Exam Details

  • Exam Code
    :EC1-349
  • Exam Name
    :Computer Hacking Forensic Investigator Exam
  • Certification
    :CHFI
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :486 Q&As
  • Last Updated
    :May 14, 2024

EC-COUNCIL CHFI EC1-349 Questions & Answers

  • Question 31:

    Which wireless standard has bandwidth up to 54 Mbps and signals in a regulated frequency spectrum around 5 GHz?

    A. 802.11a

    B. 802.11b

    C. 802.11g

    D. 802.11i

  • Question 32:

    According to US federal rules, to present a testimony in a court of law, an expert witness needs to furnish certain information to prove his eligibility. Jason, a qualified computer forensic expert who has started practicing two years back, was denied an expert testimony in a computer crime case by the US Court of Appeals for the Fourth Circuit in Richmond, Virginia. Considering the US federal rules, what could be the most appropriate reason for the court to reject Jason's eligibility as an expert witness?

    A. Jason was unable to furnish documents showing four years of previous experience in the field

    B. Being a computer forensic expert, Jason is not eligible to present testimony in a computer crime case

    C. Jason was unable to furnish documents to prove that he is a computer forensic expert

    D. Jason was not aware of legal issues involved with computer crimes

  • Question 33:

    What is the first step that needs to be carried out to crack the password?

    A. A word list is created using a dictionary generator program or dictionaries

    B. The list of dictionary words is hashed or encrypted

    C. The hashed wordlist is compared against the target hashed password, generally one word at a time

    D. If it matches, that password has been cracked and the password cracker displays the unencrypted version of the password

  • Question 34:

    When the operating system marks cluster as used, but does not allocate them to any file, such clusters are known as ___________.

    A. Lost clusters

    B. Bad clusters

    C. Empty clusters

    D. Unused clusters

  • Question 35:

    Quality of a raster Image is determined by the _________________and the amount of information in each pixel.

    A. Total number of pixels

    B. Image file format

    C. Compression method

    D. Image file size

  • Question 36:

    Smith, an employee of a reputed forensic Investigation firm, has been hired by a private organization to investigate a laptop that is suspected to be involved in hacking of organization DC server. Smith wants to find all the values typed into the Run box in the Start menu. Which of the following registry key Smith will check to find the above information?

    A. UserAssist Key

    B. MountedDevices key

    C. RunMRU key

    D. TypedURLs key

  • Question 37:

    Shortcuts are the files with the extension .Ink that are created and are accessed by the users. These files provide you with information about:

    A. Files or network shares

    B. Running application

    C. Application logs

    D. System logs

  • Question 38:

    When NTFS Is formatted, the format program assigns the __________ sectors to the boot sectors and to the bootstrap code

    A. First 12

    B. First 16

    C. First 22

    D. First 24

  • Question 39:

    What is the goal of forensic science?

    A. To determine the evidential value of the crime scene and related evidence

    B. Mitigate the effects of the information security breach

    C. Save the good will of the investigating organization

    D. It is a disciple to deal with the legal processes

  • Question 40:

    Operating System logs are most beneficial for Identifying or Investigating suspicious activities involving a particular host. Which of the following Operating System logs contains information about operational actions performed by OS components?

    A. Event logs

    B. Audit logs

    C. Firewall logs

    D. IDS logs

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC1-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.