312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 481:

    You are working on a thesis for your doctorate degree in Computer Science. Your thesis is based on HTML, DHTML, and other web-based languages and how they have evolved over the years. You navigate to archive. org and view the HTML code of news.com. You then navigate to the current news.com website and copy over the source code.

    While searching through the code, you come across something abnormal: What have you found?

    A. Web bug
    B. CGI code
    C. Trojan.downloader
    D. Blind bug

  • Question 482:

    Digital photography helps in correcting the perspective of the Image which Is used In taking the measurements of the evidence. Snapshots of the evidence and incident-prone areas need to be taken to help in the forensic process. Is digital photography accepted as evidence in the court of law?

    A. Yes
    B. No

  • Question 483:

    Forensic Investigator Alex has to collect data from a suspect's large drive in a time-bound investigation. The court would allow him to retain the original drive. Considering these factors, what should be Alex's primary considerations to ensure a forensically sound data acquisition?

    A. Using Microsoft disk compression tools and validating the data acquisition process
    B. Sanitizing the target media using the (German) VSITR method and acquiring volatile data
    C. Enabling write protection on the evidence media and prioritizing data acquisition based on evidentiary value
    D. Utilizing lossless compression tools and creating a bit-stream copy using a reliable acquisition tool

  • Question 484:

    Email archiving is a systematic approach to save and protect the data contained in emails so that it can be accessed fast at a later date. There are two main archive types, namely Local Archive and Server Storage Archive. Which of the following statements is correct while dealing with local archives?

    A. Server storage archives are the server information and settings stored on a local system, whereas the local archives are the local email client information stored on the mail server
    B. It is difficult to deal with the webmail as there is no offline archive in most cases. So consult your counsel on the case as to the best way to approach and gain access to the required data on servers
    C. Local archives should be stored together with the server storage archives in order to be admissible in a court of law
    D. Local archives do not have evidentiary value as the email client may alter the message data

  • Question 485:

    Hackers can gain access to Windows Registry and manipulate user passwords, DNS settings, access rights or others features that they may need in order to accomplish their objectives. One simple method for loading an application at startup is to add an entry (Key) to the following Registry Hive:

    A. HKEY_LOCAL_MACHINE\hardware\windows\start
    B. HKEY_LOCAL_USERS\Software\Microsoft\old\Version\Load
    C. HKEY_CURRENT_USER\Microsoft\Default
    D. HKEY_LOCAL_MACHINE\Software\Microsoft\CurrentVersion\Run

  • Question 486:

    Corporate investigations are typically easier than public investigations because:

    A. the users have standard corporate equipment and software
    B. the investigator does not have to get a warrant
    C. the investigator has to get a warrant
    D. the users can load whatever they want on their machines

  • Question 487:

    It takes _____________ mismanaged case/s to ruin your professional reputation as a computer forensics examiner?

    A. by law, three
    B. quite a few
    C. only one
    D. at least two

  • Question 488:

    When operating systems mark a cluster as used but not allocated, the cluster is considered as _________

    A. Corrupt
    B. Bad
    C. Lost
    D. Unallocated

  • Question 489:

    You are assisting in the investigation of a possible Web Server hack. The company who called you stated that customers reported to them that whenever they entered the web address of the company in their browser, what they received was a pornographic web site. The company checked the web server and nothing appears wrong. When you type in the IP address of the web site in your browser everything appears normal.

    What is the name of the attack that affects the DNS cache of the name resolution servers, resulting in those servers directing users to the wrong web site?

    A. ARP Poisoning
    B. DNS Poisoning
    C. HTTP redirect attack
    D. IP Spoofing

  • Question 490:

    What type of attack occurs when an attacker can force a router to stop forwarding packets by flooding the router with many open connections simultaneously so that all the hosts behind the router are effectively disabled?

    A. ARP redirect
    B. Physical attack
    C. Digital attack
    D. Denial of service

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.