Free 312-49V9 Exam Braindumps (page: 51)

Page 51 of 122

You have been asked to investigate the possibility of computer fraud in the finance department of a company. It is suspected that a staff member has been committing finance fraud by printing cheques that have not been authorized. You have exhaustively searched all data files on a bitmap image of the target computer, but have found no evidence. You suspect the files may not have been saved. What should you examine next in this case?

  1. The registry
  2. The swapfile
  3. The recycle bin
  4. The metadata

Answer(s): B



When marking evidence that has been collected with the aa/ddmmyy/nnnn/zz?format, what does the nnn?denote?When marking evidence that has been collected with the ?aa/ddmmyy/nnnn/zz?format, what does the ?nnn?denote?

  1. The year the evidence was taken
  2. The sequence number for the parts of the same exhibit
  3. The initials of the forensics analyst
  4. The sequential number of the exhibits seized

Answer(s): D



When searching through file headers for picture file formats, what should be searched to find a JPEG file in hexadecimal format?

  1. FF D8 FF E0 00 10
  2. FF FF FF FF FF FF
  3. FF 00 FF 00 FF 00
  4. EF 00 EF 00 EF 00

Answer(s): A



Where does Encase search to recover NTFS files and folders?

  1. MBR
  2. MFT
  3. Slack space
  4. HAL

Answer(s): B



Page 51 of 122



Post your Comments and Discuss EC-Council 312-49V9 exam with other Community members:

Olu commented on October 16, 2023
Question 235: 22,164 x 80 x 63 x 512 = 57.19 GB
UNITED STATES
upvote