312-49 Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-49 Online Questions & Answers

  • Question 161:

    What type of flash memory card comes in either Type I or Type II and consumes only five percent of the power required by small hard drives?

    A. SD memory
    B. CF memory
    C. MMC memory
    D. SM memory

  • Question 162:

    When investigating a potential e-mail crime, what is your first step in the investigation?

    A. Trace the IP address to its origin
    B. Write a report
    C. Determine whether a crime was actually committed
    D. Recover the evidence

  • Question 163:

    Before you are called to testify as an expert, what must an attorney do first?

    A. engage in damage control
    B. prove that the tools you used to conduct your examination are perfect
    C. read your curriculum vitae to the jury
    D. qualify you as an expert witness

  • Question 164:

    Which program is the bootloader when Windows XP starts up?

    A. KERNEL.EXE
    B. NTLDR
    C. LOADER
    D. LILO

  • Question 165:

    In conducting a computer abuse investigation you become aware that the suspect of the investigation is using ABC Company as his Internet Service Provider (ISP). You contact ISP and request that they provide you assistance with your investigation. What assistance can the ISP provide?

    A. The ISP can investigate anyone using their service and can provide you with assistance
    B. The ISP can investigate computer abuse committed by their employees, but must preserve the privacy of their customers and therefore cannot assist you without a warrant
    C. The ISP can't conduct any type of investigations on anyone and therefore can't assist you
    D. ISP's never maintain log files so they would be of no use to your investigation

  • Question 166:

    Which of the following is a record of the characteristics of a file system, including its size, the block size, the empty and the filled blocks and their respective counts, the size and location of the inode tables, the disk block map and usage information, and the size of the block groups?

    A. Inode bitmap block
    B. Superblock
    C. Block bitmap block
    D. Data block

  • Question 167:

    What does the 63.78.199.4(161) denotes in a Cisco router log?

    Mar 14 22:57:53.425 EST: %SEC-6-IPACCESSLOGP: list internet-inbound denied udp 66.56.16.77(1029) -> 63.78.199.4(161), 1 packet

    A. Destination IP address
    B. Source IP address
    C. Login IP address
    D. None of the above

  • Question 168:

    After passively scanning the network of Department of Defense (DoD), you switch over to active scanning to identify live hosts on their network. DoD is a large organization and should respond to any number of scans. You start an ICMP ping sweep by sending an IP packet to the broadcast address. Only five hosts respond to your ICMP pings; definitely not the number of hosts you were expecting. Why did this ping sweep only produce a few responses?

    A. Only IBM AS/400 will reply to this scan
    B. Only Windows systems will reply to this scan
    C. A switched network will not respond to packets sent to the broadcast address
    D. Only Unix and Unix-like systems will reply to this scan

  • Question 169:

    Jonathan is a network administrator who is currently testing the internal security of his network. He is attempting to hijack a session, using Ettercap, of a user connected to his Web server. Why will Jonathan not succeed?

    A. Only an HTTPS session can be hijacked
    B. HTTP protocol does not maintain session
    C. Only FTP traffic can be hijacked
    D. Only DNS traffic can be hijacked

  • Question 170:

    You are the security analyst working for a private company out of France. Your current assignment is to obtain credit card information from a Swiss bank owned by that company. After initial reconnaissance, you discover that the bank security defenses are very strong and would take too long to penetrate. You decide to get the information by monitoring the traffic between the bank and one of its subsidiaries in London. After monitoring some of the traffic, you see a lot of FTP packets traveling back and forth. You want to sniff the traffic and extract usernames and passwords. What tool could you use to get this information?

    A. Airsnort
    B. Snort
    C. Ettercap
    D. RaidSniff

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.