312-49V9 Exam Questions
696 real 312-49V9 exam questions with expert-verified answers and explanations. Page 11 of 14.
- Question #505
The surface of a hard disk consists of several concentric rings known as tracks; each of these tracks has smaller partitions called disk blocks. What is the size of each block?
- Question #506
In Windows Security Event Log, what does an event id of 530 imply?
- Question #507
Which of the following technique creates a replica of an evidence media?
- Question #508
Which among the following search warrants allows the first responder to get the victim's computer information such as service records, billing records, and subscriber information f...
- Question #509
Which of the following tool creates a bit-by-bit image of an evidence media?
- Question #510
What is the location of the binary files required for the functioning of the OS in a Linux system?
- Question #511
Which of the following files DOES NOT use Object Linking and Embedding (OLE) technology to embed and link to other objects?
- Question #512
Ivanovich, a forensics investigator, is trying to extract complete information about running processes from a system. Where should he look apart from the RAM and virtual memory?
- Question #513
When marking evidence that has been collected with the "aaa/ddmmyy/nnnn/zz" format, what does the "nnnn" denote?
- Question #514
Which MySQL log file contains information on server start and stop?
- Question #515
Which of the following is a record of the characteristics of a file system, including its size, the block size, the empty and the filled blocks and their respective counts, the siz...
- Question #516
Bob works as information security analyst for a big finance company. One day, the anomaly- based intrusion detection system alerted that a volumetric DDOS targeting the main IP of...
- Question #517
Which of the following refers to the process of the witness being questioned by the attorney who called the latter to the stand?
- Question #518
Which rule requires an original recording to be provided to prove the content of a recording?
- Question #519
The investigator wants to examine changes made to the system's registry by the suspect program. Which of the following tool can help the investigator?
- Question #520
What does the part of the log, "% SEC-6-IPACCESSLOGP", extracted from a Cisco router represent?
- Question #521
Files stored in the Recycle Bin in its physical location are renamed as Dxy.ext, where "x" represents the ___________________.
- Question #522
Which of the following is an iOS Jailbreaking tool?
- Question #523
Which of the following Registry components include offsets to other cells as well as the LastWrite time for the key?
- Question #524
What is the default IIS log location?
- Question #525
Charles has accidentally deleted an important file while working on his Mac computer. He wants to recover the deleted file as it contains some of his crucial business secrets. Whic...
- Question #526
Which file is a sequence of bytes organized into blocks understandable by the system's linker?
- Question #527
Smith, a forensic examiner, was analyzing a hard disk image to find and acquire deleted sensitive files. He stumbled upon a $Recycle.Bin folder in the root directory of the disk. I...
- Question #528
Jason discovered a file named $RIYG6VR.doc in the C:\$Recycle.Bin\<USER SID>\ while analyzing a hard disk image for the deleted data. What inferences can he make from the file name...
- Question #529
Which among the following files provides email header information in the Microsoft Exchange server?
- Question #530
Which of the following attacks allows an attacker to access restricted directories, including application source code, configuration and critical system files, and to execute comma...
- Question #531
What is the size value of a nibble?
- Question #532
Which of the following tool enables a user to reset his/her lost admin password in a Windows system?
- Question #533
Which of the following acts as a network intrusion detection system as well as network intrusion prevention system?
- Question #534
In Steganalysis, which of the following describes a Known-stego attack?
- Question #535
Annie is searching for certain deleted files on a system running Windows XP OS. Where will she find the files if they were not completely deleted from the system?
- Question #536
Which of the following files stores information about a local Google Drive installation such as User email ID, Local Sync Root Path, and Client version installed?
- Question #537
An expert witness is a __________________ who is normally appointed by a party to assist the formulation and preparation of a party's claim or defense.
- Question #538
Smith, a network administrator with a large MNC, was the first to arrive at a suspected crime scene involving criminal use of compromised computers. What should be his first respon...
- Question #539
Which of the following is a database in which information about every file and directory on an NT File System (NTFS) volume is stored?
- Question #540
Adam, a forensic investigator, is investigating an attack on Microsoft Exchange Server of a large organization. As the first step of the investigation, he examined the PRIV.EDB fil...
- Question #541
Stephen is checking an image using Compare Files by The Wizard, and he sees the file signature is shown as FF D8 FF E1. What is the file type of the image?
- Question #542
Which of the following tools will help the investigator to analyze web server logs?
- Question #543
Which of the following files gives information about the client sync sessions in Google Drive on Windows?
- Question #544
Which among the following is an act passed by the U.S. Congress in 2002 to protect investors from the possibility of fraudulent accounting activities by corporations?
- Question #545
Richard is extracting volatile data from a system and uses the command doskey/history. What is he trying to extract?
- Question #546
Jacky encrypts her documents using a password. It is known that she uses her daughter's year of birth as part of the password. Which password cracking technique would be optimal to...
- Question #547
Which of the following tool can the investigator use to analyze the network to detect Trojan activities?
- Question #548
When a user deletes a file or folder, the system stores complete path including the original filename is a special hidden file called "INFO2" in the Recycled folder. If the INFO2 f...
- Question #549
What is the primary function of the tool CHKDSK in Windows that authenticates the file system reliability of a volume?
- Question #550
Which of the following tool enables data acquisition and duplication?
- Question #551
What does 254 represent in ICCID 89254021520014515744?
- Question #552
Shane has started the static analysis of a malware and is using the tool ResourcesExtract to find more details of the malicious program. What part of the analysis is he performing?
- Question #553
A master boot record (MBR) is the first sector ("sector zero") of a data storage device. What is the size of MBR?
- Question #554
Which password cracking technique uses every possible combination of character sets?