312-49V10 Exam Details

  • Exam Code
    :312-49V10
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V10)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :1028 Q&As
  • Last Updated
    :May 31, 2026

EC-COUNCIL 312-49V10 Online Questions & Answers

  • Question 881:

    Which of the following tool captures and allows you to interactively browse the traffic on a network?

    A. Security Task Manager
    B. Wireshark
    C. ThumbsDisplay
    D. RegScanner

  • Question 882:

    Recently, an internal web app that a government agency utilizes has become unresponsive. Betty, a network engineer for the government agency, has been tasked to determine the cause of the web application's unresponsiveness. Betty launches Wireshark and begins capturing the traffic on the local network. While analyzing the results, Betty noticed that a syn flood attack was underway.

    How did Betty know a syn flood attack was occurring?

    A. Wireshark capture does not show anything unusual and the issue is related to the web application
    B. Wireshark capture shows multiple ACK requests and SYN responses from single/multiple IP address(es)
    C. Wireshark capture shows multiple SYN requests and RST responses from single/multiple IP address(es)
    D. Wireshark capture shows multiple SYN requests and ACK responses from single/multiple IP address(es)

  • Question 883:

    Watson, a forensic investigator, is examining a copy of an ISO file stored in CDFS format. What type of evidence is this?

    A. Data from a CD copied using Windows
    B. Data from a CD copied using Mac-based system
    C. Data from a DVD copied using Windows system
    D. Data from a CD copied using Linux system

  • Question 884:

    Which Linux command when executed displays kernel ring buffers or information about device drivers loaded into the kernel?

    A. pgrep
    B. dmesg
    C. fsck
    D. grep

  • Question 885:

    Billy, a computer forensics expert, has recovered a large number of DBX files during forensic investigation of a laptop. Which of the following email clients he can use to analyze the DBX files?

    A. Microsoft Outlook
    B. Microsoft Outlook Express
    C. Mozilla Thunderoird
    D. Eudora

  • Question 886:

    Damaged portions of a disk on which no read/Write operation can be performed is known as ______________.

    A. Lost sector
    B. Bad sector
    C. Empty sector
    D. Unused sector

  • Question 887:

    You are a forensic investigator who is analyzing a hard drive that was recently collected as evidence. You have been unsuccessful at locating any meaningful evidence within the file system and suspect a drive wiping utility may have been used. You have reviewed the keys within the software hive of the Windows registry and did not find any drive wiping utilities.

    How can you verify that drive wiping software was used on the hard drive?

    A. Check the list of installed programs
    B. Look for distinct repeating patterns on the hard drive at the bit level
    C. Document in your report that you suspect a drive wiping utility was used, but no evidence was found
    D. Load various drive wiping utilities offline, and export previous run reports

  • Question 888:

    A forensic investigator encounters a suspicious executable on a compromised system, believed to be packed using a known program packer, andis password-protected. The investigator has knowledge of the tool used for packing and has the corresponding unpacking tool.

    What should be the next best course of action to examine the executable?

    A. Use the unpacking tool to decompress the executable, without dealing with the password
    B. Run a dynamic analysis on the packed executable in a controlled environment
    C. Decrypt the password to unpack the executable before analyzing
    D. Use reverse engineering to understand the attack tool hidden inside

  • Question 889:

    In a situation where an investigator needs to acquire volatile data from a live Linux system, the physical access to the suspect machine is either restricted or unavailable. Which of the following steps will be the most suitable approach to perform this task?

    A. The investigator should use the Belkasoft Live RAM Capturer on the forensic workstation, then remotely execute the tool on the suspect machine to acquire the RAM image
    B. The investigator should initiate a listening session on the forensic workstation using 'netcat', then execute a 'dd' command on the suspect machine and pipe the output using 'netcat'
    C. The investigator should leverage OSXPMem to remotely parse the physical memory in the Linux machine and create AFF4 format images for analysis
    D. The investigator should employ the LiME tool and 'netcat', starting a listening session using tcp:port on the suspect machine and then establishing a connection from the forensic workstation using 'netcat'

  • Question 890:

    An investigator has been tasked to analyze a suspicious executable file potentially containing malware. She uses a static analysis method to examine the file. Which step below should she NOT include as part of her static malware analysis process?

    A. Running the executable in a sandboxed environment to observe its behavior
    B. Searching for embedded strings in the binary code to infer the functionality
    C. Conducting a file fingerprinting on the binary code to determine its function
    D. Comparing the hash value of the file with online malware databases for recognition

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V10 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.