312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 351:

    What is the First Step required in preparing a computer for forensics investigation?

    A. Do not turn the computer off or on, run any programs, or attempt to access data on a computer
    B. Secure any relevant media
    C. Suspend automated document destruction and recycling policies that may pertain to any relevant media or users at Issue
    D. Identify the type of data you are seeking, the Information you are looking for, and the urgency level of the examination

  • Question 352:

    What system details can an investigator obtain from the NetBIOS name table cache?

    A. List of files opened on other systems
    B. List of the system present on a router
    C. List of connections made to other systems
    D. List of files shared between the connected systems

  • Question 353:

    Which of the following U.S. laws requires financial institutions - companies that offer consumers financial products or services such as loans, financial or investment advice, or insurance - to protect their customers' information against security threats?

    A. SOX
    B. HIPAA
    C. GLBA
    D. FISMA

  • Question 354:

    Operating System logs are most beneficial for Identifying or Investigating suspicious activities involving a particular host. Which of the following Operating System logs contains information about operational actions performed by OS components?

    A. Event logs
    B. Audit logs
    C. Firewall logs
    D. IDS logs

  • Question 355:

    Donald made an OS disk snapshot of a compromised Azure VM under a resource group being used by the affected company as a part of forensic analysis process. He then created a vhd file out of the snapshot and stored it in a file share and as a page blob as backup in a storage account under different region.

    What is the next thing he should do as a security measure?

    A. Delete the OS disk of the affected VM altogether
    B. Delete the snapshot from the source resource group
    C. Recommend changing the access policies followed by the company
    D. Create another VM by using the snapshot

  • Question 356:

    You are called in to assist the police in an investigation involving a suspected drug dealer. The suspects house was searched by the police after a warrant was obtained and they located a floppy disk in the suspects bedroom. The disk contains several files, but they appear to be password protected.

    What are two common methods used by password cracking software that you can use to obtain the password?

    A. Limited force and library attack
    B. Brute force and dictionary attack
    C. Maximum force and thesaurus attack
    D. Minimum force and appendix attack

  • Question 357:

    Which device in a wireless local area network (WLAN) determines the next network point to which a packet should be forwarded toward its destination?

    A. Wireless router
    B. Wireless modem
    C. Antenna
    D. Mobile station

  • Question 358:

    Which of the following file in Novel GroupWise stores information about user accounts?

    A. ngwguard.db
    B. gwcheck.db
    C. PRIV.EDB
    D. PRIV.STM

  • Question 359:

    Mobile phone forensics is the science of recovering digital evidence from a mobile phone under forensically sound conditions.

    A. True
    B. False

  • Question 360:

    You are a Computer Hacking Forensic Investigator working on a high-profile case involving an Android device. You discovered an SQLite database during your investigation. However, this database has an unusual extension type and does not display content using your current tools. You recall that you have the following tools at your disposal: Oxygen Forensics SQLite Viewer, DB Browser for SQLite, X-plore, SQLitePlus Database Explorer, and SQLite Viewer.

    Given that this particular SQLite database may contain important evidence, what should be your approach?

    A. Switch between all the available tools until you find one that works with the unknown database extension
    B. Use X-plore, as it offers root access which can provide access to the database
    C. Stick to using Oxygen Forensics SQLite Viewer, which can analyze actual and deleted data
    D. Use the SQLite ".dump" command to extract the data into a readable format

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.