Verified of 312-49v10 dumps materials and simulations for EC-Council certification for IT learners, Real Success Guaranteed with Updated 312-49v10 pdf dumps vce Materials. 100% PASS Computer Hacking Forensic Investigator (CHFI-v10) exam Today!
Online 312-49v10 free questions and answers of New Version:
NEW QUESTION 1
Which of the following tasks DOES NOT come under the investigation phase of a cybercrime forensics investigation case?
- A. Data collection
- B. Secure the evidence
- C. First response
- D. Data analysis
Answer: C
NEW QUESTION 2
Which of the following attacks allows an attacker to access restricted directories, including application source code, configuration and critical system files, and to execute commands outside of the web server’s root directory?
- A. Parameter/form tampering
- B. Unvalidated input
- C. Directory traversal
- D. Security misconfiguration
Answer: C
NEW QUESTION 3
Wireless access control attacks aim to penetrate a network by evading WLAN access control measures such as AP MAC filters and Wi-Fi port access controls. Which of the following wireless access control attacks allow the attacker to set up a rogue access point outside the corporate perimeter and then lure the employees of the organization to connect to it?
- A. Ad hoc associations
- B. Client mis-association
- C. MAC spoofing
- D. Rogue access points
Answer: B
NEW QUESTION 4
Ronald, a forensic investigator, has been hired by a financial services organization to Investigate an attack on their MySQL database server, which Is hosted on a Windows machine named WIN-DTRAI83202X. Ronald wants to retrieve information on the changes that have been made to the database. Which of the following files should Ronald examine for this task?
- A. relay-log.info
- B. WIN-DTRAl83202Xrelay-bin.index
- C. WIN-DTRAI83202Xslow.log
- D. WIN-DTRAI83202X-bin.nnnnnn
Answer: C
NEW QUESTION 5
You are working on a thesis for your doctorate degree in Computer Science. Your thesis is based on HTML, DHTML, and other web-based languages and how they have evolved over the years.
You navigate to archive. org and view the HTML code of news.com. You then navigate to the current news.com website and copy over the source code. While searching through the code, you come across something abnormal: What have you found?
- A. Web bug
- B. CGI code
- C. Trojan.downloader
- D. Blind bug
Answer: A
NEW QUESTION 6
Which of the following email headers specifies an address for mailer-generated errors, like "no such user" bounce messages, to go to (instead of the sender's address)?
- A. Mime-Version header
- B. Content-Type header
- C. Content-Transfer-Encoding header
- D. Errors-To header
Answer: D
NEW QUESTION 7
Which of the following statements is TRUE with respect to the Registry settings in the user start-up folder HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\.
- A. All the values in this subkey run when specific user logs on, as this setting is user-specific
- B. The string specified in the value run executes when user logs on
- C. All the values in this key are executed at system start-up
- D. All values in this subkey run when specific user logs on and then the values are deleted
Answer: D
NEW QUESTION 8
Which of the following ISO standard defines file systems and protocol for exchanging data between optical disks?
- A. ISO 9660
- B. ISO/IEC 13940
- C. ISO 9060
- D. IEC 3490
Answer: A
NEW QUESTION 9
Which of the following files gives information about the client sync sessions in Google Drive on Windows?
- A. sync_log.log
- B. Sync_log.log
- C. sync.log
- D. Sync.log
Answer: B
NEW QUESTION 10
Meyer Electronics Systems just recently had a number of laptops stolen out of their office. On these laptops contained sensitive corporate information regarding patents and company strategies. A month after the laptops were stolen, a competing company was found to have just developed products that almost exactly duplicated products that Meyer produces. What could have prevented this information from being stolen from the laptops?
- A. EFS Encryption
- B. DFS Encryption
- C. IPS Encryption
- D. SDW Encryption
Answer: A
NEW QUESTION 11
When you are running a vulnerability scan on a network and the IDS cuts off your connection, what type of IDS is being used?
- A. Passive IDS
- B. Active IDS
- C. Progressive IDS
- D. NIPS
Answer: B
NEW QUESTION 12
Where does Encase search to recover NTFS files and folders?
- A. MBR
- B. MFT
- C. Slack space
- D. HAL
Answer: B
NEW QUESTION 13
The Recycle Bin exists as a metaphor for throwing files away, but it also allows a user to retrieve and restore files. Once the file is moved to the recycle bin, a record is added to the log file that exists in the Recycle Bin. Which of the following files contains records that correspond to each deleted file in the Recycle Bin?
- A. INFO2
- B. INFO1
- C. LOGINFO1
- D. LOGINFO2
Answer: D
NEW QUESTION 14
In a Fllesystem Hierarchy Standard (FHS), which of the following directories contains the binary files required for working?
- A. /sbin
- B. /proc
- C. /mm
- D. /media
Answer: A
NEW QUESTION 15
Robert, a cloud architect, received a huge bill from the cloud service provider, which usually doesn't happen. After analyzing the bill, he found that the cloud resource consumption was very high. He then examined the cloud server and discovered that a malicious code was running on the server, which was generating huge but harmless traffic from the server. This means that the server has been compromised by an attacker with the sole intention to hurt the cloud customer financially. Which attack is described in the above scenario?
- A. XSS Attack
- B. DDoS Attack (Distributed Denial of Service)
- C. Man-in-the-cloud Attack
- D. EDoS Attack (Economic Denial of Service)
Answer: B
NEW QUESTION 16
An investigator is searching through the firewall logs of a company and notices ICMP packets that are larger than 65,536 bytes. What type of activity is the investigator seeing?
- A. Smurf
- B. Ping of death
- C. Fraggle
- D. Nmap scan
Answer: B
NEW QUESTION 17
......
Recommend!! Get the Full 312-49v10 dumps in VCE and PDF From Certleader, Welcome to Download: https://www.certleader.com/312-49v10-dumps.html (New 701 Q&As Version)