Dec-2021 EC-COUNCIL 312-49v10 Actual Questions and Braindumps [Q281-Q296]

Share

Dec-2021 EC-COUNCIL 312-49v10 Actual Questions and Braindumps

312-49v10 Dumps To Pass EC-COUNCIL Exam in 24 Hours - TestPassed


EC-COUNCIL 312-49v10 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Computer Forensics in Today’s World
  • Investigating Web Attacks
Topic 2
  • Computer Forensics Investigation Process
  • Dark Web Forensics
  • Mobile Forensics
Topic 3
  • Data Acquisition and Duplication
  • Linux and Mac Forensics
Topic 4
  • Understanding Hard Disks and File Systems
  • Investigating Email Crimes
Topic 5
  • Defeating Anti-Forensics Techniques
  • Malware Forensics
Topic 6
  • Database Forensics
  • Network Forensics
  • Windows Forensics

 

NEW QUESTION 281
When investigating a computer forensics case where Microsoft Exchange and Blackberry Enterprise server are used, where would investigator need to search to find email sent from a Blackberry device?

  • A. RIM Messaging center
  • B. Blackberry desktop redirector
  • C. Blackberry Enterprise server
  • D. Microsoft Exchange server

Answer: D

 

NEW QUESTION 282
What stage of the incident handling process involves reporting events?

  • A. Containment
  • B. Follow-up
  • C. Identification
  • D. Recovery

Answer: C

 

NEW QUESTION 283
Which type of attack is possible when attackers know some credible information about the victim's password, such as the password length, algorithms involved, or the strings and characters used in its creation?

  • A. Hybrid Password Guessing Attack
  • B. Rule-Based Attack
  • C. Brute-Forcing Attack
  • D. Dictionary Attack

Answer: B

 

NEW QUESTION 284
Hard disk data addressing is a method of allotting addresses to each _______ of data on a hard disk.

  • A. Operating system block
  • B. Physical block
  • C. Logical block
  • D. Hard disk block

Answer: B

 

NEW QUESTION 285
Pagefile.sys is a virtual memory file used to expand the physical memory of a computer. Select the registry path for the page file:

  • A. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\System Management
  • B. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
  • C. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters
  • D. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Device Management

Answer: B

 

NEW QUESTION 286
What type of analysis helps to identify the time and sequence of events in an investigation?

  • A. Functional
  • B. Time-based
  • C. Temporal
  • D. Relational

Answer: C

 

NEW QUESTION 287
Which of the following statements is true regarding SMTP Server?

  • A. SMTP Server breaks the recipient's address into Recipient's name and domain name before passing it to the DNS Server
  • B. SMTP Server breaks the recipient's address into Recipient's name and his/her initial before passing it to the DNS Server
  • C. SMTP Server breaks the recipient's address into Recipient's name and his/her designation before passing it to the DNS Server
  • D. SMTP Server breaks the recipient's address into Recipient's name and recipient's address before passing it to the DNS Server

Answer: A

 

NEW QUESTION 288
You are assisting in the investigation of a possible Web Server Hack. The company who called you stated that customers reported to them that whenever they entered the web address of the company in their browser, what they received was a porno graphic web site. The company checked the web server and nothing appears wrong. When you type in the IP address of the web site in your browser everything appears normal. What is the name of the attack that affects the DNS cache of the name resolution servers, resulting in those servers directing users to the wrong web site?

  • A. ARP Poisoning
  • B. DNS Poisoning
  • C. IP Spoofing
  • D. HTTP redirect attack

Answer: B

 

NEW QUESTION 289
Why is it a good idea to perform a penetration test from the inside?

  • A. Because 70% of attacks are from inside the organization
  • B. It is easier to hack from the inside
  • C. To attack a network from a hacker's perspective
  • D. It is never a good idea to perform a penetration test from the inside

Answer: A

 

NEW QUESTION 290
An attacker successfully gained access to a remote Windows system and plans to install persistent backdoors on it. Before that, to avoid getting detected in future, he wants to cover his tracks by disabling the last-accessed timestamps of the machine. What would he do to achieve this?

  • A. Run the command fsutil behavior set disablelastaccess 0
  • B. Set the registry value of HKLM\SYSTEM\CurrentControlSet\Control\FileSystem\NtfsDisableLastAccessUpdate to 1
  • C. Run the command fsutil behavior set enablelastaccess 0
  • D. Set the registry value of HKLM\SYSTEM\CurrentControlSet\Control\FileSystem\NtfsDisableLastAccessUpdate to 0

Answer: B

 

NEW QUESTION 291
Richard is extracting volatile data from a system and uses the command doskey/history. What is he trying to extract?

  • A. Events history
  • B. Passwords used across the system
  • C. Previously typed commands
  • D. History of the browser

Answer: C

 

NEW QUESTION 292
Adam, a forensic investigator, is investigating an attack on Microsoft Exchange Server of a large organization. As the first step of the investigation, he examined the PRIV.EDB file and found the source from where the mail originated and the name of the file that disappeared upon execution. Now, he wants to examine the MIME stream content. Which of the following files is he going to examine?

  • A. PRIV.EDB
  • B. PRIV.STM
  • C. gwcheck.db
  • D. PUB.EDB

Answer: B

 

NEW QUESTION 293
Identify the term that refers to individuals who, by virtue of their knowledge and expertise, express an independent opinion on a matter related to a case based on the information that is provided.

  • A. Defense Witness
  • B. Evidence Examiner
  • C. Forensic Examiner
  • D. Expert Witness

Answer: D

 

NEW QUESTION 294
What does the command "C:\>wevtutil gl <log name>" display?

  • A. Event logs are saved in .xml format
  • B. Event log record structure
  • C. Configuration information of a specific Event Log
  • D. List of available Event Logs

Answer: C

 

NEW QUESTION 295
What is the CIDR from the following screenshot?

  • A. /24A./24A./24
  • B. /8D./8D./8
  • C. /16 C./16 C./16
  • D. /32 B./32 B./32

Answer: B

 

NEW QUESTION 296
......

Download the Latest 312-49v10 Dump - 2021 312-49v10 Exam Question Bank: https://www.testpassed.com/312-49v10-still-valid-exam.html

Buy Latest 312-49v10 Exam Q&A PDF - One Year Free Update: https://drive.google.com/open?id=12bt_Bssf7y_TeIWtcx-8EiTOrQr8A0AB