312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 251:

    How many bits is Source Port Number in TCP Header packet?

    A. 16
    B. 48
    C. 32
    D. 64

  • Question 252:

    An investigator has acquired packed software and needed to analyze it for the presence of malice. Which of the following tools can help in finding the packaging software used?

    A. SysAnalyzer
    B. PEiD
    C. Comodo Programs Manager
    D. Dependency Walker

  • Question 253:

    Email archiving is a systematic approach to save and protect the data contained in emails so that it can be accessed fast at a later date. There are two main archive types, namely Local Archive and Server Storage Archive. Which of the following statements is correct while dealing with local archives?

    A. It is difficult to deal with the webmail as there is no offline archive in most cases. So consult your counsel on the case as to the best way to approach and gain access to the required data on servers
    B. Local archives do not have evidentiary value as the email client may alter the message data
    C. Local archives should be stored together with the server storage archives in order to be admissible in a court of law
    D. Server storage archives are the server information and settings stored on a local system whereas the local archives are the local email client information stored on the mail server

  • Question 254:

    What type of attack sends SYN requests to a target system with spoofed IP addresses?

    A. SYN flood
    B. Ping of death
    C. Cross site scripting
    D. Land

  • Question 255:

    Shortcuts are the files with the extension .Ink that are created and are accessed by the users. These files provide you with information about:

    A. Files or network shares
    B. Running application
    C. Application logs
    D. System logs

  • Question 256:

    George is a senior security analyst working for a state agency in Florida. His state's congress just passed a bill mandating every state agency to undergo a security audit annually. After learning what will be required, George needs to

    implement an IDS as soon as possible before the first audit occurs. The state bill requires that an IDS with a "time- based induction machine" be used.

    What IDS feature must George implement to meet this requirement?

    A. Pattern matching
    B. Statistical-based anomaly detection
    C. Real-time anomaly detection
    D. Signature-based anomaly detection

  • Question 257:

    What is the first step that needs to be carried out to crack the password?

    A. A word list is created using a dictionary generator program or dictionaries
    B. The list of dictionary words is hashed or encrypted
    C. The hashed wordlist is compared against the target hashed password, generally one word at a time
    D. If it matches, that password has been cracked and the password cracker displays the unencrypted version of the password

  • Question 258:

    Your company uses Cisco routers exclusively throughout the network. After securing the routers to the best of your knowledge, an outside security firm is brought in to assess the network security. Although they found very few issues, they were able to enumerate the model, OS version, and capabilities for all your Cisco routers with very little effort.

    Which feature will you disable to eliminate the ability to enumerate this information on your Cisco routers?

    A. Simple Network Management Protocol
    B. Cisco Discovery Protocol
    C. Border Gateway Protocol
    D. Broadcast System Protocol

  • Question 259:

    Korey, a data mining specialist in a knowledge processing firm DataHub.com, reported his CISO that he has lost certain sensitive data stored on his laptop. The CISO wants his forensics investigation team to find if the data loss was accident or intentional.

    In which of the following category this case will fall?

    A. Civil Investigation
    B. Administrative Investigation
    C. Both Civil and Criminal Investigations
    D. Criminal Investigation

  • Question 260:

    During an investigation, Noel found a SIM card from the suspect's mobile. The ICCID on the card is 8944245252001451548. What does the first four digits (89 and 44) in the ICCID represent?

    A. TAC and industry identifier
    B. Industry identifier and country code
    C. Country code and industry identifier
    D. Issuer identifier number and TAC

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.