
Apr-2025 Pass Your 312-49v11 Exam at the First Try with 100% Real Exam
Get Real Exam Questions for 312-49v11 with New Questions
NEW QUESTION # 348
Why are Linux/Unix based computers better to use than Windows computers for idle scanning?
- A. Linux/Unix computers are easier to compromise
- B. Windows computers are constantly talking
- C. Windows computers will not respond to idle scans
- D. Linux/Unix computers are constantly talking
Answer: B
NEW QUESTION # 349
The system administrator of a large financial corporation detects an unauthorized attempt to access the company's database. In order to support the investigation and maintain the chain of custody, which of the following actions should be taken immediately by the administrator?
- A. Begin attempting to trace the source of the attack and retaliate to prevent future incidents
- B. Isolate the compromised computing systems from further use or tampering, document every detail relevant to the incident, and transfer copies of system logs onto clean media
- C. Independently analyze the compromised systems for evidence of a security breach without notifying the incident/duty manager
- D. Power down all computing systems to halt the unauthorized access attempt
Answer: B
NEW QUESTION # 350
Investigator Janet comes across a suspicious Windows registry key during a computer hacking forensic investigation. She believes modifying this key is associated with the recent cyberattack on the company's servers. In order to confirm this, Janet needs to reference a timestamp embedded inside the registry key. What is the correct name of this timestamp?
- A. Last Write Time
- B. System Modification Time
- C. User Activity Time
- D. Current System Time
Answer: A
NEW QUESTION # 351
Which among the following U.S. laws requires financial institutions--companies that offer consumers financial products or services such as loans, financial or investment advice, or insurance--to protect their customers' information against security threats?
- A. HIPAA
- B. GLBA
- C. FISMA
- D. SOX
Answer: B
NEW QUESTION # 352
What are the security risks of running a "repair" installation for Windows XP?
- A. Pressing Shift+F1 gives the user administrative rights
- B. Pressing Shift+F10 gives the user administrative rights
- C. Pressing Ctrl+F10 gives the user administrative rights
- D. There are no security risks when running the "repair" installation for Windows XP
Answer: B
NEW QUESTION # 353
Simona has written a regular expression for the detection of web application-specific attack attempt that reads as /((\%3C)|<K(\%2F)|V)*[a-zO-9\%I*((\%3E)|>)/lx.
Which of the following does the part (|\%3E)|>) look for?
- A. Closing angle bracket or its hex equivalent
- B. Opening angle bracket or its hex equivalent
- C. Alphanumeric string or its hex equivalent
- D. Forward slash for a closing tag or its hex equivalent
Answer: D
NEW QUESTION # 354
After attending a CEH security seminar, you make a list of changes you would like to perform on your network to increase its security. One of the first things you change is to switch the RestrictAnonymous setting from 0 to 1 on your servers. This, as you were told, would prevent anonymous users from establishing a null session on the server. Using Userinfo tool mentioned at the seminar, you succeed in establishing a null session with one of the servers. Why is that?
- A. There is no way to always prevent an anonymous null session from establishing
- B. RestrictAnonymous must be set to "2" for complete security
- C. RestrictAnonymous must be set to "10" for complete security
- D. RestrictAnonymous must be set to "3" for complete security
Answer: B
NEW QUESTION # 355
Which response organization tracks hoaxes as well as viruses?
- A. CIAC
- B. CERT
- C. NIPC
- D. FEDCIRC
Answer: A
Explanation:
Note: CIAC (Computer Incident Advisory Capability) Was run by the US Department of energy
NEW QUESTION # 356
An Expert witness gives an opinion if:
- A. To stimulate discussion between the consulting expert and the expert witness
- B. To deter the witness form expanding the scope of his or her investigation beyond the requirements of the case
- C. The Opinion, inferences or conclusions depend on special knowledge, skill or training not within the ordinary experience of lay jurors
- D. To define the issues of the case for determination by the finder of fact
Answer: C
NEW QUESTION # 357
In Steganalysis, which of the following describes a Known-stego attack?
- A. Original and stego-object are available and the steganography algorithm is known
- B. Only the steganography medium is available for analysis
- C. During the communication process, active attackers can change cover
- D. The hidden message and the corresponding stego-image are known
Answer: A
NEW QUESTION # 358
The ARP table of a router comes in handy for Investigating network attacks, as the table contains IP addresses associated with the respective MAC addresses.
The ARP table can be accessed using the __________command in Windows 7.
- A. C:\arp -b
- B. C:\arp -a
- C. C:\arp -d
- D. C:\arp -s
Answer: B
NEW QUESTION # 359
With the standard Linux second extended file system (Ext2fs), a file is deleted when the inode internal link count reaches ______
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION # 360
During an investigation of a suspected network attack, a Computer Hacking Forensics Investigator (CHFI) is analyzing a firewall log from a Cisco system. The log entry includes a mnemonic message:
"%PIX-6-302015: Built outbound UDP connection."
