EC-Council 312-49V9 Exam Questions
ECCouncil Computer Hacking Forensic Investigator (V9) (Page 12 )

Updated On: 17-Feb-2026

Which one of the following statements is not correct while preparing for testimony?

  1. Go through the documentation thoroughly
  2. Do not determine the basic facts of the case before beginning and examining the evidence
  3. Establish early communication with the attorney
  4. Substantiate the findings with documentation and by collaborating with other computer forensics professionals

Answer(s): B



Computer security logs contain information about the events occurring within an organization's systems and networks. Application and Web server log files are useful in detecting web attacks. The source, nature, and time of the attack can be determined by _________of the compromised system.

  1. Analyzing log files
  2. Analyzing SAM file
  3. Analyzing rainbow tables
  4. Analyzing hard disk boot records

Answer(s): A



An intrusion detection system (IDS) gathers and analyzes information from within a computer or a network to identify any possible violations of security policy, including unauthorized access, as well as misuse.
Which of the following intrusion detection systems audit events that occur on a specific host?

  1. Network-based intrusion detection
  2. Host-based intrusion detection
  3. Log file monitoring
  4. File integrity checking

Answer(s): B



What is a first sector ("sector zero") of a hard disk?

  1. Master boot record
  2. System boot record
  3. Secondary boot record
  4. Hard disk boot record

Answer(s): A



Ever-changing advancement or mobile devices increases the complexity of mobile device examinations. Which or the following is an appropriate action for the mobile forensic investigation?

  1. To avoid unwanted interaction with devices found on the scene, turn on any wireless interfaces such as Bluetooth and Wi-Fi radios
  2. Do not wear gloves while handling cell phone evidence to maintain integrity of physical evidence
  3. If the device's display is ON. the screen's contents should be photographed and, if necessary, recorded manually, capturing the time, service status, battery level, and other displayed icons
  4. If the phone is in a cradle or connected to a PC with a cable, then unplug the device from the computer

Answer(s): C






Post your Comments and Discuss EC-Council 312-49V9 exam dumps with other Community members:

Join the 312-49V9 Discussion