2023 Valid 312-49v10 FREE EXAM DUMPS QUESTIONS & ANSWERS
Free 312-49v10 Exam Braindumps EC-COUNCIL Pratice Exam
NEW QUESTION # 55
Which of the following files stores information about a local Google Drive installation such as User email ID, Local Sync Root Path, and Client version installed?
- A. config.db
- B. sigstore.db
- C. Sync_config.db
- D. filecache.db
Answer: A
NEW QUESTION # 56
You are assigned to work in the computer forensics lab of a state police agency. While working on a high profile criminal case, you have followed every applicable procedure, however your boss is still concerned that the defense attorney might question whether evidence has been changed while at the lab. What can you do to prove that the evidence is the same as it was when it first entered the lab?
- A. make an MD5 hash of the evidence and compare it with the original MD5 hash that was taken when the evidence first entered the lab
- B. make an MD5 hash of the evidence and compare it to the standard database developed by NIST
- C. there is no reason to worry about this possible claim because state labs are certified
- D. sign a statement attesting that the evidence is the same as it was when it entered the lab
Answer: A
NEW QUESTION # 57
This is original file structure database that Microsoft originally designed for floppy disks. It is written to the outermost track of a disk and contains information about each file stored on the drive.
- A. Disk Operating System (DOS)
- B. Master File Table (MFT)
- C. File Allocation Table (FAT)
- D. Master Boot Record (MBR)
Answer: C
NEW QUESTION # 58
Where does Encase search to recover NTFS files and folders?
- A. MBR
- B. Slack space
- C. HAL
- D. MFT
Answer: D
NEW QUESTION # 59
Identify the location of Recycle Bin on a Windows 7 machine that uses NTFS file system to store and retrieve files on the hard disk.
- A. C:\RECYCLED
- B. DriveARECYCLED
- C. Drive:\$Recycle.Bin
- D. DriveARECYCLER
Answer: C
NEW QUESTION # 60
Richard is extracting volatile data from a system and uses the command doskey/history. What is he trying to extract?
- A. History of the browser
- B. Previously typed commands
- C. Passwords used across the system
- D. Events history
Answer: B
NEW QUESTION # 61
What happens lo the header of the file once It Is deleted from the Windows OS file systems?
- A. The OS replaces the entire hex byte coding of the file.
- B. The OS replaces the first letter of a deleted file name with a hex byte code: E5h
- C. The OS replaces the second letter of a deleted file name with a hex byte code: Eh5
- D. The hex byte coding of the file remains the same, but the file location differs
Answer: B
NEW QUESTION # 62
Gary is checking for the devices connected to USB ports of a suspect system during an investigation. Select the appropriate tool that will help him document all the connected devices.
- A. DevScan
- B. fsutil
- C. Devcon
- D. Reg.exe
Answer: C
NEW QUESTION # 63
When installed on a Windows machine, which port does the Tor browser use to establish a network connection via Tor nodes?
- A. 9150/9151
- B. 49667/49668
- C. 0
- D. 49664/49665
Answer: A
NEW QUESTION # 64
____________________ is simply the application of Computer Investigation and analysis techniques in the interests of determining potential legal evidence.
- A. Network Forensics
- B. Event Reaction
- C. Incident Response
- D. Computer Forensics
Answer: D
NEW QUESTION # 65
What is the investigator trying to analyze if the system gives the following image as output?
- A. Details of users who can logon
- B. Inactive logon sessions
- C. Currently active logon sessions
- D. All the logon sessions
Answer: C
NEW QUESTION # 66
Which of the following tool can the investigator use to analyze the network to detect Trojan activities?
- A. RAM Computer
- B. TRIPWIRE
- C. Capsa
- D. Regshot
Answer: C
NEW QUESTION # 67
MAC filtering is a security access control methodology, where a ___________ is assigned to each network card to determine access to the network.
- A. 16-bit address
- B. 48-bit address
- C. 32-bit address
- D. 24-bit address
Answer: B
NEW QUESTION # 68
Which of the following tool creates a bit-by-bit image of an evidence media?
- A. FileMerlin
- B. AccessData FTK Imager
- C. Recuva
- D. Xplico
Answer: B
NEW QUESTION # 69
After passing her CEH exam, Carol wants to ensure that her network is completely secure. She implements a DMZ, stateful firewall, NAT, IPSEC, and a packet filtering firewall. Since all security measures were taken, none of the hosts on her network can reach the Internet. Why is that?
- A. NAT does not work with stateful firewalls
- B. Stateful firewalls do not work with packet filtering firewalls
- C. NAT does not work with IPSEC
- D. IPSEC does not work with packet filtering firewalls
Answer: C
NEW QUESTION # 70
Jeff is a forensics investigator for a government agency's cyber security office. Jeff Is tasked with acquiring a memory dump of a Windows 10 computer that was involved In a DDoS attack on the government agency's web application. Jeff is onsite to collect the memory. What tool could Jeff use?
- A. RAM Mapper
- B. Memcheck
- C. Autopsy
- D. Volatility
Answer: D
NEW QUESTION # 71
A cybercriminal is attempting to remove evidence from a Windows computer. He deletes the file evldence1.doc. sending it to Windows Recycle Bin. The cybercriminal then empties the Recycle Bin. After having been removed from the Recycle Bin. what will happen to the data?
- A. The data will become corrupted, making it unrecoverable
- B. The data will be overwritten with zeroes
- C. The data will be moved to new clusters in unallocated space
- D. The data will remain in its original clusters until it is overwritten
Answer: D
NEW QUESTION # 72
Mark works for a government agency as a cyber-forensic investigator. He has been given the task of restoring data from a hard drive. The partition of the hard drive was deleted by a disgruntled employee In order to hide their nefarious actions. What tool should Mark use to restore the data?
- A. iskvlew
- B. Diskmon D
- C. EFSDump
- D. R-Studio
Answer: D
NEW QUESTION # 73
The investigator wants to examine changes made to the system's registry by the suspect program. Which of the following tool can help the investigator?
- A. Regshot
- B. What's Running
- C. TRIPWIRE
- D. RAM Capturer
Answer: A
NEW QUESTION # 74
Office documents (Word, Excel, PowerPoint) contain a code that allows tracking the MAC, or unique identifier, of the machine that created the document. What is that code called?
- A. the Personal Application Protocol
- B. the Microsoft Virtual Machine Identifier
- C. the Individual ASCII String
- D. the Globally Unique ID
Answer: D
NEW QUESTION # 75
Which of the following file formats allows the user to compress the acquired data as well as keep it randomly accessible?
- A. Advanced Forensics Format (AFF)
- B. Proprietary Format
- C. Advanced Forensic Framework 4
- D. Generic Forensic Zip (gfzip)
Answer: D
NEW QUESTION # 76
......
Prepare For Realistic 312-49v10 Dumps PDF - 100% Passing Guarantee: https://www.trainingdump.com/EC-COUNCIL/312-49v10-practice-exam-dumps.html
Practice Test for 312-49v10 Certification Real 2023 Mock Exam: https://drive.google.com/open?id=1t5MIpTQIqUFeh66-qG9bYKge3h5bIMjO