312-49 Exam Questions
696 real 312-49 exam questions with expert-verified answers and explanations. Page 9 of 14.
- Question #402Computer Forensics in Today's World
The objective of this act was to protect consumers personal financial information held by financial institutions and their service providers.
Gramm-Leach-Bliley ActFinancial data protectionLegal compliancePrivacy regulations - Question #403Network Forensics
Jim performed a vulnerability analysis on his network and found no potential problems. He runs another utility that executes exploits against his system to verify the results of th...
Vulnerability AnalysisSecurity TestingFalse NegativesExploitation - Question #404Computer Forensics in Today's World
It takes _____________ mismanaged case/s to ruin your professional reputation as a computer forensics examiner?
Professional reputationForensic examiner ethicsCase mismanagementProfessional responsibility - Question #405Network Forensics
You work as an IT security auditor hired by a law firm in Boston to test whether you can gain access to sensitive information about the company clients. You have rummaged through t...
Passive FootprintingInformation GatheringReconnaissanceOSINT - Question #406Network Forensics
What header field in the TCP/IP protocol stack involves the hacker exploit known as the Ping of Death?
Ping of DeathICMPDenial of Service (DoS)Network Protocols - Question #407Computer Forensics Investigation Process
If a suspect computer is located in an area that may have toxic chemicals, you must:
Scene SafetyHazardous MaterialsEvidence Collection SafetyIncident Response - Question #408Computer Forensics in Today's World
Julie is a college student majoring in Information Systems and Computer Science. She is currently writing an essay for her computer crimes class. Julie paper focuses on white- coll...
White-collar crimeCorporate crimeIndustrial espionageCrime types - Question #409Computer Forensics in Today's World
Jason is the security administrator of ACMA metal Corporation. One day he notices the company's Oracle database server has been compromised and the customer information along with...
Computer Crime InvestigationLaw Enforcement AgenciesCybercrime ReportingNational Infrastructure Protection - Question #410Computer Forensics Investigation Process
If you plan to startup a suspect's computer, you must modify the ___________ to ensure that you do not contaminate or alter data on the suspect's hard drive by booting to the hard...
Forensic PreservationBoot ProcessData ContaminationEvidence Integrity - Question #411Computer Forensics in Today's World
Why would a company issue a dongle with the software they sell?
DongleCopyright ProtectionSoftware LicensingDRM - Question #412Network Forensics
A honey pot deployed with the IP 172.16.1.108 was compromised by an attacker . Given below is an excerpt from a Snort binary capture of the attack. Decipher the activity carried ou...
Packet AnalysisNetwork ReconnaissanceSnort LogsPort Scanning - Question #413Disk Forensics
Melanie was newly assigned to an investigation and asked to make a copy of all the evidence from the compromised system. Melanie did a DOS copy of all the files on the system. What...
Digital Forensics BasicsEvidence AcquisitionDisk ImagingForensic Best Practices - Question #414Network Forensics
Harold is finishing up a report on a case of network intrusion, corporate spying, and embezzlement that he has been working on for over six months. He is trying to find the right t...
Network espionageTerminologyCybercrime concepts - Question #415Network Forensics
Lance wants to place a honeypot on his network. Which of the following would be your recommendations?
HoneypotsNetwork SecurityDeception TechnologyIntrusion Detection - Question #416Network Forensics
What is the following command trying to accomplish? C:\> nmap -sU -p445 192.168.0.0/24
NmapPort ScanningUDPNetwork Scanning - Question #417Network Forensics
Simon is a former employee of Trinitron XML Inc. He feels he was wrongly terminated and wants to hack into his former company's network. Since Simon remembers some of the server na...
DNSZone TransferNetwork ReconnaissanceDIG command - Question #418Computer Forensics in Today's World
You are working for a local police department that services a population of 1,000,000 people and you have been given the task of building a computer forensics lab. How many law-enf...
Forensics LabStaffingLaw EnforcementResource Planning - Question #419Network Forensics
Tyler is setting up a wireless network for his business that he runs out of his home. He has followed all the directions from the ISP as well as the wireless router manual. He does...
Wireless networkingWi-Fi interference2.4 GHz bandNetwork troubleshooting - Question #420Report Writing & Presentation
An Expert witness gives an opinion if:
Expert WitnessLegal TestimonyRules of EvidenceForensic Expert Role - Question #421Computer Forensics Investigation Process
What will the following command produce on a website login page? SELECT email, passwd, login_id, full_name FROM members WHERE email = '[email protected]'; DROP TABLE members; -...
SQL InjectionDatabase SecurityWeb Application AttacksData Integrity - Question #422Mobile Forensics
All Blackberry email is eventually sent and received through what proprietary RIM-operated mechanism?
Blackberry architectureMobile emailProprietary communication - Question #423Network Forensics
At what layer of the OSI model do routers function on?
OSI ModelRoutersNetwork LayerNetworking Fundamentals - Question #424Network Forensics
In a virtual test environment, Michael is testing the strength and security of BGP using multiple routers to mimic the backbone of the Internet. This project will help him write hi...
BGPNetwork RoutingDoS AttackNetwork Resilience - Question #425Disk Forensics
If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system while doing an investigation, what can you conclude?
File analysisLinux forensicsRootkit indicatorsForensic methodology - Question #426Network Forensics
George is performing security analysis for Hammond and Sons LLC. He is testing security vulnerabilities of their wireless network. He plans on remaining as "stealthy" as possible d...
