312-49 Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-49 Online Questions & Answers

  • Question 121:

    What is the primary function of the tool CHKDSK in Windows that authenticates the file system reliability of a volume?

    A. Repairs logical file system errors
    B. Check the disk for hardware errors
    C. Check the disk for connectivity errors
    D. Check the disk for Slack Space

  • Question 122:

    Chris has been called upon to investigate a hacking incident reported by one of his clients. The company suspects the involvement of an insider accomplice in the attack. Upon reaching the incident scene, Chris secures the physical area, records the scene using visual media. He shuts the system down by pulling the power plug so that he does not disturb the system in any way. He labels all cables and connectors prior to disconnecting any. What do you think would be the next sequence of events?

    A. Connect the target media; prepare the system for acquisition; Secure the evidence; Copy the media
    B. Prepare the system for acquisition; Connect the target media; copy the media; Secure the evidence
    C. Connect the target media; Prepare the system for acquisition; Secure the evidence; Copy the media
    D. Secure the evidence; prepare the system for acquisition; Connect the target media; copy the media

  • Question 123:

    Which of the following is found within the unique instance ID key and helps investigators to map the entry from USBSTOR key to the MountedDevices key?

    A. ParentIDPrefix
    B. LastWrite
    C. UserAssist key
    D. MRUListEx key

  • Question 124:

    After suspecting a change in MS-Exchange Server storage archive, the investigator has analyzed it. Which of the following components is not an actual part of the archive?

    A. PRIV.STM
    B. PUB.EDB
    C. PRIV.EDB
    D. PUB.STM

  • Question 125:

    What file structure database would you expect to find on floppy disks?

    A. NTFS
    B. FAT32
    C. FAT16
    D. FAT12

  • Question 126:

    What is one method of bypassing a system BIOS password?

    A. Removing the processor
    B. Removing the CMOS battery
    C. Remove all the system memory
    D. Login to Windows and disable the BIOS password

  • Question 127:

    What binary coding is used most often for e-mail purposes?

    A. MIME
    B. Uuencode
    C. IMAP
    D. SMTP

  • Question 128:

    NTFS sets a flag for the file once you encrypt it and creates an EFS attribute where it stores Data Decryption Field (DDF) and Data Recovery Field (DDR). Which of the following is not a part of DDF?

    A. Encrypted FEK
    B. Checksum
    C. EFS Certificate Hash
    D. Container Name

  • Question 129:

    You are a security analyst performing a penetration tests for a company in the Midwest. After some initial reconnaissance, you discover the IP addresses of some Cisco routers used by the company. You type in the following URL that includes the IP address of one of the routers: http://172.168.4.131/level/99/exec/show/config

    After typing in this URL, you are presented with the entire configuration file for that router. What have you discovered?

    A. HTTP Configuration Arbitrary Administrative Access Vulnerability
    B. HTML Configuration Arbitrary Administrative Access Vulnerability
    C. Cisco IOS Arbitrary Administrative Access Online Vulnerability
    D. URL Obfuscation Arbitrary Administrative Access Vulnerability

  • Question 130:

    Which network attack is described by the following statement?

    "At least five Russian major banks came under a continuous hacker attack, although online client services were not disrupted. The attack came from a wide-scale botnet involving at least 24,000 computers, located in 30 countries."

    A. DDoS
    B. Sniffer Attack
    C. Buffer Overflow
    D. Man-in-the-Middle Attack

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.