Eccouncil

312-49 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 133-question bank.

Provider
Eccouncil
Question bank
133
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for 312-49, a certification listed under Eccouncil. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Eccouncil. The certification credential is issued by Eccouncil, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    When an investigator contacts by telephone the domain administrator or controller listed by a Who is lookup to request all e-mails sent and received for a user account be preserved, what U.S.C. statute authorizes this phone call and obligates the ISP to preserve e-mail records?

    Choose one answer.

    • Title 18, Section 1030
    • Title 18, Section 2703(d)
    • Title 18, Section Chapter 90
    • Title 18, Section 2703(f)
  2. Question 2 · 1

    You are contracted to work as a computer forensics investigator for a regional bank that has four 30 TB storage area networks that store customer data. What method would be most efficient for you to acquire digital evidence from this network?

    Choose one answer.

    • create a compressed copy of the file with DoubleSpace
    • create a sparse data copy of a folder or file
    • make a bit-stream disk-to-image file
    • make a bit-stream disk-to-disk file
  3. Question 3 · 1

    Melanie was newly assigned to an investigation and asked to make a copy of all the evidence from the compromised system. Melanie did a DOS copy of all the files on the system. What would be the primary reason for you to recommend a disk imaging tool?

    Choose one answer.

    • A disk imaging tool would check for CRC32s for internal self-checking and validation and have MD5 checksum
    • Evidence file format will contain case data entered by the examiner and encrypted at the beginning of the evidence file
    • A simple DOS copy will not include deleted files, file slack and other information
    • There is no case for an imaging tool as it will use a closed, proprietary format that if compared to the original will not match up sector for sector
  4. Question 4 · 1

    You are employed directly by an attorney to help investigate an alleged sexual harassment case at a large pharmaceutical manufacture. While at the corporate office of the company, the CEO demands to know the status of the investigation. What prevents you from discussing the case with the CEO?

    Choose one answer.

    • the attorney-work-product rule
    • Good manners
    • Trade secrets
    • ISO 17799
  5. Question 5 · 1

    One technique for hiding information is to change the file extension from the correct one to one that might not be noticed by an investigator. For example, [1] extension?

    Choose one answer.

    • the File Allocation Table
    • the file header
    • the file footer
    • the sector map
  6. Question 6 · 1

    You are working as Computer Forensics investigator and are called by the owner of an accounting firm to investigate possible computer abuse by one of the firm's employees. You meet with the owner of the firm and discover that the company has never published a policy stating that they reserve the right to inspect their computing assets at will. What do you do?

    Choose one answer.

    • Inform the owner that conducting an investigation without a policy is not a problem because the company is privately owned
    • Inform the owner that conducting an investigation without a policy is a violation of the 4th amendment
    • Inform the owner that conducting an investigation without a policy is a violation of the employee's expectation of privacy
    • Inform the owner that conducting an investigation without a policy is not a problem because a policy is only necessary for government agencies
  7. Question 7 · 1

    You are working for a large clothing manufacturer as a computer forensics investigator and are called in to investigate an unusual case of an employee possibly stealing clothing designs from the company and selling them under a different brand name for a different company. What you discover during the course of the investigation is that the clothing designs are actually original products of the employee and the company has no policy against an employee selling his own designs on his own time. The only thing that you can find that the employee is doing wrong is that his clothing design incorporates the same graphic symbol as that of the company with only the wording in the graphic being different. What area of the law is the employee violating?

    Choose one answer.

    • trademark law
    • copyright law
    • printright law
    • brandmark law
  8. Question 8 · 1

    To preserve digital evidence, an investigator should ____________________.

    Choose one answer.

    • Make two copies of each evidence item using a single imaging tool
    • Make a single copy of each evidence item using an approved imaging tool
    • Make two copies of each evidence item using different imaging tools
    • Only store the original evidence item
  9. Question 9 · 1

    Profiling is a forensics technique for analyzing evidence with the goal of identifying the perpetrator from their various activity. After a computer has been compromised by a hacker, which of the following would be most important in forming a profile of the incident?

    Choose one answer.

    • The manufacturer of the system compromised
    • The logic, formatting and elegance of the code used in the attack
    • The nature of the attack
    • The vulnerability exploited in the incident
  10. Question 10 · 1

    You have completed a forensic investigation case. You would like to destroy the data contained in various disks at the forensics lab due to sensitivity of the case. How would you permanently erase the data on the hard disk?

    Choose one answer.

    • Throw the hard disk into the fire
    • Run the powerful magnets over the hard disk
    • Format the hard disk multiple times using a low level disk utility
    • Overwrite the contents of the hard disk with Junk data
  11. Question 11 · 1

    You are working as a Computer forensics investigator for a corporation on a computer abuse case. You discover evidence that shows the subject of your investigation is also embezzling money from the company. The company CEO and the corporate legal counsel advise you to contact law enforcement and provide them with the evidence that you have found. The law enforcement officer that responds requests that you put a network sniffer on your network and monitor all traffic to the subject's computer. You inform the officer that you will not be able to comply with that request because doing so would:

    Choose one answer.

    • Violate your contract
    • Cause network congestion
    • Make you an agent of law enforcement
    • Write information to the subject's hard drive
  12. Question 12 · 1

    What file structure database would you expect to find on floppy disks?

    Choose one answer.

    • NTFS
    • FAT32
    • FAT16
    • FAT12
  13. Question 13 · 1

    A law enforcement officer may only search for and seize criminal evidence with _______________________, which are facts or circumstances that would lead a reasonable person to believe a crime has been committed or is about to be committed, evidence of the specific crime exists and the evidence of the specific crime exists at the place to be searched.

    Choose one answer.

    • Mere Suspicion
    • A preponderance of the evidence
    • Probable cause
    • Beyond a reasonable doubt
  14. Question 14 · 1

    When you are running a vulnerability scan on a network and the IDS cuts off your connection, what type of IDS is being used?

    Choose one answer.

    • Passive IDS
    • Active IDS
    • Progressive IDS
    • NIPS
  15. Question 15 · 1

    You are carrying out the last round of testing for your new website before it goes live. The website has many dynamic pages and connects to a SQL backend that accesses your product inventory in a database. You come across a web security site that recommends inputting the following code into a search field on web pages to check for vulnerabilities: When you type this and click on search, you receive a pop-up window that says: "This is a test." What is the result of this test?

    Choose one answer.

    • Your website is vulnerable to CSS
    • Your website is not vulnerable
    • Your website is vulnerable to SQL injection
    • Your website is vulnerable to web bugs

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free