312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 591:

    To reach a bank web site, the traffic from workstations must pass through a firewall. You have been asked to review the firewall configuration to ensure that workstations in network 10.10.10.0/24 can only reach the bank web site 10.20.20.1 using https.

    Which of the following firewall rules meets this requirement?

    A. If (source matches 10.10.10.0/24 and destination matches 10.20.20.1 and port matches 443) then permit
    B. If (source matches 10.10.10.0/24 and destination matches 10.20.20.1 and port matches 80 or 443) then permit
    C. If (source matches 10.20.20.1 and destination matches 10.10.10.0/24 and port matches 443) then permit
    D. If (source matches 10.10.10.0 and destination matches 10.20.20.1 and port matches 443) then permit

  • Question 592:

    Cybercriminals sometimes use compromised computers to commit other crimes, which may involve using computers or networks to spread malware or illegal information. Which type of cybercrime stops users from using a device or network, or prevents a company from providing a software service to its customers?

    A. Malware attack
    B. Denial-of-Service (DoS) attack
    C. Phishing
    D. Ransomware attack

  • Question 593:

    Which of the following data structures stores attributes of a process, as well as pointers to other attributes and data structures?

    A. Lsproc
    B. DumpChk
    C. RegEdit
    D. EProcess

  • Question 594:

    Fred, a cybercrime investigator for the FBI, finished storing a solid-state drive in a static resistant bag and filled out the chain of custody form. Two days later, John grabbed the solid-state drive and created a clone of it (with write blockers

    enabled) in order to investigate the drive. He did not document the chain of custody though. When John was finished, he put the solid-state drive back in the static resistant and placed it back in the evidence locker.

    A day later, the court trial began and upon presenting the evidence and the supporting documents, the chief justice outright rejected them.

    Which of the following statements strongly support the reason for rejecting the evidence?

    A. John did not document the chain of custody
    B. Block clones cannot be created with solid-state drives
    C. Write blockers were used while cloning the evidence
    D. John investigated the clone instead of the original evidence itself

  • Question 595:

    Which of the following is the most effective tool for acquiring volatile data from a Windows-based system?

    A. Helix
    B. Datagrab
    C. Coreography
    D. Ethereal

  • Question 596:

    Which root folder (hive) of registry editor contains a vast array of configuration information for the system, including hardware settings and software settings?

    A. HKEY_USERS
    B. HKEY_CURRENT_USER
    C. HKEY_LOCAL_MACHINE
    D. HKEY-CURRENT_CONFIG

  • Question 597:

    During the trial, an investigator observes that one of the principal witnesses is severely ill and cannot be present for the hearing. He decides to record the evidence and present it to the court. Under which rule should he present such evidence?

    A. Rule 1003: Admissibility of Duplicates
    B. Limited admissibility
    C. Locard's Principle
    D. Hearsay

  • Question 598:

    Why would you need to find out the gateway of a device when investigating a wireless attack?

    A. The gateway will be the IP of the proxy server used by the attacker to launch the attack
    B. The gateway will be the IP of the attacker computer
    C. The gateway will be the IP used to manage the RADIUS server
    D. The gateway will be the IP used to manage the access point

  • Question 599:

    Which of the following file system uses Master File Table (MFT) database to store information about every file and directory on a volume?

    A. FAT File System
    B. ReFS
    C. exFAT
    D. NTFS File System

  • Question 600:

    John and Hillary works at the same department in the company. John wants to find out Hillary's network password so he can take a look at her documents on the file server. He enables Lophtcrack program to sniffing mode. John sends Hillary an email with a link to Error! Reference source not found.

    What information will he be able to gather from this?

    A. The SID of Hillary network account
    B. The SAM file from Hillary computer
    C. The network shares that Hillary has permissions
    D. Hillary network username and password hash

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.