Skip to main content

312-49V8 Real Exam Questions

EC-Council Certified Computer Hacking Forensic Investigator (V8)

180 questions available · Page 1 of 18

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Wireless network discovery tools use two different methodologies to detect, monitor and log a WLAN device (i.e. active scanning and passive scanning). Active scanning methodology involves
____________and waiting for responses from available wireless networks.

  1. A

    Broadcasting a probe request frame

  2. B

    Sniffing the packets from the airwave

  3. C

    Scanning the network

  4. D

    Inspecting WLAN and surrounding networks

Show answer and explanation

Correct answer: A

Question 2 Single choice

Which of the following email headers specifies an address for mailer-generated errors, like "no such user" bounce messages, to go to (instead of the sender's address)?

  1. A

    Errors-To header

  2. B

    Content-Transfer-Encoding header

  3. C

    Mime-Version header

  4. D

    Content-Type header

Show answer and explanation

Correct answer: A

Question 3 Single choice

Smith, as a part his forensic investigation assignment, has seized a mobile device. He was asked to recover the Subscriber Identity Module (SIM card) data the mobile device. Smith found that the SIM was protected by a Personal identification Number (PIN) code but he was also aware that people generally leave the PIN numbers to the defaults or use easily guessable numbers such as 1234. He unsuccessfully tried three PIN numbers that blocked the SIM card.

What Jason can do in this scenario to reset the PIN and access SIM data?

  1. A

    He should contact the device manufacturer for a Temporary Unlock Code (TUK) to gain access to the
    SIM

  2. B

    He cannot access the SIM data in this scenario as the network operators or device manufacturers have no idea about a device PIN

  3. C

    He should again attempt PIN guesses after a time of 24 hours

  4. D

    He should ask the network operator for Personal Unlock Number (PUK) to gain access to the SIM

Show answer and explanation

Correct answer: D

Question 4 Single choice

System software password cracking is defined as cracking the operating system and all other utilities that enable a computer to function

  1. A

    True

  2. B

    False

Show answer and explanation

Correct answer: A

Question 5 Single choice

Windows Security Event Log contains records of login/logout activity or other security-related events specified by the system's audit policy.

What does event ID 531 in Windows Security Event Log indicates?

  1. A

    A user successfully logged on to a computer

  2. B

    The logon attempt was made with an unknown user name or a known user name with a bad password

  3. C

    An attempt was made to log on with the user account outside of the allowed time

  4. D

    A logon attempt was made using a disabled account

Show answer and explanation

Correct answer: D

Question 6 Single choice

The status of the network interface cards (NICs) connected to a system gives information about whether the system is connected to a wireless access point and what IP address is being used.

Which command displays the network configuration of the NICs on the system?

  1. A

    ipconfig /all

  2. B

    netstat

  3. C

    net session

  4. D

    tasklist

Show answer and explanation

Correct answer: A

Question 7 Single choice

The Recycle Bin is located on the Windows desktop. When you delete an item from the hard disk, Windows sends that deleted item to the Recycle Bin and the icon changes to full from empty, but items deleted from removable media, such as a floppy disk or network drive, are not stored in the Recycle Bin.

What is the size limit for Recycle Bin in Vista and later versions of the Windows?

  1. A

    No size limit

  2. B

    Maximum of 3.99 GB

  3. C

    Maximum of 4.99 GB

  4. D

    Maximum of 5.99 GB

Show answer and explanation

Correct answer: A

Question 8 Single choice

Which one of the following is not a consideration in a forensic readiness planning checklist?

  1. A

    Define the business states that need digital evidence

  2. B

    Identify the potential evidence available

  3. C

    Decide the procedure for securely collecting the evidence that meets the requirement fn a forensically sound manner

  4. D

    Take permission from all employees of the organization

Show answer and explanation

Correct answer: D

Question 9 Single choice

Which of the following is not an example of a cyber-crime?

  1. A

    Fraud achieved by the manipulation of the computer records

  2. B

    Firing an employee for misconduct

  3. C

    Deliberate circumvention of the computer security systems

  4. D

    Intellectual property theft, including software piracy

Show answer and explanation

Correct answer: B

Question 10 Single choice

What is cold boot (hard boot)?

  1. A

    It is the process of starting a computer from a powered-down or off state

  2. B

    It is the process of restarting a computer that is already turned on through the operating system

  3. C

    It is the process of shutting down a computer from a powered-on or on state

  4. D

    It is the process of restarting a computer that is already in sleep mode

Show answer and explanation

Correct answer: A