EC0-349 Exam Details

  • Exam Code
    :EC0-349
  • Exam Name
    :Computer Hacking Forensic Investigator
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :325 Q&As
  • Last Updated
    :May 24, 2026

EC-COUNCIL EC0-349 Online Questions & Answers

  • Question 191:

    What does mactime, an essential part of the coroner's toolkit do?

    A. It traverses the file system and produces a listing of all files based on the modification, access and change timestamps
    B. It can recover deleted file space and search it for data. However, it does not allow the investigator to preview them
    C. The tools scans for i-node information, which is used by other tools in the tool kit
    D. It is too specific to the MAC OS and forms a core component of the toolkit

  • Question 192:

    This organization maintains a database of hash signatures for known software.

    A. International Standards Organization
    B. Institute of Electrical and Electronics Engineers
    C. National Software Reference Library
    D. American National standards Institute

  • Question 193:

    Where is the default location for Apache access logs on a Linux computer?

    A. usr/local/apache/logs/access_log
    B. bin/local/home/apache/logs/access_log
    C. usr/logs/access_log
    D. logs/usr/apache/access_log

  • Question 194:

    Harold wants to set up a firewall on his network but is not sure which one would be the most appropriate. He knows he needs to allow FTP traffic to one of the servers on his network, but he wants to only allow FTP-PUT. Which firewall would be most appropriate for Harold? needs?

    A. Circuit-level proxy firewall
    B. Packet filtering firewall
    C. Application-level proxy firewall
    D. Data link layer firewall

  • Question 195:

    One technique for hiding information is to change the file extension from the correct one to one that might not be noticed by an investigator. For example, changing a .jpg extension to a .doc extension so that a picture file appears to be a document. What can an investigator examine to verify that a file has the correct extension?

    A. the File Allocation Table
    B. the file header
    C. the file footer
    D. the sector map

  • Question 196:

    John is working as a computer forensics investigator for a consulting firm in Canada. He is called to seize a computer at a local web caf purportedly used as a botnet server. John thoroughly scans the computer and finds nothing that would lead him to think the computer was a botnet server. John decides to scan the virtual memory of the computer to possibly find something he had missed. What information will the virtual memory scan produce?

    A. It contains the times and dates of when the system was last patched
    B. It is not necessary to scan the virtual memory of a computer
    C. It contains the times and dates of all the system files
    D. Hidden running processes

  • Question 197:

    To make sure the evidence you recover and analyze with computer forensics software can be admitted in court, you must test and validate the software. What group is actively providing tools and creating procedures for testing and validating computer forensics software?

    A. Computer Forensics Tools and Validation Committee (CFTVC)
    B. Association of Computer Forensics Software Manufactures (ACFSM)
    C. National Institute of Standards and Technology (NIST)
    D. Society for Valid Forensics Tools and Testing (SVFTT)

  • Question 198:

    An Expert witness give an opinion if:

    A. The Opinion, inferences or conclusions depend on special knowledge, skill or training not within the ordinary experience of lay jurors
    B. To define the issues of the case for determination by the finder of fact
    C. To stimulate discussion between the consulting expert and the expert witness
    D. To deter the witness form expanding the scope of his or her investigation beyond the requirements of the case

  • Question 199:

    While searching through a computer under investigation, you discover numerous files that appear to have had the first letter of the file name replaced by the hex code byte 5h. What does this indicate on the computer?

    A. The files have been marked as hidden
    B. The files have been marked for deletion
    C. The files are corrupt and cannot be recovered
    D. The files have been marked as read-only

  • Question 200:

    Steven has been given the task of designing a computer forensics lab for the company he works for. He has found documentation on all aspects of how to design a lab except the number of exits needed. How many exits should Steven include in his design for the computer forensics lab?

    A. Three
    B. One
    C. Two
    D. Four

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.