Considering the information provided, what can the investigator infer from this log entry?
- A. The firewall has established an outbound UDP connection
- B. The firewall has blocked a connection attempt per the security policy or user-defined rules
- C. The firewall detected suspicious traffic, but the firewall accepted it
- D. The firewall has recorded an unsuccessful attempt to establish an outbound UDP connection
Answer: A
NEW QUESTION # 361
A forensic investigator is a person who handles the complete Investigation process, that is, the preservation, identification, extraction, and documentation of the evidence. The investigator has many roles and responsibilities relating to the cybercrime analysis. The role of the forensic investigator is to:
- A. Create an image backup of the original evidence without tampering with potential evidence
- B. Take permission from all employees of the organization for investigation
- C. Keep the evidence a highly confidential and hide the evidence from law enforcement agencies
- D. Harden organization network security
Answer: A
NEW QUESTION # 362
If a suspect computer is located in an area that may have toxic chemicals, you must:
- A. assume the suspect machine is contaminated
- B. do not enter alone
- C. determine a way to obtain the suspect computer
- D. coordinate with the HAZMAT team
Answer: D
NEW QUESTION # 363
When a user deletes a file or folder, the system stores complete path including the original filename is a special hidden file called "INFO2" in the Recycled folder. If the INFO2 file is deleted, it is recovered when you ______________________.
- A. Undo the last action performed on the system
- B. Reboot Windows
- C. Use a recovery tool to undelete the file
- D. Download the file from Microsoft website
Answer: A
NEW QUESTION # 364
You are the security analyst working for a private company out of France. Your current assignment is to obtain credit card information from a Swiss bank owned by that company. After initial reconnaissance, you discover that the bank security defenses are very strong and would take too long to penetrate. You decide to get the information by monitoring the traffic between the bank and one of its subsidiaries in London. After monitoring some of the traffic, you see a lot of FTP packets traveling back and forth. You want to sniff the traffic and extract usernames and passwords. What tool could you use to get this information?
- A. Airsnort
- B. Ettercap
- C. Snort
- D. RaidSniff
Answer: B
NEW QUESTION # 365
What encryption technology is used on Blackberry devices Password Keeper?
- A. Blowfish
- B. RC5
- C. 3DES
- D. AES
Answer: D
NEW QUESTION # 366
Which of the following statements is TRUE about SQL Server error logs?
- A. SQL Server error logs record all the events occurred on the SQL Server and its databases
- B. Error logs contain IP address of SQL Server client connections
- C. Trace files record, user-defined events, and specific system events
- D. Forensic investigator uses SQL Server Profiler to view error log files
Answer: D
NEW QUESTION # 367
Assume there Is a file named myflle.txt In C: drive that contains hidden data streams.
Which of the following commands would you Issue to display the contents of a data stream?
- A. C:\>ECHO text_message > myfile.txt:stream1
- B. C:\MORE < myfile.txt:siream1
- C. myfile.dat: st ream 1
- D. echo text > program: source_file
Answer: D
NEW QUESTION # 368
Quality of a raster Image is determined by the _________________and the amount of information in each pixel.
- A. Compression method
- B. Total number of pixels
- C. Image file format
- D. Image file size
Answer: B
NEW QUESTION # 369
When searching through file headers for picture file formats, what should be searched to find a JPEG file in hexadecimal format?
- A. FF D8 FF E0 00 10
- B. EF 00 EF 00 EF 00
- C. FF 00 FF 00 FF 00
- D. FF FF FF FF FF FF
Answer: A
NEW QUESTION # 370
Raw data acquisition format creates ____________of a data set or suspect drive.
- A. Compressed image files
- B. Segmented files
- C. Segmented image files
- D. Simple sequential flat files
Answer: D
NEW QUESTION # 371
A forensics investigator is studying the Event ID logs on a domain controller for a corporation, following a suspected security breach. He notices that a domain user account was created, then modified, and then added to a group in a very short span of time. The investigator realizes that he must cross-verify the audit policies on the local system to understand if any changes were made to it. Assuming that the investigator has the correct audit policy settings, which of the following Event IDs should he focus on?
- A. Event ID 624
- B. Event ID 642
- C. Event ID 644
- D. Event ID 612
Answer: A
NEW QUESTION # 372
A mobile operating system is the operating system that operates a mobile device like a mobile phone, smartphone, PDA, etc. It determines the functions and features available on mobile devices such as keyboards, applications, email, text messaging, etc. Which of the following mobile operating systems is free and open source?
- A. Apple IOS
- B. Web OS
- C. Symbian OS
- D. Android
Answer: D
NEW QUESTION # 373
......
Updated 312-49v11 Certification Exam Sample Questions: https://www.briandumpsprep.com/312-49v11-prep-exam-braindumps.html
Get Unlimited Access to 312-49v11 Certification Exam Cert Guide: https://drive.google.com/open?id=1zUoknUb3h-jmu6XLsbZAHyqXCzlJL0gq
