312-49 Exam Details

  • Exam Code
    :312-49
  • Exam Name
    :ECCouncil Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :531 Q&As
  • Last Updated
    :May 28, 2026

EC-COUNCIL 312-49 Online Questions & Answers

  • Question 411:

    Item 2If you come across a sheepdip machine at your client site, what would you infer?

    A. A sheepdip coordinates several honeypots
    B. A sheepdip computer is another name for a honeypot
    C. A sheepdip computer is used only for virus-checking.
    D. A sheepdip computer defers a denial of service attack

  • Question 412:

    What is the purpose of using Obfuscator in malware?

    A. Execute malicious code in the system
    B. Avoid encryption while passing through a VPN
    C. Avoid detection by security mechanisms
    D. Propagate malware to other connected devices

  • Question 413:

    In a computer forensics investigation, what describes the route that evidence takes from the time you find it until the case is closed or goes to court?

    A. rules of evidence
    B. law of probability
    C. chain of custody
    D. policy of separation

  • Question 414:

    George is a senior security analyst working for a state agency in Florida. His state's congress just passed a bill mandating every state agency to undergo a security audit annually. After learning what will be required, George needs to implement an IDS as soon as possible before the first audit occurs. The state bill requires that an IDS with a "time-based induction machine" be used.

    What IDS feature must George implement to meet this requirement?

    A. Signature-based anomaly detection
    B. Pattern matching
    C. Real-time anomaly detection
    D. Statistical-based anomaly detection

  • Question 415:

    The surface of a hard disk consists of several concentric rings known as tracks; each of these tracks has smaller partitions called disk blocks. What is the size of each block?

    A. 512 bits
    B. 512 bytes
    C. 256 bits
    D. 256 bytes

  • Question 416:

    All Blackberry email is eventually sent and received through what proprietary RIM-operated mechanism?

    A. Blackberry Message Center
    B. Microsoft Exchange
    C. Blackberry WAP gateway
    D. Blackberry WEP gateway

  • Question 417:

    What value of the "Boot Record Signature" is used to indicate that the boot-loader exists?

    A. AA55
    B. 00AA
    C. AA00
    D. A100

  • Question 418:

    When searching through file headers for picture file formats, what should be searched to find a JPEG file in hexadecimal format?

    A. FF D8 FF E0 00 10
    B. FF FF FF FF FF FF
    C. FF 00 FF 00 FF 00
    D. EF 00 EF 00 EF 00

  • Question 419:

    An investigator has acquired packed software and needed to analyze it for the presence of malice. Which of the following tools can help in finding the packaging software used?

    A. SysAnalyzer
    B. PEiD
    C. Comodo Programs Manager
    D. Dependency Walker

  • Question 420:

    Harold is a computer forensics investigator working for a consulting firm out of Atlanta Georgia. Harold is called upon to help with a corporate espionage case in Miami Florida. Harold assists in the investigation by pulling all the data from the computers allegedly used in the illegal activities. He finds that two suspects in the company where stealing sensitive corporate information and selling it to competing companies. From the email and instant messenger logs recovered, Harold has discovered that the two employees notified the buyers by writing symbols on the back of specific stop signs. This way, the buyers knew when and where to meet with the alleged suspects to buy the stolen material. What type of steganography did these two suspects use?

    A. Text semagram
    B. Visual semagram
    C. Grill cipher
    D. Visual cipher

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.