312-49 Training & Certification Get Latest Certified Ethical Hacker Updated on Jun 30, 2021 [Q47-Q67]

Share

312-49 Training & Certification Get Latest Certified Ethical Hacker Updated on Jun 30, 2021

Certification Training for 312-49 Exam Dumps Test Engine

NEW QUESTION 47
Which of the following tool captures and allows you to interactively browse the traffic on a network?

  • A. RegScanner
  • B. ThumbsDisplay
  • C. Wireshark
  • D. Security Task Manager

Answer: C

 

NEW QUESTION 48
A picture file is recovered from a computer under investigation. During the investigation process, the file is enlarged 500% to get a better view of its contents. The picture quality is not degraded at all from this process. What kind of picture is this file?its contents. The picture? quality is not degraded at all from this process. What kind of picture is this file?

  • A. Vector image
  • B. Raster image
  • C. Catalog image
  • D. Metafile image

Answer: A

 

NEW QUESTION 49
Why is it still possible to recover files that have been emptied from the Recycle Bin on a
Windows computer?

  • A. The data is still present until the original location of the file is used
  • B. The data is moved to the Restore directory and is kept there indefinitely
  • C. The data will reside in the L2 cache on a Windows computer until it is manually deleted
  • D. It is not possible to recover data that has been emptied from the Recycle Bin

Answer: A

 

NEW QUESTION 50
Travis, a computer forensics investigator, is finishing up a case he has been working on for over a month involving copyright infringement and embezzlement. His last task is to prepare an investigative report for the president of the company he has been working for. Travis must submit a hard copy and an electronic copy to this president. In what electronic format should Travis send this report?

  • A. DOC
  • B. WPD
  • C. PDF
  • D. TIFF-8

Answer: C

 

NEW QUESTION 51
Frank is working on a vulnerability assessment for a company on the West coast. The company hired Frank to assess its network security through scanning, pen tests, and vulnerability assessments. After discovering numerous known vulnerabilities detected by a temporary IDS he set up, he notices a number of items that show up as unknown but Questionable in the logs. He looks up the behavior on the Internet, but cannot find anything related. What organization should Frank submit the log to find out if it is a new vulnerability or not?

  • A. APIPA
  • B. CVE
  • C. RIPE
  • D. IANA

Answer: B

 

NEW QUESTION 52
What will the following command accomplish? dd if=/dev/xxx of=mbr.backup bs=512 count=1

  • A. Mount the master boot record on the first partition of the hard drive
  • B. Restore the master boot record
  • C. Restore the first 512 bytes of the first partition of the hard drive
  • D. Back up the master boot record

Answer: D

 

NEW QUESTION 53
You have been called in to help with an investigation of an alleged network intrusion. After questioning the members of the company ITYou have been called in to help with an investigation of an alleged network intrusion. After questioning the members of the company? IT department, you search through the server log files to find any trace of the intrusion. After that you decide to telnet into one of the company routers to see if there is any evidence to be found. While connected to the router, you see some unusual activity and believe that the attackers are currently connected to that router. You start up an ethereal session to begin capturing traffic on the router that could be used in the investigation. At what layer of the OSI model are you monitoring while watching traffic to and from the router?

  • A. Transport
  • B. Session
  • C. Network
  • D. Data Link

Answer: C

 

NEW QUESTION 54
Microsoft Outlook maintains email messages in a proprietary format in what type of file?

  • A. .pst
  • B. .doc
  • C. .email
  • D. .mail

Answer: A

 

NEW QUESTION 55
John is working on his company policies and guidelines. The section he is currently working on covers company documents; how they shouldJohn is working on his company? policies and guidelines. The section he is currently working on covers company documents; how they should be handled, stored, and eventually destroyed. John is concerned about the process whereby outdated documents are destroyed. What type of shredder should
John write in the guidelines to be used when destroying documents?

  • A. Strip-cut shredder
  • B. Cross-hatch shredder
  • C. Cross-cut shredder
  • D. Cris-cross shredder

Answer: C

 

NEW QUESTION 56
In what way do the procedures for dealing with evidence in a criminal case differ from the procedures for dealing with evidence in a civil case?

  • A. evidence in a criminal case must be secured more tightly than in a civil case
  • B. evidence must be handled in the same way regardless of the type of case
  • C. evidence in a civil case must be secured more tightly than in a criminal case
  • D. evidence procedures are not important unless you work for a law enforcement agency

Answer: A

 

NEW QUESTION 57
When investigating a network that uses DHCP to assign IP addresses, where would you look to determine which system (MAC address) had a specific IP address at a specific time?

  • A. On the individual computer ARP cacheOn the individual computer? ARP cache
  • B. There is no way to determine the specific IP address
  • C. In the Web Server log files
  • D. In the DHCP Server log files

Answer: D

 

NEW QUESTION 58
You are trying to locate Microsoft Outlook Web Access Default Portal using Google search on the Internet.
What search string will you use to locate them?

  • A. locate:"logon page"
  • B. allinurl:"exchange/logon.asp"
  • C. outlook:"search"
  • D. intitle:"exchange server"

Answer: B

 

NEW QUESTION 59
Where is the default location for Apache access logs on a Linux computer?

  • A. bin/local/home/apache/logs/access_log
  • B. logs/usr/apache/access_log
  • C. usr/logs/access_log
  • D. usr/local/apache/logs/access_log

Answer: D

 

NEW QUESTION 60
What is the CIDR from the following screenshot?

  • A. /24A./24A./24
  • B. /32 B./32 B./32
  • C. /8D./8D./8
  • D. /16 C./16 C./16

Answer: C

 

NEW QUESTION 61
Where are files temporarily written in Unix when printing?

  • A. /var/spool
  • B. /var/print
  • C. /spool
  • D. /usr/spool

Answer: A

 

NEW QUESTION 62
The offset in a hexadecimal code is:

  • A. The 0x at the end of the code
  • B. The last byte after the colon
  • C. The 0x at the beginning of the code
  • D. The first byte after the colon

Answer: C

 

NEW QUESTION 63
Harold is finishing up a report on a case of network intrusion, corporate spying, and embezzlement that he has been working on for over six months. He is trying to find the right term to use in his report to describe network-enabled spying. What term should Harold use?

  • A. Hackspionage
  • B. Spycrack
  • C. Spynet
  • D. Netspionage

Answer: D

 

NEW QUESTION 64
When cataloging digital evidence, the primary goal is to

  • A. Preserve evidence integrity
  • B. Not allow the computer to be turned off
  • C. Make bit-stream images of all hard drives
  • D. Not remove the evidence from the scene

Answer: A

 

NEW QUESTION 65
Simon is a former employee of Trinitron XML Inc. He feels he was wrongly terminated and wants to hack into his former company's network. Since Simon remembers some of the server names, he attempts to run the axfr and ixfr commands using DIG. What is Simon trying to accomplish here?

  • A. Enumerate all the users in the domain
  • B. Send DOS commands to crash the DNS servers
  • C. Perform DNS poisoning
  • D. Perform a zone transfer

Answer: D

 

NEW QUESTION 66
When examining a hard disk without a write-blocker, you should not start windows because Windows will write data to the:

  • A. BIOS
  • B. Case files
  • C. Recycle Bin
  • D. MSDOS.sys

Answer: C

 

NEW QUESTION 67
......

Step by Step Guide to Prepare for 312-49 Exam: https://www.lead2passexam.com/EC-COUNCIL/valid-312-49-exam-dumps.html