312-49 Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-49 Online Questions & Answers

  • Question 341:

    What method of computer forensics will allow you to trace all ever-established user accounts on a Windows 2000 sever the course of its lifetime?

    A. forensic duplication of hard drive
    B. analysis of volatile data
    C. comparison of MD5 checksums
    D. review of SIDs in the Registry

  • Question 342:

    What type of analysis helps to identify the time and sequence of events in an investigation?

    A. Time-based
    B. Functional
    C. Relational
    D. Temporal

  • Question 343:

    If a PDA is seized in an investigation while the device is turned on, what would be the proper procedure?

    A. Keep the device powered on
    B. Turn off the device immediately
    C. Remove the battery immediately
    D. Remove any memory cards immediately

  • Question 344:

    Harold is a web designer who has completed a website for ghttech.net. As part of the maintenance agreement he signed with the client, Harold is performing research online and seeing how much exposure the site has received so far. Harold navigates to google.com and types in the following search. link:www.ghttech.net What will this search produce?

    A. All sites that ghttech.net links to
    B. All sites that link to ghttech.net
    C. All search engines that link to .net domains
    D. Sites that contain the code: link:www.ghttech.net

  • Question 345:

    After attending a CEH security seminar, you make a list of changes you would like to perform on your network to increase its security. One of the first things you change is to switch the RestrictAnonymous setting from 0 to 1 on your servers. This, as you were told, would prevent anonymous users from establishing a null session on the server. Using Userinfo tool mentioned at the seminar, you succeed in establishing a null session with one of the servers. Why is that?

    A. RestrictAnonymous must be set to "10" for complete security
    B. RestrictAnonymous must be set to "3" for complete security
    C. RestrictAnonymous must be set to "2" for complete security
    D. There is no way to always prevent an anonymous null session from establishing

  • Question 346:

    During forensics investigations, investigators tend to collect the system time at first and compare it with UTC. What does the abbreviation UTC stand for?

    A. Coordinated Universal Time
    B. Universal Computer Time
    C. Universal Time for Computers
    D. Correlated Universal Time

  • Question 347:

    A computer forensics investigator is inspecting the firewall logs for a large financial institution that has employees working 24 hours a day, 7 days a week.

    What can the investigator infer from the screenshot seen below?

    A. A smurf attack has been attempted
    B. A denial of service has been attempted
    C. Network intrusion has occurred
    D. Buffer overflow attempt on the firewall.

  • Question 348:

    What does the command "C:\>wevtutil gl " display?

    A. Configuration information of a specific Event Log
    B. Event logs are saved in .xml format
    C. Event log record structure
    D. List of available Event Logs

  • Question 349:

    ____________________ is simply the application of Computer Investigation and analysis techniques in the interests of determining potential legal evidence.

    A. Network Forensics
    B. Computer Forensics
    C. Incident Response
    D. Event Reaction

  • Question 350:

    Which of the following is a precomputed table containing word lists like dictionary files and brute force lists and their hash values?

    A. Directory Table
    B. Rainbow Table
    C. Master file Table (MFT)
    D. Partition Table

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.