312-49V9 Exam Details

  • Exam Code
    :312-49V9
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :486 Q&As
  • Last Updated
    :May 26, 2026

EC-COUNCIL 312-49V9 Online Questions & Answers

  • Question 291:

    When investigating a potential e-mail crime, what is your first step in the investigation?

    A. Trace the IP address to its origin
    B. Write a report
    C. Determine whether a crime was actually committed
    D. Recover the evidence

  • Question 292:

    George is a senior security analyst working for a state agency in Florida. His state's congress just passed a bill mandating every state agency to undergo a security audit annually. After learning what will be required, George needs to implement an IDS as soon as possible before the first audit occurs. The state bill requires that an IDS with a "time- based induction machine" be used. What IDS feature must George implement to meet this requirement?

    A. Pattern matching
    B. Statistical-based anomaly detection
    C. Real-time anomaly detection
    D. Signature-based anomaly detection

  • Question 293:

    What is a first sector ("sector zero") of a hard disk?

    A. Master boot record
    B. System boot record
    C. Secondary boot record
    D. Hard disk boot record

  • Question 294:

    What binary coding is used most often for e-mail purposes?

    A. SMTP
    B. Uuencode
    C. IMAP
    D. MIME

  • Question 295:

    JPEG is a commonly used method of compressing photographic Images. It uses a compression algorithm to minimize the size of the natural image, without affecting the quality of the image. The JPEG lossy algorithm divides the image in separate blocks of____________.

    A. 4x4 pixels
    B. 8x8 pixels
    C. 16x16 pixels
    D. 32x32 pixels

  • Question 296:

    You are working on a thesis for your doctorate degree in Computer Science. Your thesis is based on HTML, DHTML, and other web-based languages and how they have evolved over the years. You navigate to archive. org and view the HTML code of news.com. You then navigate to the current news.com website and copy over the source code. While searching through the code, you come across something abnormal: What have you found?

    A. Web bug
    B. CGI code
    C. Trojan.downloader
    D. Blind bug

  • Question 297:

    Which of the following steganography types hides the secret message in a specifically designed pattern on the document that is unclear to the average reader?

    A. Open code steganography
    B. Visual semagrams steganography
    C. Text semagrams steganography
    D. Technical steganography

  • Question 298:

    What is considered a grant of a property right given to an individual who discovers or invents a new machine, process, useful composition of matter or manufacture?

    A. Copyright
    B. Design patent
    C. Trademark
    D. Utility patent

  • Question 299:

    You are the network administrator for a small bank in Dallas, Texas. To ensure network security, you enact a security policy that requires all users to have 14 character passwords. After giving your users 2 weeks notice, you change the

    Group Policy to force 14 character passwords. A week later you dump the SAM database from the standalone server and run a password-cracking tool against it. Over 99% of the passwords are broken within an hour.

    Why were these passwords cracked so Quickly?

    A. Passwords of 14 characters or less are broken up into two 7-character hashes
    B. A password Group Policy change takes at least 3 weeks to completely replicate throughout a network
    C. Networks using Active Directory never use SAM databases so the SAM database pulled was empty
    D. The passwords that were cracked are local accounts on the Domain Controller

  • Question 300:

    While working for a prosecutor, What do you think you should do if the evidence you found appears to be exculpatory and is not being released to the defense ?

    A. Keep the information of file for later review
    B. Destroy the evidence
    C. Bring the information to the attention of the prosecutor, his or her supervisor or finally to the judge
    D. Present the evidence to the defense attorney

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V9 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.