Free EC-COUNCIL 312-49 Practice Test & Real Exam Questions
Which of the following tasks DOES NOT come under the investigation phase of a cybercrime forensics investigation case?
Correct Answer: A
Vote an answer
While looking through the IIS log file of a web server, you find the following entries:

What is evident from this log file?

What is evident from this log file?
Correct Answer: D
Vote an answer
Randy has extracted data from an old version of a Windows-based system and discovered info file Dc5.txt in the system recycle bin. What does the file name denote?
Correct Answer: B
Vote an answer
With Regard to using an Antivirus scanner during a computer forensics investigation, You should:
Correct Answer: D
Vote an answer
Jacob is a computer forensics investigator with over 10 years of experience in investigations and has written over 50 articles on computer forensics. He has been called upon as a qualified witness to testify the accuracy and integrity of the technical log files gathered in an investigation into computer fraud. What is the term used for Jacob's testimony in this case?
Correct Answer: B
Vote an answer
Chong-lee, a forensics executive, suspects that a malware is continuously making copies of files and folders on a victim system to consume the available disk space. What type of test would confirm his claim?
Correct Answer: A
Vote an answer
What hashing method is used to password protect Blackberry devices?
Correct Answer: D
Vote an answer
Microsoft Outlook maintains email messages in a proprietary format in what type of file?
Correct Answer: A
Vote an answer
Jason discovered a file named $RIYG6VR.doc in the C:\$Recycle.Bin\ < USER SID > \ while analyzing a hard disk image for the deleted data. What inferences can he make from the file name?
Correct Answer: A
Vote an answer
An Employee is suspected of stealing proprietary information belonging to your company that he had no rights to possess. The information was stored on the Employees Computer that was protected with the NTFS Encrypted File System (EFS) and you had observed him copy the files to a floppy disk just before leaving work for the weekend. You detain the Employee before he leaves the building and recover the floppy disks and secure his computer. Will you be able to break the encryption so that you can verify that that the employee was in possession of the proprietary information?
Correct Answer: D
Vote an answer
Cylie is investigating a network breach at a state organization in Florida. She discovers that the intruders were able to gain access into the company firewalls by overloading them with IP packets. Cylie then discovers through her investigation that the intruders hacked into the company phone system and used the hard drives on their PBX system to store shared music files. What would this attack on the company PBX system be called?
Correct Answer: D
Vote an answer
As a part of the investigation, Caroline, a forensic expert, was assigned the task to examine the transaction logs pertaining to a database named Transfers. She used SQL Server Management Studio to collect the active transaction log files of the database. Caroline wants to extract detailed information on the logs, including AllocUnitId, page id, slot id, etc. Which of the following commands does she need to execute in order to extract the desired information?
Correct Answer: C
Vote an answer
