312-49V9 Exam Details

  • Exam Code
    :312-49V9
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :486 Q&As
  • Last Updated
    :May 26, 2026

EC-COUNCIL 312-49V9 Online Questions & Answers

  • Question 361:

    You are contracted to work as a computer forensics investigator for a regional bank that has four 30 TB storage area networks that store customer data. What method would be most efficient for you to acquire digital evidence from this network?

    A. Make a bit-stream disk-to-disk file
    B. Make a bit-stream disk-to-image file
    C. Create a sparse data copy of a folder or file
    D. Create a compressed copy of the file with DoubleSpace

  • Question 362:

    To check for POP3 traffic using Ethereal, what port should an investigator search by?

    A. 143
    B. 25
    C. 110
    D. 125

  • Question 363:

    When obtaining a warrant it is important to:

    A. particularly describe the place to be searched and particularly describe the items to be seized
    B. generally describe the place to be searched and particularly describe the items to be seized
    C. generally describe the place to be searched and generally describe the items to be seized
    D. particularly describe the place to be searched and generally describe the items to be seized

  • Question 364:

    Which one of the following statements is not correct while preparing for testimony?

    A. Go through the documentation thoroughly
    B. Do not determine the basic facts of the case before beginning and examining the evidence
    C. Establish early communication with the attorney
    D. Substantiate the findings with documentation and by collaborating with other computer forensics professionals

  • Question 365:

    Attacker uses vulnerabilities in the authentication or session management functions such as exposed accounts, session IDs, logout, password management, timeouts, remember me. secret question, account update etc. to impersonate users, if a user simply closes the browser without logging out from sites accessed through a public computer, attacker can use the same browser later and exploit the user's privileges. Which of the following vulnerability/exploitation is referred above?

    A. Session ID in URLs
    B. Timeout Exploitation
    C. I/O exploitation
    D. Password Exploitation

  • Question 366:

    Hash injection attack allows attackers to inject a compromised hash into a local session and use the hash to validate network resources.

    A. True
    B. False

  • Question 367:

    An "idle" system is also referred to as what?

    A. PC not connected to the Internet
    B. PC not being used
    C. Zombie
    D. Bot

  • Question 368:

    You have used a newly released forensic investigation tool, which doesn't meet the Daubert Test, during a case. The case has ended-up in court. What argument could the defense make to weaken your case?

    A. The tool hasn't been tested by the International Standards Organization (ISO)
    B. Only the local law enforcement should use the tool
    C. The total has not been reviewed and accepted by your peers
    D. You are not certified for using the tool

  • Question 369:

    An intrusion detection system (IDS) gathers and analyzes information from within a computer or a network to identify any possible violations of security policy, including unauthorized access, as well as misuse. Which of the following intrusion detection systems audit events that occur on a specific host?

    A. Network-based intrusion detection
    B. Host-based intrusion detection
    C. Log file monitoring
    D. File integrity checking

  • Question 370:

    John is working as a computer forensics investigator for a consulting firm in Canada. He is called to seize a computer at a local web caf?John is working as a computer forensics investigator for a consulting firm in Canada. He is called to seize a computer at a local web caf purportedly used as a botnet server. John thoroughly scans the computer and finds nothing that would lead him to think the computer was a botnet server. John decides to scan the virtual memory of the computer to possibly find something he had missed. What information will the virtual memory scan produce?

    A. It contains the times and dates of when the system was last patched
    B. It is not necessary to scan the virtual memory of a computer
    C. It contains the times and dates of all the system files
    D. Hidden running processes

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V9 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.