EC1-349 Exam Details

  • Exam Code
    :EC1-349
  • Exam Name
    :Computer Hacking Forensic Investigator (CHFI)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :486 Q&As
  • Last Updated
    :Dec 19, 2024

EC-COUNCIL EC1-349 Online Questions & Answers

  • Question 131:

    Which one of the following statements is not correct while preparing for testimony?

    A. Go through the documentation thoroughly
    B. Do not determine the basic facts of the case before beginning and examining the evidence
    C. Establish early communication with the attorney
    D. Substantiate the findings with documentation and by collaborating with other computer forensics professionals

  • Question 132:

    In an echo data hiding technique, the secret message is embedded into a __________as an echo.

    A. Cover audio signal
    B. Phase spectrum of a digital signal
    C. Pseudo-random signal
    D. Pseudo- spectrum signal

  • Question 133:

    Corporate investigations are typically easier than public investigations because: A. the users have standard corporate equipment and software

    B. the investigator does not have to get a warrant
    C. the investigator has to get a warrant
    D. the users can load whatever they want on their machines

  • Question 134:

    What method of copying should always be performed first before carrying out an investigation?

    A. Parity-bit copy
    B. Bit-stream copy
    C. MS-DOS disc copy
    D. System level copy

  • Question 135:

    Which forensic investigating concept trails the whole incident from how the attack began to how the victim was affected?

    A. Point-to-point
    B. End-to-end
    C. Thorough
    D. Complete event analysis

  • Question 136:

    What operating system would respond to the following command? C:\> nmap -sW 10.10.145.65

    A. Windows XP
    B. Mac OS X
    C. FreeBSD
    D. Windows 95

  • Question 137:

    Shortcuts are the files with the extension .Ink that are created and are accessed by the users. These files provide you with information about:

    A. Files or network shares
    B. Running application
    C. Application logs
    D. System logs

  • Question 138:

    Email archiving is a systematic approach to save and protect the data contained in emails so that it can tie easily accessed at a later date.

    A. True
    B. False

  • Question 139:

    You are working as a computer forensics investigator for a corporation on a computer abuse case. You discover evidence that shows the subject of your investigation is also embezzling money from the company. The company CEO and the corporate legal counsel advise you to contact local law enforcement and provide them with the evidence that you have found. The law enforcement officer that responds requests that you put a network sniffer on your network and monitor all traffic to the subject computer. You inform the officer that you will not be able to comply with thatnetwork sniffer on your network and monitor all traffic to the subject? computer. You inform the officer that you will not be able to comply with that request because doing so would:

    A. Violate your contract
    B. Cause network congestion
    C. Make you an agent of law enforcement
    D. Write information to the subject hard driveWrite information to the subject? hard drive

  • Question 140:

    If a file (readme.txt) on a hard disk has a size of 2600 bytes, how many sectors are normally allocated to this file?

    A. 4 Sectors
    B. 5 Sectors
    C. 6 Sectors
    D. 7 Sectors

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC1-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.