EC-COUNCIL Computer Hacking Forensic Investigator - EC0-349 Exam Practice Test

Computer security logs contain information about the events occurring within an organization's systems and networks. Application and Web server log files are useful in detecting web attacks.
The source, nature, and time of the attack can be determined by _________of the compromised system.
Correct Answer: A
When conducting computer forensic analysis, you must guard against ______________ So that you remain focused on the primary job and insure that the level of work does not increase beyond what was originally expected.
Correct Answer: B
What binary coding is used most often for e-mail purposes?
Correct Answer: B
A small law firm located in the Midwest has possibly been breached by a computer hacker looking to obtain information on their clientele. The law firm does not have any on-site IT employees, but wants to search for evidence of the breach themselves to prevent any possible media attention. Why would this not be recommended?
Correct Answer: D
When making the preliminary investigations in a sexual harassment case, how many investigators are you recommended having?
Correct Answer: A
After passively scanning the network of Department of Defense (DoD), you switch over to active scanning to identify live hosts on their network. DoD is a large organization and should respond to any number of scans. You start an ICMP ping sweep by sending an IP packet to the broadcast address. Only five hosts responds to your ICMP pings; definitely not the number of hosts you were expecting. Why did this ping sweep only produce a few responses?
Correct Answer: A
Which program is the oot loader?when Windows XP starts up?Which program is the ?oot loader?when Windows XP starts up?
Correct Answer: B
Which of the following email headers specifies an address for mailer-generated errors, like "no such user" bounce messages, to go to (instead of the sender's address)?
Correct Answer: D
Jones had been trying to penetrate a remote production system for the past two weeks. This time however, he is able to get into the system. He was able to use the system for a period of three weeks. However law enforcement agencies were recording his every activity and this was later presented as evidence. The organization had used a virtual environment to trap Jones. What is a virtual environment?
Correct Answer: D
Where does Encase search to recover NTFS files and folders?
Correct Answer: A
During the course of a corporate investigation, you find that an employee is committing a federal crime. Can the employer file a criminal complain with the police?
Correct Answer: C
When reviewing web logs, you see an entry for resource not found in the HTTP status code filed.
What is the actual error code that you would see in the log for resource not found?
Correct Answer: C
While working for a prosecutor, What do you think you should do if the evidence you found appears to be exculpatory and is not being released to the defense ?
Correct Answer: A
You have been asked to investigate after a user has reported a threatening e-mail they have received from an external source. Which of the following are you most interested in when trying to trace the source of the message?
Correct Answer: A
0
0
0
0