312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 301:

    Computer security logs contain information about the events occurring within an organization's systems and networks. Which of the following security logs contains Logs of network and host-based security software?

    A. Operating System (OS) logs
    B. Application logs
    C. Security software logs
    D. Audit logs

  • Question 302:

    What TCP/UDP port does the toolkit program netstat use?

    A. Port 7
    B. Port 15
    C. Port 23
    D. Port 69

  • Question 303:

    Consistency in the investigative report is more important than the exact format in the report to eliminate uncertainty and confusion.

    A. True
    B. False

  • Question 304:

    After an unexpected shutdown of a company's database server, the IT forensics team is tasked with collecting data from the Database Plan Cacheto investigate potential issues. What query should they use to retrieve the SQL text of all cached entries and acquire additional aggregate performance statistics?

    A. Use: select * from sys.dm_exec_cached_plans cross apply sys.dm_exec_plan_attributes(plan_handle) followed by: select * from sys.dm_exec_query_stats
    B. Use: select * from sys.dm_exec_cached_plans cross apply sys.dm_exec_sql_text(plan_handle) followed by: select * from sys.dm_exec_plan_attributes(plan_handle)
    C. Use: select * from sys.dm_exec_sql_text(plan_handle) cross apply sys.dm_exec_cached_plans followed by: select * from sys.dm_exec_query_stats
    D. Use: select * from sys.dm_exec_cached_plans cross apply sys.dm_exec_sql_text(plan_handle) followed by: select * from sys.dm_exec_query_stats

  • Question 305:

    A top-tier forensic investigation bureau within the United States is handling a major case related to espionage. They have started electronic monitoring of a permanent lawful inhabitant of the nation suspected of participating in the case. Yet, there seems to be no compelling evidencesuggesting the individual's criminal involvement.

    How does this measure correspond with existing laws?

    A. This measure corresponds with the Protect America Act of 2007 which permits the surveillance of individuals who are thought to be residing outside the United States
    B. This measure breaches the Privacy Act of 1974, involving the unauthorized revelation of private data
    C. This measure corresponds with the Foreign Intelligence Surveillance Act of 1978, permitting the surveillance of US individuals suspected of participating in espionage
    D. This measure breaches the Foreign Intelligence Surveillance Act of 1978 as no compelling evidence suggests criminal involvement

  • Question 306:

    Which of the following filesystem is used by Mac OS X?

    A. EFS
    B. HFS+
    C. EXT2
    D. NFS

  • Question 307:

    You are a security analyst performing reconnaissance on a company you will be carrying out a penetration test for. You conduct a search for IT jobs on Dice.com and find the following information for an open position: 7+ years experience in Windows Server environment 5+ years experience in Exchange 2000/2003 environment Experience with Cisco Pix Firewall, Linksys 1376 router, Oracle 11i and MYOB v3. 4 Accounting software are required MCSA desired, MCSE, CEH preferred No Unix/Linux Experience needed.

    What is this information posted on the job website considered?

    A. Trade secret
    B. Social engineering exploit
    C. Competitive exploit
    D. Information vulnerability

  • Question 308:

    Which of the following malware analysis involves executing the malware code to know how the code interacts with the host system and its impact on the system?

    A. Primary Malware Analysis
    B. Static Malware Analysis
    C. Dynamic Malware Analysis
    D. Secondary Malware Analysis

  • Question 309:

    Which of the following tools is used to dump the memory of a running process, either immediately or when an error condition occurs?

    A. CacheInf
    B. FATKit
    C. Belkasoft Live RAM Capturer
    D. Coreography

  • Question 310:

    The working of the Tor browser is based on which of the following concepts?

    A. Onion routing
    B. Static routing
    C. Both static and default routing
    D. Default routing

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.