312-49V9 Exam Details

  • Exam Code
    :312-49V9
  • Exam Name
    :EC-Council Certified Computer Hacking Forensic Investigator (V9)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :486 Q&As
  • Last Updated
    :May 26, 2026

EC-COUNCIL 312-49V9 Online Questions & Answers

  • Question 391:

    You have compromised a lower-level administrator account on an Active Directory network of a small company in Dallas, Texas. You discover Domain Controllers through enumeration. You connect to one of the Domain Controllers on port

    389 using ldp.exe.

    What are you trying to accomplish here?

    A. Enumerate domain user accounts and built-in groups
    B. Enumerate MX and A records from DNS
    C. Establish a remote connection to the Domain Controller
    D. Poison the DNS records with false records

  • Question 392:

    You should always work with original evidence

    A. True
    B. False

  • Question 393:

    Volatile information can be easily modified or lost when the system is shut down or rebooted. It helps to determine a logical timeline of the security incident and the users who would be responsible.

    A. True
    B. False

  • Question 394:

    During the seizure of digital evidence, the suspect can be allowed touch the computer system.

    A. True
    B. False

  • Question 395:

    Your company's network just finished going through a SAS 70 audit. This audit reported that overall, your network is secure, but there are some areas that needs improvement. The major area was SNMP security. The audit company recommended turning off SNMP, but that is not an option since you have so many remote nodes to keep track of. What step could you take to help secure SNMP on your network?

    A. Block access to TCP port 171
    B. Change the default community string names
    C. Block all internal MAC address from using SNMP
    D. Block access to UDP port 171

  • Question 396:

    An investigator is searching through the firewall logs of a company and notices ICMP packets that are larger than 65,536 bytes. What type of activity is the investigator seeing?

    A. Smurf
    B. Ping of death
    C. Fraggle
    D. Nmap scan

  • Question 397:

    You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers. What type of firewall must you implement to abide by this policy?

    A. Packet filtering firewall
    B. Application-level proxy firewall
    C. Statefull firewall
    D. Circuit-level proxy firewall

  • Question 398:

    In a computer forensics investigation, what describes the route that evidence takes from the time you find it until the case is closed or goes to court?

    A. Policy of separation
    B. Chain of custody
    C. Rules of evidence
    D. Law of probability

  • Question 399:

    The following is a log file screenshot from a default installation of IIS 6.0.

    What time standard is used by IIS as seen in the screenshot?

    A. UTC
    B. GMT
    C. TAI
    D. UT

  • Question 400:

    When you are running a vulnerability scan on a network and the IDS cuts off your connection, what type of IDS is being used?

    A. Passive IDS
    B. Active IDS
    C. NIPS
    D. Progressive IDS

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-49V9 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.