312-49V9 Exam Questions
696 real 312-49V9 exam questions with expert-verified answers and explanations. Page 13 of 14.
- Question #605
Graphics Interchange Format (GIF) is a ____ RGB bitmap image format for images with up to 256 distinct colors per frame.
- Question #606
Hard disk data addressing is a method of allotting addresses to each _______ of data on a hard disk.
- Question #607
Which of the following standard represents a legal precedent regarding the admissibility of scientific examinations or experiments in legal cases?
- Question #608
Event correlation is the process of finding relevance between the events that produce a final result. What type of correlation will help an organization to correlate events across...
- Question #609
What malware analysis operation can the investigator perform using the jv16 tool?
- Question #610
Which of the following email headers specifies an address for mailer-generated errors, like "no such user" bounce messages, to go to (instead of the sender's address)?
- Question #611
Jacob is a computer forensics investigator with over 10 years of experience in investigations and has written over 50 articles on computer forensics. He has been called upon as a q...
- Question #612
When a user deletes a file, the system creates a $I file to store its details. What detail does the $I file not contain?
- Question #613
Raw data acquisition format creates _________ of a data set or suspect drive.
- Question #614
CAN-SPAM act requires that you:
- Question #615
Which of the following registry hive gives the configuration information about which application was used to open various files on the system?
- Question #616
Select the tool appropriate for examining the dynamically linked libraries of an application or malware.
- Question #617
Which among the following U.S. laws requires financial institutions--companies that offer consumers financial products or services such as loans, financial or investment advice, or...
- Question #618
Which of the following application password cracking tool can discover all password-protected items on a computer and decrypts them?
- Question #619
An investigator has found certain details after analysis of a mobile device. What can reveal the manufacturer information?
- Question #620
Which command line tool is used to determine active network connections?
- Question #621
Which of the following processes is part of the dynamic malware analysis?
- Question #622
Investigators can use the Type Allocation Code (TAC) to find the model and origin of a mobile device. Where is TAC located in mobile devices?
- Question #623
What do you call the process in which an attacker uses magnetic field over the digital media device to delete any previously stored data?
- Question #624
Which of the following tool can reverse machine code to assembly language?
- Question #625
Which of the following file formats allows the user to compress the acquired data as well as keep it randomly accessible?
- Question #626
What is the investigator trying to view by issuing the command displayed in the following screenshot?
- Question #627
Which layer of iOS architecture should a forensics investigator evaluate to analyze services such as Threading, File Access, Preferences, Networking and high-level features?
- Question #628
Which command can provide the investigators with details of all the loaded modules on a Linux- based system?
- Question #629
In a Linux-based system, what does the command "Last -F" display?
- Question #630
Which of the following examinations refers to the process of providing the opposing side in a trial the opportunity to question a witness?
- Question #631
Pick the statement which does not belong to the Rule 804. Hearsay Exceptions; Declarant Unavailable.
- Question #632
Which of the following is a responsibility of the first responder?
- Question #633
NTFS sets a flag for the file once you encrypt it and creates an EFS attribute where it stores Data Decryption Field (DDF) and Data Recovery Field (DDR). Which of the following is...
- Question #634
If the partition size is 4 GB, each cluster will be 32 K. Even if a file needs only 10 K, the entire 32 K will be allocated, resulting in 22 K of ________.
- Question #635
After suspecting a change in MS-Exchange Server storage archive, the investigator has analyzed it. Which of the following components is not an actual part of the archive?
- Question #636
Which of the following is a non-zero data that an application allocates on a hard disk cluster in systems running on Windows OS?
- Question #637
Which of the following is a tool to reset Windows admin password?
- Question #638
Ron, a computer forensics expert, is investigating a case involving corporate espionage. He has recovered several mobile computing devices from the crime scene. One of the evidence...
- Question #639
Select the data that a virtual memory would store in a Windows-based system.
- Question #640
Which of the following does not describe the type of data density on a hard disk?
- Question #641
Amelia has got an email from a well-reputed company stating in the subject line that she has won a prize money, whereas the email body says that she has to pay a certain amount for...
- Question #642
Which principle states that "anyone or anything, entering a crime scene takes something of the scene with them, and leaves something of themselves behind when they leave"?
- Question #643
During an investigation, Noel found the following SIM card from the suspect's mobile. What does the code 89 44 represent?
- Question #644
Which of the following file system uses Master File Table (MFT) database to store information about every file and directory on a volume?
- Question #645
As a part of the investigation, Caroline, a forensic expert, was assigned the task to examine the transaction logs pertaining to a database named Transfers. She used SQL Server Man...
- Question #646
%3cscript%3ealert("XXXXXXXX")%3c/script%3e is a script obtained from a Cross-Site Scripting attack. What type of encoding has the attacker employed?
- Question #647
Which of the following is a device monitoring tool?
- Question #648
What system details can an investigator obtain from the NetBIOS name table cache?
- Question #649
While analyzing a hard disk, the investigator finds that the file system does not use UEFI-based interface. Which of the following operating systems is present on the hard disk?
- Question #650
In which registry does the system store the Microsoft security IDs?
- Question #651
An investigator has extracted the device descriptor for a 1GB thumb drive that looks like: Disk&Ven_Best_Buy&Prod_Geek_Squad_U3&Rev_6.15. What does the "Geek_Squad" part represent?
- Question #652
Which of the following Perl scripts will help an investigator to access the executable image of a process?
- Question #653
Which of the following attack uses HTML tags like <script></script>?
- Question #654
Examination of a computer by a technically unauthorized person will almost always result in: