
[2024] Use Valid 312-49v10 Exam - Actual Exam Question & Answer
Test Engine to Practice 312-49v10 Test Questions
EC-COUNCIL 312-49v10 (Computer Hacking Forensic Investigator (CHFI-v10)) Certification Exam is an excellent certification for professionals who want to become experts in computer forensics. Computer Hacking Forensic Investigator (CHFI-v10) certification exam covers a wide range of topics and is designed to be comprehensive and rigorous, ensuring that certified professionals have the skills and knowledge necessary to tackle complex cybercrimes. Computer Hacking Forensic Investigator (CHFI-v10) certification is recognized globally and is an excellent way for professionals to advance their careers in the field of computer forensics.
The CHFI-v10 certification exam covers a wide range of topics related to computer forensics and investigation. This includes topics such as digital evidence collection, processing, and analysis, as well as computer crime investigation procedures and legal issues related to digital forensics. 312-49v10 exam also covers topics such as network forensics, database forensics, and mobile device forensics, making it a comprehensive test of a candidate's knowledge and skills in the field.
NEW QUESTION # 395
Bill is the accounting manager for Grummon and Sons LLC in Chicago. On a regular basis, he needs to send PDF documents containing sensitive information through E-mail to his customers.
Bill protects the PDF documents with a password and sends them to their intended recipients.
Why PDF passwords do not offer maximum protection?
- A. PDF passwords are converted to clear text when sent through E-mail
- B. When sent through E-mail, PDF passwords are stripped from the document completely
- C. PDF passwords can easily be cracked by software brute force tools
- D. PDF passwords are not considered safe by Sarbanes-Oxley
Answer: C
NEW QUESTION # 396
Which cloud model allows an investigator to acquire the instance of a virtual machine and initiate the forensics examination process?
- A. IaaS model
- B. PaaS model
- C. SaaS model
- D. SecaaS model
Answer: A
NEW QUESTION # 397
George is the network administrator of a large Internet company on the west coast. Per corporate policy, none of the employees in the company are allowed to use FTP or SFTP programs without obtaining approval from the IT department. Few managers are using SFTP program on their computers. Before talking to his boss, George wants to have some proof of their activity. George wants to use Ethereal to monitor network traffic, but only SFTP traffic to and from his network.
What filter should George use in Ethereal?
- A. udp port 22 and host 172.16.28.1/24
- B. net port 22
- C. src port 23 and dst port 23
- D. src port 22 and dst port 22
Answer: D
NEW QUESTION # 398
Which of the following commands shows you all of the network services running on Windows-based servers?
- A. Net config
- B. Netstart
- C. Net use
- D. Net Session
Answer: B
NEW QUESTION # 399
The information security manager at a national legal firm has received several alerts from the intrusion detection system that a known attack signature was detected against the organization's file server. What should the information security manager do first?
- A. Disconnect the file server from the network
- B. Update the anti-virus definitions on the file server
- C. Report the incident to senior management
- D. Manually investigate to verify that an incident has occurred
Answer: A
NEW QUESTION # 400
Company ABC has employed a firewall, IDS, Antivirus, Domain Controller, and SIEM. The company's domain controller goes down. From which system would you begin your investigation?
- A. Domain Controller
- B. SIEM
- C. IDS
- D. Firewall
Answer: B
NEW QUESTION # 401
E-mail logs contain which of the following information to help you in your investigation? (Choose four.)
- A. user account that was used to send the account
- B. contents of the e-mail message
- C. date and time the message was sent
- D. unique message identifier
- E. attachments sent with the e-mail message
Answer: A,B,C,D
NEW QUESTION # 402
When examining the log files from a Windows IIS Web Server, how often is a new log file created?
- A. a new log is created each time the Web Server is started
- B. a new log file is created each week
- C. a new log file is created everyday
- D. the same log is used at all times
Answer: D
NEW QUESTION # 403
Which of the following is NOT a graphics file?
- A. Picture3.nfo
- B. Picture2.bmp
- C. Picture4.psd
- D. Picture1.tga
Answer: A
NEW QUESTION # 404
When reviewing web logs, you see an entry for resource not found in the HTTP status code field.
What is the actual error code that you would see in the log for resource not found?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
NEW QUESTION # 405
You are assigned a task to examine the log files pertaining to MyISAM storage engine. While examining, you are asked to perform a recovery operation on a MyISAM log file. Which among the following MySQL Utilities allow you to do so?
- A. myisamaccess
- B. myisamlog
- C. myisamchk
- D. mysqldump
Answer: B
NEW QUESTION # 406
Which of the following Ii considered as the starting point of a database and stores user data and database objects in an MS SQL server?
