312-49V9 Exam Details

  • Exam Code
    :312-49V9
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :486 Q&As
  • Last Updated
    :May 26, 2026

EC-COUNCIL 312-49V9 Online Questions & Answers

  • Question 171:

    Task list command displays a list of applications and services with their Process ID (PID) for all tasks running on either a local or a remote computer.

    Which of the following task list commands provides information about the listed processes, including the image name, PID, name, and number of the session for the process?

    A. tasklist/s
    B. tasklist/u
    C. tasklist/p
    D. tasklist/V

  • Question 172:

    File deletion is a way of removing a file from a computer's file system. What happens when a file is deleted in windows7?

    A. The last letter of a file name is replaced by a hex byte code E5h
    B. The operating system marks the file's name in the MFT with a special character that indicates that the file has been deleted
    C. Corresponding clusters in FAT are marked as used
    D. The computer looks at the clusters occupied by that file and does not avails space to store a new file

  • Question 173:

    Where is the startup configuration located on a router?

    A. Static RAM
    B. BootROM
    C. NVRAM
    D. Dynamic RAM

  • Question 174:

    Where does Encase search to recover NTFS files and folders?

    A. MBR
    B. MFT
    C. Slack space
    D. HAL

  • Question 175:

    Frank is working on a vulnerability assessment for a company on the West coast. The company hired Frank to assess its network security through scanning, pen tests, and vulnerability assessments. After discovering numerous known vulnerabilities detected by a temporary IDS he set up, he notices a number of items that show up as unknown but Questionable in the logs. He looks up the behavior on the Internet, but cannot find anything related. What organization should Frank submit the log to find out if it is a new vulnerability or not?

    A. CVE
    B. IANA
    C. RIPE
    D. APIPA

  • Question 176:

    In which step of the computer forensics investigation methodology would you run MD5 checksum on the evidence?

    A. Obtain search warrant
    B. Evaluate and secure the scene
    C. Collect the evidence
    D. Acquire the data

  • Question 177:

    What header field in the TCP/IP protocol stack involves the hacker exploit known as the Ping of Death?

    A. ICMP header field
    B. TCP header field
    C. IP header field
    D. UDP header field

  • Question 178:

    When dealing with the powered-off computers at the crime scene, if the computer is switched off, turn it on

    A. True
    B. False

  • Question 179:

    Harold wants to set up a firewall on his network but is not sure which one would be the most appropriate. He knows he needs to allow FTP traffic to one of the servers on his network, but he wants to only allow FTP-PUT. Which firewall would be most appropriate for Harold? needs?

    A. Packet filtering firewall
    B. Circuit-level proxy firewall
    C. Application-level proxy firewall
    D. Data link layer firewall

  • Question 180:

    You are trying to locate Microsoft Outlook Web Access Default Portal using Google search on the Internet. What search string will you use to locate them?

    A. allinurl:"exchange/logon.asp"
    B. intitle:"exchange server"
    C. outlook:"search"
    D. locate:"logon page"

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V9 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.