[UPDATED] EC-COUNCIL 312-49v10 Certification Exam Questions
Quickly and Easily Pass EC-COUNCIL Exam with 312-49v10 real Dumps
NEW QUESTION # 263
Kimberly is studying to be an IT security analyst at a vocational school in her town. The school offers many different programming as well as networking languages. What networking protocol language should she learn that routers utilize?
- A. ATM
- B. BPG
- C. UDP
- D. OSPF
Answer: D
NEW QUESTION # 264
Diskcopy is:
- A. a standard MS-DOS command
- B. dd copying tool
- C. Digital Intelligence utility
- D. a utility by AccessData
Answer: A
Explanation:
diskcopy is a STANDARD DOS utility. C:\WINDOWS>diskcopy /? Copies the contents of one floppy disk to another.
NEW QUESTION # 265
An employee is attempting to wipe out data stored on a couple of compact discs (CDs) and digital video discs (DVDs) by using a large magnet. You inform him that this method will not be effective in wiping out the data because CDs and DVDs are ______________ media used to store large amounts of data and are not affected by the magnet.
- A. optical
- B. logical
- C. anti-magnetic
- D. magnetic
Answer: A
NEW QUESTION # 266
%3cscript%3ealert("XXXXXXXX")%3c/script%3e is a script obtained from a Cross-Site Scripting attack. What type of encoding has the attacker employed?
- A. Double encoding
- B. Unicode
- C. Hex encoding
- D. Base64
Answer: C
NEW QUESTION # 267
When investigating a wireless attack, what information can be obtained from the DHCP logs?
- A. If any computers on the network are running in promiscuous mode
- B. MAC address of the attacker
- C. The operating system of the attacker and victim computers
- D. IP traffic between the attacker and the victim
Answer: B
NEW QUESTION # 268
____________________ is simply the application of Computer Investigation and analysis techniques in the interests of determining potential legal evidence.
- A. Event Reaction
- B. Network Forensics
- C. Incident Response
- D. Computer Forensics
Answer: D
NEW QUESTION # 269
Windows identifies which application to open a file with by examining which of the following?
- A. The file Signature at the end of the file
- B. The file signature at the beginning of the file
- C. The File extension
- D. The file attributes
Answer: C
NEW QUESTION # 270
Ronald, a forensic investigator, has been hired by a financial services organization to Investigate an attack on their MySQL database server, which Is hosted on a Windows machine named WIN-DTRAI83202X. Ronald wants to retrieve information on the changes that have been made to the database. Which of the following files should Ronald examine for this task?
- A. WIN-DTRAI83202X-bin.nnnnnn
- B. relay-log.info
- C. WIN-DTRAl83202Xrelay-bin.index
- D. WIN-DTRAI83202Xslow.log
Answer: D
NEW QUESTION # 271
Which of the following file formats allows the user to compress the acquired data as well as keep it randomly accessible?
- A. Generic Forensic Zip (gfzip)
- B. Advanced Forensics Format (AFF)
- C. Advanced Forensic Framework 4
- D. Proprietary Format
Answer: A
NEW QUESTION # 272
Lance wants to place a honeypot on his network. Which of the following would be your recommendations?
- A. Use it on a system in an external DMZ in front of the firewall
- B. Use a system that has a dynamic addressing on the network
- C. It doesn't matter as all replies are faked
- D. Use a system that is not directly interacting with the router
Answer: C
NEW QUESTION # 273
You are the network administrator for a small bank in Dallas, Texas. To ensure network security, you enact a security policy that requires all users to have 14 character passwords. After giving your users 2 weeks notice, you change the Group Policy to force 14 character passwords. A week later you dump the SAM database from the standalone server and run a password-cracking tool against it. Over 99% of the passwords are broken within an hour. Why were these passwords cracked so Quickly?
- A. Passwords of 14 characters or less are broken up into two 7-character hashes
- B. The passwords that were cracked are local accounts on the Domain Controller
- C. Networks using Active Directory never use SAM databases so the SAM database pulled was empty
- D. A password Group Policy change takes at least 3 weeks to completely replicate throughout a network
Answer: A
NEW QUESTION # 274
Edgar is part of the FBI's forensic media and malware analysis team; he Is analyzing a current malware and Is conducting a thorough examination of the suspect system, network, and other connected devices. Edgar's approach Is to execute the malware code to know how It Interacts with the host system and Its Impacts on It. He is also using a virtual machine and a sandbox environment.