- A. Ibdata1
- B. Application data files (ADF)
- C. Transaction log data files (LDF)
- D. Primary data files (MDF)
Answer: D
NEW QUESTION # 407
How many sectors will a 125 KB file use in a FAT32 file system?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
NEW QUESTION # 408
Assume there Is a file named myflle.txt In C: drive that contains hidden data streams. Which of the following commands would you Issue to display the contents of a data stream?
- A. C:\MORE < myfile.txt:siream1
- B. echo text > program: source_file
- C. C:\>ECHO text_message > myfile.txt:stream1
- D. myfile.dat: st ream 1
Answer: A
NEW QUESTION # 409
You are carrying out the last round of testing for your new website before it goes live. The website has many dynamic pages and connects to a SQL backend that accesses your product inventory in a database. You come across a web security site that recommends inputting the following code into a search field on web pages to check for vulnerabilities: When you type this and click on search, you receive a pop-up window that says: "This is a test." What is the result of this test?
- A. Your website is not vulnerable
- B. Your website is vulnerable to SQL injection
- C. Your website is vulnerable to CSS
- D. Your website is vulnerable to web bugs
Answer: C
NEW QUESTION # 410
Chong-lee, a forensics executive, suspects that a malware is continuously making copies of files and folders on a victim system to consume the available disk space. What type of test would confirm his claim?
- A. Identifying file obfuscation
- B. Static analysis
- C. File fingerprinting
- D. Dynamic analysis
Answer: C
NEW QUESTION # 411
You are working as an independent computer forensics investigator and received a call from a systems administrator for a local school system requesting your assistance. One of the students at the local high school is suspected of downloading inappropriate images from the Internet to a PC in the Computer Lab. When you arrive at the school, the systems administrator hands you a hard drive and tells you that he made a "simple backup copy" of the hard drive in the PC and put it on this drive and requests that you examine the drive for evidence of the suspected images. You inform him that a "simple backup copy" will not provide deleted files or recover file fragments. What type of copy do you need to make to ensure that the evidence found is complete and admissible in future proceeding?
- A. Incremental backup copy
- B. Full backup copy
- C. Robust copy
- D. Bit-stream copy
Answer: D
NEW QUESTION # 412
Which of the following files DOES NOT use Object Linking and Embedding (OLE) technology to embed and link to other objects?
- A. MS-office Word OneNote
- B. Portable Document Format
- C. MS-office Word Document
- D. MS-office Word PowerPoint
Answer: B
NEW QUESTION # 413
Which of the following processes is part of the dynamic malware analysis?
- A. Malware disassembly
- B. File fingerprinting
- C. Searching for the strings
- D. Process Monitoring
Answer: D
NEW QUESTION # 414
Bob works as information security analyst for a big finance company. One day, the anomaly-based intrusion detection system alerted that a volumetric DDOS targeting the main IP of the main web server was occurring. What kind of attack is it?
- A. Network attack
- B. Web application attack
- C. IDS attack
- D. APT
Answer: A
NEW QUESTION # 415
The investigator wants to examine changes made to the system's registry by the suspect program. Which of the following tool can help the investigator?
- A. Regshot
- B. TRIPWIRE
- C. What's Running
- D. RAM Capturer
Answer: A
NEW QUESTION # 416
Which of the following tool can the investigator use to analyze the network to detect Trojan activities?
- A. TRIPWIRE
- B. Capsa
- C. RAM Computer
- D. Regshot
Answer: B
NEW QUESTION # 417
What does the Rule 101 of Federal Rules of Evidence states?
- A. Purpose of the Rules
- B. Scope of the Rules, where they can be applied
- C. Rulings on Evidence
- D. Limited Admissibility of the Evidence
Answer: B
NEW QUESTION # 418
An investigator seized a notebook device installed with a Microsoft Windows OS. Which type of files would support an investigation of the data size and structure in the device?
- A. Ext2 and Ext4
- B. APFSandHFS
- C. NTFSandFAT
- D. HFS and GNUC
Answer: C
NEW QUESTION # 419
Lance wants to place a honeypot on his network. Which of the following would be your recommendations?
- A. Use a system that has a dynamic addressing on the network
- B. Use it on a system in an external DMZ in front of the firewall
- C. It doesn't matter as all replies are faked
- D. Use a system that is not directly interacting with the router
Answer: C
NEW QUESTION # 420
......
312-49v10 Actual Questions Answers PDF 100% Cover Real Exam Questions: https://pass4sure.dumps4pdf.com/312-49v10-valid-braindumps.html