Jan-2022 Latest Exam4Docs 312-49v9 Exam Dumps with PDF and Exam Engine Free Updated Today!
Following are some new 312-49v9 Real Exam Questions!
NEW QUESTION 32
In the following directory listing,
Which file should be used to restore archived email messages for someone using Microsoft Outlook?
- A. Outlook ost
- B. Outlook pst
- C. Outlook bak
- D. Outlook NK2
Answer: B
NEW QUESTION 33
Which of the following statements does not support the case assessment?
- A. Review the case investigator's request for service
- B. Identify the legal authority for the forensic examination request
- C. Do not document the chain of custody
- D. Discuss whether other forensic processes need to be performed on the evidence
Answer: C
NEW QUESTION 34
You are working as an independent computer forensics investigator and received a call from a systems administrator for a local school system requesting your assistance. One of the students at the local high school is suspected of downloading inappropriate images from the Internet to a PC in the Computer Lab. When you arrive at the school, the systems administrator hands you a hard drive and tells you that he made a "simple backup copy" of the hard drive in the PC and put it on this drive and requests that you examine the drive for evidence of the suspected images. You inform him that a "simple backup copy" will not provide deleted files or recover file fragments. What type of copy do you need to make to ensure that the evidence found is complete and admissible in future proceeding?
- A. Full backup copy
- B. Bit-stream copy
- C. Incremental backup copy
- D. Robust copy
Answer: B
NEW QUESTION 35
A Linux system is undergoing investigation. In which directory should the investigators look for its current state data if the system is in powered on state?
- A. / /proc
- B. /var/spool/cron/
- C. /var/log/debug
- D. /auth
Answer: A
NEW QUESTION 36
An investigator is searching through the firewall logs of a company and notices ICMP packets that are larger than 65,536 bytes. What type of activity is the investigator seeing?
- A. Nmap scan
- B. Smurf
- C. Ping of death
- D. Fraggle
Answer: C
NEW QUESTION 37
> NMAP -sn 192.168.11.200-215 The NMAP command above performs which of the following?
- A. A trace sweep
- B. A ping scan
- C. An operating system detect
- D. A port scan
Answer: B
NEW QUESTION 38
What does the superblock in Linux define?
- A. location of the firstinode
- B. filesynames
- C. diskgeometr
- D. available space
Answer: A
NEW QUESTION 39
Law enforcement officers are conducting a legal search for which a valid warrant was obtained. While conducting the search, officers observe an item of evidence for an unrelated crime that was not included in the warrant. The item was clearly visible to the officers and immediately identified as evidence. What is the term used to describe how this evidence is admissible?
- A. Locard Exchange Principle
- B. Ex Parte Order
- C. Corpus delicti
- D. Plain view doctrine
Answer: D
NEW QUESTION 40
Which of the following Windows-based tool displays who is logged onto a computer, either locally or remotely?
- A. PSLoggedon
- B. TCPView
- C. Tokenmon
- D. Process Monitor
Answer: A
NEW QUESTION 41
You work as an IT security auditor hired by a law firm in Boston to test whether you can gain access to sensitive information about the company clients. You have rummaged through their trash and found very little information. You do not want to set off any alarms on their network, so you plan on performing passive foot printing against their Web servers. What tool should you use?
- A. Dig
- B. Netcraft
- C. Nmap
- D. Ping sweep
Answer: B
NEW QUESTION 42
You are a security analyst performing reconnaissance on a company you will be carrying out a penetration test for. You conduct a search for IT jobs on Dice.com and find the following information for an open position: 7+ years experience in Windows Server environment 5+ years experience in Exchange 2000/2003 environment Experience with Cisco Pix Firewall, Linksys 1376 router, Oracle 11i and MYOB v3.4 Accounting software are required MCSA desired, MCSE, CEH preferred No Unix/Linux Experience needed What is this information posted on the job website considered?
- A. Information vulnerability
- B. Social engineering exploit
- C. Trade secret
- D. Competitive exploit
Answer: A
NEW QUESTION 43
What will the following command accomplish?
dd if=/dev/xxx of=mbr.backup bs=512 count=1
- A. Restore the first 512 bytes of the first partition of the hard drive
- B. Restore the master boot record
- C. Mount the master boot record on the first partition of the hard drive
- D. Back up the master boot record
Answer: D
NEW QUESTION 44
When investigating a wireless attack, what information can be obtained from the DHCP logs?
- A. MAC address of the attacker
If any computers on the network are running in promiscuous mode - B. The operating system of the attacker and victim computersThe operating system of the attacker and victim? computers
- C. IP traffic between the attacker and the victim
Answer: A
NEW QUESTION 45
Which of the following Android libraries are used to render 2D (SGL) or 3D (OpenGL/ES) graphics content to the screen?
- A. Media framework
- B. WebKit
- C. Surface Manager
- D. OpenGL/ES and SGL
Answer: D
NEW QUESTION 46
Law enforcement officers are conducting a legal search for which a valid warrant was obtained.
While conducting the search, officers observe an item of evidence for an unrelated crime that was not included in the warrant. The item was clearly visible to the officers and immediately identified as evidence. What is the term used to describe how this evidence is admissible?
- A. Locard Exchange Principle
- B. Ex Parte Order
- C. Corpus delicti
- D. Plain view doctrine
Answer: D
NEW QUESTION 47
What does ICMP Type 3/Code 13 mean?
- A. Host Unreachable
- B. Administratively Blocked
- C. Protocol Unreachable
- D. Port Unreachable
Answer: B
NEW QUESTION 48
A rogue/unauthorized access point is one that Is not authorized for operation by a particular firm or network
- A. True
- B. False
Answer: A
NEW QUESTION 49
In the context of file deletion process, which of the following statement holds true?
- A. When files are deleted, the data is overwritten and the cluster marked as available
- B. While booting, the machine may create temporary files that can delete evidence
- C. The longer a disk is in use, the less likely it is that deleted files will be overwritten
- D. Secure delete programs work by completely overwriting the file in one go
Answer: B
NEW QUESTION 50
......
Resources From:
- 2022 Latest Exam4Docs 312-49v9 Exam Dumps (PDF & Exam Engine) Free Share: https://www.exam4docs.com/312-49v9-study-questions.html
Free Resources from Exam4Docs, We Devoted to Helping You 100% Pass All Exams!

