EC1-349 Exam Details

  • Exam Code
    :EC1-349
  • Exam Name
    :Computer Hacking Forensic Investigator (CHFI)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :486 Q&As
  • Last Updated
    :Dec 19, 2024

EC-COUNCIL EC1-349 Online Questions & Answers

  • Question 371:

    Law enforcement officers are conducting a legal search for which a valid warrant was obtained. While conducting the search, officers observe an item of evidence for an unrelated crime that was not included in the warrant. The item was clearly visible to the officers and immediately identified as evidence. What is the term used to describe how this evidence is admissible?

    A. Plain view doctrine
    B. Corpus delicti
    C. Locard Exchange Principle
    D. Ex Parte Order

  • Question 372:

    You should always work with original evidence

    A. True
    B. False

  • Question 373:

    From the following spam mail header, identify the host IP that sent this spam? From [email protected] [email protected] Tue Nov 27 17:27:11 2001 Received: from viruswall.ie.cuhk.edu.hk (viruswall [137.189.96.52]) by eng.ie.cuhk.edu.hk (8.11.6/8.11.6) with ESMTP id fAR9RAP23061 for ; Tue, 27 Nov 2001 17:27:10 +0800 (HKT) Received: from mydomain.com (pcd249020.netvigator.com [203.218.39.20]) by viruswall.ie.cuhk.edu.hk (8.12.1/8.12.1) with SMTP id fAR9QXwZ018431 for ; Tue, 27 Nov 2001 17:26:36 +0800 (HKT) Message-Id: >[email protected] From: "china hotel web" To: "Shlam" Subject: SHANGHAI (HILTON HOTEL) PACKAGE Date: Tue, 27 Nov 2001 17:25:58 +0800 MIME-Version: 1.0 X-Priority: 3 X-MSMail-Priority: Normal

    Reply-To: "china hotel web"

    A. 137.189.96.52
    B. 8.12.1.0
    C. 203.218.39.20
    D. 203.218.39.50

  • Question 374:

    What binary coding is used most often for e-mail purposes?

    A. SMTP
    B. Uuencode
    C. IMAP
    D. MIME

  • Question 375:

    You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers. What type of firewall must you implement to abide by this policy?

    A. Packet filtering firewall
    B. Application-level proxy firewall
    C. Statefull firewall
    D. Circuit-level proxy firewall

  • Question 376:

    After passing her CEH exam, Carol wants to ensure that her network is completely secure. She implements a DMZ, statefull firewall, NAT, IPSEC, and a packet filtering firewall. Since all security measures were taken, none of the hosts on her

    network can reach the Internet.

    Why is that?

    A. IPSEC does not work with packet filtering firewalls
    B. Statefull firewalls do not work with packet filtering firewalls
    C. NAT does not work with IPSEC
    D. NAT does not work with statefull firewalls

  • Question 377:

    Why should you note all cable connections for a computer you want to seize as evidence?

    A. to know what outside connections existed
    B. in case other devices were connected
    C. to know what peripheral devices exist
    D. to know what hardware existed

  • Question 378:

    Harold wants to set up a firewall on his network but is not sure which one would be the most appropriate. He knows he needs to allow FTP traffic to one of the servers on his network, but he wants to only allow FTP-PUT. Which firewall would be most appropriate for Harold? needs?

    A. Packet filtering firewall
    B. Circuit-level proxy firewall
    C. Application-level proxy firewall
    D. Data link layer firewall

  • Question 379:

    Where is the default location for Apache access logs on a Linux computer?

    A. usr/local/apache/logs/access_log
    B. bin/local/home/apache/logs/access_log
    C. usr/logs/access_log
    D. logs/usr/apache/access_log

  • Question 380:

    A law enforcement officer may only search for and seize criminal evidence with _______________________, which are facts or circumstances that would lead a reasonable person to believe a crime has been committed or is about to be committed, evidence of the specific crime exists and the evidence of the specific crime exists at the place to be searched.

    A. Mere Suspicion
    B. A preponderance of the evidence
    C. Probable cause
    D. Beyond a reasonable doubt

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your EC1-349 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.