Home > EC-COUNCIL > Certified Ethical Hacker > 312-49

312-49 Exam : Computer Hacking Forensic Investigator

certinside

Exam Number/Code : 312-49

Exam Name : Computer Hacking Forensic Investigator

Questions and Answers : 141 Q&As

Price : $ 100.00

Update Time : 2010-05-21

microsoft braindumps 312-49 Exam Features

microsoft braindumps has assembled to take you through 120 Q&As to your 312-49 Exam preparation. In the 312-49 exam resources, you will cover every field and category in 312-49 helping to ready you for your successful Juniper Certification.

Quality and Value for the 312-49 Exam

microsoft braindumps Practice Exams for EC-COUNCIL 312-49 are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development.

100% Guarantee to Pass Your 312-49 Exam

If you prepare for the exam using our microsoft braindumps testing engine, we guarantee your success in the first attempt. If you do not pass the Certified Ethical Hacker 312-49 exam (Computer Hacking Forensic Investigator ) on your first attempt we will give you a FULL REFUND of your purchasing fee AND send you another same value product for free.

EC-COUNCIL 312-49 Downloadable, Printable Exams (in PDF format)

Our Exam 312-49 Preparation Material provides you everything you will need to take your 312-49 Exam. The 312-49 Exam details are researched and produced by Professional Certification Experts who are constantly using industry experience to produce precise, and logical. You may get questions from different web sites or books, but logic is the key. Our Product will help you not only pass in the first try, but also save your valuable time.

312-49 Downloadable, Interactive Testing engines

We are all well aware that a major problem in the IT industry is that there is a lack of quality study materials. Our Exam Preparation Material provides you everything you will need to take a certification examination. Like actual certification exams, our Practice Tests are in multiple-choice (MCQs)

Our EC-COUNCIL Certified Ethical Hacker 312-49 Exam will provide you with exam questions with verified answers that reflect the actual exam. These questions and answers provide you with the experience of taking the actual test. High quality and Value for the 312-49 Exam:100% Guarantee to Pass Your Certified Ethical Hacker exam and get your Certified Ethical Hacker Certification.

 
 
Exam : EC-Council 312-49
Title : Computer Hacking Forensic Investigator


1. In conducting a computer abuse investigation you become aware that the suspect of the investigation is using ABC Company as his Internet Service Provider (ISP). You contact ISP and request that they provide you assistance with your investigation.
What assistance can the ISP provide?
A. The ISP can investigate anyone using their service and can provide you with assistance
B. The ISP can investigate computer abuse committed by their employees, but must preserve the privacy of their customers and therefore cannot assist you without a warrant
C. The ISP can't conduct any type of investigations on anyone and therefore can't assist you
D. ISP's never maintain log files so they would be of no use to your investigation
Answer: B

2. As a CHFI professional, which of the following is the most important to your professional reputation?
A. Your Certifications
B. The correct, successful management of each and every case
C. The free that you charge
D. The friendship of local law enforcement officers
Answer: B

3. You are assisting in the investigation of a possible Web Server Hack. The company who called you stated that customers reported to them that whenever they entered the web address of the company in their browser, what they received was a porno graphic web site. The company checked the web server and nothing appears wrong. When you type in the IP address of the web site in your browser everything appears normal. What is the name of the attack that affects the DNS cache of the name resolution servers, resulting in those servers directing users to the wrong web site?
A. ARP Poisoning
B. DNS Poisoning
C. HTTP redirect attack
D. IP Spoofing
Answer: B

4. You are working as an independent computer forensics investigator and receive a call from a systems administrator for a local school system requesting your assistance. One of the students at the local high school is suspected of downloading inappropriate images from the Internet to a PC in the Computer lab. When you arrive at the school, the systems administrator hands you a hard drive and tells you that he made a simple backup copy of the hard drive in the PC and put it on this drive and requests that you examine that drive for evidence of the suspected images. You inform him that a simple backup copy will not provide deleted files or recover file fragments. What type of copy do you need to make to ensure that the evidence found is complete and admissible in future proceedings?
A. Bit-stream Copy
B. Robust Copy
C. Full backup Copy
D. Incremental Backup Copy
Answer: A

5. Law enforcement officers are conducting a legal search for which a valid warrant was obtained. While conducting the search, officers observe an item of evidence for an unrelated crime that was not included in the warrant. The item was clearly visible to the officers and immediately identified as evidence. What is the term used to describe how this evidence is admissible?
A. Plain view doctrine
B. Corpus delicti
C. Locard Exchange Principle
D. Ex Parte Order
Answer: A

6. Microsoft Outlook maintains email messages in a proprietary format in what type of file?
A. .email
B. .mail
C. .pst
D. .doc
Answer: C

312-49 Exam News