312-49V9 Exam Details

  • Exam Code
    :312-49V9
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :486 Q&As
  • Last Updated
    :May 26, 2026

EC-COUNCIL 312-49V9 Online Questions & Answers

  • Question 111:

    Which of the following commands shows you all of the network services running on Windows-based servers?

    A. Net start
    B. Net use
    C. Net Session
    D. Net share

  • Question 112:

    Larry is an IT consultant who works for corporations and government agencies. Larry plans on shutting down the city's network using BGP devices and zombies? What type of Penetration Testing is Larry planning to carry out?

    A. Router Penetration Testing
    B. DoS Penetration Testing
    C. Internal Penetration Testing
    D. Firewall Penetration Testing

  • Question 113:

    Why is it a good idea to perform a penetration test from the inside?

    A. It is never a good idea to perform a penetration test from the inside
    B. It is easier to hack from the inside
    C. Because 70% of attacks are from inside the organization
    D. To attack a network from a hacker's perspective

  • Question 114:

    You are running known exploits against your network to test for possible vulnerabilities. To test the strength of your virus software, you load a test network to mimic your production network. Your software successfully blocks some simple macro and encrypted viruses. You decide to really test the software by using virus code where the code rewrites itself entirely and the signatures change from child to child, but the functionality stays the same. What type of virus is this that you are testing?

    A. Oligomorhic
    B. Transmorphic
    C. Polymorphic
    D. Metamorphic

  • Question 115:

    Diskcopy is: A. a utility by AccessData

    B. a standard MS-DOS command
    C. Digital Intelligence utility
    D. dd copying tool

  • Question 116:

    An on-site incident response team is called to investigate an alleged case of computer tampering within their company. Before proceeding with the investigation, the CEO informs them that the incident will be classified as ow level? How long will the team have to respond to the incident?the investigation, the CEO informs them that the incident will be classified as ?ow level? How long will the team have to respond to the incident?

    A. One working day
    B. Two working days
    C. Immediately
    D. Four hours

  • Question 117:

    One technique for hiding information is to change the file extension from the correct one to one that might not be noticed by an investigator. For example, changing a .jpg extension to a .doc extension so that a picture file appears to be a document. What can an investigator examine to verify that a file has the correct extension?

    A. the File Allocation Table
    B. the file header
    C. the file footer
    D. the sector map

  • Question 118:

    Which of the following statements is incorrect when preserving digital evidence?

    A. Document the actions and changes that you observe in the monitor, computer, printer, or in other peripherals
    B. Verily if the monitor is in on, off, or in sleep mode
    C. Remove the power cable depending on the power state of the computer i.e., in on. off, or in sleep mode
    D. Turn on the computer and extract Windows event viewer log files

  • Question 119:

    Recovery of the deleted partition is the process by which the investigator evaluates and extracts the deleted partitions.

    A. True
    B. False

  • Question 120:

    Terri works for a security consulting firm that is currently performing a penetration test on First National Bank in Tokyo. Terri's duties include bypassing firewalls and switches to gain access to the network. Terri sends an IP packet to one of the company's switches with ACK bit and the source address of her machine set. What is Terri trying to accomplish by sending this IP packet?

    A. Poison the switch's MAC address table by flooding it with ACK bits
    B. Crash the switch with aDoS attack since switches cannot send ACK bits
    C. Enable tunneling feature on the switch
    D. Trick the switch into thinking it already has a session with Terri's computer

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V9 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.