312-49 Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-49 Online Questions & Answers

  • Question 181:

    Which of the following is a list of recently used programs or opened files?

    A. Most Recently Used (MRU)
    B. Recently Used Programs (RUP)
    C. Master File Table (MFT)
    D. GUID Partition Table (GPT)

  • Question 182:

    You have been given the task to investigate web attacks on a Windows-based server. Which of the following commands will you use to look at the sessions the machine has opened with other systems?

    A. Net sessions
    B. Net config
    C. Net share
    D. Net use

  • Question 183:

    Randy has extracted data from an old version of a Windows-based system and discovered info file Dc5.txt in the system recycle bin. What does the file name denote?

    A. A text file deleted from C drive in sixth sequential order
    B. A text file deleted from C drive in fifth sequential order
    C. A text file copied from D drive to C drive in fifth sequential order
    D. A text file copied from C drive to D drive in fifth sequential order

  • Question 184:

    Sectors are pie-shaped regions on a hard disk that store data. Which of the following parts of a hard disk do not contribute in determining the addresses of data?

    A. Sectors
    B. Interface
    C. Cylinder
    D. Heads

  • Question 185:

    Jim performed a vulnerability analysis on his network and found no potential problems. He runs another utility that executes exploits against his system to verify the results of the vulnerability test. The second utility executes five known exploits against his network in which the vulnerability analysis said were not exploitable. What kind of results did Jim receive from his vulnerability analysis?

    A. False negatives
    B. False positives
    C. True negatives
    D. True positives

  • Question 186:

    Which of the following techniques delete the files permanently?

    A. Steganography
    B. Artifact Wiping
    C. Data Hiding
    D. Trail obfuscation

  • Question 187:

    Which of the following tool can reverse machine code to assembly language?

    A. PEiD
    B. RAM Capturer
    C. IDA Pro
    D. Deep Log Analyzer

  • Question 188:

    Which network attack is described by the following statement? "At least five Russian major banks came under a continuous hacker attack, although online client services were not disrupted. The attack came from a wide-scale botnet involving at least 24,000 computers, located in 30 countries."

    A. Man-in-the-Middle Attack
    B. Sniffer Attack
    C. Buffer Overflow
    D. DDoS

  • Question 189:

    You are running through a series of tests on your network to check for any security vulnerabilities.

    After normal working hours, you initiate a DoS attack against your external firewall. The firewall Quickly freezes up and becomes unusable. You then initiate an FTP connection from an external IP into your internal network. The connection is

    successful even though you have FTP blocked at the external firewall. What has happened?

    A. The firewall failed-bypass
    B. The firewall failed-closed
    C. The firewall ACL has been purged
    D. The firewall failed-open

  • Question 190:

    An investigator has found certain details after analysis of a mobile device. What can reveal the manufacturer information?

    A. Equipment Identity Register (EIR)
    B. Electronic Serial Number (ESN)
    C. International mobile subscriber identity (IMSI)
    D. Integrated circuit card identifier (ICCID)

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.