EC-COUNCIL 312-49 Dumps Updated [Nov-2021] Get 100% Real Exam Questions! [Q11-Q34]

Share

[Nov-2021] Pass EC-COUNCIL 312-49 Exam in First Attempt Guaranteed!

Full 312-49 Practice Test and 150 unique questions with explanations waiting just for you, get it now!

NEW QUESTION 11
Bob has been trying to penetrate a remote production system for the past two weeks. This time however, he is able to get into the system. He was able to use the System for a period of three weeks. However, law enforcement agencies were recoding his every activity and this was later presented as evidence.
The organization had used a Virtual Environment to trap Bob. What is a Virtual Environment?

  • A. A Honeypot that traps hackers
  • B. A system Using Trojaned commands
  • C. An environment set up before a user logs in
  • D. An environment set up after the user logs in

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 12
What is considered a grant of a property right given to an individual who discovers or invents a new machine, process, useful composition of matter or manufacture?

  • A. Utility patent
  • B. Copyright
  • C. Design patent
  • D. Trademark

Answer: A

 

NEW QUESTION 13
Using Internet logging software to investigate a case of malicious use of computers, the investigator comes across some entries that appear odd.

From the log, the investigator can see where the person in question went on the Internet. From the log, it appears that the user was manually typing in different user ID numbers. What technique this user was trying?

  • A. SQL injection
  • B. Cookie Poisoning
  • C. Cross site scripting
  • D. Parameter tampering

Answer: D

 

NEW QUESTION 14
Which of the following is a precomputed table containing word lists like dictionary files and brute force lists and their hash values?

  • A. Directory Table
  • B. Partition Table
  • C. Rainbow Table
  • D. Master file Table (MFT)

Answer: C

 

NEW QUESTION 15
During an investigation, an employee was found to have deleted harassing emails that were sent to someone else. The company was using Microsoft Exchange and had message tracking enabled. Where could the investigator search to find the message tracking log file on the Exchange server?

  • A. C:\Exchsrvr\Message Tracking\servername.log
  • B. C:\Program Files\Exchsrvr\servername.log
  • C. C:\Program Files\Microsoft Exchange\srvr\servername.log
  • D. D:\Exchsrvr\Message Tracking\servername.log

Answer: B

 

NEW QUESTION 16
When needing to search for a website that is no longer present on the Internet today but was online few years back, what site can be used to view the website collection of pages?view the website? collection of pages?

  • A. Dnsstuff.com
  • B. Archive.org
  • C. Samspade.org
  • D. Proxify.net

Answer: B

 

NEW QUESTION 17
What is the investigator trying to analyze if the system gives the following image as output?

  • A. Currently active logon sessions
  • B. Details of users who can logon
  • C. All the logon sessions
  • D. Inactive logon sessions

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 18
Rusty, a computer forensics apprentice, uses the command nbtstat -c while analyzing the network information in a suspect system. What information is he looking for?

  • A. Status of the network carrier
  • B. Network connections
  • C. Contents of the network routing table
  • D. Contents of the NetBIOS name cache

Answer: D

 

NEW QUESTION 19
Microsoft Security IDs are available in Windows Registry Editor. The path to locate IDs in Windows 7 is:

  • A. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProfileList
  • B. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegList
  • C. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
  • D. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Regedit

Answer: C

 

NEW QUESTION 20
Why should you never power on a computer that you need to acquire digital evidence from?

  • A. When the computer boots up, the system cache is cleared which could destroy evidence
  • B. When the computer boots up, files are written to the computer rendering the data nclean
  • C. Powering on a computer has no affect when needing to acquire digital evidence from it
  • D. When the computer boots up, data in the memory buffer is cleared which could destroy evidence

Answer: B

 

NEW QUESTION 21
What is a good security method to prevent unauthorized users from "tailgating"?

  • A. Man trap
  • B. Pick-resistant locks
  • C. Electronic combination locks
  • D. Electronic key systems

Answer: A

 

NEW QUESTION 22
Davidson Trucking is a small transportation company that has three local offices in Detroit
Michigan. Ten female employees that work for the company have gone to an attorney reporting that male employees repeatedly harassed them and that management did nothing to stop the problem. Davidson has employee policies that outline all company guidelines, including awareness on harassment and how it will not be tolerated. When the case is brought to court, whom should the prosecuting attorney call upon for not upholding company policy?

  • A. IT personnel
  • B. Administrative assistant in charge of writing policies
  • C. Employees themselves
  • D. Supervisors

Answer: D

 

NEW QUESTION 23
Randy has extracted data from an old version of a Windows-based system and discovered info file Dc5.txt in the system recycle bin. What does the file name denote?

