312-49 Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-49 Online Questions & Answers

  • Question 211:

    Netstat is a tool for collecting information regarding network connections. It provides a simple view of TCP and UDP connections, and their state and network traffic statistics. Which of the following commands shows you the TCP and UDP network connections, listening ports, and the identifiers?

    A. netstat - r
    B. netstat - ano
    C. netstat - b
    D. netstat - s

  • Question 212:

    Data is striped at a byte level across multiple drives, and parity information is distributed among all member drives.

    What RAID level is represented here?

    A. RAID Level 0
    B. RAID Level 5
    C. RAID Level 3
    D. RAID Level 1

  • Question 213:

    Wireless access control attacks aim to penetrate a network by evading WLAN access control measures such as AP MAC filters and Wi-Fi port access controls. Which of the following wireless access control attacks allow the attacker to set up a rogue access point outside the corporate perimeter and then lure the employees of the organization to connect to it?

    A. Ad hoc associations
    B. Client mis-association
    C. MAC spoofing
    D. Rogue access points

  • Question 214:

    John and Hillary works at the same department in the company. John wants to find out Hillary's network password so he can take a look at her documents on the file server. He enables Lophtcrack program to sniffing mode. John sends Hillary an email with a link to Error! Reference source not found. What information will he be able to gather from this?

    A. Hillary network username and password hash
    B. The SID of Hillary network account
    C. The SAM file from Hillary computer
    D. The network shares that Hillary has permissions

  • Question 215:

    Which of the following Event Correlation Approach is an advanced correlation method that assumes and predicts what an attacker can do next after the attack by studying the statistics and probability and uses only two variables?

    A. Bayesian Correlation
    B. Vulnerability-Based Approach
    C. Rule-Based Approach
    D. Route Correlation

  • Question 216:

    What technique is used by JPEGs for compression?

    A. ZIP
    B. TCD
    C. DCT
    D. TIFF-8

  • Question 217:

    Which of the following file system uses Master File Table (MFT) database to store information about every file and directory on a volume?

    A. FAT File System
    B. ReFS
    C. exFAT
    D. NTFS File System

  • Question 218:

    The process of restarting a computer that is already turned on through the operating system is called?

    A. Warm boot
    B. Ice boot
    C. Hot Boot
    D. Cold boot

  • Question 219:

    Bill is the accounting manager for Grummon and Sons LLC in Chicago. On a regular basis, he needs to send PDF documents containing sensitive information through E-mail to his customers.

    Bill protects the PDF documents with a password and sends them to their intended recipients.

    Why PDF passwords do not offer maximum protection?

    A. PDF passwords can easily be cracked by software brute force tools
    B. PDF passwords are converted to clear text when sent through E-mail
    C. PDF passwords are not considered safe by Sarbanes-Oxley
    D. When sent through E-mail, PDF passwords are stripped from the document completely

  • Question 220:

    What must be obtained before an investigation is carried out at a location?

    A. Search warrant
    B. Subpoena
    C. Habeas corpus
    D. Modus operandi

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.