EC-Council 312-49v10 Exam (page: 27)
EC-Council Computer Hacking Forensic Investigator
Updated on: 09-Feb-2026

Viewing Page 27 of 138

The rule of thumb when shutting down a system is to pull the power plug. However, it has certain drawbacks. Which of the following would that be?

  1. Any data not yet ushed to the system will be lost
  2. All running processes will be lost
  3. The /tmp directory will be ushed
  4. Power interruption will corrupt the page le

Answer(s): A



You are a computer forensics investigator working with local police department and you are called to assist in an investigation of threatening emails. The complainant has printer out 27 email messages from the suspect and gives the printouts to you. You inform her that you will need to examine her computer because you need access to the _________________________ in order to track the emails back to the suspect.

  1. Routing Table
  2. Firewall log
  3. Con guration les
  4. Email Header

Answer(s): D



Hackers can gain access to Windows Registry and manipulate user passwords, DNS settings, access rights or others features that they may need in order to accomplish their objectives. One simple method for loading an application at startup is to add an entry (Key) to the following Registry Hive:

  1. HKEY_LOCAL_MACHINE\hardware\windows\start
  2. HKEY_LOCAL_USERS\Software\Microsoft\old\Version\Load
  3. HKEY_CURRENT_USER\Microsoft\Default
  4. HKEY_LOCAL_MACHINE\Software\Microsoft\CurrentVersion\Run

Answer(s): D



Which of the following le system is used by Mac OS X?

  1. EFS
  2. HFS+
  3. EXT2
  4. NFS

Answer(s): B



When you are running a vulnerability scan on a network and the IDS cuts off your connection, what type of IDS is being used?

  1. Passive IDS
  2. Active IDS
  3. Progressive IDS
  4. NIPS

Answer(s): B



Viewing Page 27 of 138



Share your comments for EC-Council 312-49v10 exam with other users:

Emmah 7/29/2023 9:59:00 AM

are these valid chfi questions
KENYA


Christopher 9/5/2022 10:54:00 PM

the new versoin of this exam which i downloaded has all the latest questions from the exam. i only saw 3 new questions in the exam which was not in this dump.
CANADA


Aloke Paul 9/11/2023 6:53:00 AM

is this valid for chfiv9 as well... as i am reker 3rd time...
CHINA