
2022 Current 312-49v10 dumps Preparation through Our Practice Test
100% Reliable Microsoft 312-49v10 Exam Dumps Test Pdf Exam Material
EC-COUNCIL 312-49v10 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
NEW QUESTION 340
Paul's company is in the process of undergoing a complete security audit including logical and physical security testing. After all logical tests were performed; it is now time for the physical round to begin. None of the employees are made aware of this round of testing. The security-auditing firm sends in a technician dressed as an electrician. He waits outside in the lobby for some employees to get to work and follows behind them when they access the restricted areas. After entering the main office, he is able to get into the server room telling the IT manager that there is a problem with the outlets in that room. What type of attack has the technician performed?
- A. Tailgating
- B. Backtrapping
- C. Fuzzing
- D. Man trap attack
Answer: A
NEW QUESTION 341
What is the name of the Standard Linux Command that is also available as windows application that can be used to create bit-stream images?
- A. mcopy
- B. dd
- C. MD5
- D. image
Answer: B
NEW QUESTION 342
Which of the following is a MAC-based File Recovery Tool?
- A. Cisdem DataRecovery 3
- B. Smart Undeleter
- C. GetDataBack
- D. VirtualLab
Answer: A
NEW QUESTION 343
Harold wants to set up a firewall on his network but is not sure which one would be the most appropriate. He knows he needs to allow FTP traffic to one of the servers on his network, but he wants to only allow FTP-PUT. Which firewall would be most appropriate for Harold? needs?
- A. Application-level proxy firewall
- B. Data link layer firewall
- C. Packet filtering firewall
- D. Circuit-level proxy firewall
Answer: A
NEW QUESTION 344
When carrying out a forensics investigation, why should you never delete a partition on a dynamic disk?
- A. This action can corrupt the disk
- B. All virtual memory will be deleted
- C. The wrong partition may be set to active
- D. The computer will be set in a constant reboot state
Answer: A
NEW QUESTION 345
You are the network administrator for a small bank in Dallas, Texas. To ensure network security, you enact a security policy that requires all users to have 14 character passwords. After giving your users 2 weeks notice, you change the Group Policy to force 14 character passwords. A week later you dump the SAM database from the standalone server and run a password-cracking tool against it. Over 99% of the passwords are broken within an hour. Why were these passwords cracked so Quickly?
- A. A password Group Policy change takes at least 3 weeks to completely replicate throughout a network
- B. Networks using Active Directory never use SAM databases so the SAM database pulled was empty
- C. The passwords that were cracked are local accounts on the Domain Controller
- D. Passwords of 14 characters or less are broken up into two 7-character hashes
Answer: D
NEW QUESTION 346
Sheila is a forensics trainee and is searching for hidden image files on a hard disk. She used a forensic investigation tool to view the media in hexadecimal code for simplifying the search process. Which of the following hex codes should she look for to identify image files?
- A. d0 0f 11 e0
- B. ff d8 ff
- C. 25 50 44 46
- D. 50 41 03 04
Answer: B
NEW QUESTION 347
Which one of the following is not a first response procedure?
- A. Fill forms
- B. Preserve volatile data
- C. Crack passwords
- D. Take photos
Answer: C
NEW QUESTION 348
Which of the following statements is TRUE about SQL Server error logs?
- A. Error logs contain IP address of SQL Server client connections
- B. Forensic investigator uses SQL Server Profiler to view error log files
- C. SQL Server error logs record all the events occurred on the SQL Server and its databases
- D. Trace files record, user-defined events, and specific system events
Answer: B
NEW QUESTION 349
Which password cracking technique uses details such as length of password, character sets used to construct the password, etc.?
- A. Dictionary attack
- B. Man in the middle attack
- C. Rule-based attack
- D. Brute force attack
Answer: A
NEW QUESTION 350
Rusty, a computer forensics apprentice, uses the command nbtstat -c while analyzing the network information in a suspect system. What information is he looking for?
- A. Status of the network carrier
- B. Contents of the NetBIOS name cache
- C. Network connections
- D. Contents of the network routing table
Answer: B
NEW QUESTION 351
Why are Linux/Unix based computers better to use than Windows computers for idle scanning?
- A. Windows computers are constantly talking
- B. Windows computers will not respond to idle scans
- C. Linux/Unix computers are easier to compromise
- D. Linux/Unix computers are constantly talking
Answer: A
NEW QUESTION 352
Which of the following information is displayed when Netstat is used with -ano switch?
- A. Details of routing table
- B. Ethernet statistics
- C. Contents of IP routing table
- D. Details of TCP and UDP connections
Answer: D
NEW QUESTION 353
Which of the following files stores information about a local Google Drive installation such as User email ID, Local Sync Root Path, and Client version installed?
- A. sigstore.db
- B. filecache.db
- C. config.db
- D. Sync_config.db
Answer: D
NEW QUESTION 354
Which of the following Event Correlation Approach is an advanced correlation method that assumes and predicts what an attacker can do next after the attack by studying the statistics and probability and uses only two variables?
- A. Rule-Based Approach
- B. Route Correlation
- C. Bayesian Correlation
- D. Vulnerability-Based Approach
Answer: C
NEW QUESTION 355
Which of the following setups should a tester choose to analyze malware behavior?
- A. A virtual system with network simulation for internet connection
- B. A normal system without internet connect
- C. A normal system with internet connection
- D. A virtual system with internet connection
Answer: A
NEW QUESTION 356
......
Free 312-49v10 Dumps are Available for Instant Access: https://www.pass4sures.top/CHFI-v10/312-49v10-testking-braindumps.html