312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 191:

    In handling computer-related incidents, which IT role should be responsible for recovery, containment, and prevention to constituents?

    A. Security Administrator
    B. Network Administrator
    C. Director of Information Technology
    D. Director of Administration

  • Question 192:

    John is using Firewalk to test the security of his Cisco PIX firewall. He is also utilizing a sniffer located on a subnet that resides deep inside his network. After analyzing the sniffer log files, he does not see any of the traffic produced by Firewalk. Why is that?

    A. Firewalk sets all packets with a TTL of one
    B. Firewalk sets all packets with a TTL of zero
    C. Firewalk cannot pass through Cisco firewalls
    D. Firewalk cannot be detected by network sniffers

  • Question 193:

    You are assigned to work in the computer forensics lab of a state police agency. While working on a high profile criminal case, you have followed every applicable procedure, however your boss is still concerned that the defense attorney might question wheather evidence has been changed while at the lab.

    What can you do to prove that the evidence is the same as it was when it first entered the lab?

    A. Sign a statement attesting that the evidence is the same as it was when it entered the lab
    B. There is no reason to worry about this possible claim because state labs are certified
    C. Make MD5 hashes of the evidence and compare it to the standard database developed by NIST
    D. Make MD5 hashes of the evidence and compare it with the original MD5 hash that was taken when the evidence first entered the lab

  • Question 194:

    You should always work with original evidence

    A. True
    B. False

  • Question 195:

    An investigator is examining a compromised system and comes across some files that have been compressed with a packer. The investigator knows that these files contain malicious content, but cannot access them due to a password protection mechanism. The investigator does nothave the password.

    Which approach is the most suitable for accessing the contents of the packed files?

    A. The investigator should attempt static analysis on the packed file
    B. The investigator should run the packed executable in a controlled environment for dynamic analysis
    C. The investigator should attempt to crack the password using a brute force attack
    D. The investigator should attempt to reverse engineer the packed file in an attempt to bypass password protection

  • Question 196:

    A forensic investigator prepares to present digital evidence related to a high-profile cybercrime case in court. He needs to ensure that the evidence complies with the five basic rules of evidence. Which of the following actions does NOT align with these rules?

    A. He gets an expert opinion to confirm the investigation process and make the evidence understandable
    B. He gathers supporting documents regarding the authenticity of the evidence, including the source and its relevance to the case
    C. He works directly on the original digital evidence to maintain its reliability
    D. He ensures that the evidence is complete, providing sufficient information to either prove or disprove the consensual fact in the litigation

  • Question 197:

    A CHFI has been tasked to analyze Windows Security Logs in a highly complex and multi-layered security breach investigation. The breach involved an account creation, privilege escalation, and the installation of a service, all happening sequentially within a short duration. The investigator is required to retrieve a combination of Event IDs that would chronologically corroborate these events.

    Which combination of Event IDs should the investigator focus on?

    A. Event ID 624, Event ID 4670, and Event ID 6011
    B. Event ID 624, Event ID 500, and Event ID 7045
    C. Event ID 4720, Event ID 4672, and Event ID 7045
    D. Event ID 4720, Event ID 500, and Event ID 6011

  • Question 198:

    With Regard to using an Antivirus scanner during a computer forensics investigation, You should:

    A. Scan the suspect hard drive before beginning an investigation
    B. Never run a scan on your forensics workstation because it could change your systems configuration
    C. Scan your forensics workstation at intervals of no more than once every five minutes during an investigation
    D. Scan your Forensics workstation before beginning an investigation

  • Question 199:

    Which is not a part of environmental conditions of a forensics lab?

    A. Large dimensions of the room
    B. Good cooling system to overcome excess heat generated by the work station
    C. Allocation of workstations as per the room dimensions
    D. Open windows facing the public road

  • Question 200:

    You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers. What type of firewall must you implement to abide by this policy?

    A. Packet filtering firewall
    B. Application-level proxy firewall
    C. Statefull firewall
    D. Circuit-level proxy firewall

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.