312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 411:

    A clothing company has recently deployed a website on its latest product line to increase its conversion rate and base of customers. Andrew, the network administrator recently appointed by the company, has been assigned with the task of protecting the website from intrusion and vulnerabilities.

    Which of the following tool should Andrew consider deploying in this scenario?

    A. Kon-Boot
    B. Recuva
    C. CryptaPix
    D. ModSecurity

  • Question 412:

    What is the "Best Evidence Rule"?

    A. It states that the court only allows the original evidence of a document, photograph, or recording at the trial rather than a copy
    B. It contains system time, logged-on user(s), open files, network information, process information, process-to-port mapping, process memory, clipboard contents, service/driver information, and command history
    C. It contains hidden files, slack space, swap file, index.dat files, unallocated clusters, unused partitions, hidden partitions, registry settings, and event logs
    D. It contains information such as open network connection, user logout, programs that reside in memory, and cache data

  • Question 413:

    William is examining a log entry that reads 192. 168.0.1 - - [18/Jan/2020:12:42:29 +0000] "GET / HTTP/1.1" 200 1861. Which of the following logs does the log entry belong to?

    A. The common log format of Apache access log
    B. IIS log
    C. The combined log format of Apache access log
    D. Apache error log

  • Question 414:

    What header field in the TCP/IP protocol stack involves the hacker exploit known as the Ping of Death?

    A. ICMP header field
    B. TCP header field
    C. IP header field
    D. UDP header field

  • Question 415:

    You are working as Computer Forensics investigator and are called by the owner of an accounting firm to investigate possible computer abuse by one of the firm's employees. You meet with the owner of the firm and discover that the company has never published a policy stating that they reserve the right to inspect their computing assets at will. What do you do?

    A. Inform the owner that conducting an investigation without a policy is not a problem because the company is privately owned
    B. Inform the owner that conducting an investigation without a policy is a violation of the 4th amendment
    C. Inform the owner that conducting an investigation without a policy is a violation of the employees' expectation of privacy
    D. Inform the owner that conducting an investigation without a policy is not a problem because a policy is only necessary for government agencies

  • Question 416:

    Which of the following Wi-Fi chalking methods refers to drawing symbols in public places to advertise open Wi-Fi networks?

    A. WarWalking
    B. WarFlying
    C. WarChalking
    D. WarDhving

  • Question 417:

    When the operating system marks cluster as used, but does not allocate them to any file, such clusters are known as ___________.

    A. Lost clusters
    B. Bad clusters
    C. Empty clusters
    D. Unused clusters

  • Question 418:

    How many characters long is the fixed-length MD5 algorithm checksum of a critical system file?

    A. 16
    B. 32
    C. 64
    D. 48

  • Question 419:

    Gill is a computer forensics investigator who has been called upon to examine a seized computer. This computer, according to the police, was used by a hacker who gained access to numerous banking institutions to steal customer information. After preliminary investigations, Gill finds in the computer's log files that the hacker was able to gain access to these banks through the use of Trojan horses. The hacker then used these Trojan horses to obtain remote access to the companies' domain controllers. From this point, Gill found that the hacker pulled off the SAM files from the domain controllers to then attempt and crack network passwords.

    What is the most likely password cracking technique used by this hacker to break the user passwords from the SAM files?

    A. Syllable attack
    B. Hybrid attack
    C. Brute force attack
    D. Dictionary attack

  • Question 420:

    Which of the following components within the android architecture stack take care of displaying windows owned by different applications?

    A. Media Framework
    B. Surface Manager
    C. Resource Manager
    D. Application Framework

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.