What type of malware analysis is Edgar performing?
- A. Malware disassembly
- B. VirusTotal analysis
- C. Dynamic malware analysis/behavioral analysis
- D. Static analysis
Answer: C
NEW QUESTION # 275
In a virtual test environment, Michael is testing the strength and security of BGP using multiple routers to mimic the backbone of the Internet. This project will help him write his doctoral thesis on "bringing down the Internet". Without sniffing the traffic between the routers, Michael sends millions of RESET packets to the routers in an attempt to shut one or all of them down. After a few hours, one of the routers finally shuts itself down. What will the other routers communicate between themselves?
- A. RESTART packets to the affected router to get it to power back up
- B. STOP packets to all other routers warning of where the attack originated
- C. The change in the routing fabric to bypass the affected router
- D. More RESET packets to the affected router to get it to power back up
Answer: C
NEW QUESTION # 276
Using Internet logging software to investigate a case of malicious use of computers, the investigator comes across some entries that appear odd.
From the log, the investigator can see where the person in question went on the Internet. From the log, it appears that the user was manually typing in different user ID numbers. What technique this user was trying?
- A. Parameter tampering
- B. SQL injection
- C. Cookie Poisoning
- D. Cross site scripting
Answer: A
NEW QUESTION # 277
When conducting computer forensic analysis, you must guard against ______________ So that you remain focused on the primary job and insure that the level of work does not increase beyond what was originally expected.
- A. Unauthorized expenses
- B. Overzealous marketing
- C. Hard Drive Failure
- D. Scope Creep
Answer: D
NEW QUESTION # 278
Madison is on trial for allegedly breaking into her university's internal network. The police raided her dorm room and seized all of her computer equipment. Madison's lawyer is trying to convince the judge that the seizure was unfounded and baseless. Under which US Amendment is Madison's lawyer trying to prove the police violated?
- A. The 10th Amendment
- B. The 5th Amendment
- C. The 1st Amendment
- D. The 4th Amendment
Answer: D
NEW QUESTION # 279
An attacker has compromised a cloud environment of a company and used the employee information to perform an identity theft attack. Which type of attack is this?
- A. Cloud as an object
- B. Cloud as a service
- C. Cloud as a tool
- D. Cloud as a subject
Answer: D
NEW QUESTION # 280
You are using DriveSpy, a forensic tool and want to copy 150 sectors where the starting sector is 1709 on the primary hard drive. Which of the following formats correctly specifies these sectors?
- A. 1:1709, 150
- B. 0:1000, 150
- C. 0:1709-1858
- D. 0:1709, 150
Answer: D
NEW QUESTION # 281
You work as an IT security auditor hired by a law firm in Boston to test whether you can gain access to sensitive information about the company clients. You have rummaged through their trash and found very little information. You do not want to set off any alarms on their network, so you plan on performing passive foot printing against their Web servers. What tool should you use?
- A. Nmap
- B. Ping sweep
- C. Netcraft
- D. Dig
Answer: C
NEW QUESTION # 282
Korey, a data mining specialist in a knowledge processing firm DataHub.com, reported his CISO that he has lost certain sensitive data stored on his laptop. The CISO wants his forensics investigation team to find if the data loss was accident or intentional. In which of the following category this case will fall?
- A. Criminal Investigation
- B. Both Civil and Criminal Investigations
- C. Administrative Investigation
- D. Civil Investigation
Answer: C
NEW QUESTION # 283
An investigator has found certain details after analysis of a mobile device. What can reveal the manufacturer information?
- A. International mobile subscriber identity (IMSI)
- B. Electronic Serial Number (ESN)
- C. Equipment Identity Register (EIR)
- D. Integrated circuit card identifier (ICCID)
Answer: B
NEW QUESTION # 284
......
Start your 312-49v10 Exam Questions Preparation: https://www.exam4labs.com/312-49v10-practice-torrent.html
Realistic 312-49v10 Dumps Questions To Gain Brilliant Result: https://drive.google.com/open?id=1ySzDj3xfnt8NtI5lARavhp21-MCsuFoR