CHFI v10 Certification 312-49v10 Sample Questions Reliable
Prepare for the Actual CHFI v10 312-49v10 Exam Practice Materials Collection
EC-COUNCIL 312-49v10 (Computer Hacking Forensic Investigator (CHFI-v10)) Certification Exam is an internationally recognized certification that provides professionals with a comprehensive understanding of computer forensics and investigation techniques. Computer Hacking Forensic Investigator (CHFI-v10) certification exam tests the ability of the candidate to conduct an investigation on different types of computer systems, including mobile devices and networks. It is a highly respected certification in the cybersecurity industry and provides individuals with the knowledge and skills needed to identify and prevent cyber threats.
NEW QUESTION # 259
Frank is working on a vulnerability assessment for a company on the West coast. The company hired Frank to assess its network security through scanning, pen tests, and vulnerability assessments. After discovering numerous known vulnerabilities detected by a temporary IDS he set up, he notices a number of items that show up as unknown but Questionable in the logs. He looks up the behavior on the Internet, but cannot find anything related. What organization should Frank submit the log to find out if it is a new vulnerability or not?
- A. CVE
- B. RIPE
- C. APIPA
- D. IANA
Answer: A
NEW QUESTION # 260
An attacker has compromised a cloud environment of a company and used the employee information to perform an identity theft attack. Which type of attack is this?
- A. Cloud as an object
- B. Cloud as a subject
- C. Cloud as a tool
- D. Cloud as a service
Answer: B
NEW QUESTION # 261
Microsoft Outlook maintains email messages in a proprietary format in what type of file?
- A. .doc
- B. .pst
- C. .mail
- D. .email
Answer: B
NEW QUESTION # 262
Fred, a cybercrime Investigator for the FBI, finished storing a solid-state drive In a static resistant bag and filled out the chain of custody form. Two days later. John grabbed the solid-state drive and created a clone of It (with write blockers enabled) In order to Investigate the drive. He did not document the chain of custody though. When John was finished, he put the solid-state drive back in the static resistant and placed it back in the evidence locker. A day later, the court trial began and upon presenting the evidence and the supporting documents, the chief Justice outright rejected them. Which of the following statements strongly support the reason for rejecting the evidence?
- A. Block clones cannot be created with solid-state drives
- B. John did not document the chain of custody
- C. John investigated the clone instead of the original evidence itself
- D. Write blockers were used while cloning the evidence
Answer: B
NEW QUESTION # 263
Which command line tool is used to determine active network connections?
- A. nslookup
- B. netstat
- C. netsh
- D. nbstat
Answer: B
NEW QUESTION # 264
In a virtual test environment, Michael is testing the strength and security of BGP using multiple routers to mimic the backbone of the Internet. This project will help him write his doctoral thesis on "bringing down the Internet". Without sniffing the traffic between the routers, Michael sends millions of RESET packets to the routers in an attempt to shut one or all of them down. After a few hours, one of the routers finally shuts itself down. What will the other routers communicate between themselves?
- A. More RESET packets to the affected router to get it to power back up
- B. The change in the routing fabric to bypass the affected router
- C. RESTART packets to the affected router to get it to power back up
- D. STOP packets to all other routers warning of where the attack originated
Answer: B
NEW QUESTION # 265
You are conducting an investigation of fraudulent claims in an insurance company that involves complex text searches through large numbers of documents. Which of the following tools would allow you to quickly and efficiently search for a string within a file on the bitmap image of the target computer?
- A. dir
- B. Stringsearch
- C. grep
- D. vim
Answer: C
NEW QUESTION # 266
You are called in to assist the police in an investigation involving a suspected drug dealer. The suspects house was searched by the police after a warrant was obtained and they located a floppy disk in the suspects bedroom. The disk contains several files, but they appear to be password protected. What are two common methods used by password cracking software that you can use to obtain the password?
- A. Brute Force and dictionary Attack
- B. Maximum force and thesaurus Attack
- C. Limited force and library attack
- D. Minimum force and appendix Attack
Answer: A
NEW QUESTION # 267
Office Documents (Word, Excel and PowerPoint) contain a code that allows tracking the MAC or unique identifier of the machine that created the document. What is that code called?
- A. Microsoft Virtual Machine Identifier
- B. Individual ASCII string
- C. Globally unique ID
- D. Personal Application Protocol
Answer: C
NEW QUESTION # 268
Wireless access control attacks aim to penetrate a network by evading WLAN access control measures such as AP MAC filters and Wi-Fi port access controls. Which of the following wireless access control attacks allow the attacker to set up a rogue access point outside the corporate perimeter and then lure the employees of the organization to connect to it?
- A. MAC spoofing
- B. Ad hoc associations
- C. Rogue access points
- D. Client mis-association
Answer: D
NEW QUESTION # 269
What type of flash memory card comes in either Type I or Type II and consumes only five percent of the power required by small hard drives?
- A. CF memory
- B. SD memory
- C. MMC memory
- D. SM memory
Answer: A
NEW QUESTION # 270
A forensics investigator needs to copy data from a computer to some type of removable media so he can examine the information at another location. The problem is that the data is around 42GB in size. What type of removable media could the investigator use?
