312-49 Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-49 Online Questions & Answers

  • Question 401:

    Which among the following laws emphasizes the need for each Federal agency to develop, document, and implement an organization-wide program to provide information security for the information systems that support its operations and assets?

    A. FISMA
    B. HIPAA
    C. GLBA
    D. SOX

  • Question 402:

    Paul's company is in the process of undergoing a complete security audit including logical and physical security testing. After all logical tests were performed; it is now time for the physical round to begin. None of the employees are made aware of this round of testing. The security-auditing firm sends in a technician dressed as an electrician. He waits outside in the lobby for some employees to get to work and follows behind them when they access the restricted areas. After entering the main office, he is able to get into the server room telling the IT manager that there is a problem with the outlets in that room. What type of attack has the technician performed?

    A. Tailgating
    B. Backtrapping
    C. Man trap attack
    D. Fuzzing

  • Question 403:

    With the standard Linux second extended file system (Ext2fs), a file is deleted when the inode internal link count reaches ________.

    B. 10
    C. 100
    D. 1

  • Question 404:

    How many times can data be written to a DVD+R disk?

    A. Twice
    B. Once
    C. Zero
    D. Infinite

  • Question 405:

    If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system while doing an investigation, what can you conclude?

    A. The system files have been copied by a remote attacker
    B. The system administrator has created an incremental backup
    C. The system has been compromised using a t0rnrootkit
    D. Nothing in particular as these can be operational files

  • Question 406:

    To preserve digital evidence, an investigator should ____________________.

    A. Make two copies of each evidence item using a single imaging tool
    B. Make a single copy of each evidence item using an approved imaging tool
    C. Make two copies of each evidence item using different imaging tools
    D. Only store the original evidence item

  • Question 407:

    You are working as an investigator for a corporation and you have just received instructions from your manager to assist in the collection of 15 hard drives that are part of an ongoing investigation. Your job is to complete the required evidence custody forms to properly document each piece of evidence as it is collected by other members of your team. Your manager instructs you to complete one multi-evidence form for the entire case and a single-evidence form for each hard drive. How will these forms be stored to help preserve the chain of custody of the case?

    A. All forms should be placed in an approved secure container because they are now primary evidence in the case.
    B. The multi-evidence form should be placed in the report file and the single-evidence forms should be kept with each hard drive in an approved secure container.
    C. The multi-evidence form should be placed in an approved secure container with the hard drives and the single-evidence forms should be placed in the report file.
    D. All forms should be placed in the report file because they are now primary evidence in the case.

  • Question 408:

    Which among the following files provides email header information in the Microsoft Exchange server?

    A. gwcheck.db
    B. PRIV.EDB
    C. PUB.EDB
    D. PRIV.STM

  • Question 409:

    You work as a penetration tester for Hammond Security Consultants. You are currently working on a contract for the state government of California. Your next step is to initiate a DoS attack on their network. Why would you want to initiate a DoS attack on a system you are testing?

    A. Show outdated equipment so it can be replaced
    B. List weak points on their network
    C. Use attack as a launching point to penetrate deeper into the network
    D. Demonstrate that no system can be protected against DoS attacks

  • Question 410:

    Files stored in the Recycle Bin in its physical location are renamed as Dxy.ext, where "x" represents the ___________________.

    A. Drive name
    B. Original file name's extension
    C. Sequential number
    D. Original file name

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.