EC-COUNCIL Computer Hacking Forensic Investigator - EC1-349 Exam Practice Test
Question 1
If the partition size Is 4 GB, each cluster will be 32 K.
Even If a file needs only 10 K, the entire 32 K will be allocated, resulting In 22 K of___________.
Even If a file needs only 10 K, the entire 32 K will be allocated, resulting In 22 K of___________.
Correct Answer: D
Question 2
What is the "Best Evidence Rule"?
Correct Answer: A
Question 3
Determine the message length from following hex viewer record:


Correct Answer: D
Question 4
In which step of the computer forensics investigation methodology would you run MD5 checksum on the evidence?
Correct Answer: C
Question 5
Subscriber Identity Module (SIM) is a removable component that contains essential information about the subscriber. Its main function entails authenticating the user of the cell phone to the network to gain access to subscribed services. SIM contains a 20-digit long Integrated Circuit Card identification (ICCID) number, identify the issuer identifier Number from the ICCID below.


Correct Answer: B
Question 6
When collecting electronic evidence at the crime scene, the collection should proceed from the most volatile to the least volatile
Correct Answer: A
Question 7
Which of the following attacks allows attacker to acquire access to the communication channels between the victim and server to extract the information?
Correct Answer: B
Question 8
Smith, as a part his forensic investigation assignment, has seized a mobile device. He was asked to recover the Subscriber Identity Module (SIM card) data the mobile device. Smith found that the SIM was protected by a Personal identification Number (PIN) code but he was also aware that people generally leave the PIN numbers to the defaults or use easily guessable numbers such as 1234. He unsuccessfully tried three PIN numbers that blocked the SIM card. What Jason can do in this scenario to reset the PIN and access SIM data?
Correct Answer: D
Question 9
Which of the following steganography types hides the secret message in a specifically designed pattern on the document that is unclear to the average reader?
Correct Answer: C
Question 10
Which of the following statements is incorrect related to acquiring electronic evidence at crime scene?
Correct Answer: B
Question 11
When the operating system marks cluster as used, but does not allocate them to any file, such clusters are known as ___________.
Correct Answer: D
Question 12
Ever-changing advancement or mobile devices increases the complexity of mobile device examinations. Which or the following is an appropriate action for the mobile forensic investigation?
Correct Answer: C
Question 13
Depending upon the Jurisdictional areas, different laws apply to different incidents. Which of the following law is related to fraud and related activity in connection with computers?
Correct Answer: D
Question 14
Quality of a raster Image is determined by the _________________and the amount of information in each pixel.
Correct Answer: A

