312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 121:

    You are working for a large clothing manufacturer as a computer forensics investigator and are called in to investigate an unusual case of an employee possibly stealing clothing designs from the company and selling them under a different brand name for a different company. What you discover during the course of the investigation is that the clothing designs are actually original products of the employee and the company has no policy against an employee selling his own designs on his own time. The only thing that you can find that the employee is doing wrong is that his clothing design incorporates the same graphic symbol as that of the company with only the wording in the graphic being different.

    What area of the law is the employee violating?

    A. Copyright law
    B. Brandmark law
    C. Trademark law
    D. Printright law

  • Question 122:

    In an echo data hiding technique, the secret message is embedded into a __________as an echo.

    A. Cover audio signal
    B. Phase spectrum of a digital signal
    C. Pseudo-random signal
    D. Pseudo- spectrum signal

  • Question 123:

    An expert witness is a __________________ who is normally appointed by a party to assist the formulation and preparation of a party's claim or defense.

    A. Expert in criminal investigation
    B. Subject matter specialist
    C. Witness present at the crime scene
    D. Expert law graduate appointed by attorney

  • Question 124:

    When a system is compromised, attackers often try to disable auditing, in Windows 7; modifications to the audit policy are recorded as entries of Event ID____________.

    A. 4902
    B. 3902
    C. 4904
    D. 3904

  • Question 125:

    When investigating a network that uses DHCP to assign IP addresses, where would you look to determine which system (MAC address) had a specific IP address at a specific time?

    A. on the individual computer's ARP cache
    B. In the Web Server log files
    C. in the DHCP Server log files
    D. There is no way to determine the specific IP address

  • Question 126:

    Which of the following protocols allows non-ASCII files, such as video, graphics, and audio, to be sent through the email messages?

    A. MIME
    B. BINHEX
    C. UT-16
    D. UUCODE

  • Question 127:

    Casey has acquired data from a hard disk in an open source acquisition format that allows her to generate compressed or uncompressed image files. What format did she use?

    A. Portable Document Format
    B. Advanced Forensics Format (AFF)
    C. Proprietary Format
    D. Raw Format

  • Question 128:

    Paul's company is in the process of undergoing a complete security audit including logical and physical security testing. After all logical tests were performed; it is now time for the physical round to begin. None of the employees are made aware of this round of testing. The security-auditing firm sends in a technician dressed as an electrician. He waits outside in the lobby for some employees to get to work and follows behind them when they access the restricted areas. After entering the main office, he is able to get into the server room telling the IT manager that there is a problem with the outlets in that room.

    What type of attack has the technician performed?

    A. Fuzzing
    B. Tailgating
    C. Backtrapping
    D. Man trap attack

  • Question 129:

    Under confession, an accused criminal admitted to encrypting child pornography pictures and then hiding them within other pictures. What technique did the accused criminal employ?

    A. Typography
    B. Steganalysis
    C. Picture encoding
    D. Steganography

  • Question 130:

    In a computer forensics investigation, what describes the route that evidence takes from the time you find it until the case is closed or goes to court?

    A. Policy of separation
    B. Chain of custody
    C. Rules of evidence
    D. Law of probability

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.