312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 671:

    What is a chain of custody?

    A. A legal document that demonstrates the progression of evidence as it travels from the original evidence location to the forensic laboratory
    B. It is a search warrant that is required for seizing evidence at a crime scene
    C. It Is a document that lists chain of windows process events
    D. Chain of custody refers to obtaining preemptive court order to restrict further damage of evidence in electronic seizures

  • Question 672:

    In both pharming and phishing attacks, an attacker can create websites that look similar to legitimate sites with the intent of collecting personal identifiable information from its victims. What is the difference between pharming and phishing attacks?

    A. Both pharming and phishing attacks are purely technical and are not considered forms of social engineering
    B. In a pharming attack, a victim is redirected to a fake website by modifying their host configuration file or by exploiting vulnerabilities in DNS. In a phishing attack, an attacker provides the victim with a URL that is either misspelled or looks similar to the actual websites domain name
    C. In a phishing attack, a victim is redirected to a fake website by modifying their host configuration file or by exploiting vulnerabilities in DNS. In a pharming attack, an attacker provides the victim with a URL that is either misspelled or looks very similar to the actual websites domain name
    D. Both pharming and phishing attacks are identical

  • Question 673:

    What is the following command trying to accomplish?

    A. Verify that TCP port 445 is open for the 192. 168.0.0 network
    B. Verify that UDP port 445 is open for the 192. 168.0.0 network
    C. Verify that UDP port 445 is closed for the 192. 168.0.0 network
    D. Verify that NETBIOS is running for the 192. 168.0.0 network

  • Question 674:

    A Linux system is undergoing investigation. In which directory should the investigators look for its current state data if the system is in powered on state?

    A. /auth
    B. /proc
    C. /var/log/debug
    D. /var/spool/cron/

  • Question 675:

    Which network attack is described by the following statement?

    "At least five Russian major banks came under a continuous hacker attack, although online client services were not disrupted. The attack came from a wide-scale botnet involving at least 24,000 computers, located in 30 countries."

    A. Man-in-the-Middle Attack
    B. Sniffer Attack
    C. Buffer Overflow
    D. DDoS

  • Question 676:

    While presenting his case to the court, Simon calls many witnesses to the stand to testify. Simon decides to call Hillary Taft, a lay witness, to the stand. Since Hillary is a lay witness, what field would she be considered an expert in?

    A. Technical material related to forensics
    B. No particular field
    C. Judging the character of defendants/victims
    D. Legal issues

  • Question 677:

    Which of the following commands shows you the username and IP address used to access the system via a remote login session and the Type of client from which they are accessing the system?

    A. Net sessions
    B. Net file
    C. Net config
    D. Net share

  • Question 678:

    You are working as an investigator for a corporation and you have just received instructions from your manager to assist in the collection of 15 hard drives that are part of an ongoing investigation. Your job is to complete the required evidence custody forms to properly document each piece of evidence as other members of your team collect it. Your manager instructs you to complete one multi-evidence form for the entire case and a single-evidence form for each hard drive.

    How will these forms be stored to help preserve the chain of custody of the case?

    A. All forms should be placed in an approved secure container because they are now primary evidence in the case
    B. The multi-evidence form should be placed in an approved secure container with the hard drives and the single-evidence forms should be placed in the report file
    C. All forms should be placed in the report file because they are now primary evidence in the case
    D. The multi-evidence form should be placed in the report file and the single-evidence forms should be kept with each hard drive in an approved secure container

  • Question 679:

    At what layer does a cross site scripting attack occur on?

    A. Presentation
    B. Application
    C. Session
    D. Data Link

  • Question 680:

    When a file or folder is deleted, the complete path, including the original file name, is stored in a special hidden file called "INF02" in the Recycled folder. If the INF02 file is deleted, it is re-created when you___________.

    A. Restart Windows
    B. Kill the running processes in Windows task manager
    C. Run the antivirus tool on the system
    D. Run the anti-spyware tool on the system

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.