NessusVulnerability ScanningStealth ScanNetwork Reconnaissance - Question #427Disk Forensics
One technique for hiding information is to change the file extension from the correct one to one that might not be noticed by an investigator. For example, changing a .jpg extensio...
File identificationFile signaturesDigital evidence analysisObfuscation detection - Question #428Network Forensics
Larry is an IT consultant who works for corporations and government agencies. Larry plans on shutting down the city's network using BGP devices and zombies? What type of Penetratio...
DoS AttackDDoSPenetration TestingBGP - Question #429Computer Forensics in Today's World
____________________ is simply the application of Computer Investigation and analysis techniques in the interests of determining potential legal evidence.
Computer Forensics DefinitionDigital EvidenceInvestigation Techniques - Question #430Computer Forensics Investigation Process
Which of the following should a computer forensics lab used for investigations have?
Forensics labLab securityRestricted accessOperational security - Question #431Network Forensics
Jonathan is a network administrator who is currently testing the internal security of his network. He is attempting to hijack a session, using Ettercap, of a user connected to his...
Session HijackingHTTP ProtocolEttercapNetwork Security - Question #432Network Forensics
When reviewing web logs, you see an entry for esource not found?in the HTTP status code field. What is the actual error code that you wouldWhen reviewing web logs, you see an entry...
HTTP status codesWeb logsNetwork analysisError codes - Question #433Mobile Forensics
What encryption technology is used on Blackberry devices?Password Keeper?
Blackberry encryptionAESMobile device securityPassword Keeper - Question #434Disk Forensics
Printing under a Windows Computer normally requires which one of the following files types to be created?
Windows printingEMF fileSpooling file types - Question #435Disk Forensics
Which program is the oot loader?when Windows XP starts up?Which program is the ?oot loader?when Windows XP starts up?
Windows Boot ProcessBoot LoaderNTLDROperating Systems - Question #436Computer Forensics in Today's World
Corporate investigations are typically easier than public investigations because:
Corporate InvestigationsLegal AspectsWarrantless SearchInvestigation Scope - Question #437Computer Forensics Investigation Process
The rule of thumb when shutting down a system is to pull the power plug. However, it has certain drawbacks. Which of the following would that be?
System ShutdownData LossData IntegrityRAM - Question #438Network Forensics
You have been called in to help with an investigation of an alleged network intrusion. After questioning the members of the company ITYou have been called in to help with an invest...
Network ForensicsOSI ModelRoutersPacket Capture - Question #439Network Forensics
A computer forensics investigator is inspecting the firewall logs for a large financial institution that has employees working 24 hours a day, 7 days a week. What can the investiga...
Firewall logsLog analysisIntrusion detectionNetwork forensics - Question #440Network Forensics
As a security analyst you setup a false survey website that will reQuire users to create a username and a strong password. You send the link to all the employees of the company. Wh...
PhishingCredential HarvestingSocial EngineeringInformation Gathering - Question #441Computer Forensics Investigation Process
The police believe that Mevin Matthew has been obtaining unauthorized access to computers belonging to numerous computer software and computer operating systems manufacturers, cell...
Fourth AmendmentSearch and SeizureWarrantsLegal Procedures - Question #442Network Forensics
Sniffers that place NICs in promiscuous mode work at what layer of the OSI model?
SniffingPromiscuous ModeOSI ModelNetwork Interface Card - Question #443Computer Forensics Investigation Process
A state department site was recently attacked and all the servers had their disks erased. The incident response team sealed the area and commenced investigation. During evidence co...
Evidence HandlingForensic Best PracticesEvidence Integrity - Question #444Disk Forensics
This is the original file structure database that Microsoft originally designed for floppy disks. It is written to the outermost track of a disk and contains information about each...
File Allocation TableFATFile SystemsDisk Structure - Question #445Computer Forensics in Today's World
Which federal computer crime law specifically refers to fraud and related activity in connection with access devices like routers?
Federal LawComputer CrimeAccess Devices18 U.S.C. 1029 - Question #446Disk Forensics
How many sectors will a 125 KB file use in a FAT32 file system?
File systemsFAT32Sector sizeStorage allocation - Question #447Disk Forensics
Office documents (Word, Excel, PowerPoint) contain a code that allows tracking the MAC, or unique identifier, of the machine that created the document. What is that code called?
Document ForensicsMetadata AnalysisGlobally Unique IDDigital Artifacts - Question #448Computer Forensics in Today's World
You are a security analyst performing reconnaissance on a company you will be carrying out a penetration test for. You conduct a search for IT jobs on Dice.com and find the followi...
ReconnaissanceOSINTInformation VulnerabilityPenetration Testing - Question #449Network Forensics
Using Internet logging software to investigate a case of malicious use of computers, the investigator comes across some entries that appear odd. From the log, the investigator can...
Parameter TamperingWeb Application AttacksDigital ForensicsLog Analysis - Question #450Network Forensics
Frank is working on a vulnerability assessment for a company on the West coast. The company hired Frank to assess its network security through scanning, pen tests, and vulnerabilit...
CVEVulnerability identificationIDS logsVulnerability assessment - Question #451Network Forensics
You have been asked to investigate after a user has reported a threatening e-mail they have received from an external source. Which of the following are you most interested in when...
Email ForensicsEmail Header AnalysisSource TracingDigital Investigation