[2025] Use Valid Exam 312-49v11 by Lead1Pass Books For Free Website [Q25-Q50]

Share

[2025] Use Valid Exam 312-49v11 by Lead1Pass Books For Free Website

Free Certified Ethical Hacker 312-49v11 Official Cert Guide PDF Download

NEW QUESTION # 25
An Expert witness gives an opinion if:

  • A. The Opinion, inferences or conclusions depend on special knowledge, skill or training not within the ordinary experience of lay jurors
  • B. To stimulate discussion between the consulting expert and the expert witness
  • C. To define the issues of the case for determination by the finder of fact
  • D. To deter the witness form expanding the scope of his or her investigation beyond the requirements of the case

Answer: A


NEW QUESTION # 26
Which of the following methods of mobile device data acquisition captures all the data present on the device, as well as all deleted data and access to unallocated space?

  • A. Physical acquisition
  • B. Direct acquisition
  • C. Logical acquisition
  • D. Manual acquisition

Answer: A


NEW QUESTION # 27
Where is the startup configuration located on a router?

  • A. Static RAM
  • B. NVRAM
  • C. Dynamic RAM
  • D. BootROM

Answer: B


NEW QUESTION # 28
While searching through a computer under investigation, you discover numerous files that appear to have had the first letter of the file name replaced by the hex code byte 5h.
What does this indicate on the computer?

  • A. The files are corrupt and cannot be recovered
  • B. The files have been marked as read-only
  • C. The files have been marked as hidden
  • D. The files have been marked for deletion

Answer: D


NEW QUESTION # 29
Which of the following files store the MySQL database data permanently, including the data that had been deleted, helping the forensic investigator in examining the case and finding the culprit?

  • A. iblog
  • B. ibdata1
  • C. mysql-log
  • D. mysql-bin

Answer: B


NEW QUESTION # 30
A computer forensics investigator is analyzing a hard disk drive (HDD) that is suspected to contain evidence of criminal activity. The HDD has 20,000 cylinders, 16 heads, and 63 sectors per track, with each sector having 512 bytes. During the analysis, the investigator discovered a file of 1.5KB in size on the disk. How many sectors are allocated for the file, and what could be the consequences of such allocation for the investigation?

  • A. 3 sectors; the file might be fragmented, making it harder to retrieve
  • B. 4 sectors; it may cause inefficiency in space utilization on the disk
  • C. 3 sectors; it may increase the retrieval time due to increased sector overhead
  • D. 2 sectors; the file might be fragmented, making it harder to retrieve

Answer: B


NEW QUESTION # 31
Which of the following tools is used to dump the memory of a running process, either immediately or when an error condition occurs?

  • A. FATKit
  • B. Coreography
  • C. Cachelnf
  • D. Belkasoft Live RAM Capturer

Answer: D


NEW QUESTION # 32
Billy, a computer forensics expert, has recovered a large number of DBX files during forensic investigation of a laptop. Which of the following email clients he can use to analyze the DBX files?

  • A. Mozilla Thunderoird
  • B. Microsoft Outlook Express
  • C. Eudora
  • D. Microsoft Outlook

Answer: B


NEW QUESTION # 33
Subscriber Identity Module (SIM) is a removable component that contains essential information about the subscriber. Its main function entails authenticating the user of the cell phone to the network to gain access to subscribed services. SIM contains a 20-digit long Integrated Circuit Card identification (ICCID) number, identify the issuer identifier Number from the ICCID below.

  • A. 0
  • B. 1
  • C. 2
  • D. 001451548

Answer: C


NEW QUESTION # 34
What is a SCSI (Small Computer System Interface)?

  • A. A "plug-and-play" interface, which allows a device to be added without an adapter card and without rebooting the computer
  • B. A standard electronic interface used between a computer motherboard's data paths or bus and the computer's disk storage devices
  • C. A point-to-point serial bi-directional interface for transmitting data between computer devices at data rates of up to 4 Gbps
  • D. A set of ANSI standard electronic interfaces that allow personal computers to communicate with peripheral hardware such as disk drives, tape drives. CD-ROM drives, printers, and scanners

Answer: D


NEW QUESTION # 35
Which of the following tool enables a user to reset his/her lost admin password in a Windows system?

  • A. Active@ Password Changer
  • B. Advanced Office Password Recovery
  • C. Passware Kit Forensic
  • D. Smartkey Password Recovery Bundle Standard

Answer: A


NEW QUESTION # 36
You are assigned a task to examine the log files pertaining to MyISAM storage engine. While examining, you are asked to perform a recovery operation on a MyISAM log file. Which among the following MySQL Utilities allow you to do so?

