Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1006 Q&As
  • Last Updated
    :Apr 12, 2025

EC-COUNCIL EC-COUNCIL Certifications 312-49V10 Questions & Answers

  • Question 91:

    Which among the following is an act passed by the U.S. Congress in 2002 to protect investors from the possibility of fraudulent accounting activities by corporations?

    A. HIPAA

    B. GLBA

    C. SOX

    D. FISMA

  • Question 92:

    Stephen is checking an image using Compare Files by The Wizard, and he sees the file signature is shown as FF D8 FF E1. What is the file type of the image?

    A. gif

    B. bmp

    C. jpeg

    D. png

  • Question 93:

    Which of the following tools will help the investigator to analyze web server logs?

    A. XRY LOGICAL

    B. LanWhois

    C. Deep Log Monitor

    D. Deep Log Analyzer

  • Question 94:

    Adam, a forensic investigator, is investigating an attack on Microsoft Exchange Server of a large organization. As the first step of the investigation, he examined the PRIV.EDB file and found the source from where the mail originated and the name of the file that disappeared upon execution. Now, he wants to examine the MIME stream content. Which of the following files is he going to examine?

    A. PRIV.STM

    B. gwcheck.db

    C. PRIV.EDB

    D. PUB.EDB

  • Question 95:

    Which of the following is a database in which information about every file and directory on an NT File System (NTFS) volume is stored?

    A. Volume Boot Record

    B. Master Boot Record

    C. GUID Partition Table

    D. Master File Table

  • Question 96:

    Smith, a network administrator with a large MNC, was the first to arrive at a suspected crime scene involving criminal use of compromised computers. What should be his first response while maintaining the integrity of evidence?

    A. Record the system state by taking photographs of physical system and the display

    B. Perform data acquisition without disturbing the state of the systems

    C. Open the systems, remove the hard disk and secure it

    D. Switch off the systems and carry them to the laboratory

  • Question 97:

    An expert witness is a __________________ who is normally appointed by a party to assist the formulation and preparation of a party's claim or defense.

    A. Expert in criminal investigation

    B. Subject matter specialist

    C. Witness present at the crime scene

    D. Expert law graduate appointed by attorney

  • Question 98:

    Annie is searching for certain deleted files on a system running Windows XP OS. Where will she find the files if they were not completely deleted from the system?

    A. C: $Recycled.Bin

    B. C: \$Recycle.Bin

    C. C:\RECYCLER

    D. C:\$RECYCLER

  • Question 99:

    Which of the following files stores information about a local Google Drive installation such as User email ID, Local Sync Root Path, and Client version installed?

    A. filecache.db

    B. config.db

    C. sigstore.db

    D. Sync_config.db

  • Question 100:

    Which of the following acts as a network intrusion detection system as well as network intrusion prevention system?

    A. Accunetix

    B. Nikto

    C. Snort

    D. Kismet

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.