
EC-COUNCIL Computer Hacking Forensic Investigator - EC0-349 Exam Questions
QUESTION NO: 1
An employee is attempting to wipe out data stored on a couple of compact discs (CDs) and digital video discs (DVDs) by using a large magnet. You inform him that this method will not be effective in wiping out the data because CDs and DVDs are _________ media used to store large amounts of data and are not affected by the magnet.
An employee is attempting to wipe out data stored on a couple of compact discs (CDs) and digital video discs (DVDs) by using a large magnet. You inform him that this method will not be effective in wiping out the data because CDs and DVDs are _________ media used to store large amounts of data and are not affected by the magnet.
Correct Answer: C
QUESTION NO: 2
You work as a penetration tester for Hammond Security Consultants. You are currently working on a contract for the state government of California. Your next step is to initiate a DoS attack on their network. Why would you want to initiate a DoS attack on a system you are testing?
You work as a penetration tester for Hammond Security Consultants. You are currently working on a contract for the state government of California. Your next step is to initiate a DoS attack on their network. Why would you want to initiate a DoS attack on a system you are testing?
Correct Answer: C
QUESTION NO: 3
A swap file is a space on a hard disk used as the virtual memory extension of a computer's RAM.
Where is the hidden swap file in Windows located?
A swap file is a space on a hard disk used as the virtual memory extension of a computer's RAM.
Where is the hidden swap file in Windows located?
Correct Answer: D
QUESTION NO: 4
You have used a newly released forensic investigation tool, which doesn't meet the Daubert Test, during a case. The case has ended-up in court. What argument could the defense make to weaken your case?
You have used a newly released forensic investigation tool, which doesn't meet the Daubert Test, during a case. The case has ended-up in court. What argument could the defense make to weaken your case?
Correct Answer: B
QUESTION NO: 5
What file is processed at the end of a Windows XP boot to initialize the logon dialog box?
What file is processed at the end of a Windows XP boot to initialize the logon dialog box?
Correct Answer: A
QUESTION NO: 6
When monitoring for both intrusion and security events between multiple computers, it is essential that the computers' clocks are synchronized. Synchronized time allows an administrator to reconstruct what took place during an attack against multiple computers. Without synchronized time, it is very difficult to determine exactly when specific events took place, and how events interlace. What is the name of the service used to synchronize time among multiple computers?
When monitoring for both intrusion and security events between multiple computers, it is essential that the computers' clocks are synchronized. Synchronized time allows an administrator to reconstruct what took place during an attack against multiple computers. Without synchronized time, it is very difficult to determine exactly when specific events took place, and how events interlace. What is the name of the service used to synchronize time among multiple computers?
Correct Answer: D
QUESTION NO: 7
Jason has set up a honeypot environment by creating a DMZ that has no physical or logical access to his production network. In this honeypot, he has placed a server running Windows Active Directory. He has also placed a Web server in the DMZ that services a number of web pages that offer visitors a chance to download sensitive information by clicking on a button. A week later, Jason finds in his network logs how an intruder accessed the honeypot and downloaded sensitive information. Jason uses the logs to try and prosecute the intruder for stealing sensitive corporate information. Why will this not be viable?
Jason has set up a honeypot environment by creating a DMZ that has no physical or logical access to his production network. In this honeypot, he has placed a server running Windows Active Directory. He has also placed a Web server in the DMZ that services a number of web pages that offer visitors a chance to download sensitive information by clicking on a button. A week later, Jason finds in his network logs how an intruder accessed the honeypot and downloaded sensitive information. Jason uses the logs to try and prosecute the intruder for stealing sensitive corporate information. Why will this not be viable?
Correct Answer: C
QUESTION NO: 8
Wireless network discovery tools use two different methodologies to detect, monitor and log a WLAN device (i.e. active scanning and passive scanning). Active scanning methodology involves
____________and waiting for responses from available wireless networks.
Wireless network discovery tools use two different methodologies to detect, monitor and log a WLAN device (i.e. active scanning and passive scanning). Active scanning methodology involves
____________and waiting for responses from available wireless networks.
Correct Answer: C
QUESTION NO: 9
How do you define Technical Steganography?
How do you define Technical Steganography?
Correct Answer: A
QUESTION NO: 10
When should an MD5 hash check be performed when processing evidence?
When should an MD5 hash check be performed when processing evidence?
Correct Answer: A
QUESTION NO: 11
Raw data acquisition format creates ____________of a data set or suspect drive.
Raw data acquisition format creates ____________of a data set or suspect drive.
Correct Answer: A
QUESTION NO: 12
At the time of evidence transfer, both sender and receiver need to give the information about date and time of transfer in the chain of custody record.
At the time of evidence transfer, both sender and receiver need to give the information about date and time of transfer in the chain of custody record.
Correct Answer: A
QUESTION NO: 13
Julie is a college student majoring in Information Systems and Computer Science. She is currently writing an essay for her computer crimes class. Julie paper focuses on white- collar crimes in America and how forensics investigators investigate the cases. Julie would like to focus the subjectJulie? paper focuses on white-collar crimes in America and how forensics investigators investigate the cases. Julie would like to focus the subject of the essay on the most common type of crime found in corporate America. What crime should Julie focus on?
Julie is a college student majoring in Information Systems and Computer Science. She is currently writing an essay for her computer crimes class. Julie paper focuses on white- collar crimes in America and how forensics investigators investigate the cases. Julie would like to focus the subjectJulie? paper focuses on white-collar crimes in America and how forensics investigators investigate the cases. Julie would like to focus the subject of the essay on the most common type of crime found in corporate America. What crime should Julie focus on?
Correct Answer: A
QUESTION NO: 14
If you come across a sheepdip machine at your client site, what would you infer?
If you come across a sheepdip machine at your client site, what would you infer?
Correct Answer: B




