312-49V9 Exam Details

  • Exam Code
    :312-49V9
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :486 Q&As
  • Last Updated
    :May 26, 2026

EC-COUNCIL 312-49V9 Online Questions & Answers

  • Question 281:

    At the time of evidence transfer, both sender and receiver need to give the information about date and time of transfer in the chain of custody record.

    A. True
    B. False

  • Question 282:

    Which federal computer crime law specifically refers to fraud and related activity in connection with access devices like routers?

    A. 18 U.S.C. 1029
    B. 18 U.S.C. 1362
    C. 18 U.S.C. 2511
    D. 18 U.S.C. 2703

  • Question 283:

    What will the following command accomplish in Linux? fdisk /dev/hda

    A. Partition the hard drive
    B. Format the hard drive
    C. Delete all files under the /dev/hda folder
    D. Fill the disk with zeros

  • Question 284:

    From the following spam mail header, identify the host IP that sent this spam?

    From [email protected] [email protected] Tue Nov 27 17:27:11 2001

    Received: from viruswall.ie.cuhk.edu.hk (viruswall [137.189.96.52]) by eng.ie.cuhk.edu.hk (8.11.6/8.11.6) with ESMTP id

    fAR9RAP23061 for ; Tue, 27 Nov 2001 17:27:10 +0800 (HKT)

    Received: from mydomain.com (pcd249020.netvigator.com [203.218.39.20]) by viruswall.ie.cuhk.edu.hk (8.12.1/8.12.1)

    with SMTP id fAR9QXwZ018431 for ; Tue, 27 Nov 2001 17:26:36 +0800 (HKT)

    Message-Id: >[email protected]

    From: "china hotel web"

    To: "Shlam"

    Subject: SHANGHAI (HILTON HOTEL) PACKAGE

    Date: Tue, 27 Nov 2001 17:25:58 +0800 MIME-Version: 1.0

    X-Priority: 3 X-MSMail-

    Priority: Normal

    Reply-To: "china hotel web"

    A. 137.189.96.52
    B. 8.12.1.0
    C. 203.218.39.20
    D. 203.218.39.50

  • Question 285:

    Daryl, a computer forensics investigator, has just arrived at the house of an alleged computer hacker. Daryl takes pictures and tags all computer and peripheral equipment found in the house. Daryl packs all the items found in his van and takes them back to his lab for further examination. At his lab, Michael his assistant helps him with the investigation. Since Michael is still in training, Daryl supervises all of his work very carefully. Michael is not quite sure about the procedures to copy all the data off the computer and peripheral devices. How many data acquisition tools should Michael use when creating copies of the evidence for the investigation?

    A. Two
    B. One
    C. Three
    D. Four

  • Question 286:

    When needing to search for a website that is no longer present on the Internet today but was online few years back, what site can be used to view the website collection of pages?view the website? collection of pages?

    A. Proxify.net
    B. Dnsstuff.com
    C. Samspade.org
    D. Archive.org

  • Question 287:

    What are the security risks of running a "repair" installation for Windows XP?

    A. Pressing Shift+F1 gives the user administrative rights
    B. Pressing Ctrl+F10 gives the user administrative rights
    C. There are no security risks when running the "repair" installation for Windows XP
    D. Pressing Shift+F10 gives the user administrative rights

  • Question 288:

    When investigating a wireless attack, what information can be obtained from the DHCP logs?

    A. The operating system of the attacker and victim computersThe operating system of the attacker and victim? computers
    B. IP traffic between the attacker and the victim
    C. MAC address of the attacker If any computers on the network are running in promiscuous mode

  • Question 289:

    You are the security analyst working for a private company out of France. Your current assignment is to obtain credit card information from a Swiss bank owned by that company. After initial reconnaissance, you discover that the bank security defenses are very strong and would take too long to penetrate. You decide to get the information by monitoring the traffic between the bank and one of its subsidiaries in London. After monitoring some of the traffic, you see a lot of FTP packets traveling back and forth. You want to sniff the traffic and extract usernames and passwords. What tool could you use to get this information?

    A. Snort
    B. Airsnort
    C. Ettercap
    D. RaidSniff

  • Question 290:

    A swap file is a space on a hard disk used as the virtual memory extension of a computer's RAM. Where is the hidden swap file in Windows located?

    A. C:\pagefile.sys
    B. C:\hiberfil.sys
    C. C:\config.sys
    D. C:\ALCSetup.log

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V9 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.