Free EC-Council 312-49v10 Exam Questions (page: 33)

In conducting a computer abuse investigation you become aware that the suspect of the investigation is using ABC Company as his Internet Service Provider
(ISP). You contact ISP and request that they provide you assistance with your investigation.
What assistance can the ISP provide?

  1. The ISP can investigate anyone using their service and can provide you with assistance
  2. The ISP can investigate computer abuse committed by their employees, but must preserve the privacy of their customers and therefore cannot assist you without a warrant
  3. The ISP can't conduct any type of investigations on anyone and therefore can't assist you
  4. ISP's never maintain log les so they would be of no use to your investigation

Answer(s): B



You are assisting in the investigation of a possible Web Server Hack. The company who called you stated that customers reported to them that whenever they entered the web address of the company in their browser, what they received was a porno graphic web site. The company checked the web server and nothing appears wrong.
When you type in the IP address of the web site in your browser everything appears normal.
What is the name of the attack that affects the DNS cache of the name resolution servers, resulting in those servers directing users to the wrong web site?

  1. ARP Poisoning
  2. DNS Poisoning
  3. HTTP redirect attack
  4. IP Spoo ng

Answer(s): B



Analyze the hex representation of mysql-bin.000013 le in the screenshot below. Which of the following will be an inference from this analysis?

  1. A user with username bad_guy has logged into the WordPress web application
  2. A WordPress user has been created with the username anonymous_hacker
  3. An attacker with name anonymous_hacker has replaced a user bad_guy in the WordPress database
  4. A WordPress user has been created with the username bad_guy

Answer(s): D



Law enforcement o cers are conducting a legal search for which a valid warrant was obtained. While conducting the search, o cers observe an item of evidence for an unrelated crime that was not included in the warrant. The item was clearly visible to the o cers and immediately identi ed as evidence.
What is the term used to describe how this evidence is admissible?

  1. Plain view doctrine
  2. Corpus delicti
  3. Locard Exchange Principle
  4. Ex Parte Order

Answer(s): A



Viewing page 33 of 171



Post your Comments and Discuss EC-Council 312-49v10 exam prep with other Community members:

312-49v10 Exam Discussions & Posts