EC1-349 Exam Details

  • Exam Code
    :EC1-349
  • Exam Name
    :Computer Hacking Forensic Investigator (CHFI)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :486 Q&As
  • Last Updated
    :Dec 19, 2024

EC-COUNCIL EC1-349 Online Questions & Answers

  • Question 361:

    To make sure the evidence you recover and analyze with computer forensics software can be admitted in court, you must test and validate the software. What group is actively providing tools and creating procedures for testing and validating computer forensics software ?

    A. Computer Forensics Tools and Validation Committee (CFTVC)
    B. Association of Computer Forensics Software Manufactures (ACFSM)
    C. National Institute of Standards and Technology (NIST)
    D. Society for Valid Forensics Tools and Testing (SVFTT)

  • Question 362:

    Ever-changing advancement or mobile devices increases the complexity of mobile device examinations. Which or the following is an appropriate action for the mobile forensic investigation?

    A. To avoid unwanted interaction with devices found on the scene, turn on any wireless interfaces such as Bluetooth and Wi-Fi radios
    B. Do not wear gloves while handling cell phone evidence to maintain integrity of physical evidence
    C. If the device's display is ON. the screen's contents should be photographed and, if necessary, recorded manually, capturing the time, service status, battery level, and other displayed icons
    D. If the phone is in a cradle or connected to a PC with a cable, then unplug the device from the computer

  • Question 363:

    Which of the following statements is incorrect when preserving digital evidence?

    A. Document the actions and changes that you observe in the monitor, computer, printer, or in other peripherals
    B. Verily if the monitor is in on, off, or in sleep mode
    C. Remove the power cable depending on the power state of the computer i.e., in on. off, or in sleep mode
    D. Turn on the computer and extract Windows event viewer log files

  • Question 364:

    Attacker uses vulnerabilities in the authentication or session management functions such as exposed accounts, session IDs, logout, password management, timeouts, remember me. secret question, account update etc. to impersonate users, if a user simply closes the browser without logging out from sites accessed through a public computer, attacker can use the same browser later and exploit the user's privileges. Which of the following vulnerability/exploitation is referred above?

    A. Session ID in URLs
    B. Timeout Exploitation
    C. I/O exploitation
    D. Password Exploitation

  • Question 365:

    Which of the following attacks allows an attacker to access restricted directories, including application source code, configuration and critical system files, and to execute commands outside of the web server's root directory?

    A. Unvalidated input
    B. Parameter/form tampering
    C. Directory traversal
    D. Security misconfiguration

  • Question 366:

    When making the preliminary investigations in a sexual harassment case, how many investigators are you recommended having?

    A. One
    B. Two
    C. Three
    D. Four

  • Question 367:

    What type of analysis helps to identify the time and sequence of events in an investigation?

    A. Time-based
    B. Functional
    C. Relational
    D. Temporal

  • Question 368:

    Davidson Trucking is a small transportation company that has three local offices in Detroit Michigan. Ten female employees that work for the company have gone to an attorney reporting that male employees repeatedly harassed them and that management did nothing to stop the problem. Davidson has employee policies that outline all company guidelines, including awareness on harassment and how it will not be tolerated. When the case is brought to court, whom should the prosecuting attorney call upon for not upholding company policy?

    A. IT personnel
    B. Employees themselves
    C. Supervisors
    D. Administrative assistant in charge of writing policies

  • Question 369:

    Bill is the accounting manager for Grummon and Sons LLC in Chicago. On a regular basis, he needs to send PDF documents containing sensitive information through E-mail to his customers. Bill protects the PDF documents with a password and sends them to their intended recipients. Why PDF passwords do not offer maximum protection?

    A. PDF passwords are converted to clear text when sent through E-mail
    B. PDF passwords are not considered safe by Sarbanes-Oxley
    C. When sent through E-mail, PDF passwords are stripped from the document completely
    D. PDF passwords can easily be cracked by software brute force tools

  • Question 370:

    What is the slave device connected to the secondary IDE controller on a Linux OS referred to?

    A. hda
    B. hdd
    C. hdb
    D. hdc

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC1-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.