Free Sales Ending Soon - 100% Valid 312-49 Exam Dumps with 150 Questions
Verified 312-49 dumps Q&As on your Certified Ethical Hacker Exam Questions Certain Success!
EC-Council CHFI Exam Certification Details:
| Duration | 240 mins |
| Exam Name | EC-Council Computer Hacking Forensic Investigator (CHFI) |
| Schedule Exam | Pearson VUE |
| Books / Training | Courseware |
| Exam Price | $600 (USD) |
| Passing Score | 70% |
| Exam Code | 312-49 |
| Number of Questions | 150 |
| Sample Questions | EC-Council CHFI Sample Questions |
NEW QUESTION 57
To preserve digital evidence, an investigator should ____________
- A. Make two copies of each evidence item using a single imaging tool
- B. Make two copies of each evidence item using different imaging tools
- C. Only store the original evidence item
- D. Make a single copy of each evidence item using an approved imaging tool
Answer: B
NEW QUESTION 58
What will the following command accomplish?
dd if=/dev/xxx of=mbr.backup bs=512 count=1
- A. Mount the master boot record on the first partition of the hard drive
- B. Restore the master boot record
- C. Restore the first 512 bytes of the first partition of the hard drive
- D. Back up the master boot record
Answer: D
NEW QUESTION 59
What feature of Windows is the following command trying to utilize?
- A. White space
- B. AFS
- C. Slack file
- D. ADS
Answer: D
NEW QUESTION 60
You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers. What type of firewall must you implement to abide by this policy?
- A. Circuit-level proxy firewall
- B. Packet filtering firewall
- C. Stateful firewall
- D. Application-level proxy firewall
Answer: C
Explanation:
Explanation
NEW QUESTION 61
Which of the following tool can reverse machine code to assembly language?
- A. PEiD
- B. IDA Pro
- C. Deep Log Analyzer
- D. RAM Capturer
Answer: B
NEW QUESTION 62
NTFS has reduced slack space than FAT, thus having lesser potential to hide data in the slack space. This is because:
- A. NTFS has lower cluster size space
- B. FAT does not index files
- C. FAT is an older and inefficient file system
- D. NTFS is a journaling file system
Answer: A
NEW QUESTION 63
What type of equipment would a forensics investigator store in a StrongHold bag?
- A. Backup tapes
- B. PDAPDA?
- C. Wireless cards
- D. Hard drives
Answer: C
NEW QUESTION 64
In the following directory listing,
Which file should be used to restore archived email messages for someone using Microsoft Outlook?
- A. Outlook ost
- B. Outlook bak
- C. Outlook pst
- D. Outlook NK2
Answer: C
NEW QUESTION 65
When is it appropriate to use computer forensics?
- A. If a financial institution is burglarized by robbers
- B. If employees do not care for their boss?management techniques
- C. If copyright and intellectual property theft/misuse has occurred
- D. If sales drop off for no apparent reason for an extended period of time
Answer: C
NEW QUESTION 66
Which of the following stages in a Linux boot process involve initialization of the system's hardware?
- A. Bootloader Stage
- B. BootROM Stage
- C. BIOS Stage
- D. Kernel Stage
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION 67
What operating system would respond to the following command?
c:\> nmap -sW 10.10.145.65
- A. Mac OS X
- B. Windows 95
- C. FreeBSD
- D. Windows XP
Answer: C
NEW QUESTION 68
You are working in the Security Department of a law firm. One of the attorneys asks you about the topic of sending fake email because he has a client who has been charged with doing just that. His client alleges that he is innocent and that there is no way for a fake email to actually be sent. You inform the attorney that his client is mistaken and that fake email is a possibility and that you can prove it. You return to your desk and craft a fake email to the attorney that appears to come from his boss. What port do you send the email to on the company SMTP server?fake email to the attorney that appears to come from his boss. What port do you send the email to on the company? SMTP server?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION 69
What is the primary function of the tool CHKDSK in Windows that authenticates the file system reliability of a volume?
- A. Check the disk for hardware errors
- B. Repairs logical file system errors
- C. Check the disk for Slack Space
- D. Check the disk for connectivity errors
Answer: B
NEW QUESTION 70
What binary coding is used most often for e-mail purposes?
- A. SMTP
- B. IMAP
- C. MIME
- D. Uuencode
Answer: C
NEW QUESTION 71
Using Internet logging software to investigate a case of malicious use of computers, the investigator comes across some entries that appear odd.
From the log, the investigator can see where the person in question went on the Internet. From the log, it appears that the user was manually typing in different user ID numbers. What technique this user was trying?
- A. Parameter tampering
- B. SQL injection
- C. Cookie Poisoning
- D. Cross site scripting
Answer: A
NEW QUESTION 72
Which of the following Windows-based tool displays who is logged onto a computer, either locally or remotely?
- A. Tokenmon
- B. Process Monitor
- C. PSLoggedon
- D. TCPView
Answer: C
NEW QUESTION 73
Which of the following application password cracking tool can discover all password-protected items on a computer and decrypts them?
- A. R-Studio
- B. Passware Kit Forensic
- C. TestDisk for Windows
- D. Windows Password Recovery Bootdisk
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION 74
What type of attack occurs when an attacker can force a router to stop forwarding packets by flooding the router with many open connections simultaneously so that all the hosts behind the router are effectively disabled?
- A. Denial of service
- B. ARP redirect
- C. Digital attack
- D. Physical attack
Answer: A
NEW QUESTION 75
......
This certification exam measures the individuals’ knowledge of identifying the intruders’ footprints. It also equips the interested candidates with the skills required to collect the relevant proof to indict defaulters in a court of law. Those students who achieve the passing score in EC-Council 312-49 qualify to earn the Computer Hacking Forensic Investigator certificate. The certification you obtain validates your skills in specific security specialization in the domain of computer forensics. The potential applicants for this track will develop the expertise required to function in a range of career paths associated with cybersecurity and other legal professions.
EC-COUNCIL 312-49 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
312-49 Exam Dumps - 100% Marks In 312-49 Exam: https://www.real4dumps.com/312-49_examcollection.html
Exam Dumps Use Real Certified Ethical Hacker Dumps With 150 Questions: https://drive.google.com/open?id=1A9HHZBqL6deLzyF70jc-3wUqTdzD6rRw

