312-49V11 Exam Questions
179 real 312-49V11 exam questions with expert-verified answers and explanations. Page 4 of 4.
- Question #152Defeating Anti-Forensics Techniques
During a forensic investigation of a system suspected to be involved in cybercrime, the investigator observes discrepancies between the $STANDARD_INFORMATION and $FILE_NAME creatio...
anti-forensicstimestamp manipulationBCWipeNTFS metadata discrepancy - Question #153Computer Forensics Investigation Process
In the middle of a high-pressure cybercrime investigation, you stumble upon a cryptic message. It appears to be encoded with the ASCII standard. The encrypted message contains a co...
ASCII encodingcharacter encodingdata representationcryptography basics - Question #154Computer Forensics Investigation Process
After a major data breach in a financial institution, a forensic investigator is brought in to determine the source and the extent of the breach. The investigator needs to ensure c...
Gramm-Leach-Bliley Actfinancial data privacyregulatory compliancenon-public personal information - Question #155Computer Forensics Investigation Process
An experienced computer forensics investigator, Vince, was tasked with examining digital evidence associated with a serious corporate cybercrime. He successfully seized and bagged...
evidence transportationchain of custodyelectronic evidence handlingevidence integrity - Question #156Computer Forensics Investigation Process
A Computer Hacking Forensic Investigator (CHFI) arrives at the crime scene in an incident involving cybercrime. While performing the initial search of the scene, the investigator s...
crime scene investigationsearch and seizure loginitial responseevidence documentation - Question #157Computer Forensics Investigation Process
An organization is working to minimize the eDiscovery costs associated with the extensive analysis of large sets of electronic data. To achieve this, the organization employs advan...
eDiscoverytechnology-assisted reviewdata reductionTAR - Question #158Windows Forensics
Sarah, a security analyst, is reviewing the security audit logs from a Windows machine to detect unauthorized activities. She comes across an event with the ID 4663 in the Windows...
Windows Event ID 4663object access auditingsecurity event logsregistry key access - Question #159Windows Forensics
As a cybersecurity investigator, you're conducting system behavior analysis on a suspect system to detect hidden Trojans. One method involves monitoring startup programs to identif...
bcdeditboot manager entriesTrojan detectionstartup programs - Question #160Data Acquisition and Duplication
Before data acquisition, media must be sanitized to erase previous information. Industry standards dictate data destruction methods based on sensitivity levels. Investigators follo...
data sanitizationmedia sanitizationNIST SP 800-88data acquisition - Question #161Defeating Anti-Forensics Techniques
During a forensic investigation into a suspected data breach, the investigator discovers that the attacker has intentionally tampered with the digital storage media to erase eviden...
anti-forensicsdata substitutionevidence tamperingdata overwriting - Question #162Computer Forensics Investigation Process
During a forensic investigation of a compromised system, the investigator is analyzing various forensic artifacts to determine the nature and scope of the attack. The investigator...
log file anomaliesforensic artifactssecurity event logsIDS alerts - Question #163Dark Web Forensics
Lucas, a forensics expert, was extracting artifacts related to the Tor browser from a memory dump obtained from a victim's system. During his investigation, he used a forensic tool...
Tor browser artifactsmemory forensicsdark web forensicsbrowser uninstall - Question #164Cloud Forensics
During a forensic investigation into a cyberattack that compromised a company's sensitive data, the investigator discovers that the organization uses a cloud-based solution for man...
Identity-as-a-Servicecloud service modelsSSOcloud forensics - Question #165Understanding Hard Disks and File Systems
John, a system administrator at a growing e-commerce company, is tasked with configuring a RAID 5 array to support the company's increasing data storage needs. He needs to set up t...
RAID 5parity data distributionstorage redundancydrive array - Question #166Computer Forensics in Today's World
During a cybercrime investigation, forensic analysts discover evidence of data theft from a company's network. The attackers have utilized sophisticated techniques to cover their t...
forensics objectivesdeleted file recoverydigital evidencecybercrime investigation - Question #167Windows Forensics
A CHFI professional is investigating a data breach in a Windows 10 system. The initial analysis revealed some alterations in the system event logs. As part of the investigation, th...
wevtutilevent log tamperingEVTX fileWindows security logs - Question #168Data Acquisition and Duplication
In a computer forensics investigation, an investigator is dealing with a system that has been recently shut down. The data they need is of a non-volatile nature. Which type of data...
dead acquisitionnon-volatile datapowered-off systemdata acquisition methodology - Question #169Computer Forensics in Today's World
Dave, a Computer Hacking Forensic Investigator (CHFI), is investigating a case of suspected cybercrime in a major organization. During the investigation, he identified a suspect s...
search warrantlegal authorizationprivacy lawsforensics compliance - Question #170Windows Forensics
A CHFI has been asked to recover browser history from a seized Microsoft Edge browser on a Windows system. This is important to pinpoint the suspect's online activities. The suspec...
Microsoft Edge forensicsbrowser history recoveryWebCacheBrowsingHistoryView - Question #171Network Forensics
During an investigation, a forensics analyst discovers an unusual increase in outbound network traffic, network traffic traversing on non-standard ports, and multiple failed login...
indicators of compromisenetwork forensicsintrusion investigationlog analysis - Question #172Windows Forensics
A forensics investigator is studying the Event ID logs on a domain controller for a corporation, following a suspected security breach. He notices that a domain user account was cr...
Windows Event ID 624domain controller logsuser account creationaudit policy - Question #173Malware Forensics
A cybersecurity investigator is analyzing a sophisticated malware program that has infiltrated a corporate network. The malware appears to use multiple propagation methods and expl...
malware analysissandbox environmentmalware behaviorcontrolled lab - Question #174Computer Forensics in Today's World
As a newly appointed Quality Manager in a digital forensics lab. you are reviewing the lab's current Quality Assurance Manual. You notice that the last update to the Quality Manage...
quality management systemforensics lab QAQA manualASCLD accreditation - Question #175Investigating Email Crimes
In a corporate setting, Bob, a software engineer, urgently needs to send an encrypted email containing sensitive project details to Alice, his project manager. Bob carefully compos...
email forensicsMTA serversSMTP communicationemail flow - Question #176Windows Forensics
Kaysen, a forensic investigator, was examining a compromised Windows machine. During the investigation, Kaysen needs to collect crucial information about the applications and servi...
volatile evidenceWindows forensicsactive processestasklist command - Question #177Cloud Forensics
During a digital forensics investigation, suspicious activity is detected in a Google Cloud Platform (GCP) environment. The investigation team gains access to logs and metadata fro...
cloud forensicsGCP logsmetadata analysisuser activity tracking - Question #178Defeating Anti-Forensics Techniques
A digital forensics investigator is tasked with analyzing a compromised Mac computer recovered from a cybercrime scene. However, upon examination, the investigator discovers that t...
anti-forensicslog tamperingdata manipulationMac forensics - Question #179Malware Forensics
In a digital forensics investigation, persistent malware is discovered on a compromised system despite repeated attempts to remove it. The malware reinstalls itself upon system reb...
malware persistencemalware forensicspersistence mechanismsincident response - Question #180Understanding Hard Disks and File Systems
Hazel, a forensic investigator, is working with a Windows computer that has recently had several files deleted. She is tasked with determining whether the contents of these deleted...
file recoverydeleted filesFAT file systemWindows forensics