Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :May 05, 2025

EC-COUNCIL EC-COUNCIL Certifications 312-49 Questions & Answers

  • Question 171:

    Which among the following files provides email header information in the Microsoft Exchange server?

    A. gwcheck.db

    B. PRIV.EDB

    C. PUB.EDB

    D. PRIV.STM

  • Question 172:

    Which of the following attacks allows an attacker to access restricted directories, including application source code, configuration and critical system files, and to execute commands outside of the web server's root directory?

    A. Parameter/form tampering

    B. Unvalidated input

    C. Directory traversal

    D. Security misconfiguration

  • Question 173:

    Jason discovered a file named $RIYG6VR.doc in the C:\$Recycle.Bin\\ while analyzing a

    hard disk image for the deleted data. What inferences can he make from the file name?

    A. It is a doc file deleted in seventh sequential order

    B. RIYG6VR.doc is the name of the doc file deleted from the system

    C. It is file deleted from R drive

    D. It is a deleted doc file

  • Question 174:

    Which file is a sequence of bytes organized into blocks understandable by the system's linker?

    A. executable file

    B. source file

    C. Object file

    D. None of these

  • Question 175:

    Smith, a forensic examiner, was analyzing a hard disk image to find and acquire deleted sensitive files. He stumbled upon a $Recycle.Bin folder in the root directory of the disk. Identify the operating system in use.

    A. Windows 98

    B. Linux

    C. Windows 8.1

    D. Windows XP

  • Question 176:

    Charles has accidentally deleted an important file while working on his Mac computer. He wants to recover the deleted file as it contains some of his crucial business secrets. Which of the following tool will help Charles?

    A. Xplico

    B. Colasoft's Capsa

    C. FileSalvage

    D. DriveSpy

  • Question 177:

    What is the default IIS log location?

    A. SystemDrive\inetpub\LogFiles

    B. %SystemDrive%\inetpub\logs\LogFiles

    C. %SystemDrive\logs\LogFiles

    D. SystemDrive\logs\LogFiles

  • Question 178:

    Which of the following is an iOS Jailbreaking tool?

    A. Kingo Android ROOT

    B. Towelroot

    C. One Click Root

    D. Redsn0w

  • Question 179:

    Which of the following Registry components include offsets to other cells as well as the LastWrite time for the key?

    A. Value list cell

    B. Value cell

    C. Key cell

    D. Security descriptor cell

  • Question 180:

    What does the part of the log, "% SEC-6-IPACCESSLOGP", extracted from a Cisco router represent?

    A. The system was not able to process the packet because there was not enough room for all of the desired IP header options

    B. Immediate action required messages

    C. Some packet-matching logs were missed because the access list log messages were rate limited, or no access list log buffers were available

    D. A packet matching the log criteria for the given access list has been detected (TCP or UDP)

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.