312-49V9 Exam Details

  • Exam Code
    :312-49V9
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :486 Q&As
  • Last Updated
    :May 26, 2026

EC-COUNCIL 312-49V9 Online Questions & Answers

  • Question 251:

    A(n) _____________________ is one that's performed by a computer program rather than the attacker manually performing the steps in the attack sequence.

    A. blackout attack
    B. automated attack
    C. distributed attack
    D. central processing attack

  • Question 252:

    After undergoing an external IT audit, George realizes his network is vulnerable to DDoS attacks. What countermeasures could he take to prevent DDoS attacks?

    A. Enable BGP
    B. Enable direct broadcasts
    C. Disable BGP
    D. Disable direct broadcasts

  • Question 253:

    What is a good security method to prevent unauthorized users from "tailgating"?

    A. Pick-resistant locks
    B. Electronic key systems
    C. Man trap
    D. Electronic combination locks

  • Question 254:

    SMTP (Simple Mail Transfer protocol) receives outgoing mail from clients and validates source and destination addresses, and also sends and receives emails to and from other SMTP servers.

    A. True
    B. False

  • Question 255:

    What type of equipment would a forensics investigator store in a StrongHold bag?

    A. PDAPDA?
    B. Backup tapes
    C. Hard drives
    D. Wireless cards

  • Question 256:

    What is the slave device connected to the secondary IDE controller on a Linux OS referred to?

    A. hda
    B. hdd
    C. hdb
    D. hdc

  • Question 257:

    Why would you need to find out the gateway of a device when investigating a wireless attack?

    A. The gateway will be the IP of the proxy server used by the attacker to launch the attack
    B. The gateway will be the IP of the attacker computerThe gateway will be the IP of the attacker? computer
    C. The gateway will be the IP used to manage the RADIUS server
    D. The gateway will be the IP used to manage the access point

  • Question 258:

    During first responder procedure you should follow all laws while collecting the evidence, and contact a computer forensic examiner as soon as possible

    A. True
    B. False

  • Question 259:

    Digital evidence validation involves using a hashing algorithm utility to create a binary or hexadecimal number that represents the uniqueness of a data set, such as a disk drive or file. Which of the following hash algorithms produces a message digest that is 128 bits long?

    A. CRC-32
    B. MD5
    C. SHA-1
    D. SHA-512

  • Question 260:

    Law enforcement officers are conducting a legal search for which a valid warrant was obtained. While conducting the search, officers observe an item of evidence for an unrelated crime that was not included in the warrant. The item was clearly visible to the officers and immediately identified as evidence. What is the term used to describe how this evidence is admissible?

    A. Plain view doctrine
    B. Corpus delicti
    C. Locard Exchange Principle
    D. Ex Parte Order

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V9 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.