EC0-349 Exam Details

  • Exam Code
    :EC0-349
  • Exam Name
    :Computer Hacking Forensic Investigator
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :325 Q&As
  • Last Updated
    :May 24, 2026

EC-COUNCIL EC0-349 Online Questions & Answers

  • Question 141:

    You are working in the security Department of law firm. One of the attorneys asks you about the topic of sending fake email because he has a client who has been charged with doing just that. His client alleges that he is innocent and that there is no way for a fake email to actually be sent. You inform the attorney that his client is mistaken and that fake email is possibility and that you can prove it. You return to your desk and craft a fake email to the attorney that appears to come from his boss. What port do you send the email to on the company SMTP server?

    A. 10
    B. 25
    C. 110
    D. 135

  • Question 142:

    Why are Linux/Unix based computers better to use than Windows computers for idle scanning?

    A. Linux/Unix computers are easier to compromise
    B. Linux/Unix computers are constantly talking
    C. Windows computers are constantly talking
    D. Windows computers will not respond to idle scans

  • Question 143:

    James is testing the ability of his routers to withstand DoS attacks. James sends ICMP ECHO requests to the broadcast address of his network. What type of DoS attack is James testing against his network?

    A. Smurf
    B. Trinoo
    C. Fraggle
    D. SYN flood

  • Question 144:

    Which Windows artifact is most likely to contain evidence of recently executed commands and programs?

    A. $LogFile only
    B. Prefetch files and Recent Items (Jump Lists)
    C. Boot sector code
    D. Pagefile only

  • Question 145:

    Law enforcement officers are conducting a legal search for which a valid warrant was obtained.

    While conducting the search, officers observe an item of evidence for an unrelated crime that was not included in the warrant. The item was clearly visible to the officers and immediately identified as evidence. What is the term used to

    describe how this evidence is admissible?

    A. Plain view doctrine
    B. Corpus delicti
    C. Locard Exchange Principle
    D. Ex Parte Order

  • Question 146:

    What operating system would respond to the following command?

    A. Windows 95
    B. FreeBSD
    C. Windows XP
    D. Mac OS X

  • Question 147:

    An "idle" system is also referred to as what?

    A. PC not connected to the Internet
    B. Zombie
    C. PC not being used
    D. Bot

  • Question 148:

    When a file is deleted by Windows Explorer or through the MS-DOS delete command, the operating system inserts _______________ in the first letter position of the filename in the FAT database.

    A. A Capital X
    B. A Blank Space
    C. The Underscore Symbol
    D. The lowercase Greek Letter Sigma (s)

  • Question 149:

    Under which Federal Statutes does FBI investigate for computer crimes involving e-mail scams and mail fraud?

    A. 18 U.S.C. 1029 Possession of Access Devices
    B. 18 U.S.C. 1030 Fraud and related activity in connection with computers
    C. 18 U.S.C. 1343 Fraud by wire, radio or television
    D. 18 U.S.C. 1361 Injury to Government Property
    E. 18 U.S.C. 1362 Government communication systems
    F. 18 U.S.C. 1831 Economic Espionage Act
    G. 18 U.S.C. 1832 Trade Secrets Act

  • Question 150:

    During the course of a corporate investigation, you find that an Employee is committing a crime. Can the Employer file a criminal complaint with Police?

    A. Yes, and all evidence can be turned over to the police
    B. Yes, but only if you turn the evidence over to a federal law enforcement agency
    C. No, because the investigation was conducted without following standard police procedures
    D. No, because the investigation was conducted without warrant

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.