312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 111:

    Which one of the following is not a consideration in a forensic readiness planning checklist?

    A. Define the business states that need digital evidence
    B. Identify the potential evidence available
    C. Decide the procedure for securely collecting the evidence that meets the requirement fn a forensically sound manner
    D. Take permission from all employees of the organization

  • Question 112:

    Which Intrusion Detection System (IDS) usually produces the most false alarms due to the unpredictable behaviors of users and networks?

    A. network-based IDS systems (NIDS)
    B. host-based IDS systems (HIDS)
    C. anomaly detection
    D. signature recognition

  • Question 113:

    Which of the following commands shows you all of the network services running on Windows-based servers?

    A. Net start
    B. Net use
    C. Net Session
    D. Net share

  • Question 114:

    A forensic investigator is examining an attack on a MySQL database. The investigator has been given access to a server, but the physical MySQL data les are encrypted, and the database is currently inaccessible. The attacker seems to have tampered with the data.

    Which MySQL utility program would most likely assist the investigator in determining the changes that occurred during the attack?

    A. Mysqlbinlog, because it reads the binary log les directly and displays them in text format
    B. Myisamchk, because it views the status of the MylSAM table or checks, repairs, and optimizes them
    C. Mysqldump, because it allows dumping a database for backup purposes
    D. Mysqlaccess, because it checks the access privileges de ned for a hostname or username

  • Question 115:

    Which of the following tool enables data acquisition and duplication?

    A. Colasoft's Capsa
    B. DriveSpy
    C. Wireshark
    D. Xplico

  • Question 116:

    An organization is concerned about potential attacks using steganography to hide malicious data within image files. After a recent breach, the incident response team found that an attacker had managed to sneak past their defenses by hiding a keylogger inside a legitimate image.

    Given that the attacker has knowledge of the organization's steganography detection techniques, which method of steganalysis would likely be the most effective in detecting such a steganographic attack in the future?

    A. Chi-square attack, where the analyst performs probability analysis to test whether the stego object and original data are identical
    B. Known-message attack, where the analyst has a known hidden message in the corresponding stego-image and looks for patterns that arisefrom hiding the message
    C. Known-stego attack, where the analyst knows both the steganography algorithm and original and stego-object
    D. Chosen-message attack, where the analyst uses a known message to generate a stego-object in order to find the steganography algorithmused

  • Question 117:

    Which type of attack is possible when attackers know some credible information about the victim's password, such as the password length, algorithms involved, or the strings and characters used in its creation?

    A. Rule-Based Attack
    B. Brute-Forcing Attack
    C. Dictionary Attack
    D. Hybrid Password Guessing Attack

  • Question 118:

    The Apache server saves diagnostic information and error messages that it encounters while processing requests. The default path of this file is usr/local/apache/logs/error.log in Linux. Identify the Apache error log from the following logs.

    A. http://victim.com/scripts/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..% c0%af../..%c0%af../winnt/system32/cmd.exe?/c+dir+C:\Winnt\system32\Logfiles\W3SVC1
    B. [Wed Oct 11 14:32:52 2000] [error] [client 127. 0.0.1] client denied by server configuration: /export/home/live/ap/htdocs/test
    C. 127. 0.0.1 - frank [10/Oct/2000:13:55:36 -0700]"GET /apache_pb.gif HTTP/1.0" 200 2326
    D. 127. 0.0.1 - - [10/Apr/2007:10:39:11 +0300] ] [error] "GET /apache_pb.gif HTTP/1.0" 200 2326

  • Question 119:

    Network forensics allows Investigators to inspect network traffic and logs to identify and locate the attack system Network forensics can reveal: (Select three answers)

    A. Source of security incidents' and network attacks
    B. Path of the attack
    C. Intrusion techniques used by attackers
    D. Hardware configuration of the attacker's system

  • Question 120:

    In General, __________________ Involves the investigation of data that can be retrieved from the hard disk or other disks of a computer by applying scientific methods to retrieve the data.

    A. Network Forensics
    B. Data Recovery
    C. Disaster Recovery
    D. Computer Forensics

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.