312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 391:

    Why is it a good idea to perform a penetration test from the inside?

    A. It is never a good idea to perform a penetration test from the inside
    B. It is easier to hack from the inside
    C. Because 70% of attacks are from inside the organization
    D. To attack a network from a hacker's perspective

  • Question 392:

    "To ensure that the digital evidence is collected, preserved, examined, or transferred in a manner safeguarding the accuracy and reliability of the evidence, law enforcement, and forensics organizations must establish and maintain an effective quality system" is a principle established by:

    A. SWGDE
    B. EC-Council
    C. NIST
    D. NCIS

  • Question 393:

    The MAC attributes are timestamps that refer to a time at which the file was last modified or last accessed or originally created. Which of the following file systems store MAC attributes in Coordinated Universal Time (UTC) format?

    A. File Allocation Table (FAT)
    B. New Technology File System (NTFS)
    C. Hierarchical File System (HFS)
    D. Global File System (GFS)

  • Question 394:

    Shane, a forensic specialist, is investigating an ongoing attack on a MySQL database server hosted on a Windows machine with SID "WIN-ABCDE12345F." Which of the following log file will help Shane in tracking all the client connections and activities performed on the database server?

    A. WIN-ABCDE12345F.err
    B. WIN-ABCDE12345F-bin.n
    C. WIN-ABCDE12345F.pid
    D. WIN-ABCDE12345F.log

  • Question 395:

    Matthew has been assigned the task of analyzing a suspicious MS Office document via static analysis over an Ubuntu-based forensic machine. He wants to see what type of document it is, whether it is encrypted, or contains any flash objects/VBA macros.

    Which of the following python-based script should he run to get relevant information?

    A. oleid.py
    B. oleform.py
    C. oledir.py
    D. pdfid.py

  • Question 396:

    Which legal document allows law enforcement to search an office, place of business, or other locale for evidence relating to an alleged crime?

    A. Search warrant
    B. Subpoena
    C. Wire tap
    D. Bench warrant

  • Question 397:

    What does the 63. 78.199.4(161) denotes in a Cisco router log?

    Mar 14 22:57:53. 425 EST: %SEC-6-IPACCESSLOGP: list internet-inbound denied udp 66. 56. 16. 77(1029) -> 63. 78.199.4(161), 1 packet

    A. Destination IP address
    B. Source IP address
    C. Login IP address
    D. None of the above

  • Question 398:

    Brian has the job of analyzing malware for a software security company. Brian has setup a virtual environment that includes virtual machines running various versions of OSes. Additionally, Brian has setup separated virtual networks within

    this environment. The virtual environment does not connect to the company's intranet nor does it connect to the external Internet.

    With everything setup, Brian now received an executable file from client that has undergone a cyberattack. Brian ran the executable file in the virtual environment to see what it would do.

    What type of analysis did Brian perform?

    A. Status malware analysis
    B. Static OS analysis
    C. Static malware analysis
    D. Dynamic malware analysis

  • Question 399:

    During an investigation of a suspected network attack, a Computer Hacking Forensics Investigator (CHFI) is analyzing a firewall log from a Cisco system. The log entry includes a mnemonic message:

    "%PIX-6-302015: Built outbound UDP connection."

    Considering the information provided, what can the investigator infer from this log entry?

    A. The firewall detected suspicious traffic, but the firewall accepted it
    B. The firewall has blocked a connection attempt per the security policy or user-defined rules
    C. The firewall has recorded an unsuccessful attempt to establish an outbound UDP connection
    D. The firewall has established an outbound UDP connection

  • Question 400:

    An investigator has extracted the device descriptor for a 1GB thumb drive that looks like: DiskandVen_Best_BuyandProd_Geek_Squad_U3andRev_6. 15. What does the "Geek_Squad" part represent?

    A. Product description
    B. Manufacturer Details
    C. Developer description
    D. Software or OS used

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.