Skip to main content

312-49V10 Real Exam Questions

EC-Council Certified Computer Hacking Forensic Investigator (V10)

1,028 questions available · Page 1 of 103

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Smith, a network administrator with a large MNC, was the first to arrive at a suspected crime scene involving criminal use of compromised computers.

What should be his first response while maintaining the integrity of evidence?

  1. A

    Record the system state by taking photographs of physical system and the display

  2. B

    Perform data acquisition without disturbing the state of the systems

  3. C

    Open the systems, remove the hard disk and secure it

  4. D

    Switch off the systems and carry them to the laboratory

Show answer and explanation

Correct answer: A

Question 2 Single choice

Profiling is a forensics technique for analyzing evidence with the goal of identifying the perpetrator from their various activity.
After a computer has been compromised by a hacker, which of the following would be most important in forming a profile of the incident?

  1. A

    The manufacturer of the system compromised

  2. B

    The logic, formatting and elegance of the code used in the attack

  3. C

    The nature of the attack

  4. D

    The vulnerability exploited in the incident

Show answer and explanation

Correct answer: B

Question 3 Single choice

You are assigned to work in the computer forensics lab of a state police agency. While working on a high profile criminal case, you have followed every applicable procedure, however your boss is still concerned that the defense attorney might question whether evidence has been changed while at the lab.

What can you do to prove that the evidence is the same as it was when it first entered the lab?

  1. A

    make an MD5 hash of the evidence and compare it with the original MD5 hash that was taken when the evidence first entered the lab

  2. B

    make an MD5 hash of the evidence and compare it to the standard database developed by NIST

  3. C

    there is no reason to worry about this possible claim because state labs are certified

  4. D

    sign a statement attesting that the evidence is the same as it was when it entered the lab

Show answer and explanation

Correct answer: A

Question 4 Single choice

When the operating system marks cluster as used, but does not allocate them to any file, such clusters are known as ___________.

  1. A

    Lost clusters

  2. B

    Bad clusters

  3. C

    Empty clusters

  4. D

    Unused clusters

Show answer and explanation

Correct answer: A

Question 5 Single choice

Which of the following Android libraries are used to render 2D (SGL) or 3D (OpenGL/ES) graphics content to the screen?

  1. A

    OpenGL/ES and SGL

  2. B

    Surface Manager

  3. C

    Media framework

  4. D

    WebKit

Show answer and explanation

Correct answer: A

Question 6 Single choice

An organization is concerned about potential attacks using steganography to hide malicious data within image files. After a recent breach, the incident response team found that an attacker had managed to sneak past their defenses by hiding a keylogger inside a legitimate image.

Given that the attacker has knowledge of the organization's steganography detection techniques, which method of steganalysis would likely be the most effective in detecting such a steganographic attack in the future?

  1. A

    Chi-square attack, where the analyst performs probability analysis to test whether the stego object and original data are identical

  2. B

    Known-message attack, where the analyst has a known hidden message in the corresponding stego-image and looks for patterns that arisefrom hiding the message

  3. C

    Known-stego attack, where the analyst knows both the steganography algorithm and original and

    stego-object

  4. D

    Chosen-message attack, where the analyst uses a known message to generate a stego-object in order to find the steganography algorithmused

Show answer and explanation

Correct answer: A

Question 7 Single choice

A law enforcement officer may only search for and seize criminal evidence with _______________________, which are facts or circumstances that would lead a reasonable person to believe a crime has been committed or is about to be committed, evidence of the specific crime exists and the evidence of the specific crime exists at the place to be searched.

  1. A

    Mere Suspicion

  2. B

    A preponderance of the evidence

  3. C

    Probable cause

  4. D

    Beyond a reasonable doubt

Show answer and explanation

Correct answer: C

Question 8 Single choice

A cybercrime investigator is evaluating a data breach in a company's AWS infrastructure. The breached service was categorized as an AWS container service.

What primary security aspects were likely managed by the company and not by AWS, which the investigator should first focus on?

  1. A

    Physical infrastructure and foundational services

  2. B

    Network configuration of the container services

  3. C

    Data management and firewall configuration

  4. D

    Application platform and Operating System (OS) security

Show answer and explanation

Correct answer: C

Question 9 Single choice

Which of the following web browser uses the Extensible Storage Engine (ESE) database format to store browsing records, including history, cache, and cookies?

  1. A

    Safari

  2. B

    Mozilla Firefox

  3. C

    Microsoft Edge

  4. D

    Google Chrome

Show answer and explanation

Correct answer: C

Question 10 Single choice

Click on the Exhibit Button Paulette works for an IT security consulting company that is currently performing an audit for the firm ACE Unlimited. Paulette's duties include logging on to all the company's network equipment to ensure IOS versions are up-to-date and all the other security settings are as stringent as possible. Paulette presents the following screenshot to her boss so he can inform the client about necessary changes need to be made.

From the screenshot, what changes should the client company make?

  1. A

    The banner should include the Cisco tech support contact information as well

  2. B

    The banner should have more detail on the version numbers for the network equipment

  3. C

    The banner should not state "only authorized IT personnel may proceed"

  4. D

    Remove any identifying numbers, names, or version information

Show answer and explanation

Correct answer: D