EC-Council 312-49v10 Exam (page: 10)
EC-Council Computer Hacking Forensic Investigator
Updated on: 25-Dec-2025

Viewing Page 10 of 138

From the following spam mail header, identify the host IP that sent this spam?

From jie02@netvigator.com jie02@netvigator.com Tue Nov 27 17:27:11 2001
Received: from viruswall.ie.cuhk.edu.hk (viruswall [137.189.96.52]) by eng.ie.cuhk.edu.hk (8.11.6/8.11.6) with ESMTP id
fAR9RAP23061 for ; Tue, 27 Nov 2001 17:27:10 +0800 (HKT)
Received: from mydomain.com (pcd249020.netvigator.com [203.218.39.20]) by viruswall.ie.cuhk.edu.hk (8.12.1/8.12.1) with SMTP id fAR9QXwZ018431 for ; Tue, 27 Nov 2001 17:26:36 +0800 (HKT)
Message-Id: >200111270926.fAR9QXwZ018431@viruswall.ie.cuhk.edu.hk
From: "china hotel web"
To: "Shlam"
Subject: SHANGHAI (HILTON HOTEL) PACKAGE
Date: Tue, 27 Nov 2001 17:25:58 +0800 MIME-Version: 1.0
X-Priority: 3 X-MSMail-

Priority: Normal -
Reply-To: "china hotel web"

  1. 137.189.96.52
  2. 8.12.1.0
  3. 203.218.39.20
  4. 203.218.39.50

Answer(s): C



If you plan to startup a suspect's computer, you must modify the ___________ to ensure that you do not contaminate or alter data on the suspect's hard drive by booting to the hard drive.

  1. deltree command
  2. CMOS
  3. Boot.sys
  4. Scandisk utility

Answer(s): B



You are working for a local police department that services a population of 1,000,000 people and you have been given the task of building a computer forensics lab. How many law-enforcement computer investigators should you request to staff the lab?

  1. 8
  2. 1
  3. 4
  4. 2

Answer(s): C



When obtaining a warrant, it is important to:

  1. particularlydescribe the place to be searched and particularly describe the items to be seized
  2. generallydescribe the place to be searched and particularly describe the items to be seized
  3. generallydescribe the place to be searched and generally describe the items to be seized
  4. particularlydescribe the place to be searched and generally describe the items to be seized

Answer(s): A



What does the superblock in Linux de ne?

  1. lesynames
  2. diskgeometr
  3. location of the rstinode
  4. available space

Answer(s): C



Viewing Page 10 of 138



Share your comments for EC-Council 312-49v10 exam with other users:

Emmah 7/29/2023 9:59:00 AM

are these valid chfi questions
KENYA


Christopher 9/5/2022 10:54:00 PM

the new versoin of this exam which i downloaded has all the latest questions from the exam. i only saw 3 new questions in the exam which was not in this dump.
CANADA


Aloke Paul 9/11/2023 6:53:00 AM

is this valid for chfiv9 as well... as i am reker 3rd time...
CHINA