Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :May 05, 2025

EC-COUNCIL EC-COUNCIL Certifications 312-49 Questions & Answers

  • Question 211:

    Which of the following files stores information about local Dropbox installation and account, email IDs linked with the account, current version/build for the local application, the host_id, and local path information?

    A. host.db

    B. sigstore.db

    C. config.db

    D. filecache.db

  • Question 212:

    An executive has leaked the company trade secrets through an external drive. What process should the investigation team take if they could retrieve his system?

    A. Postmortem Analysis

    B. Real-Time Analysis

    C. Packet Analysis

    D. Malware Analysis

  • Question 213:

    Bob has encountered a system crash and has lost vital data stored on the hard drive of his Windows computer. He has no cloud storage or backup hard drives. he wants to recover all those data, which includes his personal photos, music, documents, videos, official email, etc. Which of the following tools shall resolve Bob's purpose?

    A. Colasoft's Capsa

    B. Recuva

    C. Cain and Abel

    D. Xplico

  • Question 214:

    Which of the following options will help users to enable or disable the last access time on a system running Windows 10 OS?

    A. wmic service

    B. Reg.exe

    C. fsutil

    D. Devcon

  • Question 215:

    Which of the following techniques can be used to beat steganography?

    A. Encryption

    B. Steganalysis

    C. Decryption

    D. Cryptanalysis

  • Question 216:

    You have been given the task to investigate web attacks on a Windows-based server. Which of the following commands will you use to look at the sessions the machine has opened with other systems?

    A. Net sessions

    B. Net config

    C. Net share

    D. Net use

  • Question 217:

    Watson, a forensic investigator, is examining a copy of an ISO file stored in CDFS format. What type of evidence is this?

    A. Data from a CD copied using Windows

    B. Data from a CD copied using Mac-based system

    C. Data from a DVD copied using Windows system

    D. Data from a CD copied using Linux system

  • Question 218:

    Wireless access control attacks aim to penetrate a network by evading WLAN access control measures such as AP MAC filters and Wi-Fi port access controls. Which of the following wireless access control attacks allow the attacker to set up a rogue access point outside the corporate perimeter and then lure the employees of the organization to connect to it?

    A. Ad hoc associations

    B. Client mis-association

    C. MAC spoofing

    D. Rogue access points

  • Question 219:

    Who is responsible for the following tasks?

    Secure the scene and ensure that is maintained in a secure state until the Forensic Team advises Make notes about the scene that will eventually be handed over to the Forensic Team

    A. Non-forensics staff

    B. Lawyers

    C. System administrators

    D. Local managers or other non-forensic staff

  • Question 220:

    Which of the following stages in a Linux boot process involve initialization of the system's hardware?

    A. BIOS Stage

    B. Bootloader Stage

    C. BootROM Stage

    D. Kernel Stage

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.