312-49V9 Exam Questions
696 real 312-49V9 exam questions with expert-verified answers and explanations. Page 6 of 14.
- Question #251
In a computer forensics investigation, what describes the route that evidence takes from the time you find it until the case is closed or goes to court?
- Question #252
As a CHFI professional, which of the following is the most important to your professional reputation?
- Question #253
Kyle is performing the final testing of an application he developed for the accounting department. His last round of testing is to ensure that the program is as secure as possible....
- Question #254
What type of flash memory card comes in either Type I or Type II and consumes only five percent of the power required by small hard drives?
- Question #255
Where are files temporarily written in Unix when printing?
- Question #256
Harold wants to set up a firewall on his network but is not sure which one would be the most appropriate. He knows he needs to allow FTP traffic to one of the servers on his networ...
- Question #257
Area density refers to:
- Question #258
A(n) _____________________ is one that's performed by a computer program rather than the attacker manually performing the steps in the attack sequence.
- Question #259
Steven has been given the task of designing a computer forensics lab for the company he works for. He has found documentation on all aspects of how to design a lab except the numbe...
- Question #260
On an Active Directory network using NTLM authentication, where on the domain controllers are the passwords stored?
- Question #261
What will the following URL produce in an unpatched IIS Web Server? co%af../..%co%af../windows/system32/cmd.exe?/c+dir+c:\
- Question #262
Why is it still possible to recover files that have been emptied from the Recycle Bin on a Windows computer?
- Question #263
Which of the following refers to the data that might still exist in a cluster even though the original file has been overwritten by another file?
- Question #264
What binary coding is used most often for e-mail purposes?
- Question #265
Which part of the Windows Registry contains the user's password file?
- Question #266
You are a computer forensics investigator working with local police department and you are called to assist in an investigation of threatening emails. The complainant has printed o...
- Question #267
During the course of a corporate investigation, you find that an employee is committing a federal crime. Can the employer file a criminal complain with the police?
- Question #268
During the course of an investigation, you locate evidence that may prove the innocence of the suspect of the investigation. You must maintain an unbiased opinion and be objective...
- Question #269
While working for a prosecutor, What do you think you should do if the evidence you found appears to be exculpatory and is not being released to the defense ?
- Question #270
When conducting computer forensic analysis, you must guard against ______________ So that you remain focused on the primary job and insure that the level of work does not increase...
- Question #271
The newer Macintosh Operating System (MacOS X) is based on:
- Question #272
Profiling is a forensics technique for analyzing evidence with the goal of identifying the perpetrator from their various activity. After a computer has been compromised by a hacke...
- Question #273
A forensics investigator needs to copy data from a computer to some type of removable media so he can examine the information at another location. The problem is that the data is a...
- Question #274
In Linux, what is the smallest possible shellcode?
- Question #275
After passively scanning the network of Department of Defense (DoD), you switch over to active scanning to identify live hosts on their network. DoD is a large organization and sho...
- Question #276
On Linux/Unix based Web servers, what privilege should the daemon service be run under?
- Question #277
A suspect is accused of violating the acceptable use of computing resources, as he has visited adult websites and downloaded images. The investigator wants to demonstrate that the...
- Question #278
When operating systems mark a cluster as used but not allocated, the cluster is considered as _________
- Question #279
Where is the startup configuration located on a router?
- Question #280
When examining a hard disk without a write-blocker, you should not start windows because Windows will write data to the:
- Question #281
If you come across a sheepdip machine at your client site, what would you infer?
- Question #282
Which Intrusion Detection System (IDS) usually produces the most false alarms due to the unpredictable behaviors of users and networks?
- Question #283
George is the network administrator of a large Internet company on the west coast. Per corporate policy, none of the employees in the company are allowed to use FTP or SFTP program...
- Question #284
You are assisting in the investigation of a possible Web Server hack. The company who called you stated that customers reported to them that whenever they entered the web address o...
- Question #285
You are the security analyst working for a private company out of France. Your current assignment is to obtain credit card information from a Swiss bank owned by that company. Afte...
- Question #286
If an attacker's computer sends an IPID of 31400 to a zombie computer on an open port in IDLE scanning, what will be the response?
- Question #287
In what way do the procedures for dealing with evidence in a criminal case differ from the procedures for dealing with evidence in a civil case?
- Question #288
Volatile Memory is one of the leading problems for forensics. Worms such as code Red are memory resident and do not write themselves to the hard drive, if you turn the system off t...
- Question #289
What stage of the incident handling process involves reporting events?
- Question #290
Chris has been called upon to investigate a hacking incident reported by one of his clients. The company suspects the involvement of an insider accomplice in the attack. Upon reach...
- Question #291
Which forensic investigating concept trails the whole incident from how the attack began to how the victim was affected?
- Question #292
George is a senior security analyst working for a state agency in Florida. His state's congress just passed a bill mandating every state agency to undergo a security audit annually...
- Question #293
James is testing the ability of his routers to withstand DoS attacks. James sends ICMP ECHO requests to the broadcast address of his network. What type of DoS attack is James testi...
- Question #294
E-mail logs contain which of the following information to help you in your investigation? (Select up to 4)
- Question #295
You are assigned to work in the computer forensics lab of a state police agency. While working on a high profile criminal case, you have followed every applicable procedure, howeve...
- Question #296
In Microsoft file structures, sectors are grouped together to form:
- Question #297
Which response organization tracks hoaxes as well as viruses?
- Question #298
You just passed your ECSA exam and are about to start your first consulting job running security audits for a financial institution in Los Angeles. The IT manager of the company yo...
- Question #299
Windows identifies which application to open a file with by examining which of the following?
- Question #300
You are conducting an investigation of fraudulent claims in an insurance company that involves complex text searches through large numbers of documents. Which of the following tool...