312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 651:

    A suspect is accused of violating the acceptable use of computing resources, as he has visited adult websites and downloaded images. The investigator wants to demonstrate that the suspect did indeed visit these sites. However, the suspect has cleared the search history and emptied the cookie cache. Moreover, he has removed any images he might have downloaded.

    What can the investigator do to prove the violation?

    A. Image the disk and try to recover deleted files
    B. Seek the help of co-workers who are eye-witnesses
    C. Check the Windows registry for connection data (You may or may not recover)
    D. Approach the websites for evidence

  • Question 652:

    Your company's network just finished going through a SAS 70 audit. This audit reported that overall, your network is secure, but there are some areas that needs improvement. The major area was SNMP security. The audit company recommended turning off SNMP, but that is not an option since you have so many remote nodes to keep track of.

    What step could you take to help secure SNMP on your network?

    A. Block access to TCP port 171
    B. Change the default community string names
    C. Block all internal MAC address from using SNMP
    D. Block access to UDP port 171

  • Question 653:

    When analyzing logs, it is important that the clocks of all the network devices are synchronized. Which protocol will help in synchronizing these clocks?

    A. UTC
    B. PTP
    C. Time Protocol
    D. NTP

  • Question 654:

    A computer forensics investigator is analyzing a hard disk drive (HDD) that is suspected to contain evidence of criminal activity. The HDD has 20,000 cylinders, 16 heads, and 63 sectors per track, with each sector having 512 bytes. During the analysis, the investigator discovered a file of 1.5KB in size on the disk.

    How many sectors are allocated for the file, and what could be the consequences of such allocation for the investigation?

    A. 2 sectors; the file might be fragmented, making it harder to retrieve
    B. 4 sectors; it may cause inefficiency in space utilization on the disk
    C. 3 sectors; it may increase the retrieval time due to increased sector overhead
    D. 3 sectors; the file might be fragmented, making it harder to retrieve

  • Question 655:

    Which of the following is a precomputed table containing word lists like dictionary files and brute force lists and their hash values?

    A. Directory Table
    B. Rainbow Table
    C. Master file Table (MFT)
    D. Partition Table

  • Question 656:

    Shane has started the static analysis of a malware and is using the tool ResourcesExtract to find more details of the malicious program. What part of the analysis is he performing?

    A. Identifying File Dependencies
    B. Strings search
    C. Dynamic analysis
    D. File obfuscation

  • Question 657:

    What technique used by Encase makes it virtually impossible to tamper with evidence once it has been acquired?

    A. Every byte of the file(s) is given an MD5 hash to match against a master file
    B. Every byte of the file(s) is verified using 32-bit CRC
    C. Every byte of the file(s) is copied to three different hard drives
    D. Every byte of the file(s) is encrypted using three different methods

  • Question 658:

    CAN-SPAM act requires that you:

    A. Don't use deceptive subject lines
    B. Don't tell the recipients where you are located
    C. Don't identify the message as an ad
    D. Don't use true header information

  • Question 659:

    A company has been receiving unsolicited commercial emails from an unknown source promoting a third-party product. The email contains false header information and is not identified as an advertisement. The emails are being sent to

    addresses that are generated through a dictionary attack.

    As a Computer Hacking Forensics Investigator, which violations of the CAN-SPAM Act are present in this scenario?

    A. Using false or misleading header information and violating the prohibition against dictionary attacks only
    B. Using false or misleading header information and not identifying the commercial email as an ad only
    C. Using false or misleading header information, not identifying the commercial email as an ad. and violating the prohibition against dictionary attacks
    D. Violating the prohibition against dictionary attacks and not identifying the commercial email as an ad only

  • Question 660:

    During an incident response to a data breach in a company's AWS environment, a forensic investigator is tasked to analyze and extract data from different storage types for further examination. What would be the most appropriate and effective course of action given that Amazon S3, EBS, and EFS were used?

    A. Implement ACL permissions for S3 buckets, and attach the affected EFS to a Linux instance for data extraction
    B. Create IAM policies to restrict access, and proceed with data extraction from EBS and EFS storage types
    C. Extract all data directly from Amazon S3 and EBS, and attach the EFS to a Linux instance for data extraction
    D. Snapshot the affected EBS volumes and S3 buckets, and mount EFS to a Linux instance for analysis

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.