody forms to properly document each piece of evidence as it is collected by other members of your team. Your manager instructs you to complete one multi-evidence form for the entire case and a single-evidence form for each hard drive. How will these forms be stored to help preserve the chain of custody of the case?

 
 
 
 

Q121. Where is the default location for Apache access logs on a Linux computer?

 
 
 
 

Q122. You are a forensic investigator who is analyzing a hard drive that was recently collected as evidence. You have been unsuccessful at locating any meaningful evidence within the file system and suspect a drive wiping utility may have been used. You have reviewed the keys within the software hive of the Windows registry and did not find any drive wiping utilities. How can you verify that drive wiping software was used on the hard drive?

 
 
 
 

Q123. Which of the following tasks DOES NOT come under the investigation phase of a cybercrime forensics investigation case?

 
 
 
 

Q124. Amelia has got an email from a well-reputed company stating in the subject line that she has won a prize money, whereas the email body says that she has to pay a certain amount for being eligible for the contest. Which of the following acts does the email breach?

 
 
 
 

Q125. Which of the following tool enables data acquisition and duplication?

 
 
 
 

EC-COUNCIL 312-49v10 Exam Syllabus Topics:

Topic Details
Topic 1
  • Defeating Anti-Forensics Techniques
  • Malware Forensics
Topic 2
  • Understanding Hard Disks and File Systems
  • Investigating Email Crimes
Topic 3
  • Computer Forensics Investigation Process
  • Dark Web Forensics
  • Mobile Forensics
Topic 4
  • Computer Forensics in Today’s World
  • Investigating Web Attacks
Topic 5
  • Database Forensics
  • Network Forensics
  • Windows Forensics

 

EC-COUNCIL 312-49v10 Pre-Exam Practice Tests | SurePassExams: https://www.surepassexams.com/312-49v10-exam-bootcamp.html

         

Related Links: myportal.utt.edu.tt www.stes.tyc.edu.tw myportal.utt.edu.tt myportal.utt.edu.tt www.stes.tyc.edu.tw myportal.utt.edu.tt

Leave a Reply

Your email address will not be published. Required fields are marked *

Enter the text from the image below