312-49 Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-49 Online Questions & Answers

  • Question 391:

    Which of the following examinations refers to the process of providing the opposing side in a trial the opportunity to question a witness?

    A. Cross Examination
    B. Direct Examination
    C. Indirect Examination
    D. Witness Examination

  • Question 392:

    Which of the following ISO standard defines file systems and protocol for exchanging data between optical disks?

    A. ISO 9660
    B. ISO/IEC 13940
    C. ISO 9060
    D. IEC 3490

  • Question 393:

    Microsoft Outlook maintains email messages in a proprietary format in what type of file?

    A. .email
    B. .mail
    C. .pst
    D. .doc

  • Question 394:

    At what layer does a cross site scripting attack occur on?

    A. Presentation
    B. Application
    C. Session
    D. Data Link

  • Question 395:

    Lance wants to place a honeypot on his network. Which of the following would be your recommendations?

    A. Use a system that has a dynamic addressing on the network
    B. Use a system that is not directly interacting with the router
    C. Use it on a system in an external DMZ in front of the firewall
    D. It doesn't matter as all replies are faked

  • Question 396:

    When performing a forensics analysis, what device is used to prevent the system from recording data on an evidence disk?

    A. a write-blocker
    B. a protocol analyzer
    C. a firewall
    D. a disk editor

  • Question 397:

    Which among the following search warrants allows the first responder to get the victim's computer information such as service records, billing records, and subscriber information from the service provider?

    A. Citizen Informant Search Warrant
    B. Electronic Storage Device Search Warrant
    C. John Doe Search Warrant
    D. Service Provider Search Warrant

  • Question 398:

    Email archiving is a systematic approach to save and protect the data contained in emails so that it can be accessed fast at a later date. There are two main archive types, namely Local Archive and Server Storage Archive. Which of the following statements is correct while dealing with local archives?

    A. Server storage archives are the server information and settings stored on a local system, whereas the local archives are the local email client information stored on the mail server
    B. It is difficult to deal with the webmail as there is no offline archive in most cases. So consult your counsel on the case as to the best way to approach and gain access to the required data on servers
    C. Local archives should be stored together with the server storage archives in order to be admissible in a court of law
    D. Local archives do not have evidentiary value as the email client may alter the message data

  • Question 399:

    The given image displays information about date and time of installation of the OS along with service packs, patches, and sub-directories. What command or tool did the investigator use to view this output?

    A. dir /o:d
    B. dir /o:s
    C. dir /o:e
    D. dir /o:n

  • Question 400:

    What does the superblock in Linux define?

    A. filesynames
    B. diskgeometr
    C. location of the firstinode
    D. available space

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.