EC0-349 Exam Details

  • Exam Code
    :EC0-349
  • Exam Name
    :Computer Hacking Forensic Investigator
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :325 Q&As
  • Last Updated
    :

EC-COUNCIL EC0-349 Online Questions & Answers

  • Question 71:

    Which of the following best describes steganography?

    A. Encrypting files with a strong cipher to prevent access
    B. Hiding a message within another file so the existence of the message is concealed
    C. Overwriting free space with random data to prevent recovery
    D. Changing timestamps to mislead investigators

  • Question 72:

    You are called by an author who is writing a book and he wants to know how long the copyright for his book will last after he has the book published?

    A. 70 years
    B. the life of the author
    C. the life of the author plus 70 years
    D. copyrights last forever

  • Question 73:

    You are working as a Computer forensics investigator for a corporation on a computer abuse case. You discover evidence that shows the subject of your investigation is also embezzling money from the company. The company CEO and the corporate legal counsel advise you to contact law enforcement and provide them with the evidence that you have found. The law enforcement officer that responds requests that you put a network sniffer on your network and monitor all traffic to the subject's computer. You inform the officer that you will not be able to comply with that request because doing so would:

    A. Violate your contract
    B. Cause network congestion
    C. Make you an agent of law enforcement
    D. Write information to the subject's hard drive

  • Question 74:

    Frank is working on a vulnerability assessment for a company on the West coast. The company hired Frank to assess its network security through scanning, pen tests, and vulnerability assessments. After discovering numerous known vulnerabilities detected by a temporary IDS he set up, he notices a number of items that show up as unknown but Questionable in the logs. He looks up the behavior on the Internet, but cannot find anything related. What organization should Frank submit the log to find out if it is a new vulnerability or not?

    A. APIPA
    B. IANA
    C. CVE
    D. RIPE

  • Question 75:

    What does the superblock in Linux define?

    A. filesynames
    B. diskgeometr
    C. location of the firstinode
    D. available space

  • Question 76:

    You have compromised a lower-level administrator account on an Active Directory network of a small company in Dallas, Texas. You discover Domain Controllers through enumeration. You connect to one of the Domain Controllers on port 389 using ldp.exe. What are you trying to accomplish here?

    A. Poison the DNS records with false records
    B. Enumerate MX and A records from DNS
    C. Establish a remote connection to the Domain Controller
    D. Enumerate domain user accounts and built-in groups

  • Question 77:

    When investigating a wireless attack, what information can be obtained from the DHCP logs?

    A. The operating system of the attacker and victim computers
    B. IP traffic between the attacker and the victim
    C. MAC address of the attacker
    D. If any computers on the network are running in promiscuous mode

  • Question 78:

    When reviewing web logs, you see an entry for resource not found in the HTTP status code filed. What is the actual error code that you would see in the log for resource not found?

    A. 202
    B. 404
    C. 505
    D. 909

  • Question 79:

    In conducting a computer abuse investigation you become aware that the suspect of the investigation is using ABC Company as his Internet Service Provider (ISP). You contact ISP and request that they provide you assistance with your investigation. What assistance can the ISP provide?

    A. The ISP can investigate anyone using their service and can provide you with assistance
    B. The ISP can investigate computer abuse committed by their employees, but must preserve the privacy of their customers and therefore cannot assist you without a warrant
    C. The ISP can't conduct any type of investigations on anyone and therefore can't assist you
    D. ISP's never maintain log files so they would be of no use to your investigation

  • Question 80:

    Simon is a former employee of Trinitron XML Inc. He feels he was wrongly terminated and wants to hack into his former company's network. Since Simon remembers some of the server names, he attempts to run the axfr and ixfr commands using DIG. What is Simon trying to accomplish here?

    A. Send DOS commands to crash the DNS servers
    B. Perform DNS poisoning
    C. Perform a zone transfer
    D. Enumerate all the users in the domain

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC0-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.