EC-COUNCIL Computer Hacking Forensic Investigator - EC0-349 Exam Practice Test

Question 1
At what layer of the OSI model do routers function on?

Correct Answer: C
Question 2
Lance wants to place a honeypot on his network. Which of the following would be your recommendations?

Correct Answer: A
Question 3
You are a security analyst performing a penetration tests for a company in the Midwest. After some initial reconnaissance, you discover the IP addresses of some Cisco routers used by the company. You type in the following URL that includes the IP address of one of the routers:
http://172.168.4.131/level/99/exec/show/config
After typing in this URL, you are presented with the entire configuration file for that router.
What have you discovered?

Correct Answer: A
Question 4
Using Linux to carry out a forensics investigation, what would the following command accomplish? dd if=/usr/home/partition.image of=/dev/sdb2 bs=4096 conv=notrunc,noerror

Correct Answer: C
Question 5
FAT32 is a 32-bit version of FAT file system using smaller clusters and results in efficient storage capacity. What is the maximum drive size supported?

Correct Answer: B
Question 6
In Windows 7 system files, which file reads the Boot.ini file and loads Ntoskrnl.exe. Bootvid.dll.
Hal.dll, and boot-start device drivers?

Correct Answer: B
Question 7
You are trying to locate Microsoft Outlook Web Access Default Portal using Google search on the Internet. What search string will you use to locate them?

Correct Answer: B
Question 8
Which of the following Wi-Fi chalking methods refers to drawing symbols in public places to advertise open Wi-Fi networks?

Correct Answer: D
Question 9
____________________ is simply the application of Computer Investigation and analysis techniques in the interests of determining potential legal evidence.

Correct Answer: C
Question 10
If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system while doing an investigation, what can you conclude?

Correct Answer: C
Question 11
A computer forensic report is a report which provides detailed information on the complete forensics investigation process.

Correct Answer: A
Question 12
Under which Federal Statutes does FBI investigate for computer crimes involving e- mail scams and mail fraud?

Correct Answer: B
Question 13
What advantage does the tool Evidor have over the built-in Windows search?

Correct Answer: A
Question 14
A forensics investigator needs to copy data from a computer to some type of removable media so he can examine the information at another location. The problem is that the data is around 42GB in size. What type of removable media could the investigator use?

Correct Answer: A
Question 15
You should always work with original evidence

Correct Answer: B