312-49 Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-49 Online Questions & Answers

  • Question 331:

    E-mail logs contain which of the following information to help you in your investigation? (Choose four.)

    A. user account that was used to send the account
    B. attachments sent with the e-mail message
    C. unique message identifier
    D. contents of the e-mail message
    E. date and time the message was sent

  • Question 332:

    Tyler is setting up a wireless network for his business that he runs out of his home. He has followed all the directions from the ISP as well as the wireless router manual. He does not have any encryption set and the SSID is being broadcast. On his laptop, he can pick up the wireless signal for short periods of time, but then the connection drops and the signal goes away. Eventually the wireless signal shows back up, but drops intermittently. What could be Tyler issue with his home wireless network?

    A. Computers on his wired network
    B. Satellite television
    C. 2.4Ghz Cordless phones
    D. CB radio

  • Question 333:

    You are assisting in the investigation of a possible Web Server Hack. The company who called you stated that customers reported to them that whenever they entered the web address of the company in their browser, what they received was a porno graphic web site. The company checked the web server and nothing appears wrong. When you type in the IP address of the web site in your browser everything appears normal. What is the name of the attack that affects the DNS cache of the name resolution servers, resulting in those servers directing users to the wrong web site?

    A. ARP Poisoning
    B. DNS Poisoning
    C. HTTP redirect attack
    D. IP Spoofing

  • Question 334:

    Adam, a forensic investigator, is investigating an attack on Microsoft Exchange Server of a large organization. As the first step of the investigation, he examined the PRIV.EDB file and found the source from where the mail originated and the name of the file that disappeared upon execution. Now, he wants to examine the MIME stream content. Which of the following files is he going to examine?

    A. PRIV.STM
    B. gwcheck.db
    C. PRIV.EDB
    D. PUB.EDB

  • Question 335:

    The use of warning banners helps a company avoid litigation by overcoming an employee assumed __________________________. When connecting to the company's intranet, network or Virtual Private Network(VPN) and will allow the company's investigators to monitor, search and retrieve information stored within the network.

    A. Right to work
    B. Right of free speech
    C. Right to Internet Access
    D. Right of Privacy

  • Question 336:

    If you are concerned about a high level of compression but not concerned about any possible data loss, what type of compression would you use?

    A. Lossful compression
    B. Lossy compression
    C. Lossless compression
    D. Time-loss compression

  • Question 337:

    You are trying to locate Microsoft Outlook Web Access Default Portal using Google search on the Internet. What search string will you use to locate them?

    A. allinurl:"exchange/logon.asp"
    B. intitle:"exchange server"
    C. locate:"logon page"
    D. outlook:"search"

  • Question 338:

    What does the acronym POST mean as it relates to a PC?

    A. Primary Operations Short Test
    B. PowerOn Self Test
    C. Pre Operational Situation Test
    D. Primary Operating System Test

  • Question 339:

    In General, __________________ Involves the investigation of data that can be retrieved from the hard disk or other disks of a computer by applying scientific methods to retrieve the data.

    A. Network Forensics
    B. Data Recovery
    C. Disaster Recovery
    D. Computer Forensics

  • Question 340:

    John is working as a computer forensics investigator for a consulting firm in Canada. He is called to seize a computer at a local web caf purportedly used as a botnet server. John thoroughly scans the computer and finds nothing that would lead him to think the computer was a botnet server. John decides to scan the virtual memory of the computer to possibly find something he had missed. What information will the virtual memory scan produce?

    A. It contains the times and dates of when the system was last patched
    B. It is not necessary to scan the virtual memory of a computer
    C. It contains the times and dates of all the system files
    D. Hidden running processes

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.