EC-COUNCIL 312-49v10 Real Exam Questions and Answers FREE [Q12-Q28]

Share

EC-COUNCIL 312-49v10 Real Exam Questions and Answers FREE

Exam Dumps 312-49v10 Practice Free Latest EC-COUNCIL Practice Tests


EC-COUNCIL 312-49v10 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Defeating Anti-Forensics Techniques
  • Malware Forensics
Topic 2
  • Data Acquisition and Duplication
  • Linux and Mac Forensics
Topic 3
  • Computer Forensics in Today’s World
  • Investigating Web Attacks
Topic 4
  • Understanding Hard Disks and File Systems
  • Investigating Email Crimes
Topic 5
  • Database Forensics
  • Network Forensics
  • Windows Forensics

 

NEW QUESTION 12
When examining a file with a Hex Editor, what space does the file header occupy?

  • A. one byte at the beginning of the file
  • B. the last several bytes of the file
  • C. none, file headers are contained in the FAT
  • D. the first several bytes of the file

Answer: A

 

NEW QUESTION 13
Which of the following files stores information about a local Google Drive installation such as User email ID, Local Sync Root Path, and Client version installed?

  • A. config.db
  • B. Sync_config.db
  • C. sigstore.db
  • D. filecache.db

Answer: B

 

NEW QUESTION 14
What will the following command accomplish?
dd if=/dev/xxx of=mbr.backup bs=512 count=1

  • A. Restore the first 512 bytes of the first partition of the hard drive
  • B. Back up the master boot record
  • C. Restore the master boot record
  • D. Mount the master boot record on the first partition of the hard drive

Answer: B

 

NEW QUESTION 15
Which Event Correlation approach assumes and predicts what an attacker can do next after the attack by studying statistics and probability?

  • A. Bayesian Correlation
  • B. Automated Field Correlation
  • C. Profile/Fingerprint-Based Approach
  • D. Time (Clock Time) or Role-Based Approach

Answer: A

 

NEW QUESTION 16
What type of attack sends SYN requests to a target system with spoofed IP addresses?

  • A. Cross site scripting
  • B. Ping of death
  • C. SYN flood
  • D. Land

Answer: C

 

NEW QUESTION 17
Robert is a regional manager working in a reputed organization. One day, he suspected malware attack after unwanted programs started to popup after logging into his computer. The network administrator was called upon to trace out any intrusion on the computer and he/she finds that suspicious activity has taken place within Autostart locations. In this situation, which of the following tools is used by the network administrator to detect any intrusion on a system?

  • A. Report Viewer
  • B. Internet Evidence Finder
  • C. Process Monitor
  • D. Hex Editor

Answer: C

 

NEW QUESTION 18
Preparing an image drive to copy files to is the first step in Linux forensics. For this purpose, what would the following command accomplish?
dcfldd if=/dev/zero of=/dev/hda bs=4096 conv=noerror, sync

  • A. Fill the disk with 4096 zeros
  • B. Low-level format
  • C. Fill the disk with zeros
  • D. Copy files from the master disk to the slave disk on the secondary IDE controller

Answer: C

 

NEW QUESTION 19
One technique for hiding information is to change the file extension from the correct one to one that might not be noticed by an investigator. For example, changing a .jpg extension to a .doc extension so that a picture file appears to be a document. What can an investigator examine to verify that a file has the correct extension?

  • A. the file footer
  • B. the file header
  • C. the File Allocation Table
  • D. the sector map

Answer: B

 

NEW QUESTION 20
What is kept in the following directory? HKLM\SECURITY\Policy\Secrets

  • A. Local store PKI Kerberos certificates
  • B. Cached password hashes for the past 20 users
  • C. IAS account names and passwords
  • D. Service account passwords in plain text

Answer: D

 

NEW QUESTION 21
If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system while doing an investigation, what can you conclude?

  • A. Nothing in particular as these can be operational files
  • B. The system has been compromised using a t0rnrootkit
  • C. The system files have been copied by a remote attacker
  • D. The system administrator has created an incremental backup

Answer: A

 

NEW QUESTION 22
Which of the following options will help users to enable or disable the last access time on a system running Windows 10 OS?

  • A. wmic service
  • B. Reg.exe
  • C. fsutil
  • D. Devcon

Answer: C

 

NEW QUESTION 23
Where is the startup configuration located on a router?

  • A. Dynamic RAM
  • B. BootROM
  • C. NVRAM
  • D. Static RAM

Answer: C

 

NEW QUESTION 24
When you are running a vulnerability scan on a network and the IDS cuts off your connection, what type of IDS is being used?

  • A. NIPS
  • B. Progressive IDS
  • C. Passive IDS
  • D. Active IDS

Answer: D

 

NEW QUESTION 25
Sectors in hard disks typically contain how many bytes?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B

 

NEW QUESTION 26
Which of the following is a responsibility of the first responder?

  • A. Collect as much information about the incident as possible
  • B. Document the findings
  • C. Share the collected information to determine the root cause
  • D. Determine the severity of the incident

Answer: A

 

NEW QUESTION 27
How many sectors will a 125 KB file use in a FAT32 file system?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B

 

NEW QUESTION 28
......

Verified 312-49v10 Exam Dumps Q&As - Provide 312-49v10 with Correct Answers: https://pass4sure.trainingquiz.com/312-49v10-training-materials.html