Exam Details

  • Exam Code
    :EC0-349
  • Exam Name
    :Computer Hacking Forensic Investigator
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :304 Q&As
  • Last Updated
    :Apr 04, 2025

EC-COUNCIL EC-COUNCIL Certifications EC0-349 Questions & Answers

  • Question 131:

    The offset in a hexadecimal code is:

    A. The last byte after the colon

    B. The 0x at the beginning of the code

    C. The 0x at the end of the code

    D. The first byte after the colon

  • Question 132:

    It takes _____________ mismanaged case/s to ruin your professional reputation as a computer forensics examiner?

    A. by law, three

    B. quite a few

    C. only one

    D. at least two

  • Question 133:

    With the standard Linux second extended file system (Ext2fs), a file is deleted when the inode internal link count reaches ________.

    A. 0

    B. 10

    C. 100

    D. 1

  • Question 134:

    When examining the log files from a Windows IIS Web Server, how often is a new log file created?

    A. the same log is used at all times

    B. a new log file is created everyday

    C. a new log file is created each week

    D. a new log is created each time the Web Server is started

  • Question 135:

    The newer Macintosh Operating System is based on: A. OS/2

    B. BSD Unix

    C. Linux

    D. Microsoft Windows

  • Question 136:

    Before you are called to testify as an expert, what must an attorney do first?

    A. engage in damage control

    B. prove that the tools you used to conduct your examination are perfect

    C. read your curriculum vitae to the jury

    D. qualify you as an expert witness

  • Question 137:

    You are contracted to work as a computer forensics investigator for a regional bank that has four 30 TB storage area networks that store customer data.

    What method would be most efficient for you to acquire digital evidence from this network?

    A. create a compressed copy of the file with DoubleSpace

    B. create a sparse data copy of a folder or file

    C. make a bit-stream disk-to-image file

    D. make a bit-stream disk-to-disk file

  • Question 138:

    You are working for a large clothing manufacturer as a computer forensics investigator and are called in to investigate an unusual case of an employee possibly stealing clothing designs from the company and selling them under a different brand name for a different company. What you discover during the course of the investigation is that the clothing designs are actually original products of the employee and the company has no policy against an employee selling his own designs on his own time. The only thing that you can find that the employee is doing wrong is that his clothing design incorporates the same graphic symbol as that of the company with only the wording in the graphic being different. What area of the law is the employee violating?

    A. trademark law

    B. copyright law

    C. printright law

    D. brandmark law

  • Question 139:

    What file structure database would you expect to find on floppy disks?

    A. NTFS

    B. FAT32

    C. FAT16

    D. FAT12

  • Question 140:

    What type of attack occurs when an attacker can force a router to stop forwarding packets by flooding the router with many open connections simultaneously so that all the hosts behind the router are effectively disabled?

    A. digital attack

    B. denial of service

    C. physical attack

    D. ARP redirect

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.