312-49 Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-49 Online Questions & Answers

  • Question 241:

    Sheila is a forensics trainee and is searching for hidden image files on a hard disk. She used a forensic investigation tool to view the media in hexadecimal code for simplifying the search process. Which of the following hex codes should she look for to identify image files?

    A. ff d8 ff
    B. 25 50 44 46
    C. d0 0f 11 e0
    D. 50 41 03 04

  • Question 242:

    Volatile Memory is one of the leading problems for forensics. Worms such as code Red are memory resident and do write themselves to the hard drive, if you turn the system off they disappear. In a lab environment, which of the following options would you suggest as the most appropriate to overcome the problem of capturing volatile memory?

    A. Use VMware to be able to capture the data in memory and examine it
    B. Give the Operating System a minimal amount of memory, forcing it to use a swap file
    C. Create a Separate partition of several hundred megabytes and place the swap file there
    D. Use intrusion forensic techniques to study memory resident infections

  • Question 243:

    Which of the following technique creates a replica of an evidence media?

    A. Data Extraction
    B. Backup
    C. Bit Stream Imaging
    D. Data Deduplication

  • Question 244:

    Jason discovered a file named $RIYG6VR.doc in the C:\$Recycle.Bin\\ while analyzing a hard disk image for the deleted data. What inferences can he make from the file name?

    A. It is a doc file deleted in seventh sequential order
    B. RIYG6VR.doc is the name of the doc file deleted from the system
    C. It is file deleted from R drive
    D. It is a deleted doc file

  • Question 245:

    Which password cracking technique uses every possible combination of character sets?

    A. Rainbow table attack
    B. Brute force attack
    C. Rule-based attack
    D. Dictionary attack

  • Question 246:

    For what purpose do the investigators use tools like iPhoneBrowser, iFunBox, OpenSSHSSH, and iMazing?

    A. Bypassing iPhone passcode
    B. Debugging iPhone
    C. Rooting iPhone
    D. Copying contents of iPhone

  • Question 247:

    What will the following command accomplish? dd if=/dev/xxx of=mbr.backup bs=512 count=1

    A. Back up the master boot record
    B. Restore the master boot record
    C. Mount the master boot record on the first partition of the hard drive
    D. Restore the first 512 bytes of the first partition of the hard drive

  • Question 248:

    When investigating a computer forensics case where Microsoft Exchange and Blackberry Enterprise server are used, where would investigator need to search to find email sent from a Blackberry device?

    A. RIM Messaging center
    B. Blackberry Enterprise server
    C. Microsoft Exchange server
    D. Blackberry desktop redirector

  • Question 249:

    When should an MD5 hash check be performed when processing evidence?

    A. After the evidence examination has been completed
    B. On an hourly basis during the evidence examination
    C. Before and after evidence examination
    D. Before the evidence examination has been completed

  • Question 250:

    Jacky encrypts her documents using a password. It is known that she uses her daughter's year of birth as part of the password. Which password cracking technique would be optimal to crack her password?

    A. Rule-based attack
    B. Brute force attack
    C. Syllable attack
    D. Hybrid attack

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.