312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 151:

    When examining a hard disk without a write-blocker, you should not start windows because Windows will write data to the:

    A. Recycle Bin
    B. MSDOS.sys
    C. BIOS
    D. Case files

  • Question 152:

    Which of the following standard represents a legal precedent regarding the admissibility of scientific examinations or experiments in legal cases?

    A. SWGDE and SWGIT
    B. Daubert
    C. Frye
    D. IOCE

  • Question 153:

    Which password cracking technique uses details such as length of password, character sets used to construct the password, etc.?

    A. Dictionary attack
    B. Brute force attack
    C. Rule-based attack
    D. Man in the middle attack

  • Question 154:

    When obtaining a warrant, it is important to:

    A. particularly describe the place to be searched and particularly describe the items to be seized
    B. generally describe the place to be searched and particularly describe the items to be seized
    C. generally describe the place to be searched and generally describe the items to be seized
    D. particularly describe the place to be searched and generally describe the items to be seized

  • Question 155:

    Which of the following stand true for BIOS Parameter Block?

    A. The BIOS Partition Block describes the physical layout of a data storage volume
    B. The BIOS Partition Block is the first sector of a data storage device
    C. The length of BIOS Partition Block remains the same across all the file systems
    D. The BIOS Partition Block always refers to the 512-byte boot sector

  • Question 156:

    According to RFC 3227, which of the following is considered as the most volatile item on a typical system?

    A. Archival media
    B. Temporary system files
    C. Kernel statistics and memory
    D. Registers and cache

  • Question 157:

    Which of the following commands shows you the names of all open shared files on a server and number of file locks on each file?

    A. Net sessions
    B. Net file
    C. Netconfig
    D. Net share

  • Question 158:

    A company's policy requires employees to perform file transfers using protocols which encrypt traffic. You suspect some employees are still performing file transfers using unencrypted protocols because the employees do not like changes. You have positioned a network sniffer to capture traffic from the laptops used by employees in the data ingest department.

    Using Wireshark to examine the captured traffic, which command can be used as display filter to find unencrypted file transfers?

    A. tcp. port = 23
    B. tcp port = = 21
    C. tcp.port = = 21 | | tcp.port = =22
    D. tcp.port ! = 21

  • Question 159:

    On an Active Directory network using NTLM authentication, where on the domain controllers are the passwords stored?

    A. SAM
    B. AMS
    C. Shadow file
    D. Password.conf

  • Question 160:

    Smith, a forensic examiner, was analyzing a hard disk image to find and acquire deleted sensitive files. He stumbled upon a $Recycle.Bin folder in the root directory of the disk. Identify the operating system in use.

    A. Windows 98
    B. Linux
    C. Windows 8.1
    D. Windows XP

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.