EC0-349 Exam Details

  • Exam Code
    :EC0-349
  • Exam Name
    :Computer Hacking Forensic Investigator
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :325 Q&As
  • Last Updated
    :Jun 01, 2026

EC-COUNCIL EC0-349 Online Questions & Answers

  • Question 61:

    What does the acronym POST mean as it relates to a PC?

    A. Primary Operations Short Test
    B. PowerOn Self Test
    C. Pre Operational Situation Test
    D. Primary Operating System Test

  • Question 62:

    What type of analysis helps to identify the time and sequence of events in an investigation?

    A. Time-based
    B. Functional
    C. Relational
    D. Temporal

  • Question 63:

    Corporate investigations are typically easier than public investigations because:

    A. the users have standard corporate equipment and software
    B. the investigator does not have to get a warrant
    C. the investigator has to get a warrant
    D. the users can load whatever they want on their machines

  • Question 64:

    You have used a newly released forensic investigation tool, which doesn't meet the Daubert Test, during a case. The case has ended-up in court. What argument could the defense make to weaken your case?

    A. The tool hasn't been tested by the International Standards Organization (ISO)
    B. Only the local law enforcement should use the tool
    C. The total has not been reviewed and accepted by your peers
    D. You are not certified for using the tool

  • Question 65:

    Which tool or technique is most appropriate for capturing the contents of a system's volatile memory for later analysis?

    A. dd to copy the hard drive
    B. Use a hardware write-blocker and image the disk
    C. Use a memory acquisition tool (live RAM dump)
    D. Pull the power plug to preserve memory contents

  • Question 66:

    Using Linux to carry out a forensics investigation, what would the following command accomplish? dd if=/usr/home/partition.image of=/dev/sdb2 bs=4096 conv=notrunc,noerror

    A. Search for disk errors within an image file
    B. Backup a disk to an image file
    C. Copy a partition to an image file
    D. Restore a disk from an image file

  • Question 67:

    An attacker performs a DNS cache poisoning attack that redirects users to a malicious site. Which countermeasure helps prevent this?

    A. Disable UDP entirely on the network
    B. Configure DNSSEC and validate DNS responses
    C. Increase web server timeouts
    D. Block TCP port 80 outbound

  • Question 68:

    From the following spam mail header, identify the host IP that sent this spam?

    From [email protected] [email protected] Tue Nov 27 17:27:11 2001 Received: from viruswall.ie.cuhk.edu.hk (viruswall [137. 189.96. 52]) by eng.ie.cuhk.edu.hk (8.11.6/8.11.6) with ESMTP id fAR9RAP23061 for ; Tue, 27 Nov 2001 17:27:10 +0800 (HKT) Received: from mydomain.com (pcd249020.netvigator.com [203. 218.39.20]) by viruswall.ie.cuhk.edu.hk (8.12. 1/8.12. 1) with SMTP id fAR9QXwZ018431 for ; Tue, 27 Nov 2001 17:26:36 +0800 (HKT) Message-Id: >200111270926. [email protected] From: "china hotel web" To: "Shlam" Subject: SHANGHAI (HILTON HOTEL) PACKAGE Date: Tue, 27 Nov 2001 17:25:58 +0800 MIME-Version: 1.0 X-Priority: 3 X-MSMail-Priority: Normal Reply-To: "china hotel web"

    A. 137. 189.96. 52
    B. 8.12. 1.0
    C. 203. 218.39.20
    D. 203. 218.39.50

  • Question 69:

    What filesystem metadata records the last modification, last access, and last status change times for files on Unix systems?

    A. MFT timestamps
    B. inode timestamps (mtime, atime, ctime)
    C. FAT directory timestamps
    D. Registry lastwrite times

  • Question 70:

    Julie is a college student majoring in Information Systems and Computer Science. She is currently writing an essay for her computer crimes class. Julie paper focuses on white-collar crimes in America and how forensics investigators investigate the cases. Julie would like to focus the subject. Julie would like to focus the subject of the essay on the most common type of crime found in corporate America. What crime should Julie focus on?

    A. Physical theft
    B. Copyright infringement
    C. Industrial espionage
    D. Denial of Service attacks

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.