312-49 Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-49 Online Questions & Answers

  • Question 231:

    Which of the following setups should a tester choose to analyze malware behavior?

    A. A virtual system with internet connection
    B. A normal system without internet connect
    C. A normal system with internet connection
    D. A virtual system with network simulation for internet connection

  • Question 232:

    When a user deletes a file, the system creates a $I file to store its details. What detail does the $I file not contain?

    A. File Size
    B. File origin and modification
    C. Time and date of deletion
    D. File Name

  • Question 233:

    What is the location of the binary files required for the functioning of the OS in a Linux system?

    A. /run
    B. /bin
    C. /root
    D. /sbin

  • Question 234:

    A small law firm located in the Midwest has possibly been breached by a computer hacker looking to obtain information on their clientele. The law firm does not have any on-site IT employees, but wants to search for evidence of the breach themselves to prevent any possible media attention. Why would this not be recommended?

    A. Searching for evidence themselves would not have any ill effects
    B. Searching could possibly crash the machine or device
    C. Searching creates cache files, which would hinder the investigation
    D. Searching can change date/time stamps

  • Question 235:

    Rusty, a computer forensics apprentice, uses the command nbtstat while analyzing the network information in a suspect system. What information is he looking for?

    A. Contents of the network routing table
    B. Status of the network carrier
    C. Contents of the NetBIOS name cache
    D. Network connections

  • Question 236:

    Linux operating system has two types of typical bootloaders namely LILO (Linux Loader) and GRUB (Grand Unified Bootloader). In which stage of the booting process do the bootloaders become active?

    A. Bootloader Stage
    B. Kernel Stage
    C. BootROM Stage
    D. BIOS Stage

  • Question 237:

    You are using DriveSpy, a forensic tool and want to copy 150 sectors where the starting sector is 1709 on the primary hard drive. Which of the following formats correctly specifies these sectors?

    A. 0:1000, 150
    B. 0:1709, 150
    C. 1:1709, 150
    D. 0:1709-1858

  • Question 238:

    Which command line tool is used to determine active network connections?

    A. netsh
    B. nbstat
    C. nslookup
    D. netstat

  • Question 239:

    What is the name of the first reserved sector in File allocation table?

    A. Volume Boot Record
    B. Partition Boot Sector
    C. Master Boot Record
    D. BIOS Parameter Block

  • Question 240:

    BMP (Bitmap) is a standard file format for computers running the Windows operating system. BMP images can range from black and white (1 bit per pixel) up to 24 bit color (16.7 million colors). Each bitmap file contains a header, the RGBQUAD array, information header, and image data. Which of the following element specifies the dimensions, compression type, and color format for the bitmap?

    A. Information header
    B. Image data
    C. The RGBQUAD array
    D. Header

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.