412-79V8 Exam Questions
200 real 412-79V8 exam questions with expert-verified answers and explanations. Page 4 of 4.
- Question #152
You are working as an independent computer forensics investigator and receive a call from a systems administrator for a local school system requesting your assistance. One of the s...
- Question #153
You are assisting in the investigation of a possible Web Server Hack. The company who called you stated that customers reported to them that whenever they entered the web address o...
- Question #154
In conducting a computer abuse investigation you become aware that the suspect of the investigation is using ABC Company as his Internet Service Provider (ISP). You contact ISP and...
- Question #155
As a CHFI professional, which of the following is the most important to your professional reputation?
- Question #156
You are conducting an investigation of fraudulent claims in an insurance company that involves complex text searches through large numbers of documents. Which of the following tool...
- Question #157
When cataloging digital evidence, the primary goal is to:
- Question #158
The police believe that Mevin Mattew has been obtaining unauthorized access to computers belonging to numerous computer software and computer operating systems manufacturers, cellu...
- Question #159
A law enforcement officer may only search for and seize criminal evidence with _____________, which are facts or circumstances that would lead a reasonable person to believe a crim...
- Question #160
You are working as a Computer forensics investigator for a corporation on a computer abuse case. You discover evidence that shows the subject of your investigation is also embezzli...
- Question #161
You have been asked to investigate after a user has reported a threatening e-mail they have received from an external source. Which of the following are you most interested in when...
- Question #162
This attack uses social engineering techniques to trick users into accessing a fake Web site and divulging personal information. Attackers send a legitimate-looking e-mail asking u...
- Question #163
How many bits encryption does SHA-1 use?
- Question #164
What does ICMP (type 11, code 0) denote?
- Question #165
An Expert witness give an opinion if:
- Question #166
Printing under a Windows Computer normally requires which one of the following files types to be created?
- Question #167
Profiling is a forensics technique for analyzing evidence with the goal of identifying the perpetrator from their various activity. After a computer has been compromised by a hacke...
- Question #168
To preserve digital evidence, an investigator should ____________________
- Question #169
What is the name of the Standard Linux Command that is also available as windows application that can be used to create bit-stream images?
- Question #170
____________________ is simply the application of Computer Investigation and analysis techniques in the interests of determining potential legal evidence.
- Question #171
During the course of a corporate investigation, you find that an Employee is committing a crime. Can the Employer file a criminal complain with Police?
- Question #172
The ____________________ refers to handing over the results of private investigations to the authorities because of indications of criminal activity.
- Question #173
This organization maintains a database of hash signatures for known software:
- Question #174
One technique for hiding information is to change the file extension from the correct one to one that might not be noticed by an investigator. For example, changing a .jpg extensio...
- Question #175
You are employed directly by an attorney to help investigate an alleged sexual harassment case at a large pharmaceutical manufacture. While at the corporate office of the company,...
- Question #176
Melanie was newly assigned to an investigation and asked to make a copy of all the evidence from the compromised system. Melanie did a DOS copy of all the files on the system. What...
- Question #177
What information do you need to recover when searching a victims computer for a crime committed with specific e-mail message?
- Question #178
One way to identify the presence of hidden partitions on a suspects hard drive is to:
- Question #179
What does mactime, an essential part of the coroners toolkit do?
- Question #180
The use of warning banners helps a company avoid litigation by overcoming an employees assumed ____________ When connecting to the companys intranet, network or Virtual Private Net...
- Question #181
Chris has been called upon to investigate a hacking incident reported by one of his clients. The company suspects the involvement of an insider accomplice in the attack. Upon reach...
- Question #182
When investigating a Windows System, it is important to view the contents of the page or swap file because:
- Question #183
A state department site was recently attacked and all the servers had their disks eraseD. The incident response team sealed the area and commenced investigation. During evidence co...
- Question #184
Which of the following refers to the data that might still exist in a cluster even though the original file has been overwritten by another file?
- Question #185
What should you do when approached by a reporter about a case that you are working on or have worked on?
- Question #186
This is original file structure database that Microsoft originally designed for floppy disks. It is written to the outermost track of a disk and contains information about each fil...
- Question #187
You are working in the security Department of law firm. One of the attorneys asks you about the topic of sending fake email because he has a client who has been charged with doing...
- Question #188
Volatile Memory is one of the leading problems for forensics. Worms such as code Red are memory resident and do write themselves to the hard drive, if you turn the system off they...
- Question #190
You are working as Computer Forensics investigator and are called by the owner of an accounting firm to investigate possible computer abuse by one of the firms employees. You meet...
- Question #191
Your company's network just finished going through a SAS 70 audit. This audit reported that overall, your network is secure, but there are some areas that needs improvement. The ma...
- Question #192
At what layer of the OSI model do routers function on?
- Question #193
An "idle" system is also referred to as what?
- Question #194
What operating system would respond to the following command?
- Question #195
Why are Linux/Unix based computers better to use than Windows computers for idle scanning?
- Question #196
How many bits is Source Port Number in TCP Header packet?
- Question #197
Why are Linux/Unix based computers better to use than Windows computers for idle scanning?
- Question #198
Simon is a former employee of Trinitron XML Inc. He feels he was wrongly terminated and wants to hack into his former company's network. Since Simon remembers some of the server na...
- Question #199
You are carrying out the last round of testing for your new website before it goes live. The website has many dynamic pages and connects to a SQL backend that accesses your product...
- Question #200
After attending a CEH security seminar, you make a list of changes you would like to perform on your network to increase its security. One of the first things you change is to swit...
- Question #201
You are working for a local police department that services a population of 1,000,000 people and you have been given the task of building a computer forensics laB. How many law-enf...
- Question #723
An attacker injects malicious query strings in user input fields to bypass web service authentication mechanisms and to access back-end databases. Which of the following attacks is...