- A. Blu-Ray single-layer
- B. Blu-Ray dual-layer
- C. HD-DVD
- D. DVD-18
Answer: B
NEW QUESTION # 271
In the following email header, where did the email first originate from?
- A. Somedomain.com
- B. Simon1.state.ok.gov.us
- C. Smtp1.somedomain.com
- D. David1.state.ok.gov.us
Answer: B
NEW QUESTION # 272
Steve received a mail that seemed to have come from her bank. The mail has instructions for Steve to click on a link and provide information to avoid the suspension of her account. The link in the mail redirected her to a form asking for details such as name, phone number, date of birth, credit card number or PIN, CW code, SNNs, and email address. On a closer look, Steve realized that the URL of the form in not the same as that of her bank's. Identify the type of external attack performed by the attacker In the above scenario?
- A. Taiigating
- B. Aphishing
- C. Brute-force
- D. Espionage
Answer: B
NEW QUESTION # 273
On Linux/Unix based Web servers, what privilege should the daemon service be run under?
- A. Something other than root
- B. Guest
- C. Root
- D. You cannot determine what privilege runs the daemon service
Answer: A
NEW QUESTION # 274
If the partition size is 4 GB, each cluster will be 32 K. Even if a file needs only 10 K, the entire 32 K will be allocated, resulting in 22 K of ________.
- A. Deleted space
- B. Cluster space
- C. Slack space
- D. Sector space
Answer: C
NEW QUESTION # 275
You work as an IT security auditor hired by a law firm in Boston to test whether you can gain access to sensitive information about the company clients. You have rummaged through their trash and found very little information. You do not want to set off any alarms on their network, so you plan on performing passive foot printing against their Web servers. What tool should you use?
- A. Nmap
- B. Netcraft
- C. Dig
- D. Ping sweep
Answer: B
NEW QUESTION # 276
Simona has written a regular expression for the detection of web application-specific attack attempt that reads as /((\%3C)|<K(\%2F)|V)*[a-zO-9\%I*((\%3E)|>)/lx. Which of the following does the part (|\%3E)|>) look for?
- A. Opening angle bracket or its hex equivalent
- B. Closing angle bracket or its hex equivalent
- C. Forward slash for a closing tag or its hex equivalent
- D. Alphanumeric string or its hex equivalent
Answer: B
NEW QUESTION # 277
In a forensic examination of hard drives for digital evidence, what type of user is most likely to have the most file slack to analyze?
- A. one who has lots of allocation units per block or cluster
- B. one who uses hard disk writes on IRQ 13 and 21
- C. one who has NTFS 4 or 5 partitions
- D. one who uses dynamic swap file capability
Answer: A
NEW QUESTION # 278
An on-site incident response team is called to investigate an alleged case of computer tampering within their company. Before proceeding with the investigation, the CEO informs them that the incident will be classified as low level. How long will the team have to respond to the incident?
- A. Immediately
- B. Two working days
- C. Four hours
- D. One working day
Answer: D
NEW QUESTION # 279
What is the investigator trying to analyze if the system gives the following image as output?
- A. Currently active logon sessions
- B. Inactive logon sessions
- C. Details of users who can logon
- D. All the logon sessions
Answer: A
NEW QUESTION # 280
Robert needs to copy an OS disk snapshot of a compromised VM to a storage account in different region for further investigation. Which of the following should he use in this scenario?
- A. Azure CLI
- B. Azure Monitor
- C. Azure Active Directory
- D. Azure Portal
Answer: D
NEW QUESTION # 281
Identify the file system that uses $BitMap file to keep track of all used and unused clusters on a volume.
- A. NTFS
- B. FAT
- C. EXT
- D. FAT32
Answer: A
NEW QUESTION # 282
Which of the following Windows event logs record events related to device drives and hardware changes?
- A. Security log
- B. Application log
- C. System log
- D. Forwarded events log
Answer: C
NEW QUESTION # 283
Which password cracking technique uses every possible combination of character sets?
- A. Brute force attack
- B. Dictionary attack
- C. Rule-based attack
- D. Rainbow table attack
Answer: A
NEW QUESTION # 284
......
EC-COUNCIL 312-49v10 (Computer Hacking Forensic Investigator (CHFI-v10)) Exam is a certification exam designed for professionals who are interested in pursuing a career in computer forensics. 312-49v10 exam tests the candidate’s knowledge and skills in the field of computer forensics, including the ability to investigate and analyze digital evidence, as well as the ability to prevent, detect, and respond to cybercrime incidents.
EC-COUNCIL 312-49v10 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
Ace EC-COUNCIL 312-49v10 Certification with Actual Questions Jul 09, 2023 Updated: https://www.testpassed.com/312-49v10-still-valid-exam.html
CHFI v10 Certified Official Practice Test 312-49v10: https://drive.google.com/open?id=16MibdiZCvWKBxlF3VqRJMaAfWdNF3LeM