
EC-COUNCIL ECCouncil Computer Hacking Forensic Investigator (V9) - 312-49v9 Exam Questions
QUESTION NO: 1
George is performing security analysis for Hammond and Sons LLC. He is testing security vulnerabilities of their wireless network. He plans on remaining as "stealthy" as possible during the scan. Why would a scanner like Nessus is not recommended in this situation?
George is performing security analysis for Hammond and Sons LLC. He is testing security vulnerabilities of their wireless network. He plans on remaining as "stealthy" as possible during the scan. Why would a scanner like Nessus is not recommended in this situation?
Correct Answer: B
QUESTION NO: 2
Harold is a computer forensics investigator working for a consulting firm out of Atlanta Georgi a. Harold is called upon to help with a corporate espionage case in Miami Florida. Harold assists in the investigation by pulling all the data from the computers allegedly used in the illegal activities. He finds that two suspects in the company where stealing sensitive corporate information and selling it to competing companies. From the email and instant messenger logs recovered, Harold has discovered that the two employees notified the buyers by writing symbols on the back of specific stop signs. This way, the buyers knew when and where to meet with the alleged suspects to buy the stolen material. What type of steganography did these two suspects use?
Harold is a computer forensics investigator working for a consulting firm out of Atlanta Georgi a. Harold is called upon to help with a corporate espionage case in Miami Florida. Harold assists in the investigation by pulling all the data from the computers allegedly used in the illegal activities. He finds that two suspects in the company where stealing sensitive corporate information and selling it to competing companies. From the email and instant messenger logs recovered, Harold has discovered that the two employees notified the buyers by writing symbols on the back of specific stop signs. This way, the buyers knew when and where to meet with the alleged suspects to buy the stolen material. What type of steganography did these two suspects use?
Correct Answer: A
QUESTION NO: 3
Jacob is a computer forensics investigator with over 10 years of experience in investigations and has written over 50 articles on computer forensics. He has been called upon as a qualified witness to testify the accuracy and integrity of the technical log files gathered in an investigation into computer fraud. What is the term used for Jacob's testimony in this case?
Jacob is a computer forensics investigator with over 10 years of experience in investigations and has written over 50 articles on computer forensics. He has been called upon as a qualified witness to testify the accuracy and integrity of the technical log files gathered in an investigation into computer fraud. What is the term used for Jacob's testimony in this case?
Correct Answer: A
QUESTION NO: 4
Harold is finishing up a report on a case of network intrusion, corporate spying, and embezzlement that he has been working on for over six months. He is trying to find the right term to use in his report to describe network-enabled spying. What term should Harold use?
Harold is finishing up a report on a case of network intrusion, corporate spying, and embezzlement that he has been working on for over six months. He is trying to find the right term to use in his report to describe network-enabled spying. What term should Harold use?
Correct Answer: A
QUESTION NO: 5
At what layer does a cross site scripting attack occur on?
At what layer does a cross site scripting attack occur on?
Correct Answer: C
QUESTION NO: 6
Which of the following application password cracking tool can discover all password-protected items on a computer and decrypts them?
Which of the following application password cracking tool can discover all password-protected items on a computer and decrypts them?
Correct Answer: B
QUESTION NO: 7
After undergoing an external IT audit, George realizes his network is vulnerable to DDoS attacks.
What countermeasures could he take to prevent DDoS attacks?
After undergoing an external IT audit, George realizes his network is vulnerable to DDoS attacks.
What countermeasures could he take to prevent DDoS attacks?
Correct Answer: B
QUESTION NO: 8
Which command line tool is used to determine active network connections?
Which command line tool is used to determine active network connections?
Correct Answer: A
QUESTION NO: 9
Analyze the hex representation of mysql-bin.000013 file in the screenshot below. Which of the following will be an inference from this analysis?

Analyze the hex representation of mysql-bin.000013 file in the screenshot below. Which of the following will be an inference from this analysis?

Correct Answer: A
QUESTION NO: 10
What does ICMP Type 3/Code 13 mean?
What does ICMP Type 3/Code 13 mean?
Correct Answer: C
QUESTION NO: 11
An investigator has found certain details after analysis of a mobile device. What can reveal the manufacturer information?
An investigator has found certain details after analysis of a mobile device. What can reveal the manufacturer information?
Correct Answer: C
QUESTION NO: 12
Which federal computer crime law specifically refers to fraud and related activity in connection with access devices like routers?
Which federal computer crime law specifically refers to fraud and related activity in connection with access devices like routers?
Correct Answer: B




