Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1006 Q&As
  • Last Updated
    :Apr 12, 2025

EC-COUNCIL EC-COUNCIL Certifications 312-49V10 Questions & Answers

  • Question 41:

    What value of the "Boot Record Signature" is used to indicate that the boot-loader exists?

    A. AA55

    B. 00AA

    C. AA00

    D. A100

  • Question 42:

    Which of the following ISO standard defines file systems and protocol for exchanging data between optical disks?

    A. ISO 9660

    B. ISO/IEC 13940

    C. ISO 9060

    D. IEC 3490

  • Question 43:

    Lynne receives the following email:

    Dear [email protected]! We are sorry to inform you that your ID has been temporarily frozen due to

    incorrect or missing information saved at 2016/11/10 20:40:24

    You have 24 hours to fix this problem or risk to be closed permanently!

    To proceed Please Connect >> My Apple ID

    Thank You The link to My Apple ID shows http://byggarbetsplatsen.se/backup/signon/

    What type of attack is this?

    A. Mail Bombing

    B. Phishing

    C. Email Spamming

    D. Email Spoofing

  • Question 44:

    Which of the following statements is incorrect when preserving digital evidence?

    A. Verify if the monitor is in on, off, or in sleep mode

    B. Turn on the computer and extract Windows event viewer log files

    C. Remove the plug from the power router or modem

    D. Document the actions and changes that you observe in the monitor, computer, printer, or in other peripherals

  • Question 45:

    Which of the following is a part of a Solid-State Drive (SSD)?

    A. Head

    B. Cylinder

    C. NAND-based flash memory

    D. Spindle

  • Question 46:

    Which of the following standard represents a legal precedent set in 1993 by the Supreme Court of the United States regarding the admissibility of expert witnesses' testimony during federal legal proceedings?

    A. SWGDE and SWGIT

    B. IOCE

    C. Frye

    D. Daubert

  • Question 47:

    Which of the following is NOT a physical evidence?

    A. Removable media

    B. Cables

    C. Image file on a hard disk

    D. Publications

  • Question 48:

    During forensics investigations, investigators tend to collect the system time at first and compare it with UTC. What does the abbreviation UTC stand for?

    A. Coordinated Universal Time

    B. Universal Computer Time

    C. Universal Time for Computers

    D. Correlated Universal Time

  • Question 49:

    Buffer overflow vulnerability of a web application occurs when it fails to guard its buffer properly and allows writing beyond its maximum size. Thus, it overwrites the_________. There are multiple forms of buffer overflow, including a Heap Buffer Overflow and a Format String Attack.

    A. Adjacent memory locations

    B. Adjacent bit blocks

    C. Adjacent buffer locations

    D. Adjacent string locations

  • Question 50:

    Gary is checking for the devices connected to USB ports of a suspect system during an investigation. Select the appropriate tool that will help him document all the connected devices.

    A. DevScan

    B. Devcon

    C. fsutil

    D. Reg.exe

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.