EC-Council EC0-349 Exam Questions
EC0-349 ECCouncil Computer Hacking Forensic Investigator (Page 10 )

Updated On: 24-Feb-2026

What happens when a file is deleted by a Microsoft operating system using the FAT file system?

  1. a copy of the file is stored and the original file is erased
  2. the file is erased and cannot be recovered
  3. only the reference to the file is removed from the FAT
  4. the file is erased but can be recovered

Answer(s): C



Jones had been trying to penetrate a remote production system for the past two weeks. This time however, he is able to get into the system. He was able to use the system for a period of three weeks. However law enforcement agencies were recording his every activity and this was later presented as evidence. The organization had used a virtual environment to trap Jones. What is a virtual environment?

  1. A system using Trojaned commands
  2. A honeypot that traps hackers
  3. An environment set up beforean user logs in
  4. An environment set up after the user logs in

Answer(s): B



You are called by an author who is writing a book and he wants to know how long the copyright for his book will last after he has the book published?

  1. the life of the author
  2. the life of the author plus 70 years
  3. 70 years
  4. copyrights last forever

Answer(s): B



If a suspect's computer is located in an area that may have toxic chemicals, you must

  1. coordinate with the HAZMAT team
  2. determine a way to obtain the suspect computer
  3. do not enter alone
  4. assume the suspect machine is contaminated

Answer(s): A



When investigating a network that uses DHCP to assign IP addresses, where would you look to determine which system (MAC address) had a specific IP address at a specific time?

  1. in the Web Server log files
  2. in the DHCP Server log files
  3. on the individual computer's ARP cache
  4. there is no way to determine the specific IP address

Answer(s): B






Post your Comments and Discuss EC-Council EC0-349 exam dumps with other Community members:

Join the EC0-349 Discussion