Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :Apr 19, 2025

EC-COUNCIL EC-COUNCIL Certifications 312-49 Questions & Answers

  • Question 261:

    What is the first step taken in an investigation for laboratory forensic staff members?

    A. Packaging the electronic evidence

    B. Securing and evaluating the electronic crime scene

    C. Conducting preliminary interviews

    D. Transporting the electronic evidence

  • Question 262:

    Which program is the bootloader when Windows XP starts up?

    A. KERNEL.EXE

    B. NTLDR

    C. LOADER

    D. LILO

  • Question 263:

    Sniffers that place NICs in promiscuous mode work at what layer of the OSI model?

    A. Network

    B. Transport

    C. Physical

    D. Data Link

  • Question 264:

    Where are files temporarily written in Unix when printing?

    A. /usr/spool

    B. /var/print

    C. /spool

    D. /var/spool

  • Question 265:

    All Blackberry email is eventually sent and received through what proprietary RIM-operated mechanism?

    A. Blackberry Message Center

    B. Microsoft Exchange

    C. Blackberry WAP gateway

    D. Blackberry WEP gateway

  • Question 266:

    Which forensic investigating concept trails the whole incident from how the attack began to how the victim was affected?

    A. Point-to-point

    B. End-to-end

    C. Thorough

    D. Complete event analysis

  • Question 267:

    You have been called in to help with an investigation of an alleged network intrusion. After questioning the members of the company IT department, you search through the server log files to find any trace of the intrusion. After that you decide to telnet into one of the company routers to see if there is any evidence to be found. While connected to the router, you see some unusual activity and believe that the attackers are currently connected to that router. You start up an ethereal session to begin capturing traffic on the router that could be used in the investigation. At what layer of the OSI model are you monitoring while watching traffic to and from the router?

    A. Network

    B. Transport

    C. Data Link

    D. Session

  • Question 268:

    Steven has been given the task of designing a computer forensics lab for the company he works for. He has found documentation on all aspects of how to design a lab except the number of exits needed. How many exits should Steven include in his design for the computer forensics lab?

    A. Three

    B. One

    C. Two

    D. Four

  • Question 269:

    A forensics investigator needs to copy data from a computer to some type of removable media so he can examine the information at another location. The problem is that the data is around 42GB in size. What type of removable media could the investigator use?

    A. Blu-Ray single-layer

    B. HD-DVD

    C. Blu-Ray dual-layer

    D. DVD-18

  • Question 270:

    Julie is a college student majoring in Information Systems and Computer Science. She is currently writing an essay for her computer crimes class. Julie paper focuses on white-collar crimes in America and how forensics investigators investigate the cases. Julie would like to focus the subject. Julie would like to focus the subject of the essay on the most common type of crime found in corporate America. What crime should Julie focus on?

    A. Physical theft

    B. Copyright infringement

    C. Industrial espionage

    D. Denial of Service attacks

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.