EC0-349 Exam Details

  • Exam Code
    :EC0-349
  • Exam Name
    :Computer Hacking Forensic Investigator
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :325 Q&As
  • Last Updated
    :May 24, 2026

EC-COUNCIL EC0-349 Online Questions & Answers

  • Question 101:

    What stage of the incident handling process involves reporting events?

    A. Containment
    B. Follow-up
    C. Identification
    D. Recovery

  • Question 102:

    Meyer Electronics Systems just recently had a number of laptops stolen out of their office. On these laptops contained sensitive corporate information regarding patents and company strategies. A month after the laptops were stolen, a competing company was found to have just developed products that almost exactly duplicated products that Meyer produces. What could have prevented this information from being stolen from the laptops?

    A. EFS Encryption
    B. DFS Encryption
    C. IPS Encryption
    D. SDW Encryption

  • Question 103:

    During a network compromise, the attacker established a reverse shell by downloading netcat and starting a listener on the server. Which log artifact would most likely show the attacker's initial download activity?

    A. DNS server query log
    B. Web server access log showing GET of nc.exe
    C. DHCP assignment log
    D. SMTP mailqueue log

  • Question 104:

    E-mail logs contain which of the following information to help you in your investigation? (Choose four.)

    A. user account that was used to send the account
    B. attachments sent with the e-mail message
    C. unique message identifier
    D. contents of the e-mail message
    E. date and time the message was sent

  • Question 105:

    When an investigator contacts by telephone the domain administrator or controller listed by a Who is lookup to request all e-mails sent and received for a user account be preserved, what U.S.C. statute authorizes this phone call and obligates the ISP to preserve e-mail records?

    A. Title 18, Section 1030
    B. Title 18, Section 2703(d)
    C. Title 18, Section Chapter 90
    D. Title 18, Section 2703(f)

  • Question 106:

    When operating systems mark a cluster as used but not allocated, the cluster is considered as _________

    A. Corrupt
    B. Bad
    C. Lost
    D. Unallocated

  • Question 107:

    Jacob is a computer forensics investigator with over 10 years experience in investigations and has written over 50 articles on computer forensics. He has been called upon as a qualified witness to testify the accuracy and integrity of the technical log files gathered in an investigation into computer fraud. What is the term used for Jacob testimony in this case?

    A. Justification
    B. Authentication
    C. Reiteration
    D. Certification

  • Question 108:

    When obtaining a warrant, it is important to:

    A. particularlydescribe the place to be searched and particularly describe the items to be seized
    B. generallydescribe the place to be searched and particularly describe the items to be seized
    C. generallydescribe the place to be searched and generally describe the items to be seized
    D. particularlydescribe the place to be searched and generally describe the items to be seized

  • Question 109:

    Jim performed a vulnerability analysis on his network and found no potential problems. He runs another utility that executes exploits against his system to verify the results of the vulnerability test. The second utility executes five known exploits against his network in which the vulnerability analysis said were not exploitable. What kind of results did Jim receive from his vulnerability analysis?

    A. False negatives
    B. False positives
    C. True negatives
    D. True positives

  • Question 110:

    During the course of an investigation, you locate evidence that may prove the innocence of the suspect of the investigation. You must maintain an unbiased opinion and be objective in your entire fact finding process. Therefore, you report this evidence. This type of evidence is known as:

    A. Inculpatory evidence
    B. Mandatory evidence
    C. Exculpatory evidence
    D. Terrible evidence

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.