EC0-349 Exam Details

  • Exam Code
    :EC0-349
  • Exam Name
    :Computer Hacking Forensic Investigator
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :325 Q&As
  • Last Updated
    :May 24, 2026

EC-COUNCIL EC0-349 Online Questions & Answers

  • Question 211:

    Paraben Lockdown device uses which operating system to write hard drive data?

    A. Mac OS
    B. Red Hat
    C. Unix
    D. Windows

  • Question 212:

    Preparing an image drive to copy files to is the first step in Linux forensics. For this purpose, what would the following command accomplish? dcfldd if=/dev/zero of=/dev/hda bs=4096 conv=noerror, sync

    A. Fill the disk with zeros
    B. Low-level format
    C. Fill the disk with 4096 zeros
    D. Copy files from the master disk to the slave disk on the secondary IDE controller

  • Question 213:

    In a forensic examination of hard drives for digital evidence, what type of user is most likely to have the most file slack to analyze?

    A. one who has NTFS 4 or 5 partitions
    B. one who uses dynamic swap file capability
    C. one who uses hard disk writes on IRQ 13 and 21
    D. one who has lots of allocation units per block or cluster

  • Question 214:

    Which Windows Registry hive contains system-wide configuration and the SAM database pointers?

    A. HKEY_CURRENT_USER
    B. HKEY_LOCAL_MACHINE
    C. HKEY_USERS
    D. HKEY_CURRENT_CONFIG

  • Question 215:

    Which of the following should a computer forensics lab used for investigations have?

    A. isolation
    B. restricted access
    C. open access
    D. an entry log

  • Question 216:

    You are working as an investigator for a corporation and you have just received instructions from your manager to assist in the collection of 15 hard drives that are part of an ongoing investigation. Your job is to complete the required evidence custody forms to properly document each piece of evidence as it is collected by other members of your team. Your manager instructs you to complete one multi-evidence form for the entire case and a single-evidence form for each hard drive. How will these forms be stored to help preserve the chain of custody of the case?

    A. All forms should be placed in an approved secure container because they are now primary evidence in the case.
    B. The multi-evidence form should be placed in the report file and the single-evidence forms should be kept with each hard drive in an approved secure container.
    C. The multi-evidence form should be placed in an approved secure container with the hard drives and the single-evidence forms should be placed in the report file.
    D. All forms should be placed in the report file because they are now primary evidence in the case.

  • Question 217:

    What does ICMP Type 3/Code 13 mean?

    A. Host Unreachable
    B. Administratively Blocked
    C. Port Unreachable
    D. Protocol Unreachable

  • Question 218:

    Harold is a security analyst who has just run the rdisk /s command to grab the backup SAM files on a computer. Where should Harold navigate on the computer to find the file?

    A. %systemroot%\system32\LSA
    B. %systemroot%\system32\drivers\etc
    C. %systemroot%\repair
    D. %systemroot%\LSA

  • Question 219:

    You are using DriveSpy, a forensic tool and want to copy 150 sectors where the starting sector is 1709 on the primary hard drive. Which of the following formats correctly specifies these sectors?

    A. 0:1000, 150
    B. 0:1709, 150
    C. 1:1709, 150
    D. 0:1709-1858

  • Question 220:

    To check for POP3 traffic using Ethereal, what port should an investigator search by?

    A. 143
    B. 25
    C. 110
    D. 125

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.