Exam Details

  • Exam Code
    :312-49V8
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V8)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :180 Q&As
  • Last Updated
    :Apr 10, 2025

EC-COUNCIL EC-COUNCIL Certifications 312-49V8 Questions & Answers

  • Question 81:

    Networks are vulnerable to an attack which occurs due to overextension of bandwidth, bottlenecks,

    network data interception, etc.

    Which of the following network attacks refers to a process in which an attacker changes his or her IP

    address so that he or she appears to be someone else?

    A. IP address spoofing

    B. Man-in-the-middle attack

    C. Denial of Service attack

    D. Session sniffing

  • Question 82:

    In Windows 7 system files, which file reads the Boot.ini file and loads Ntoskrnl.exe. Bootvid.dll. Hal.dll, and boot-start device drivers?

    A. Ntldr

    B. Gdi32.dll

    C. Kernel32.dll

    D. Boot.in

  • Question 83:

    Which of the following passwords are sent over the wire (and wireless) network, or stored on some media as it is typed without any alteration?

    A. Clear text passwords

    B. Obfuscated passwords

    C. Hashed passwords

    D. Hex passwords

  • Question 84:

    SIM is a removable component that contains essential information about the subscriber. It has both volatile and non-volatile memory. The file system of a SIM resides in _____________ memory.

    A. Volatile

    B. Non-volatile

  • Question 85:

    What is the "Best Evidence Rule"?

    A. It states that the court only allows the original evidence of a document, photograph, or recording at the trial rather than a copy

    B. It contains system time, logged-on user(s), open files, network information, process information, process-to-port mapping, process memory, clipboard contents, service/driver information, and command history

    C. It contains hidden files, slack space, swap file, index.dat files, unallocated clusters, unused partitions, hidden partitions, registry settings, and event logs

    D. It contains information such as open network connection, user logout, programs that reside in memory, and cache data

  • Question 86:

    Computer security logs contain information about the events occurring within an organization's systems and networks. Which of the following security logs contains Logs of network and host-based security software?

    A. Operating System (OS) logs

    B. Application logs

    C. Security software logs

    D. Audit logs

  • Question 87:

    Digital photography helps in correcting the perspective of the Image which Is used In taking the measurements of the evidence. Snapshots of the evidence and incident-prone areas need to be taken to help in the forensic process. Is digital photography accepted as evidence in the court of law?

    A. Yes

    B. No

  • Question 88:

    At the time of evidence transfer, both sender and receiver need to give the information about date and time of transfer in the chain of custody record.

    A. True

    B. False

  • Question 89:

    Which of the following is not a part of data acquisition forensics Investigation?

    A. Permit only authorized personnel to access

    B. Protect the evidence from extremes in temperature

    C. Work on the original storage medium not on the duplicated copy

    D. Disable all remote access to the system

  • Question 90:

    Depending upon the Jurisdictional areas, different laws apply to different incidents. Which of the following law is related to fraud and related activity in connection with computers?

    A. 18 USC 7029

    B. 18 USC 7030

    C. 18 USC 7361

    D. 18 USC 7371

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V8 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.