312-49 Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-49 Online Questions & Answers

  • Question 261:

    A picture file is recovered from a computer under investigation. During the investigation process, the file is enlarged 500% to get a better view of its contents. The picture quality is not degraded at all from this process. What kind of picture is this file. What kind of picture is this file?

    A. Raster image
    B. Vector image
    C. Metafile image
    D. Catalog image

  • Question 262:

    Which of the following is a database in which information about every file and directory on an NT File System (NTFS) volume is stored?

    A. Volume Boot Record
    B. Master Boot Record
    C. GUID Partition Table
    D. Master File Table

  • Question 263:

    Which federal computer crime law specifically refers to fraud and related activity in connection with access devices like routers?

    A. 18 U.S.C. 1029
    B. 18 U.S.C. 1362
    C. 18 U.S.C. 2511
    D. 18 U.S.C. 2703

  • Question 264:

    Julie is a college student majoring in Information Systems and Computer Science. She is currently writing an essay for her computer crimes class. Julie paper focuses on white-collar crimes in America and how forensics investigators investigate the cases. Julie would like to focus the subject. Julie would like to focus the subject of the essay on the most common type of crime found in corporate America. What crime should Julie focus on?

    A. Physical theft
    B. Copyright infringement
    C. Industrial espionage
    D. Denial of Service attacks

  • Question 265:

    Which is a standard procedure to perform during all computer forensics investigations?

    A. with the hard drive removed from the suspect PC, check the date and time in the system's CMOS
    B. with the hard drive in the suspect PC, check the date and time in the File Allocation Table
    C. with the hard drive removed from the suspect PC, check the date and time in the system's RAM
    D. with the hard drive in the suspect PC, check the date and time in the system's CMOS

  • Question 266:

    Which of the following Event Correlation Approach checks and compares all the fields systematically and intentionally for positive and negative correlation with each other to determine the correlation across one or multiple fields?

    A. Rule-Based Approach
    B. Automated Field Correlation
    C. Field-Based Approach
    D. Graph-Based Approach

  • Question 267:

    Which of the following standard represents a legal precedent sent in 1993 by the Supreme Court of the United States regarding the admissibility of expert witnesses' testimony during federal legal proceedings?

    A. IOCE
    B. SWGDE and SWGIT
    C. Frye
    D. Daubert

  • Question 268:

    Given the drive dimensions as follows and assuming a sector has 512 bytes, what is the capacity of the described hard drive?

    22,164 cylinders/disk 80 heads/cylinder 63 sectors/track

    A. 53.26 GB
    B. 57.19 GB
    C. 11.17 GB
    D. 10 GB

  • Question 269:

    When a file is deleted by Windows Explorer or through the MS-DOS delete command, the operating system inserts _______________ in the first letter position of the filename in the FAT database.

    A. A Capital X
    B. A Blank Space
    C. The Underscore Symbol
    D. The lowercase Greek Letter Sigma (s)

  • Question 270:

    John is using Firewalk to test the security of his Cisco PIX firewall. He is also utilizing a sniffer located on a subnet that resides deep inside his network. After analyzing the sniffer log files, he does not see any of the traffic produced by Firewalk. Why is that?

    A. Firewalk cannot pass through Cisco firewalls
    B. Firewalk sets all packets with a TTL of zero
    C. Firewalk cannot be detected by network sniffers
    D. Firewalk sets all packets with a TTL of one

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.