EC0-349 Exam Details

  • Exam Code
    :EC0-349
  • Exam Name
    :Computer Hacking Forensic Investigator
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :325 Q&As
  • Last Updated
    :May 24, 2026

EC-COUNCIL EC0-349 Online Questions & Answers

  • Question 221:

    A state department site was recently attacked and all the servers had their disks erased. The incident response team sealed the area and commenced investigation. During evidence collection they came across a zip disks that did not have the standard labeling on it. The incident team ran the disk on an isolated system and found that the system disk was accidentally erased. They decided to call in the FBI for further investigation. Meanwhile, they short listed possible suspects including three summer interns. Where did the incident team go wrong?

    A. They examined the actual evidence on an unrelated system
    B. They attempted to implicate personnel without proof
    C. They tampered with evidence by using it
    D. They called in the FBI without correlating with the fingerprint data

  • Question 222:

    How many possible sequence number combinations are there in TCP/IP protocol?

    A. 1 billion
    B. 320 billion
    C. 4 billion
    D. 32 million

  • Question 223:

    Windows identifies which application to open a file with by examining which of the following?

    A. The File extension
    B. The file attributes
    C. The file Signature at the end of the file
    D. The file signature at the beginning of the file

  • Question 224:

    What is the main risk of powering on a suspect system at the scene without proper precautions?

    A. It will always increase the available evidence
    B. Volatile data may change and the system may write to disk, altering evidence
    C. It prevents you from taking photographs of the scene
    D. It invalidates all future warrants automatically

  • Question 225:

    Why is it still possible to recover files that have been emptied from the Recycle Bin on a Windows computer?

    A. The data is still present until the original location of the file is used
    B. The data is moved to the Restore directory and is kept there indefinitely
    C. The data will reside in the L2 cache on a Windows computer until it is manually deleted
    D. It is not possible to recover data that has been emptied from the Recycle Bin

  • Question 226:

    Harold is finishing up a report on a case of network intrusion, corporate spying, and embezzlement that he has been working on for over six months. He is trying to find the right term to use in his report to describe network-enabled spying. What term should Harold use?

    A. Spycrack
    B. Spynet
    C. Netspionage
    D. Hackspionage

  • Question 227:

    Jason has set up a honeypot environment by creating a DMZ that has no physical or logical access to his production network. In this honeypot, he has placed a server running Windows Active Directory. He has also placed a Web server in the DMZ that services a number of web pages that offer visitors a chance to download sensitive information by clicking on a button. A week later, Jason finds in his network logs how an intruder accessed the honeypot and downloaded sensitive information. Jason uses the logs to try and prosecute the intruder for stealing sensitive corporate information. Why will this not be viable?

    A. Entrapment
    B. Enticement
    C. Intruding into a honeypot is not illegal
    D. Intruding into a DMZ is not illegal

  • Question 228:

    Why would a company issue a dongle with the software they sell?

    A. To provide source code protection
    B. To provide wireless functionality with the software
    C. To provide copyright protection
    D. To ensure that keyloggers cannot be used

  • Question 229:

    In the context of file deletion process, which of the following statement holds true?

    A. When files are deleted, the data is overwritten and the cluster marked as available
    B. The longer a disk is in use, the less likely it is that deleted files will be overwritten
    C. While booting, the machine may create temporary files that can delete evidence
    D. Secure delete programs work by completely overwriting the file in one go

  • Question 230:

    You are a computer forensics investigator working with local police department and you are called to assist in an investigation of threatening emails. The complainant has printer out 27 email messages from the suspect and gives the printouts to you. You inform her that you will need to examine her computer because you need access to the _________________________ in order to track the emails back to the suspect.

    A. Routing Table
    B. Firewall log
    C. Configuration files
    D. Email Header

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.