EC-Council Computer Hacking Forensic Investigator 312-49v11 Dumps in PDF

Free EC-Council 312-49v11 Real Questions (page: 2)

Annie is searching for certain deleted files on a system running Windows XP OS.
Where will she find the files if they were not completely deleted from the system?

  1. C: $Recycled.Bin
  2. C: \$Recycle.Bin
  3. C:\RECYCLER
  4. C:\$RECYCLER

Answer(s): B



Which of the following files stores information about a local Google Drive installation such as User email ID, Local Sync Root Path, and Client version installed?

  1. filecache.db
  2. config.db
  3. sigstore.db
  4. Sync_config.db

Answer(s): D



An expert witness is a __________________ who is normally appointed by a party to assist the formulation and preparation of a party's claim or defense.

  1. Expert in criminal investigation
  2. Subject matter specialist
  3. Witness present at the crime scene
  4. Expert law graduate appointed by attorney

Answer(s): B



Smith, a network administrator with a large MNC, was the first to arrive at a suspected crime scene involving criminal use of compromised computers.
What should be his first response while maintaining the integrity of evidence?

  1. Record the system state by taking photographs of physical system and the display
  2. Perform data acquisition without disturbing the state of the systems
  3. Open the systems, remove the hard disk and secure it
  4. Switch off the systems and carry them to the laboratory

Answer(s): A



Which among the following is an act passed by the U.S. Congress in 2002 to protect investors from the possibility of fraudulent accounting activities by corporations?

  1. HIPAA
  2. GLBA
  3. SOX
  4. FISMA

Answer(s): C



Jacky encrypts her documents using a password. It is known that she uses her daughter's year of birth as part of the password.
Which password cracking technique would be optimal to crack her password?

  1. Rule-based attack
  2. Brute force attack
  3. Syllable attack
  4. Hybrid attack

Answer(s): A



Which of the following Event Correlation Approach is an advanced correlation method that assumes and predicts what an attacker can do next after the attack by studying the statistics and probability and uses only two variables?

  1. Bayesian Correlation
  2. Vulnerability-Based Approach
  3. Rule-Based Approach
  4. Route Correlation

Answer(s): A



Smith, as a part his forensic investigation assignment, seized a mobile device. He was asked to recover the Subscriber Identity Module (SIM card) data in the mobile device. Smith found that the SIM was protected by a Personal Identification Number (PIN) code, but he was also aware that people generally leave the PIN numbers to the defaults or use easily guessable numbers such as 1234. He made three unsuccessful attempts, which blocked the SIM card.
What can Jason do in this scenario to reset the PIN and access SIM data?

  1. He should contact the network operator for a Temporary Unlock Code (TUK)
  2. Use system and hardware tools to gain access
  3. He can attempt PIN guesses after 24 hours
  4. He should contact the network operator for Personal Unlock Number (PUK)

Answer(s): D



Share your comments for EC-Council 312-49v11 exam with other users:

R
Randall
9/28/2023 8:25:00 PM

on question 22, option b-once per session is also valid.

T
Tshegofatso
8/28/2023 11:51:00 AM

this website is very helpful

P
philly
9/18/2023 2:40:00 PM

its my first time exam

B
Beexam
9/4/2023 9:06:00 PM

correct answers are device configuration-enable the automatic installation of webview2 runtime. & policy management- prevent users from submitting feedback.

R
RAWI
7/9/2023 4:54:00 AM

is this dump still valid? today is 9-july-2023

A
Annie
6/7/2023 3:46:00 AM

i need this exam.. please upload these are really helpful

S
Shubhra Rathi
8/26/2023 1:08:00 PM

please upload the oracle 1z0-1059-22 dumps

S
Shiji
10/15/2023 1:34:00 PM

very good questions

R
Rita Rony
11/27/2023 1:36:00 PM

nice, first step to exams

A
Aloke Paul
9/11/2023 6:53:00 AM

is this valid for chfiv9 as well... as i am reker 3rd time...

C
Calbert Francis
1/15/2024 8:19:00 PM

great exam for people taking 220-1101

A
Ayushi Baria
11/7/2023 7:44:00 AM

this is very helpfull for me

A
alma
8/25/2023 1:20:00 PM

just started preparing for the exam

C
CW
7/10/2023 6:46:00 PM

these are the type of questions i need.

N
Nobody
8/30/2023 9:54:00 PM

does this actually work? are they the exam questions and answers word for word?

S
Salah
7/23/2023 9:46:00 AM

thanks for providing these questions

R
Ritu
9/15/2023 5:55:00 AM

interesting

R
Ron
5/30/2023 8:33:00 AM

these dumps are pretty good.

S
Sowl
8/10/2023 6:22:00 PM

good questions

B
Blessious Phiri
8/15/2023 2:02:00 PM

dbua is used for upgrading oracle database

R
Richard
10/24/2023 6:12:00 AM

i am thrilled to say that i passed my amazon web services mls-c01 exam, thanks to study materials. they were comprehensive and well-structured, making my preparation efficient.

J
Janjua
5/22/2023 3:31:00 PM

please upload latest ibm ace c1000-056 dumps

M
Matt
12/30/2023 11:18:00 AM

if only explanations were provided...

R
Rasha
6/29/2023 8:23:00 PM

yes .. i need the dump if you can help me

A
Anonymous
7/25/2023 8:05:00 AM

good morning, could you please upload this exam again?

A
AJ
9/24/2023 9:32:00 AM

hi please upload sre foundation and practitioner exam questions

P
peter parker
8/10/2023 10:59:00 AM

the exam is listed as 80 questions with a pass mark of 70%, how is your 50 questions related?

B
Berihun
7/13/2023 7:29:00 AM

all questions are so important and covers all ccna modules

N
nspk
1/19/2024 12:53:00 AM

q 44. ans:- b (goto setup > order settings > select enable optional price books for orders) reference link --> https://resources.docs.salesforce.com/latest/latest/en-us/sfdc/pdf/sfom_impl_b2b_b2b2c.pdf(decide whether you want to enable the optional price books feature. if so, select enable optional price books for orders. you can use orders in salesforce while managing price books in an external platform. if you’re using d2c commerce, you must select enable optional price books for orders.)

M
Muhammad Rawish Siddiqui
12/2/2023 5:28:00 AM

"cost of replacing data if it were lost" is also correct.

A
Anonymous
7/14/2023 3:17:00 AM

pls upload the questions

M
Mukesh
7/10/2023 4:14:00 PM

good questions

E
Elie Abou Chrouch
12/11/2023 3:38:00 AM

question 182 - correct answer is d. ethernet frame length is 64 - 1518b. length of user data containing is that frame: 46 - 1500b.

D
Damien
9/23/2023 8:37:00 AM

i need this exam pls

AI Tutor 👋 I’m here to help!