  • A. myisamaccess
  • B. myisamchk
  • C. mysqldump
  • D. myisamlog

Answer: D


NEW QUESTION # 37
Frank, a cloud administrator in his company, needs to take backup of the OS disks of two Azure VMs that store business-critical data.
Which type of Azure blob storage can he use for this purpose?

  • A. Medium blob
  • B. Block blob
  • C. Page blob
  • D. Append blob

Answer: C


NEW QUESTION # 38
Which is a standard procedure to perform during all computer forensics investigations?

  • A. With the hard drive removed from the suspect PC, check the date and time in the system RAM
  • B. With the hard drive in the suspect PC, check the date and time in the File Allocation Table
  • C. With the hard drive removed from the suspect PC, check the date and time in the system CMOS
  • D. With the hard drive in the suspect PC, check the date and time in the system CMOS

Answer: C


NEW QUESTION # 39
When should an MD5 hash check be performed when processing evidence?

  • A. Before the evidence examination has been completed
  • B. After the evidence examination has been completed
  • C. Before and after evidence examination
  • D. On an hourly basis during the evidence examination

Answer: C


NEW QUESTION # 40
A steganographic file system is a method to store the files in a way that encrypts and hides the data without the knowledge of others

  • A. False
  • B. True

Answer: B


NEW QUESTION # 41
In Linux OS, different log files hold different information, which help the investigators to analyze various issues during a security incident. What information can the investigators obtain from the log file var/log/dmesg?

  • A. Debugging log messages
  • B. Global system messages
  • C. Kernel ring buffer information
  • D. All mail server message logs

Answer: C


NEW QUESTION # 42
Which of the following commands shows you all of the network services running on Windows- based servers?

  • A. Net share
  • B. Net use
  • C. Net start
  • D. Net Session

Answer: C


NEW QUESTION # 43
Jacky encrypts her documents using a password. It is known that she uses her daughter's year of birth as part of the password. Which password cracking technique would be optimal to crack her password?

  • A. Syllable attack
  • B. Brute force attack
  • C. Rule-based attack
  • D. Hybrid attack

Answer: C


NEW QUESTION # 44
In an investigation into a cyber-attack incident, you are a Computer Hacking Forensics Investigator tasked with gathering digital evidence. The targeted system has been turned off unexpectedly, and you know the system was running a crucial process during the attack. Which types of evidence might be lost due to the system being switched off?

  • A. Volatile data such as command history and process-to-port mapping, but not non-volatile data like event logs and hidden files
  • B. Non-volatile data such as event logs and hidden files, but not volatile data like command history and process-to-port mapping
  • C. Neither volatile data, such as command history and process-to-port mapping, nor non-volatile data, like event logs and hidden files
  • D. Both volatile data, such as command history and process-to-port mapping, and non-volatile data, like event logs and hidden files

Answer: A


NEW QUESTION # 45
What is the First Step required in preparing a computer for forensics investigation?

  • A. Secure any relevant media
  • B. Suspend automated document destruction and recycling policies that may pertain to any relevant media or users at Issue
  • C. Identify the type of data you are seeking, the Information you are looking for, and the urgency level of the examination
  • D. Do not turn the computer off or on, run any programs, or attempt to access data on a computer

Answer: D


NEW QUESTION # 46
Consider a scenario where a forensic investigator is performing malware analysis on a memory dump acquired from a victims computer. The investigator uses Volatility Framework to analyze RAM contents; which plugin helps investigator to identify hidden processes or injected code/DLL in the memory dump?

  • A. mallist
  • B. malfind
  • C. malscan
  • D. pslist

Answer: B


NEW QUESTION # 47
What is the name of the first reserved sector in File allocation table?

  • A. BIOS Parameter Block
  • B. Volume Boot Record
  • C. Master Boot Record
  • D. Partition Boot Sector

Answer: C


NEW QUESTION # 48
An attack vector is a path or means by which an attacker can gain access to computer or network resources in order to deliver an attack payload or cause a malicious outcome.

  • A. False
  • B. True

Answer: B


NEW QUESTION # 49
Daryl, a computer forensics investigator, has just arrived at the house of an alleged computer hacker. Daryl takes pictures and tags all computer and peripheral equipment found in the house.
Daryl packs all the items found in his van and takes them back to his lab for further examination.
At his lab, Michael his assistant helps him with the investigation. Since Michael is still in training, Daryl supervises all of his work very carefully. Michael is not quite sure about the procedures to copy all the data off the computer and peripheral devices. How many data acquisition tools should Michael use when creating copies of the evidence for the investigation?

  • A. Three
  • B. Four
  • C. One
  • D. Two

Answer: D


NEW QUESTION # 50
......

EC-COUNCIL 312-49v11 Official Cert Guide PDF: https://crucialexams.lead1pass.com/EC-COUNCIL/312-49v11-practice-exam-dumps.html