2023 Correct Practice Tests of 312-49v10 Dumps with Practice Exam [Q22-Q46]

Share

2023 Correct Practice Tests of 312-49v10 Dumps with Practice Exam

Certification Sample Questions of 312-49v10 Dumps With 100% Exam Passing Guarantee


EC-COUNCIL 312-49v10 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Data Acquisition and Duplication
  • Linux and Mac Forensics
Topic 2
  • Computer Forensics Investigation Process
  • Dark Web Forensics
  • Mobile Forensics
Topic 3
  • Database Forensics
  • Network Forensics
  • Windows Forensics

 

NEW QUESTION 22
Which of the following refers to the data that might still exist in a cluster even though the original file has been overwritten by another file?

  • A. Slack Space
  • B. Sector
  • C. Metadata
  • D. MFT

Answer: A

 

NEW QUESTION 23
In the following email header, where did the email first originate from?

  • A. David1.state.ok.gov.us
  • B. Somedomain.com
  • C. Simon1.state.ok.gov.us
  • D. Smtp1.somedomain.com

Answer: C

 

NEW QUESTION 24
Which of the following tool enables a user to reset his/her lost admin password in a Windows system?

  • A. Advanced Office Password Recovery
  • B. Smartkey Password Recovery Bundle Standard
  • C. Active@ Password Changer
  • D. Passware Kit Forensic

Answer: C

 

NEW QUESTION 25
Melanie was newly assigned to an investigation and asked to make a copy of all the evidence from the compromised system. Melanie did a DOS copy of all the files on the system. What would be the primary reason for you to recommend a disk imaging tool?

  • A. There is no case for an imaging tool as it will use a closed, proprietary format that if compared to the original will not match up sector for sector
  • B. A disk imaging tool would check for CRC32s for internal self-checking and validation and have MD5 checksum
  • C. Evidence file format will contain case data entered by the examiner and encrypted at the beginning of the evidence file
  • D. A simple DOS copy will not include deleted files, file slack and other information

Answer: D

 

NEW QUESTION 26
While analyzing a hard disk, the investigator finds that the file system does not use UEFI-based interface. Which of the following operating systems is present on the hard disk?

  • A. Windows 8.1
  • B. Windows 8
  • C. Windows 10
  • D. Windows 7

Answer: D

 

NEW QUESTION 27
Rusty, a computer forensics apprentice, uses the command nbtstat -c while analyzing the network information in a suspect system. What information is he looking for?

  • A. Network connections
  • B. Contents of the NetBIOS name cache
  • C. Contents of the network routing table
  • D. Status of the network carrier

Answer: B

 

NEW QUESTION 28
What will the following URL produce in an unpatched IIS Web Server?
http://www.thetargetsite.com/scripts/..% co%af../..%co%af../windows/system32/cmd.exe?/c+dir+c:\

  • A. Insert a Trojan horse into the C: drive of the web server
  • B. Directory listing of the C:\windows\system32 folder on the web server
  • C. Execute a buffer flow in the C: drive of the web server
  • D. Directory listing of C: drive on the web server

Answer: D

 

NEW QUESTION 29
The use of warning banners helps a company avoid litigation by overcoming an employee assumed __________________________. When connecting to the company's intranet, network or Virtual Private Network(VPN) and will allow the company's investigators to monitor, search and retrieve information stored within the network.

  • A. Right to work
  • B. Right to Internet Access
  • C. Right of free speech
  • D. Right of Privacy

Answer: D

 

NEW QUESTION 30
Which of the following statements is incorrect when preserving digital evidence?

  • A. Document the actions and changes that you observe in the monitor, computer, printer, or in other peripherals
  • B. Turn on the computer and extract Windows event viewer log files
  • C. Remove the plug from the power router or modem
  • D. Verify if the monitor is in on, off, or in sleep mode

Answer: B

 

NEW QUESTION 31
In Linux OS, different log files hold different information, which help the investigators to analyze various issues during a security incident. What information can the investigators obtain from the log file var/log/dmesg?

  • A. All mail server message logs
  • B. Global system messages
  • C. Debugging log messages
  • D. Kernel ring buffer information

Answer: D

 

NEW QUESTION 32
This is a statement, other than one made by the declarant while testifying at the trial or hearing, offered in evidence to prove the truth of the matter asserted. Which among the following is suitable for the above statement?

  • A. Hearsay rule
  • B. Limited admissibility
  • C. Rule 1001
  • D. Testimony by the accused

Answer: A

 

NEW QUESTION 33
Examination of a computer by a technically unauthorized person will almost always result in:

  • A. Rendering any evidence found admissible in a court of law
  • B. The chain of custody being fully maintained
  • C. Rendering any evidence found inadmissible in a court of law
  • D. Completely accurate results of the examination

Answer: C

 

NEW QUESTION 34
Which of the following Perl scripts will help an investigator to access the executable image of a process?

