[Jan 22, 2022] Prepare For The 312-49v10 Question Papers In Advance
312-49v10 PDF Dumps Real 2022 Recently Updated Questions
NEW QUESTION 149
You work as a penetration tester for Hammond Security Consultants. You are currently working on a contract for the state government of Californi a. Your next step is to initiate a DoS attack on their network. Why would you want to initiate a DoS attack on a system you are testing?
- A. Use attack as a launching point to penetrate deeper into the network
- B. List weak points on their network
- C. Demonstrate that no system can be protected against DoS attacks
- D. Show outdated equipment so it can be replaced
Answer: B
NEW QUESTION 150
What does 254 represent in ICCID 89254021520014515744?
- A. Country Code
- B. Issuer Identifier Number
- C. Industry Identifier Prefix
- D. Individual Account Identification Number
Answer: A
NEW QUESTION 151
Which of the following file system uses Master File Table (MFT) database to store information about every file and directory on a volume?
- A. exFAT
- B. FAT File System
- C. NTFS File System
- D. ReFS
Answer: C
NEW QUESTION 152
Jonathan is a network administrator who is currently testing the internal security of his network. He is attempting to hijack a session, using Ettercap, of a user connected to his Web server. Why will Jonathan not succeed?
- A. Only DNS traffic can be hijacked
- B. HTTP protocol does not maintain session
- C. Only an HTTPS session can be hijacked
- D. Only FTP traffic can be hijacked
Answer: B
NEW QUESTION 153
Michael works for Kimball Construction Company as senior security analyst. As part of yearly security audit, Michael scans his network for vulnerabilities. Using Nmap, Michael conducts XMAS scan and most of the ports scanned do not give a response. In what state are these ports?
- A. Open
- B. Closed
- C. Stealth
- D. Filtered
Answer: A
NEW QUESTION 154
Which Linux command when executed displays kernel ring buffers or information about device drivers loaded into the kernel?
- A. grep
- B. pgrep
- C. dmesg
- D. fsck
Answer: C
NEW QUESTION 155
Andie, a network administrator, suspects unusual network services running on a windows system. Which of the following commands should he use to verify unusual network services started on a Windows system?
- A. netmgr
- B. net serv
- C. net start
- D. lusrmgr
Answer: C
NEW QUESTION 156
Diskcopy is:
- A. Digital Intelligence utility
- B. a standard MS-DOS command
- C. dd copying tool
- D. a utility by AccessData
Answer: B
Explanation:
diskcopy is a STANDARD DOS utility. C:\WINDOWS>diskcopy /? Copies the contents of one floppy disk to another.
NEW QUESTION 157
Select the tool appropriate for examining the dynamically linked libraries of an application or malware.
- A. DependencyWalker
- B. PEiD
- C. SysAnalyzer
- D. ResourcesExtract
Answer: A
NEW QUESTION 158
What do you call the process in which an attacker uses magnetic field over the digital media device to delete any previously stored data?
- A. Disk magnetization
- B. Disk degaussing
- C. Disk deletion
- D. Disk cleaning
Answer: B
NEW QUESTION 159
You are asked to build a forensic lab and your manager has specifically informed you to use copper for lining the walls, ceilings, and floor. What is the main purpose of lining the walls, ceilings, and floor with copper?
- A. To avoid electromagnetic emanations
- B. To strengthen the walls, ceilings, and floor
- C. To control the room temperature
- D. To make the lab sound proof
Answer: D
NEW QUESTION 160
What is the investigator trying to view by issuing the command displayed in the following screenshot?
- A. List of services stopped
- B. List of services installed
- C. List of services closed recently
- D. List of services recently started
Answer: B
NEW QUESTION 161
James, a hacker, identifies a vulnerability in a website. To exploit the vulnerability, he visits the login page and notes down the session ID that is created. He appends this session ID to the login URL and shares the link with a victim. Once the victim logs into the website using the shared URL, James reloads the webpage (containing the URL with the session ID appended) and now, he can browse the active session of the victim. Which attack did James successfully execute?
- A. Cookie Tampering
- B. Cross Site Request Forgery
- C. Parameter Tampering
- D. Session Fixation Attack
Answer: D
NEW QUESTION 162
This is original file structure database that Microsoft originally designed for floppy disks. It is written to the outermost track of a disk and contains information about each file stored on the drive.
- A. File Allocation Table (FAT)
- B. Disk Operating System (DOS)
- C. Master File Table (MFT)
- D. Master Boot Record (MBR)
Answer: A
NEW QUESTION 163
What advantage does the tool Evidor have over the built-in Windows search?
- A. It can find bad sectors on the hard drive
- B. It can find files hidden within ADS
- C. It can search slack space
- D. It can find deleted files even after they have been physically removed
Answer: C
NEW QUESTION 164
What type of attack sends SYN requests to a target system with spoofed IP addresses?
- A. Cross site scripting
- B. Ping of death
- C. SYN flood
- D. Land
Answer: C
NEW QUESTION 165
Which of the following commands shows you the names of all open shared files on a server and the number of file locks on each file?
- A. Net file
- B. Net config
- C. Net sessions
- D. Net share
Answer: A
NEW QUESTION 166
The rule of thumb when shutting down a system is to pull the power plug. However, it has certain drawbacks. Which of the following would that be?
- A. All running processes will be lost
- B. Any data not yet flushed to the system will be lost
- C. Power interruption will corrupt the pagefile
- D. The /tmp directory will be flushed
Answer: B
NEW QUESTION 167
Which of the following stages in a Linux boot process involve initialization of the system's hardware?
- A. Bootloader Stage
- B. BootROM Stage
- C. BIOS Stage
- D. Kernel Stage
Answer: C
NEW QUESTION 168
Which of the following tool enables data acquisition and duplication?
- A. Wireshark
- B. Xplico
- C. DriveSpy
- D. Colasoft's Capsa
Answer: C
NEW QUESTION 169
When conducting computer forensic analysis, you must guard against ______________ So that you remain focused on the primary job and insure that the level of work does not increase beyond what was originally expected.
- A. Overzealous marketing
- B. Hard Drive Failure
- C. Scope Creep
- D. Unauthorized expenses
Answer: C
NEW QUESTION 170
Which one of the following is not a first response procedure?
- A. Crack passwords
- B. Fill forms
- C. Preserve volatile data
- D. Take photos
Answer: A
NEW QUESTION 171
When carrying out a forensics investigation, why should you never delete a partition on a dynamic disk?
- A. The wrong partition may be set to active
- B. All virtual memory will be deleted
- C. The computer will be set in a constant reboot state
- D. This action can corrupt the disk
Answer: D
NEW QUESTION 172
......
EC-COUNCIL 312-49v10 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
312-49v10 Dumps and Practice Test (598 Exam Questions): https://www.pass4sures.top/CHFI-v10/312-49v10-testking-braindumps.html