Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :Apr 11, 2025

EC-COUNCIL EC-COUNCIL Certifications 312-49 Questions & Answers

  • Question 391:

    Michael works for Kimball Construction Company as senior security analyst. As part of yearly security audit, Michael scans his network for vulnerabilities. Using Nmap, Michael conducts XMAS scan and most of the ports scanned do not give a response. In what state are these ports?

    A. Closed

    B. Open

    C. Stealth

    D. Filtered

  • Question 392:

    If an attacker's computer sends an IPID of 31400 to a zombie computer on an open port in IDLE scanning, what will be the response?

    A. The zombie will not send a response

    B. 31402

    C. 31399

    D. 31401

  • Question 393:

    You setup SNMP in multiple offices of your company. Your SNMP software manager is not receiving data from other offices like it is for your main office. You suspect that firewall changes are to blame. What ports should you open for SNMP to work through Firewalls? (Choose two.)

    A. 162

    B. 161

    C. 163

    D. 160

  • Question 394:

    You are carrying out the last round of testing for your new website before it goes live. The website has many dynamic pages and connects to a SQL backend that accesses your product inventory in a database. You come across a web security site that recommends inputting the following code into a search field on web pages to check for vulnerabilities: When you type this and click on search, you receive a pop-up window that says: "This is a test."

    What is the result of this test?

    A. Your website is vulnerable to CSS

    B. Your website is not vulnerable

    C. Your website is vulnerable to SQL injection

    D. Your website is vulnerable to web bugs

  • Question 395:

    What will the following command produce on a website login page? SELECT email, passwd, login_id, full_name FROM members WHERE email = '[email protected]'; DROP TABLE members; --'

    A. Deletes the entire members table

    B. Inserts the Error! Reference source not found.email address into the members table

    C. Retrieves the password for the first user in the members table

    D. This command will not produce anything since the syntax is incorrect

  • Question 396:

    When you are running a vulnerability scan on a network and the IDS cuts off your connection, what type of IDS is being used?

    A. Passive IDS

    B. Active IDS

    C. Progressive IDS

    D. NIPS

  • Question 397:

    Simon is a former employee of Trinitron XML Inc. He feels he was wrongly terminated and wants to hack into his former company's network. Since Simon remembers some of the server names, he attempts to run the axfr and ixfr commands using DIG. What is Simon trying to accomplish here?

    A. Send DOS commands to crash the DNS servers

    B. Perform DNS poisoning

    C. Perform a zone transfer

    D. Enumerate all the users in the domain

  • Question 398:

    Hackers can gain access to Windows Registry and manipulate user passwords, DNS settings, access rights or others features that they may need in order to accomplish their objectives. One simple method for loading an application at startup is to add an entry (Key) to the following Registry Hive:

    A. HKEY_LOCAL_MACHINE\hardware\windows\start

    B. HKEY_LOCAL_USERS\Software\Microsoft\old\Version\Load

    C. HKEY_CURRENT_USER\Microsoft\Default

    D. HKEY_LOCAL_MACHINE\Software\Microsoft\CurrentVersion\Run

  • Question 399:

    Which of the following file system is used by Mac OS X?

    A. EFS

    B. HFS+

    C. EXT2

    D. NFS

  • Question 400:

    The rule of thumb when shutting down a system is to pull the power plug. However, it has certain drawbacks. Which of the following would that be?

    A. Any data not yet flushed to the system will be lost

    B. All running processes will be lost

    C. The /tmp directory will be flushed

    D. Power interruption will corrupt the pagefile

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.