Updated Sep-2021 Test Engine to Practice Test for 312-49 Exam Questions and Answers!
Computer Hacking Forensic Investigator Certification Sample Questions and Practice Exam
NEW QUESTION 38
Which is a standard procedure to perform during all computer forensics investigations?
- A. With the hard drive in the suspect PC, check the date and time in the system CMOSWith the hard drive in the suspect PC, check the date and time in the system? CMOS
- B. With the hard drive removed from the suspect PC, check the date and time in the system CMOSWith the hard drive removed from the suspect PC, check the date and time in the system? CMOS
- C. With the hard drive in the suspect PC, check the date and time in the File Allocation
Table - D. With the hard drive removed from the suspect PC, check the date and time in the system RAMWith the hard drive removed from the suspect PC, check the date and time in the system? RAM
Answer: B
NEW QUESTION 39
Which legal document allows law enforcement to search an office, place of business, or other locale for evidence relating to an alleged crime?
- A. Bench warrant
- B. Subpoena
- C. Wire tap
- D. Search warrant
Answer: D
NEW QUESTION 40
When conducting computer forensic analysis, you must guard against ______________ So that you remain focused on the primary job and insure that the level of work does not increase beyond what was originally expected.
- A. Unauthorized expenses
- B. Overzealous marketing
- C. Hard Drive Failure
- D. Scope Creep
Answer: D
NEW QUESTION 41
An investigator has acquired packed software and needed to analyze it for the presence of malice. Which of the following tools can help in finding the packaging software used?
- A. SysAnalyzer
- B. Dependency Walker
- C. PEiD
- D. Comodo Programs Manager
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION 42
When setting up a wireless network with multiple access points, why is it important to set each access point on a different channel?
- A. Multiple access points can be set up on the same channel without any issues
- B. So that the access points will work on different frequencies
- C. Avoid over-saturation of wireless signals
- D. Avoid cross talk
Answer: D
NEW QUESTION 43
Why is it still possible to recover files that have been emptied from the Recycle Bin on a
Windows computer?
- A. The data is still present until the original location of the file is used
- B. The data is moved to the Restore directory and is kept there indefinitely
- C. The data will reside in the L2 cache on a Windows computer until it is manually deleted
- D. It is not possible to recover data that has been emptied from the Recycle Bin
Answer: A
NEW QUESTION 44
While working for a prosecutor, what do you think you should do if the evidence you found appears to be exculpatory and is not being released to the defense?
- A. Present the evidence to the defense attorney
- B. Destroy the evidence
- C. Bring the information to the attention of the prosecutor, his or her supervisor or finally to the judge
- D. Keep the information of file for later review
Answer: C
NEW QUESTION 45
What operating system would respond to the following command?
- A. Mac OS X
- B. Windows 95
- C. FreeBSD
- D. Windows XP
Answer: C
NEW QUESTION 46
Steven has been given the task of designing a computer forensics lab for the company he works for. He has found documentation on all aspects of how to design a lab except the number of exits needed. How many exits should Steven include in his design for the computer forensics lab?
- A. Two
- B. Four
- C. Three
- D. One
Answer: D
Explanation:
Explanation/Reference:
NEW QUESTION 47
Where does Encase search to recover NTFS files and folders?
- A. HAL
- B. Slack space
- C. MBR
- D. MFT
Answer: D
NEW QUESTION 48
Frank is working on a vulnerability assessment for a company on the West coast. The company hired Frank to assess its network security through scanning, pen tests, and vulnerability assessments. After discovering numerous known vulnerabilities detected by a temporary IDS he set up, he notices a number of items that show up as unknown but Questionable in the logs. He looks up the behavior on the Internet, but cannot find anything related. What organization should Frank submit the log to find out if it is a new vulnerability or not?
- A. APIPA
- B. CVE
- C. RIPE
- D. IANA
Answer: B
NEW QUESTION 49
In the following email header, where did the email first originate from?
- A. Simon1.state.ok.gov.us
- B. Smtp1.somedomain.com
- C. Somedomain.com
- D. David1.state.ok.gov.us
Answer: A
NEW QUESTION 50
The following is a log file screenshot from a default installation of IIS 6.0.
What time standard is used by IIS as seen in the screenshot?
- A. TAI
- B. GMT
- C. UT
- D. UTC
Answer: D
Explanation:
Explanation
NEW QUESTION 51
Lance wants to place a honeypot on his network. Which of the following would be your recommendations?
- A. It doesn't matter as all replies are faked
- B. Use a system that has a dynamic addressing on the network
- C. Use it on a system in an external DMZ in front of the firewall
- D. Use a system that is not directly interacting with the router
Answer: A
NEW QUESTION 52
A computer forensics investigator is inspecting the firewall logs for a large financial institution that has employees working 24 hours a day, 7 days a week.
What can the investigator infer from the screenshot seen below?
- A. Buffer overflow attempt on the firewall.
- B. A denial of service has been attempted
- C. Network intrusion has occurred
- D. A smurf attack has been attempted
Answer: C
NEW QUESTION 53
Sectors in hard disks typically contain how many bytes?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
NEW QUESTION 54
Larry is an IT consultant who works for corporations and government agencies. Larry plans on shutting down the city's network using BGP devices and zombies? What type of Penetration Testing is Larry planning to carry out?
- A. Router Penetration Testing
- B. DoS Penetration Testing
- C. Firewall Penetration Testing
- D. Internal Penetration Testing
Answer: B
NEW QUESTION 55
A honey pot deployed with the IP 172.16.1.108 was compromised by an attacker. Given below is an excerpt from a Snort binary capture of the attack. Decipher the activity carried out by the attacker by studying the log. Please note that you are required to infer only what is explicit in the excerpt.
(Note: The student is being tested on concepts learnt during passive OS fingerprinting, basic TCP/IP connection concepts and the ability to read packet signatures from a sniff dump.)
03/15-20:21:24.107053 211.185.125.124:3500 -> 172.16.1.108:111
TCP TTL:43 TOS:0x0 ID:29726 IpLen:20 DgmLen:52 DF
***A**** Seq: 0x9B6338C5 Ack: 0x5820ADD0 Win: 0x7D78 TcpLen: 32
TCP Options (3) => NOP NOP TS: 23678634 2878772
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
03/15-20:21:24.452051 211.185.125.124:789 -> 172.16.1.103:111
UDP TTL:43 TOS:0x0 ID:29733 IpLen:20 DgmLen:84
Len: 64
01 0A 8A 0A 00 00 00 00 00 00 00 02 00 01 86 A0 ................
00 00 00 02 00 00 00 03 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 01 86 B8 00 00 00 01 ................
00 00 00 11 00 00 00 00 ........
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
03/15-20:21:24.730436 211.185.125.124:790 -> 172.16.1.103:32773
UDP TTL:43 TOS:0x0 ID:29781 IpLen:20 DgmLen:1104
Len: 1084
47 F7 9F 63 00 00 00 00 00 00 00 02 00 01 86 B8
- A. The attacker has installed a backdoor
- B. The attacker has used a Trojan on port 32773
- C. The attacker has conducted a network sweep on port 111
- D. The attacker has scanned and exploited the system using Buffer Overflow
Answer: C
NEW QUESTION 56
......
Certification dumps Certified Ethical Hacker 312-49 guides - 100% valid: https://www.examstorrent.com/312-49-exam-dumps-torrent.html