EC-COUNCIL ECCouncil Computer Hacking Forensic Investigator (V9) - 312-49v9 Exam Practice Test
If the partition size is 4 GB, each cluster will be 32 K.
Even if a file needs only 10 K, the entire 32 K will be allocated, resulting in 22 K of ________.
Even if a file needs only 10 K, the entire 32 K will be allocated, resulting in 22 K of ________.
Correct Answer: B
Vote an answer
This organization maintains a database of hash signatures for known software.
Correct Answer: C
Vote an answer
What is the primary function of the tool CHKDSK in Windows that authenticates the file system reliability of a volume?
Correct Answer: D
Vote an answer
When investigating a Windows System, it is important to view the contents of the page or swap file because:
Correct Answer: D
Vote an answer
Which among the following files provides email header information in the Microsoft Exchange server?
Correct Answer: B
Vote an answer
What method of computer forensics will allow you to trace all ever-established user accounts on a Windows 2000 sever the course of its lifetime?
Correct Answer: D
Vote an answer
Randy has extracted data from an old version of a Windows-based system and discovered info file Dc5.txt in the system recycle bin. What does the file name denote?
Correct Answer: D
Vote an answer
NTFS sets a flag for the file once you encrypt it and creates an EFS attribute where it stores Data Decryption Field (DDF) and Data Recovery Field (DDR). Which of the following is not a part of DDF?
Correct Answer: C
Vote an answer
You have compromised a lower-level administrator account on an Active Directory network of a small company in Dallas, Texas. You discover Domain Controllers through enumeration. You connect to one of the Domain Controllers on port 389 using ldp.exe. What are you trying to accomplish here?
Correct Answer: D
Vote an answer
Event correlation is the process of finding relevance between the events that produce a final result. What type of correlation will help an organization to correlate events across a set of servers, systems, routers and network?
Correct Answer: C
Vote an answer
Which of the following acts as a network intrusion detection system as well as network intrusion prevention system?
Correct Answer: A
Vote an answer
The MAC attributes are timestamps that refer to a time at which the file was last modified or last accessed or originally created. Which of the following file systems store MAC attributes in Coordinated Universal Time (UTC) format?
Correct Answer: B
Vote an answer
%3cscript%3ealert("XXXXXXXX")%3c/script%3e is a script obtained from a Cross-Site Scripting attack. What type of encoding has the attacker employed?
Correct Answer: D
Vote an answer
To preserve digital evidence, an investigator should ____________________.
Correct Answer: A
Vote an answer
A company's policy requires employees to perform file transfers using protocols which encrypt traffic. You suspect some employees are still performing file transfers using unencrypted protocols because the employees don't like changes. You have positioned a network sniffer to capture traffic from the laptops used by employees in the data ingest department. Using Wireshark to examine the captured traffic, which command can be used as a display filter to find unencrypted file transfers?
Correct Answer: A
Vote an answer