  • A. Lspi.pl
  • B. Lpsi.pl
  • C. Lspd.pl
  • D. Lspm.pl

Answer: A

 

NEW QUESTION 35
Checkpoint Firewall logs can be viewed through a Check Point Log viewer that uses icons and colors in the log table to represent different security events and their severity. What does the icon in the checkpoint logs represent?

  • A. An email was marked as potential spam
  • B. The firewall rejected a connection
  • C. A virus was detected in an email
  • D. The firewall dropped a connection

Answer: D

 

NEW QUESTION 36
What will the following Linux command accomplish?
dd if=/dev/mem of=/home/sam/mem.bin bs=1024

  • A. Copy the memory dump file to an image file
  • B. Copy the contents of the system folder to a file
  • C. Copy the running memory to a file
  • D. Copy the master boot record to a file

Answer: C

 

NEW QUESTION 37
companyXYZ has asked you to assess the security of their perimeter email gateway. From your office in New York you craft a specially formatted email message and send it across the Internet to an employee of CompanyXYZ. The employee of CompanyXYZ is aware.

  • A. Source code review
  • B. Data items and vulnerability scanning
  • C. Interviewing employees and network engineers
  • D. Reviewing the firewalls configuration

Answer: A

 

NEW QUESTION 38
Tyler is setting up a wireless network for his business that he runs out of his home. He has followed all the directions from the ISP as well as the wireless router manual. He does not have any encryption set and the SSID is being broadcast. On his laptop, he can pick up the wireless signal for short periods of time, but then the connection drops and the signal goes away.
Eventually the wireless signal shows back up, but drops intermittently. What could be Tyler issue with his home wireless network?

  • A. Satellite television
  • B. Computers on his wired network
  • C. 2.4Ghz Cordless phones
  • D. CB radio

Answer: C

 

NEW QUESTION 39
A cybercriminal is attempting to remove evidence from a Windows computer. He deletes the file evldence1.doc. sending it to Windows Recycle Bin. The cybercriminal then empties the Recycle Bin. After having been removed from the Recycle Bin. what will happen to the data?

  • A. The data will remain in its original clusters until it is overwritten
  • B. The data will become corrupted, making it unrecoverable
  • C. The data will be moved to new clusters in unallocated space
  • D. The data will be overwritten with zeroes

Answer: A

 

NEW QUESTION 40
Bob works as information security analyst for a big finance company. One day, the anomaly-based intrusion detection system alerted that a volumetric DDOS targeting the main IP of the main web server was occurring. What kind of attack is it?

  • A. IDS attack
  • B. APT
  • C. Web application attack
  • D. Network attack

Answer: D

 

NEW QUESTION 41
Where is the default location for Apache access logs on a Linux computer?

  • A. usr/local/apache/logs/access_log
  • B. usr/logs/access_log
  • C. logs/usr/apache/access_log
  • D. bin/local/home/apache/logs/access_log

Answer: A

 

NEW QUESTION 42
Which set of anti-forensic tools/techniques allows a program to compress and/or encrypt an executable file to hide attack tools from being detected by reverse-engineering or scanning?

  • A. Emulators
  • B. Packers
  • C. Botnets
  • D. Password crackers

Answer: B

 

NEW QUESTION 43
What does the acronym POST mean as it relates to a PC?

  • A. PowerOn Self Test
  • B. Primary Operations Short Test
  • C. Primary Operating System Test
  • D. Pre Operational Situation Test

Answer: A

 

NEW QUESTION 44
What is the primary function of the tool CHKDSK in Windows that authenticates the file system reliability of a volume?

  • A. Check the disk for hardware errors
  • B. Check the disk for Slack Space
  • C. Check the disk for connectivity errors
  • D. Repairs logical file system errors

Answer: D

 

NEW QUESTION 45
How often must a company keep log files for them to be admissible in a court of law?

  • A. Monthly
  • B. All log files are admissible in court no matter their frequency
  • C. Continuously
  • D. Weekly

Answer: C

 

NEW QUESTION 46
......

312-49v10 Sample Practice Exam Questions 2023 Updated Verified: https://www.braindumpspass.com/EC-COUNCIL/312-49v10-practice-exam-dumps.html

Pass Key features of 312-49v10 Course with Updated 705 Questions: https://drive.google.com/open?id=1nHlLjDFrhsEfdZelKDQ9HhVVuyFXBguM