ExamGecko
Home Home / ECCouncil / 312-49v10

ECCouncil 312-49v10 Practice Test - Questions Answers, Page 33

Question list
Search
Search

List of questions

Search

Related questions











Which of the following files stores information about local Dropbox installation and account, email IDs linked with the account, current version/build for the local application, the host_id, and local path information?

A.
host.db
A.
host.db
Answers
B.
sigstore.db
B.
sigstore.db
Answers
C.
config.db
C.
config.db
Answers
D.
filecache.db
D.
filecache.db
Answers
Suggested answer: C

An executive has leaked the company trade secrets through an external drive. What process should the investigation team take if they could retrieve his system?

A.
Postmortem Analysis
A.
Postmortem Analysis
Answers
B.
Real-Time Analysis
B.
Real-Time Analysis
Answers
C.
Packet Analysis
C.
Packet Analysis
Answers
D.
Malware Analysis
D.
Malware Analysis
Answers
Suggested answer: A

Company ABC has employed a firewall, IDS, Antivirus, Domain Controller, and SIEM. The company's domain controller goes down. From which system would you begin your investigation?

A.
Domain Controller
A.
Domain Controller
Answers
B.
Firewall
B.
Firewall
Answers
C.
SIEM
C.
SIEM
Answers
D.
IDS
D.
IDS
Answers
Suggested answer: C

Which code does the FAT file system use to mark the file as deleted?

A.
ESH
A.
ESH
Answers
B.
5EH
B.
5EH
Answers
C.
H5E
C.
H5E
Answers
D.
E5H
D.
E5H
Answers
Suggested answer: D

What does the 63.78.199.4(161) denotes in a Cisco router log?

Mar 14 22:57:53.425 EST: %SEC-6-IPACCESSLOGP: list internet-inbound denied udp 66.56.16.77(1029) -> 63.78.199.4(161), 1 packet

A.
Destination IP address
A.
Destination IP address
Answers
B.
Source IP address
B.
Source IP address
Answers
C.
Login IP address
C.
Login IP address
Answers
D.
None of the above
D.
None of the above
Answers
Suggested answer: A

Microsoft Security IDs are available in Windows Registry Editor. The path to locate IDs in Windows 7 is:

A.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
A.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
Answers
B.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProfileList
B.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProfileList
Answers
C.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegList
C.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegList
Answers
D.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Regedit
D.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Regedit
Answers
Suggested answer: A

Which of the following commands shows you all of the network services running on Windows-based servers?

A.
Netstart
A.
Netstart
Answers
B.
Net Session
B.
Net Session
Answers
C.
Net use
C.
Net use
Answers
D.
Net config
D.
Net config
Answers
Suggested answer: A

Which of the following are small pieces of data sent from a website and stored on the user's computer by the user's web browser to track, validate, and maintain specific user information?

A.
Temporary Files
A.
Temporary Files
Answers
B.
Open files
B.
Open files
Answers
C.
Cookies
C.
Cookies
Answers
D.
Web Browser Cache
D.
Web Browser Cache
Answers
Suggested answer: C

Pagefile.sys is a virtual memory file used to expand the physical memory of a computer. Select the registry path for the page file:

A.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
A.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
Answers
B.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\System Management
B.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\System Management
Answers
C.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Device Management
C.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Device Management
Answers
D.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters
D.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters
Answers
Suggested answer: A

Which of the following commands shows you the names of all open shared files on a server and the number of file locks on each file?

A.
Net config
A.
Net config
Answers
B.
Net file
B.
Net file
Answers
C.
Net share
C.
Net share
Answers
D.
Net sessions
D.
Net sessions
Answers
Suggested answer: B
Total 704 questions
Go to page: of 71