312-49V9 Exam Questions
696 real 312-49V9 exam questions with expert-verified answers and explanations. Page 4 of 14.
- Question #151
The IIS log file format is a fixed (cannot be customized) ASCII text-based format. The IIS format includes basic items, such as client IP address, user name, date and time, service...
- Question #152
Which of the following Steganography techniques allows you to encode information that ensures creation of cover for secret communication?
- Question #153
Data files from original evidence should be used for forensics analysis
- Question #154
FAT32 is a 32-bit version of FAT file system using smaller clusters and results in efficient storage capacity. What is the maximum drive size supported?
- Question #155
Data acquisition system is a combination of tools or processes used to gather, analyze and record Information about some phenomenon. Different data acquisition system are used depe...
- Question #156
Network forensics allows Investigators to inspect network traffic and logs to identify and locate the attack system. Network forensics can reveal: (Select three answers)
- Question #157
Dumpster Diving refers to:
- Question #158
Which of the following Wi-Fi chalking methods refers to drawing symbols in public places to advertise open Wi-Fi networks?
- Question #159
Which of the following is not a part of the technical specification of the laboratory-based imaging system?
- Question #160
BMP (Bitmap) is a standard file format for computers running the Windows operating system. BMP images can range from black and white (1 bit per pixel) up to 24 bit color (16.7 mill...
- Question #161
Which of the following statement is not correct when dealing with a powered-on computer at the crime scene?
- Question #162
According to US federal rules, to present a testimony in a court of law, an expert witness needs to furnish certain information to prove his eligibility. Jason, a qualified compute...
- Question #163
Ron. a computer forensics expert, Is Investigating a case involving corporate espionage. He has recovered several mobile computing devices from the crime scene. One of the evidence...
- Question #164
A mobile operating system manages communication between the mobile device and other compatible devices like computers, televisions, or printers. Which mobile operating system archi...
- Question #165
Preparing an image drive to copy files to is the first step in Linux forensics. For this purpose, what would the following command accomplish? dcfldd if=/dev/zero of=/dev/hda bs=40...
- Question #166
When examining a file with a Hex Editor, what space does the file header occupy?
- Question #167
Paraben Lockdown device uses which operating system to write hard drive data?Paraben? Lockdown device uses which operating system to write hard drive data?
- Question #168
What type of file is represented by a colon (:) with a name following it in the Master File Table (MFT) of an NTFS disk?
- Question #169
You are called by an author who is writing a book and he wants to know how long the copyright for his book will last after he has the book published?
- Question #170
What is one method of bypassing a system BIOS password?
- Question #171
When investigating a network that uses DHCP to assign IP addresses, where would you look to determine which system (MAC address) had a specific IP address at a specific time?
- Question #172
What hashing method is used to password protect Blackberry devices?
- Question #173
Paul is a computer forensics investigator working for Tyler & Company Consultants. Paul has been called upon to help investigate a computer hacking ring broken up by the local poli...
- Question #174
To check for POP3 traffic using Ethereal, what port should an investigator search by?
- Question #175
In conducting a computer abuse investigation you become aware that the suspect of the investigation is using ABC Company as his Internet Service Provider (ISP). You contact the ISP...
- Question #176
What does the acronym POST mean as it relates to a PC?
- Question #177
What type of equipment would a forensics investigator store in a StrongHold bag?
- Question #178
What method of copying should always be performed first before carrying out an investigation?
- Question #179
You are working in the Security Department of a law firm. One of the attorneys asks you about the topic of sending fake email because he has a client who has been charged with doin...
- Question #180
With regard to using an antivirus scanner during a computer forensics investigation, you should:
- Question #181
When performing a forensics analysis, what device is used to prevent the system from recording data on an evidence disk?
- Question #182
What term is used to describe a cryptographic technique for embedding information into something else for the sole purpose of hiding that information from the casual observer?
- Question #183
A picture file is recovered from a computer under investigation. During the investigation process, the file is enlarged 500% to get a better view of its contents. The picture quali...
- Question #184
What layer of the OSI model do TCP and UDP utilize?
- Question #185
You have been asked to investigate the possibility of computer fraud in the finance department of a company. It is suspected that a staff member has been committing finance fraud b...
- Question #186
When marking evidence that has been collected with the aa/ddmmyy/nnnn/zz format, what does the nnn denote?
- Question #187
When searching through file headers for picture file formats, what should be searched to find a JPEG file in hexadecimal format?
- Question #188
Where does Encase search to recover NTFS files and folders?
- Question #189
To preserve digital evidence, an investigator should ____________
- Question #190
Where is the default location for Apache access logs on a Linux computer?
- Question #191
What is the CIDR from the following screenshot?
- Question #192
How many times can data be written to a DVD+R disk?
- Question #193
How often must a company keep log files for them to be admissible in a court of law?
- Question #194
When needing to search for a website that is no longer present on the Internet today but was online few years back, what site can be used to view the website collection of pages?vi...
- Question #195
When using an iPod and the host computer is running Windows, what file system will be used?
- Question #196
Harold is a computer forensics investigator working for a consulting firm out of Atlanta Georgia. Harold is called upon to help with a corporate espionage case in Miami Florida. Ha...
- Question #197
Travis, a computer forensics investigator, is finishing up a case he has been working on for over a month involving copyright infringement and embezzlement. His last task is to pre...
- Question #198
What is the smallest physical storage unit on a hard drive?
- Question #199
What technique used by Encase makes it virtually impossible to tamper with evidence once it has been acquired?
- Question #200
You are called in to assist the police in an investigation involving a suspected drug dealer. The police searched the suspect house after aYou are called in to assist the police in...