EC1-349 Exam Details

  • Exam Code
    :EC1-349
  • Exam Name
    :Computer Hacking Forensic Investigator (CHFI)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :486 Q&As
  • Last Updated
    :Dec 19, 2024

EC-COUNCIL EC1-349 Online Questions & Answers

  • Question 211:

    Which of the following steganography types hides the secret message in a specifically designed pattern on the document that is unclear to the average reader?

    A. Open code steganography
    B. Visual semagrams steganography
    C. Text semagrams steganography
    D. Technical steganography

  • Question 212:

    Why should you never power on a computer that you need to acquire digital evidence from?

    A. When the computer boots up, files are written to the computer rendering the data nclean?When the computer boots up, files are written to the computer rendering the data ?nclean
    B. When the computer boots up, the system cache is cleared which could destroy evidence
    C. When the computer boots up, data in the memory buffer is cleared which could destroy evidenceWhen the computer boots up, data in the memory? buffer is cleared which could destroy evidence
    D. Powering on a computer has no affect when needing to acquire digital evidence from it

  • Question 213:

    Operating System logs are most beneficial for Identifying or Investigating suspicious activities involving a particular host. Which of the following Operating System logs contains information about operational actions performed by OS components?

    A. Event logs
    B. Audit logs
    C. Firewall logs
    D. IDS logs

  • Question 214:

    Computer security logs contain information about the events occurring within an organization's systems and networks. Which of the following security logs contains Logs of network and host- based security software?

    A. Operating System (OS) logs
    B. Application logs
    C. Security software logs
    D. Audit logs

  • Question 215:

    International Mobile Equipment Identifier (IMEI) is a 15-dlgit number that indicates the manufacturer, model type, and country of approval for GSM devices. The first eight digits of an IMEI number that provide information about the model and origin of the mobile device is also known as:

    A. Type Allocation Code (TAC)
    B. Device Origin Code (DOC)
    C. Manufacturer identification Code (MIC)
    D. Integrated Circuit Code (ICC)

  • Question 216:

    In Windows 7 system files, which file reads the Boot.ini file and loads Ntoskrnl.exe. Bootvid.dll. Hal.dll, and boot-start device drivers?

    A. Ntldr
    B. Gdi32.dll
    C. Kernel32.dll
    D. Boot.in

  • Question 217:

    TCP/IP (Transmission Control Protocol/Internet Protocol) is a communication protocol used to connect different hosts in the Internet. It contains four layers, namely the network interface layer. Internet layer, transport layer, and application layer.

    Which of the following protocols works under the transport layer of TCP/IP?

    A. UDP
    B. HTTP
    C. FTP
    D. SNMP

  • Question 218:

    In Microsoft file structures, sectors are grouped together to form:

    A. Clusters
    B. Drives
    C. Bitstreams
    D. Partitions

  • Question 219:

    What does the superblock in Linux define?

    A. file synames
    B. disk geometr
    C. location of the first inode
    D. available space

  • Question 220:

    Data compression involves encoding the data to take up less storage space and less bandwidth for transmission. It helps in saving cost and high data manipulation in many business applications. Which data compression technique maintains data integrity?

    A. Lossless compression
    B. Lossy compression
    C. Speech encoding compression
    D. Lossy video compression

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC1-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.