312-49v10 Training & Certification Get Latest CHFI v10 Updated on Oct 24, 2021
Certification Training for 312-49v10 Exam Dumps Test Engine
EC-COUNCIL 312-49v10 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
NEW QUESTION 271
As a Certified Ethical Hacker, you were contracted by a private firm to conduct an external security assessment through penetration testing . What document describes the specifics of the testing, the associated violations, and essentially protects both the organization's interest and your liabilities as a tester?
- A. Service Level Agreement
- B. Non-Disclosure Agreement
- C. Project Scope
- D. Rules of Engagement
Answer: D
NEW QUESTION 272
Which of the following techniques delete the files permanently?
- A. Trail obfuscation
- B. Steganography
- C. Artifact Wiping
- D. Data Hiding
Answer: C
NEW QUESTION 273
You setup SNMP in multiple offices of your company. Your SNMP software manager is not receiving data from other offices like it is for your main office. You suspect that firewall changes are to blame. What ports should you open for SNMP to work through Firewalls? (Choose two.)
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B,C
NEW QUESTION 274
What is an investigator looking for in the rp.log file stored in a system running on Windows 10 operating system?
- A. Restore point functions
- B. Restore point interval
- C. Automatically created restore points
- D. System CheckPoints required for restoring
Answer: D
NEW QUESTION 275
Which of the following commands shows you all of the network services running on Windows-based servers?
- A. Net use
- B. Net config
- C. Netstart
- D. Net Session
Answer: C
NEW QUESTION 276
Which file is a sequence of bytes organized into blocks understandable by the system's linker?
- A. source file
- B. executable file
- C. Object file
- D. None of these
Answer: C
NEW QUESTION 277
During an investigation, Noel found the following SIM card from the suspect's mobile. What does the code 89 44 represent?
- A. Issuer Identifier Number and TAC
- B. Industry Identifier and Country code
- C. TAC and Industry Identifier
- D. Individual Account Identification Number and Country Code
Answer: B
NEW QUESTION 278
Sectors are pie-shaped regions on a hard disk that store dat
a. Which of the following parts of a hard disk do not contribute in determining the addresses of data?
- A. Sectors
- B. Heads
- C. Interface
- D. Cylinder
Answer: C
NEW QUESTION 279
What will the following command accomplish?
dd if=/dev/xxx of=mbr.backup bs=512 count=1
- A. Mount the master boot record on the first partition of the hard drive
- B. Restore the master boot record
- C. Restore the first 512 bytes of the first partition of the hard drive
- D. Back up the master boot record
Answer: D
NEW QUESTION 280
Which of the following files contains the traces of the applications installed, run, or uninstalled from a system?
- A. Virtual Files
- B. Prefetch Files
- C. Image Files
- D. Shortcut Files
Answer: D
NEW QUESTION 281
Depending upon the jurisdictional areas, different laws apply to different incidents. Which of the following law is related to fraud and related activity in connection with computers?
- A. 18 USC §1029
- B. 18 USC §1371
- C. 18 USC §1361
- D. 18 USC §1030
Answer: D
NEW QUESTION 282
Which of the following is a non-zero data that an application allocates on a hard disk cluster in systems running on Windows OS?
- A. Master File Table
- B. Meta Block Group
- C. Sparse File
- D. Slack Space
Answer: A
NEW QUESTION 283
During the course of an investigation, you locate evidence that may prove the innocence of the suspect of the investigation. You must maintain an unbiased opinion and be objective in your entire fact finding process. Therefore, you report this evidence. This type of evidence is known as:
- A. Inculpatory evidence
- B. Mandatory evidence
- C. Exculpatory evidence
- D. Terrible evidence
Answer: C
NEW QUESTION 284
You have been asked to investigate the possibility of computer fraud in the finance department of a company. It is suspected that a staff member has been committing finance fraud by printing cheques that have not been authorized. You have exhaustively searched all data files on a bitmap image of the target computer, but have found no evidence. You suspect the files may not have been saved. What should you examine next in this case?
- A. The swap file
- B. The registry
- C. The metadata
- D. The recycle bin
Answer: A
NEW QUESTION 285
Which of the following acts as a network intrusion detection system as well as network intrusion prevention system?
- A. Snort
- B. Kismet
- C. Accunetix
- D. Nikto
Answer: A
NEW QUESTION 286
In a computer forensics investigation, what describes the route that evidence takes from the time you find it until the case is closed or goes to court?
- A. chain of custody
- B. policy of separation
- C. rules of evidence
- D. law of probability
Answer: A
NEW QUESTION 287
What does the superblock in Linux define?
- A. location of the firstinode
- B. diskgeometr
- C. available space
- D. filesynames
Answer: A
NEW QUESTION 288
What advantage does the tool Evidor have over the built-in Windows search?
- A. It can search slack space
- B. It can find files hidden within ADS
- C. It can find deleted files even after they have been physically removed
- D. It can find bad sectors on the hard drive
Answer: A
NEW QUESTION 289
You are working for a local police department that services a population of 1,000,000 people and you have been given the task of building a computer forensics lab. How many law-enforcement computer investigators should you request to staff the lab?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
NEW QUESTION 290
While looking through the IIS log file of a web server, you find the following entries:
What is evident from this log file?
- A. Hidden fields
- B. SQL injection is possible
- C. Web bugs
- D. Cross site scripting
Answer: B
NEW QUESTION 291
A computer forensics investigator is inspecting the firewall logs for a large financial institution that has employees working 24 hours a day, 7 days a week.
What can the investigator infer from the screenshot seen below?
- A. Buffer overflow attempt on the firewall.
- B. Network intrusion has occurred
- C. A smurf attack has been attempted
- D. A denial of service has been attempted
Answer: B
NEW QUESTION 292
What are the security risks of running a "repair" installation for Windows XP?
- A. There are no security risks when running the "repair" installation for Windows XP
- B. Pressing Shift+F10gives the user administrative rights
- C. Pressing Shift+F1gives the user administrative rights
- D. Pressing Ctrl+F10 gives the user administrative rights
Answer: B
NEW QUESTION 293
A suspect is accused of violating the acceptable use of computing resources, as he has visited adult websites and downloaded images. The investigator wants to demonstrate that the suspect did indeed visit these sites. However, the suspect has cleared the search history and emptied the cookie cache. Moreover, he has removed any images he might have downloaded. What can the investigator do to prove the violation?
- A. Check the Windows registry for connection data (you may or may not recover)
- B. Approach the websites for evidence
- C. Seek the help of co-workers who are eye-witnesses
- D. Image the disk and try to recover deleted files
Answer: D
NEW QUESTION 294
......
Step by Step Guide to Prepare for 312-49v10 Exam: https://www.testpassed.com/312-49v10-still-valid-exam.html
CHFI v10 312-49v10 Real Exam Questions and Answers FREE Updated: https://drive.google.com/open?id=1xevvLrbAGN-65Ff4lsNXs6i5ie2H7U7s