EC0-349 Exam Details

  • Exam Code
    :EC0-349
  • Exam Name
    :Computer Hacking Forensic Investigator
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :325 Q&As
  • Last Updated
    :May 24, 2026

EC-COUNCIL EC0-349 Online Questions & Answers

  • Question 111:

    You are working as Computer Forensics investigator and are called by the owner of an accounting firm to investigate possible computer abuse by one of the firm's employees. You meet with the owner of the firm and discover that the company has never published a policy stating that they reserve the right to inspect their computing assets at will. What do you do?

    A. Inform the owner that conducting an investigation without a policy is not a problem because the company is privately owned
    B. Inform the owner that conducting an investigation without a policy is a violation of the 4th amendment
    C. Inform the owner that conducting an investigation without a policy is a violation of the employee's expectation of privacy
    D. Inform the owner that conducting an investigation without a policy is not a problem because a policy is only necessary for government agencies

  • Question 112:

    What file is processed at the end of a Windows XP boot to initialize the logon dialog box?

    A. NTOSKRNL.EXE
    B. NTLDR
    C. LSASS.EXE
    D. NTDETECT.COM

  • Question 113:

    A law enforcement officer may only search for and seize criminal evidence with _______________________, which are facts or circumstances that would lead a reasonable person to believe a crime has been committed or is about to be committed, evidence of the specific crime exists and the evidence of the specific crime exists at the place to be searched.

    A. Mere Suspicion
    B. A preponderance of the evidence
    C. Probable cause
    D. Beyond a reasonable doubt

  • Question 114:

    You are employed directly by an attorney to help investigate an alleged sexual harassment case at a large pharmaceutical manufacture. While at the corporate office of the company, the CEO demands to know the status of the investigation. What prevents you from discussing the case with the CEO?

    A. the attorney-work-product rule
    B. Good manners
    C. Trade secrets
    D. ISO 17799

  • Question 115:

    What is kept in the following directory? HKLM\SECURITY\Policy\Secrets

    A. Cached password hashes for the past 20 users
    B. Service account passwords in plain text
    C. IAS account names and passwords
    D. Local store PKI Kerberos certificates

  • Question 116:

    Travis, a computer forensics investigator, is finishing up a case he has been working on for over a month involving copyright infringement and embezzlement. His last task is to prepare an investigative report for the president of the company he has been working for. Travis must submit a hard copy and an electronic copy to this president. In what electronic format should Travis send this report?

    A. TIFF-8
    B. DOC
    C. WPD
    D. PDF

  • Question 117:

    What should you do when approached by a reporter about a case that you are working on or have worked on?

    A. Refer the reporter to the attorney that retained you
    B. Say, "no comment"
    C. Answer all the reporter's questions as completely as possible
    D. Answer only the questions that help your case

  • Question 118:

    Julia is a senior security analyst for Berber Consulting group. She is currently working on a contract for a small accounting firm in Florid a. They have given her permission to perform social engineering attacks on the company to see if their in-house training did any good. Julia calls the main number for the accounting firm and talks to the receptionist. Julia says that she is an IT technician from the company's main office in Iowa. She states that she needs the receptionist's network username and password to troubleshoot a problem they are having. Julia says that Bill Hammond, the CEO of the company, requested this information. After hearing the name of the CEO, the receptionist gave Julia all the information she asked for. What principal of social engineering did Julia use?

    A. Social Validation
    B. Scarcity
    C. Friendship/Liking
    D. Reciprocation

  • Question 119:

    You are carrying out the last round of testing for your new website before it goes live. The website has many dynamic pages and connects to a SQL backend that accesses your product inventory in a database. You come across a web security site that recommends inputting the following code into a search field on web pages to check for vulnerabilities: When you type this and click on search, you receive a pop-up window that says: "This is a test."

    What is the result of this test?

    A. Your website is vulnerable to CSS
    B. Your website is not vulnerable
    C. Your website is vulnerable to SQL injection
    D. Your website is vulnerable to web bugs

  • Question 120:

    You are working on a thesis for your doctorate degree in Computer Science. Your thesis is based on HTML, DHTML, and other web-based languages and how they have evolved over the years. You navigate to archive. org and view the HTML code of news.com. You then navigate to the current news.com website and copy over the source code. While searching through the code, you come across something abnormal: What have you found?

    A. Web bug
    B. CGI code
    C. Trojan.downloader
    D. Blind bug

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.