  • A. A text file copied from C drive to D drive in fifth sequential order
  • B. A text file copied from D drive to C drive in fifth sequential order
  • C. A text file deleted from C drive in fifth sequential order
  • D. A text file deleted from C drive in sixth sequential order

Answer: C

 

NEW QUESTION 24
Andie, a network administrator, suspects unusual network services running on a windows system. Which of the following commands should he use to verify unusual network services started on a Windows system?

  • A. net serv
  • B. net start
  • C. lusrmgr
  • D. netmgr

Answer: B

Explanation:
Explanation

 

NEW QUESTION 25
Which network attack is described by the following statement? "At least five Russian major banks came under a continuous hacker attack, although online client services were not disrupted. The attack came from a wide- scale botnet involving at least 24,000 computers, located in 30 countries."

  • A. Sniffer Attack
  • B. DDoS
  • C. Man-in-the-Middle Attack
  • D. Buffer Overflow

Answer: B

 

NEW QUESTION 26
Steven has been given the task of designing a computer forensics lab for the company he works for. He has found documentation on all aspects of how to design a lab except the number of exits needed. How many exits should Steven include in his design for the computer forensics lab?

  • A. Two
  • B. One
  • C. Three
  • D. Four

Answer: B

 

NEW QUESTION 27
You have used a newly released forensic investigation tool, which doesn't meet the Daubert Test, during a case. The case has ended-up in court. What argument could the defense make to weaken your case?

  • A. Only the local law enforcement should use the tool
  • B. The tool hasn't been tested by the International Standards Organization (ISO)
  • C. The total has not been reviewed and accepted by your peers
  • D. You are not certified for using the tool

Answer: C

 

NEW QUESTION 28
Which is a standard procedure to perform during all computer forensics investigations?

  • A. With the hard drive removed from the suspect PC, check the date and time in the system CMOSWith the hard drive removed from the suspect PC, check the date and time in the system? CMOS
  • B. With the hard drive in the suspect PC, check the date and time in the File Allocation
    Table
  • C. With the hard drive removed from the suspect PC, check the date and time in the system RAMWith the hard drive removed from the suspect PC, check the date and time in the system? RAM
  • D. With the hard drive in the suspect PC, check the date and time in the system CMOSWith the hard drive in the suspect PC, check the date and time in the system? CMOS

Answer: A

 

NEW QUESTION 29
Which among the following U.S. laws requires financial institutions-companies that offer consumers financial products or services such as loans, financial or investment advice, or insurance-to protect their customers' information against security threats?

  • A. HIPAA
  • B. FISMA
  • C. GLBA
  • D. SOX

Answer: C

 

NEW QUESTION 30
You work as a penetration tester for Hammond Security Consultants. You are currently working on a contract for the state government of California. Your next step is to initiate a DoS attack on their network.
Why would you want to initiate a DoS attack on a system you are testing?

  • A. Show outdated equipment so it can be replaced
  • B. Use attack as a launching point to penetrate deeper into the network
  • C. List weak points on their network
  • D. Demonstrate that no system can be protected against DoS attacks

Answer: C

 

NEW QUESTION 31
The rule of thumb when shutting down a system is to pull the power plug. However, it has certain drawbacks. Which of the following would that be?

  • A. Any data not yet flushed to the system will be lost
  • B. Power interruption will corrupt the pagefile
  • C. All running processes will be lost
  • D. The /tmp directory will be flushed

Answer: A

 

NEW QUESTION 32
Simon is a former employee of Trinitron XML Inc. He feels he was wrongly terminated and wants to hack into his former company's network. Since Simon remembers some of the server names, he attempts to run the axfr and ixfr commands using DIG. What is Simon trying to accomplish here?

  • A. Enumerate all the users in the domain
  • B. Perform DNS poisoning
  • C. Send DOS commands to crash the DNS servers
  • D. Perform a zone transfer

Answer: D

 

NEW QUESTION 33
You work as an IT security auditor hired by a law firm in Boston to test whether you can gain access to sensitive information about the company clients. You have rummaged through their trash and found very little information. You do not want to set off any alarms on their network, so you plan on performing passive foot printing against their Web servers. What tool should you use?

  • A. Nmap
  • B. Netcraft
  • C. Dig
  • D. Ping sweep

Answer: B

 

NEW QUESTION 34
......

Get Latest 312-49 Dumps Exam Questions in here: https://www.actualcollection.com/312-49-exam-questions.html