312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 231:

    Digital evidence is not fragile in nature.

    A. True
    B. False

  • Question 232:

    Where does Encase search to recover NTFS files and folders?

    A. MBR
    B. MFT
    C. Slack space
    D. HAL

  • Question 233:

    An organization has hired a digital forensics investigator to evaluate its Standard Operating Procedures (SOPs) for digital evidence handling. The investigator has identified some issues and needs to recommend improvements. Which of the following would NOT be a recommendation per Scientific Working Group on Digital Evidence (SWGDE) guidelines?

    A. The organization should use software that has been tested and confirmed to provide accurate and reliable results
    B. The organization should alter the SOPs at the time of implementation without communicating any changes before the commencement of an investigation
    C. The organization's management must annually review the SOPs to address the rapid technological changes
    D. The organization must maintain a written copy of the technical procedures for evidence handling

  • Question 234:

    Williamson is a forensic investigator. While investigating a case of data breach at a company, he is maintaining a document that records details such as the forensic processes applied on the collected evidence, particulars of people handling it, the dates and times when it is being handled, and the place of storage of the evidence.

    What do you call this document?

    A. Authorization form
    B. Consent form
    C. Chain of custody
    D. Log book

  • Question 235:

    Data files from original evidence should be used for forensics analysis

    A. True
    B. False

  • Question 236:

    A state department site was recently attacked and all the servers had their disks erased. The incident response team sealed the area and commenced investigation. During evidence collection they came across a zip disks that did not have the standard labeling on it. The incident team ran the disk on an isolated system and found that the system disk was accidentally erased. They decided to call in the FBI for further investigation. Meanwhile, they short listed possible suspects including three summer interns. Where did the incident team go wrong?

    A. They examined the actual evidence on an unrelated system
    B. They attempted to implicate personnel without proof
    C. They tampered with evidence by using it
    D. They called in the FBI without correlating with the fingerprint data

  • Question 237:

    Which layer in the IoT architecture is comprised of hardware parts such as sensors, RFID tags, and devices that play an important role in data collection?

    A. Access gateway layer
    B. Application layer
    C. Edge technology layer
    D. Middleware layer

  • Question 238:

    A steganographic file system is a method to store the files in a way that encrypts and hides the data without the knowledge of others

    A. True
    B. False

  • Question 239:

    You are a Penetration Tester and are assigned to scan a server. You need to use a scanning technique wherein the TCP Header is split into many packets so that it becomes difficult to detect what the packets are meant for. Which of the below scanning technique will you use?

    A. Inverse TCP flag scanning
    B. ACK flag scanning
    C. TCP Scanning
    D. IP Fragment Scanning

  • Question 240:

    You are a security analyst performing a penetration tests for a company in the Midwest. After some initial reconnaissance, you discover the IP addresses of some Cisco routers used by the company. You type in the following URL that

    includes the IP address of one of the routers:

    http://172. 168.4. 131/level/99/exec/show/config

    After typing in this URL, you are presented with the entire configuration file for that router. What have you discovered?

    A. URL Obfuscation Arbitrary Administrative Access Vulnerability
    B. HTML Configuration Arbitrary Administrative Access Vulnerability
    C. Cisco IOS Arbitrary Administrative Access Online Vulnerability
    D. HTTP Configuration Arbitrary Administrative Access Vulnerability

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.