312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 71:

    You just passed your ECSA exam and are about to start your first consulting job running security audits for a financial institution in Los Angeles. The IT manager of the company you will be working for tries to see if you remember your ECSA class.

    He asks about the methodology you will be using to test the company's network. How would you answer?

    A. IBM Methodology
    B. Microsoft Methodology
    C. Google Methodology
    D. LPT Methodology

  • Question 72:

    Which of the following is not an example of a cyber-crime?

    A. Fraud achieved by the manipulation of the computer records
    B. Firing an employee for misconduct
    C. Deliberate circumvention of the computer security systems
    D. Intellectual property theft, including software piracy

  • Question 73:

    Email spoofing refers to:

    A. The forgery of an email header so that the message appears to have originated from someone or somewhere other than the actual source
    B. The criminal act of sending an illegitimate email, falsely claiming to be from a legitimate site in an attempt to acquire the user's personal or account information
    C. Sending huge volumes of email to an address in an attempt to overflow the mailbox or overwhelm the server where the email address Is hosted to cause a denial-of-service attack
    D. A sudden spike of "Reply All" messages on an email distribution list, caused by one misdirected message

  • Question 74:

    What is the location of a Protective MBR in a GPT disk layout?

    A. Logical Block Address (LBA) 2
    B. Logical Block Address (LBA) 0
    C. Logical Block Address (LBA) 1
    D. Logical Block Address (LBA) 3

  • Question 75:

    A forensics investigator is searching the hard drive of a computer for files that were recently moved to the Recycle Bin. He searches for files in C:\RECYCLED using a command line tool but does not find anything. What is the reason for this?

    A. He should search in C:\Windows\System32\RECYCLED folder
    B. The Recycle Bin does not exist on the hard drive
    C. The files are hidden and he must use switch to view themThe files are hidden and he must use ? switch to view them
    D. Only FAT system contains RECYCLED folder and not NTFS

  • Question 76:

    Identify the term that refers to individuals who, by virtue of their knowledge and expertise, express an independent opinion on a matter related to a case based on the information that is provided.

    A. Expert Witness
    B. Evidence Examiner
    C. Forensic Examiner
    D. Defense Witness

  • Question 77:

    The Recycle Bin is located on the Windows desktop. When you delete an item from the hard disk, Windows sends that deleted item to the Recycle Bin and the icon changes to full from empty, but items deleted from removable media, such as a floppy disk or network drive, are not stored in the Recycle Bin.

    What is the size limit for Recycle Bin in Vista and later versions of the Windows?

    A. No size limit
    B. Maximum of 3. 99 GB
    C. Maximum of 4. 99 GB
    D. Maximum of 5. 99 GB

  • Question 78:

    Terri works for a security consulting firm that is currently performing a penetration test on First National Bank in Tokyo. Terri's duties include bypassing firewalls and switches to gain access to the network. Terri sends an IP packet to one of the company's switches with ACK bit and the source address of her machine set.

    What is Terri trying to accomplish by sending this IP packet?

    A. Poison the switch's MAC address table by flooding it with ACK bits
    B. Crash the switch with aDoS attack since switches cannot send ACK bits
    C. Enable tunneling feature on the switch
    D. Trick the switch into thinking it already has a session with Terri's computer

  • Question 79:

    A forensics investigator is studying the Event ID logs on a domain controller for a corporation, following a suspected security breach. He notices that a domain user account was created, then modified, and then added to a group in a very short span of time. The investigator realizes that he must cross-verify the audit policies on the local system to understand if any changes were made to it.

    Assuming that the investigator has the correct audit policy settings, which of the following Event IDs should he focus on?

    A. Event ID 642
    B. Event ID 644
    C. Event ID 624
    D. Event ID 612

  • Question 80:

    In a virtual test environment, Michael is testing the strength and security of BGP using multiple routers to mimic the backbone of the Internet. This project will help him write his doctoral thesis on "bringing down the Internet". Without sniffing the traffic between the routers, Michael sends millions of RESET packets to the routers in an attempt to shut one or all of them down. After a few hours, one of the routers finally shuts itself down.

    What will the other routers communicate between themselves?

    A. The change in the routing fabric to bypass the affected router
    B. More RESET packets to the affected router to get it to power back up
    C. STOP packets to all other routers warning of where the attack originated
    D. RESTART packets to the affected router to get it to power back up

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.