EC0-349 Exam Details

  • Exam Code
    :EC0-349
  • Exam Name
    :Computer Hacking Forensic Investigator
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :325 Q&As
  • Last Updated
    :May 24, 2026

EC-COUNCIL EC0-349 Online Questions & Answers

  • Question 131:

    What TCP/UDP port does the toolkit program netstat use?

    A. Port 7
    B. Port 15
    C. Port 23
    D. Port 69

  • Question 132:

    What is the slave device connected to the secondary IDE controller on a Linux OS referred to?

    A. hda
    B. hdd
    C. hdb
    D. hdc

  • Question 133:

    You are called in to assist the police in an investigation involving a suspected drug dealer. The suspects house was searched by the police after a warrant was obtained and they located a floppy disk in the suspects bedroom. The disk contains several files, but they appear to be password protected. What are two common methods used by password cracking software that you can use to obtain the password?

    A. Limited force and library attack
    B. Brute Force and dictionary Attack
    C. Maximum force and thesaurus Attack
    D. Minimum force and appendix Attack

  • Question 134:

    When investigating a potential e-mail crime, what is your first step in the investigation?

    A. Trace the IP address to its origin
    B. Write a report
    C. Determine whether a crime was actually committed
    D. Recover the evidence

  • Question 135:

    When cataloging digital evidence, the primary goal is to

    A. Make bit-stream images of all hard drives
    B. Preserve evidence integrity
    C. Not remove the evidence from the scene
    D. Not allow the computer to be turned off

  • Question 136:

    A forensics investigator is searching the hard drive of a computer for files that were recently moved to the Recycle Bin. He searches for files in C:\RECYCLED using a command line tool but does not find anything. What is the reason for this?

    A. He should search in C:\Windows\System32\RECYCLED folder
    B. The Recycle Bin does not exist on the hard drive
    C. The files are hidden and he must use switch to view them
    D. Only FAT system contains RECYCLED folder and not NTFS

  • Question 137:

    Office Documents (Word, Excel and PowerPoint) contain a code that allows tracking the MAC or unique identifier of the machine that created the document. What is that code called?

    A. Globally unique ID
    B. Microsoft Virtual Machine Identifier
    C. Personal Application Protocol
    D. Individual ASCII string

  • Question 138:

    An employee is attempting to wipe out data stored on a couple of compact discs (CDs) and digital video discs (DVDs) by using a large magnet. You inform him that this method will not be effective in wiping out the data because CDs and DVDs are ______________ media used to store large amounts of data and are not affected by the magnet.

    A. logical
    B. anti-magnetic
    C. magnetic
    D. optical

  • Question 139:

    What is the name of the Standard Linux Command that is also available as windows application that can be used to create bit-stream images?

    A. mcopy
    B. image
    C. MD5
    D. dd

  • Question 140:

    You are trying to locate Microsoft Outlook Web Access Default Portal using Google search on the Internet. What search string will you use to locate them?

    A. allinurl:"exchange/logon.asp"
    B. intitle:"exchange server"
    C. locate:"logon page"
    D. outlook:"search"

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.