312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 371:

    If you discover a criminal act while investigating a corporate policy abuse, it becomes a public-sector investigation and should be referred to law enforcement?

    A. True
    B. False

  • Question 372:

    During an investigation, an employee was found to have deleted harassing emails that were sent to someone else. The company was using Microsoft Exchange and had message tracking enabled. Where could the investigator search to find the message tracking log file on the Exchange server?

    A. C:\Program Files\Exchsrvr\servername.log
    B. D:\Exchsrvr\Message Tracking\servername.log
    C. C:\Exchsrvr\Message Tracking\servername.log
    D. C:\Program Files\Microsoft Exchange\srvr\servername.log

  • Question 373:

    During an investigation of an XSS attack, the investigator comes across the term "[a-zA-Z0-9\%]+" in analyzed evidence details. What is the expression used for?

    A. Checks for upper and lower-case alphanumeric string inside the tag, or its hex representation
    B. Checks for forward slash used in HTML closing tags, its hex or double-encoded hex equivalent
    C. Checks for opening angle bracket, its hex or double-encoded hex equivalent
    D. Checks for closing angle bracket, hex or double-encoded hex equivalent

  • Question 374:

    In Windows, prefetching is done to improve system performance. There are two types of prefetching: boot prefetching and application prefetching. During boot prefetching, what does the Cache Manager do?

    A. Determines the data associated with value EnablePrefetcher
    B. Monitors the first 10 seconds after the process is started
    C. Checks whether the data is processed
    D. Checks hard page faults and soft page faults

  • Question 375:

    Which OWASP IoT vulnerability talks about security flaws such as lack of firmware validation, lack of secure delivery, and lack of anti-rollback mechanisms on IoT devices?

    A. Insecure default settings
    B. Use of insecure or outdated components
    C. Lack of secure update mechanism
    D. Insecure data transfer and storage

  • Question 376:

    Injection flaws are web application vulnerabilities that allow untrusted data to be Interpreted and executed as part of a command or query. Attackers exploit injection flaws by constructing malicious commands or queries that result in data loss or corruption, lack of accountability, or denial of access.

    Which of the following injection flaws involves the injection of malicious code through a web application?

    A. SQL Injection
    B. Password brute force
    C. Nmap Scanning
    D. Footprinting

  • Question 377:

    To preserve digital evidence, an investigator should ____________

    A. Make two copies of each evidence item using a single imaging tool
    B. Make a single copy of each evidence item using an approved imaging tool
    C. Make two copies of each evidence item using different imaging tools
    D. Only store the original evidence item

  • Question 378:

    Choose the layer in iOS architecture that provides frameworks for iOS app development?

    A. Core OS
    B. Core services
    C. Media services
    D. Cocoa Touch

  • Question 379:

    A section of your forensics lab houses several electrical and electronic equipment. Which type of fire extinguisher you must install in this area to contain any fire incident?

    A. Class B
    B. Class D
    C. Class C
    D. Class A

  • Question 380:

    An organization discovered an internal policy violation that resulted in financial loss. The incident involved unauthorized resource misuse, possibly by a staff member. The case is significant enough to warrant a thorough investigation but does not require law enforcement involvement. The organization wants to ensure the investigation is conducted appropriately without disrupting overall operations.

    What type of investigation would be most appropriate in this scenario?

    A. Civil Investigation
    B. Criminal Investigation
    C. Regulatory Compliance Investigation
    D. Administrative Investigation

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.