EC1-349 Exam Details

  • Exam Code
    :EC1-349
  • Exam Name
    :Computer Hacking Forensic Investigator (CHFI)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :486 Q&As
  • Last Updated
    :Dec 19, 2024

EC-COUNCIL EC1-349 Online Questions & Answers

  • Question 311:

    In handling computer-related incidents, which IT role should be responsible for recovery, containment, and prevention to constituents?

    A. Security Administrator
    B. Network Administrator
    C. Director of Information Technology
    D. Director of Administration

  • Question 312:

    Which of the following standard is based on a legal precedent regarding the admissibility of scientific examinations or experiments in legal cases?

    A. Daubert Standard
    B. Schneiderman Standard
    C. Frye Standard
    D. FERPA standard

  • Question 313:

    System software password cracking is defined as cracking the operating system and all other utilities that enable a computer to function A. True

    B. False

  • Question 314:

    You are working as Computer Forensics investigator and are called by the owner of an accounting firm to investigate possible computer abuse by one of the firm's employees. You meet with the owner of the firm and discover that the company has never published a policy stating that they reserve the right to inspect their computing assets at will. What do you do?

    A. Inform the owner that conducting an investigation without a policy is not a problem because the company is privately owned
    B. Inform the owner that conducting an investigation without a policy is a violation of the 4th amendment
    C. Inform the owner that conducting an investigation without a policy is a violation of the employees' expectation of privacy
    D. Inform the owner that conducting an investigation without a policy is not a problem because a policy is only necessary for government agencies

  • Question 315:

    You are contracted to work as a computer forensics investigator for a regional bank that has four 30 TB storage area networks that store customer data. What method would be most efficient for you to acquire digital evidence from this network?

    A. Make a bit-stream disk-to-disk file
    B. Make a bit-stream disk-to-image file
    C. Create a sparse data copy of a folder or file
    D. Create a compressed copy of the file with DoubleSpace

  • Question 316:

    What is considered a grant of a property right given to an individual who discovers or invents a new machine, process, useful composition of matter or manufacture?

    A. Copyright
    B. Design patent
    C. Trademark
    D. Utility patent

  • Question 317:

    You are working for a large clothing manufacturer as a computer forensics investigator and are called in to investigate an unusual case of an employee possibly stealing clothing designs from the company and selling them under a different brand name for a different company. What you discover during the course of the investigation is that the clothing designs are actually original products of the employee and the company has no policy against an employee selling his own designs on his own time. The only thing that you can find that the employee is doing wrong is that his clothing design incorporates the same graphic symbol as that of the company with only the wording in the graphic being different. What area of the law is the employee violating?

    A. Copyright law
    B. Brandmark law
    C. Trademark law
    D. Printright law

  • Question 318:

    You are assigned to work in the computer forensics lab of a state police agency. While working on a high profile criminal case, you have followed every applicable procedure, however your boss is still concerned that the defense attorney might question wheather evidence has been changed while at the lab. What can you do to prove that the evidence is the same as it was when it first entered the lab?

    A. Sign a statement attesting that the evidence is the same as it was when it entered the lab
    B. There is no reason to worry about this possible claim because state labs are certified
    C. Make MD5 hashes of the evidence and compare it to the standard database developed by NIST
    D. Make MD5 hashes of the evidence and compare it with the original MD5 hash that was taken when the evidence first entered the lab

  • Question 319:

    Under confession, an accused criminal admitted to encrypting child pornography pictures and then hiding them within other pictures. What technique did the accused criminal employ?

    A. Typography
    B. Steganalysis
    C. Picture encoding
    D. Steganography

  • Question 320:

    The newer Macintosh Operating System (MacOS X) is based on: A. Microsoft Windows

    B. OS/2
    C. BSD Unix
    D. Linux

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC1-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.