EC0-349 Exam Details

  • Exam Code
    :EC0-349
  • Exam Name
    :Computer Hacking Forensic Investigator
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :325 Q&As
  • Last Updated
    :May 24, 2026

EC-COUNCIL EC0-349 Online Questions & Answers

  • Question 231:

    This type of testimony is presented by someone who does the actual fieldwork and does not offer a view in court.

    A. Civil litigation testimony
    B. Expert testimony
    C. Victim advocate testimony
    D. Technical testimony

  • Question 232:

    What binary coding is used most often for e-mail purposes?

    A. MIME
    B. Uuencode
    C. IMAP
    D. SMTP

  • Question 233:

    What are the security risks of running a "repair" installation for Windows XP?

    A. Pressing Shift+F10gives the user administrative rights
    B. Pressing Shift+F1gives the user administrative rights
    C. Pressing Ctrl+F10 gives the user administrative rights
    D. There are no security risks when running the "repair" installation for Windows XP

  • Question 234:

    Which Intrusion Detection System (IDS) usually produces the most false alarms due to the unpredictable behaviors of users and networks?

    A. network-based IDS systems (NIDS)
    B. host-based IDS systems (HIDS)
    C. anomaly detection
    D. signature recognition

  • Question 235:

    When conducting computer forensic analysis, you must guard against ______________ So that you remain focused on the primary job and insure that the level of work does not increase beyond what was originally expected.

    A. Hard Drive Failure
    B. Scope Creep
    C. Unauthorized expenses
    D. Overzealous marketing

  • Question 236:

    In a computer forensics investigation, what describes the route that evidence takes from the time you find it until the case is closed or goes to court?

    A. rules of evidence
    B. law of probability
    C. chain of custody
    D. policy of separation

  • Question 237:

    George is a senior security analyst working for a state agency in Florida. His state's congress just passed a bill mandating every state agency to undergo a security audit annually. After learning what will be required, George needs to implement an IDS as soon as possible before the first audit occurs. The state bill requires that an IDS with a "time-based induction machine" be used.

    What IDS feature must George implement to meet this requirement?

    A. Signature-based anomaly detection
    B. Pattern matching
    C. Real-time anomaly detection
    D. Statistical-based anomaly detection

  • Question 238:

    If a PDA is seized in an investigation while the device is turned on, what would be the proper procedure?

    A. Keep the device powered on
    B. Turn off the device immediately
    C. Remove the battery immediately
    D. Remove any memory cards immediately

  • Question 239:

    When performing a forensics analysis, what device is used to prevent the system from recording data on an evidence disk?

    A. a write-blocker
    B. a protocol analyzer
    C. a firewall
    D. a disk editor

  • Question 240:

    An Employee is suspected of stealing proprietary information belonging to your company that he had no rights to possess. The information was stored on the Employees Computer that was protected with the NTFS Encrypted File System (EFS) and you had observed him copy the files to a floppy disk just before leaving work for the weekend. You detain the Employee before he leaves the building and recover the floppy disks and secure his computer. Will you be able to break the encryption so that you can verify that that the employee was in possession of the proprietary information?

    A. EFS uses a 128-bit key that can't be cracked, so you will not be able to recover the information
    B. When the encrypted file was copied to the floppy disk, it was automatically unencrypted, so you can recover the information.
    C. The EFS Revoked Key Agent can be used on the Computer to recover the information
    D. When the Encrypted file was copied to the floppy disk, the EFS private key was also copied to the floppy disk, so you can recover the information.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.