Skip to main content

EC0-349 Real Exam Questions

Computer Hacking Forensic Investigator

325 questions available · Page 1 of 33

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

The newer Macintosh Operating System is based on:

  1. A

    OS/2

  2. B

    BSD Unix

  3. C

    Linux

  4. D

    Microsoft Windows

Show answer and explanation

Correct answer: B

Question 2 Single choice

You are the security analyst working for a private company out of France. Your current assignment is to obtain credit card information from a Swiss bank owned by that company. After initial reconnaissance, you discover that the bank security defenses are very strong and would take too long to penetrate. You decide to get the information by monitoring the traffic between the bank and one of its subsidiaries in London.
After monitoring some of the traffic, you see a lot of FTP packets traveling back and forth. You want to sniff the traffic and extract usernames and passwords.

What tool could you use to get this information?

  1. A

    Airsnort

  2. B

    Snort

  3. C

    Ettercap

  4. D

    RaidSniff

Show answer and explanation

Correct answer: C

Question 3 Single choice

When a file is deleted by Windows Explorer or through the MS-DOS delete command, the operating system inserts _______________ in the first letter position of the filename in the FAT database.

  1. A

    A Capital X

  2. B

    A Blank Space

  3. C

    The Underscore Symbol

  4. D

    The lowercase Greek Letter Sigma (s)

Show answer and explanation

Correct answer: D

Question 4 Single choice

You are called by an author who is writing a book and he wants to know how long the copyright for his book will last after he has the book published?

  1. A

    70 years

  2. B

    the life of the author

  3. C

    the life of the author plus 70 years

  4. D

    copyrights last forever

Show answer and explanation

Correct answer: C

Question 5 Single choice

You work as an IT security auditor hired by a law firm in Boston to test whether you can gain access to sensitive information about the company clients. You have rummaged through their trash and found very little information. You do not want to set off any alarms on their network, so you plan on performing passive foot printing against their Web servers.

What tool should you use?

  1. A

    Ping sweep

  2. B

    Nmap

  3. C

    Netcraft

  4. D

    Dig

Show answer and explanation

Correct answer: C

Question 6 Single choice

Harold is a computer forensics investigator working for a consulting firm out of Atlanta Georgia. Harold is called upon to help with a corporate espionage case in Miami Florida. Harold assists in the investigation by pulling all the data from the computers allegedly used in the illegal activities. He finds that two suspects in the company where stealing sensitive corporate information and selling it to competing companies. From the email and instant messenger logs recovered, Harold has discovered that the two employees notified the buyers by writing symbols on the back of specific stop signs. This way, the buyers knew when and where to meet with the alleged suspects to buy the stolen material.

What type of steganography did these two suspects use?

  1. A

    Text semagram

  2. B

    Visual semagram

  3. C

    Grill cipher

  4. D

    Visual cipher

Show answer and explanation

Correct answer: B

Question 7 Single choice

When examining a hard disk without a write-blocker, you should not start windows because Windows will write data to the:

  1. A

    Recycle Bin

  2. B

    MSDOS.sys

  3. C

    BIOS

  4. D

    Case files

Show answer and explanation

Correct answer: A

Question 8 Single choice

You are running known exploits against your network to test for possible vulnerabilities. To test the strength of your virus software, you load a test network to mimic your production network. Your software successfully blocks some simple macro and encrypted viruses. You decide to really test the software by using virus code where the code rewrites itself entirely and the signatures change from child to child, but the functionality stays the same.

What type of virus is this that you are testing?

  1. A

    Polymorphic

  2. B

    Metamorphic

  3. C

    Oligomorhic

  4. D

    Transmorphic

Show answer and explanation

Correct answer: B

Question 9 Single choice

Corporate investigations are typically easier than public investigations because:

  1. A

    the users have standard corporate equipment and software

  2. B

    the investigator does not have to get a warrant

  3. C

    the investigator has to get a warrant

  4. D

    the users can load whatever they want on their machines

Show answer and explanation

Correct answer: B

Question 10 Single choice

What is a good security method to prevent unauthorized users from "tailgating"?

  1. A

    Man trap

  2. B

    Electronic combination locks

  3. C

    Pick-resistant locks

  4. D

    Electronic key systems

Show answer and explanation

Correct answer: A