ExamGecko
Home Home / ECCouncil / 312-49v10

ECCouncil 312-49v10 Practice Test - Questions Answers, Page 36

Question list
Search
Search

Related questions











The investigator wants to examine changes made to the system's registry by the suspect program.

Which of the following tool can help the investigator?

A.
TRIPWIRE
A.
TRIPWIRE
Answers
B.
RAM Capturer
B.
RAM Capturer
Answers
C.
Regshot
C.
Regshot
Answers
D.
What's Running
D.
What's Running
Answers
Suggested answer: C

What does the part of the log, "% SEC-6-IPACCESSLOGP", extracted from a Cisco router represent?

A.
The system was not able to process the packet because there was not enough room for all of the desired IP header options
A.
The system was not able to process the packet because there was not enough room for all of the desired IP header options
Answers
B.
Immediate action required messages
B.
Immediate action required messages
Answers
C.
Some packet-matching logs were missed because the access list log messages were rate limited, or no access list log buffers were available
C.
Some packet-matching logs were missed because the access list log messages were rate limited, or no access list log buffers were available
Answers
D.
A packet matching the log criteria for the given access list has been detected (TCP or UDP)
D.
A packet matching the log criteria for the given access list has been detected (TCP or UDP)
Answers
Suggested answer: D

Files stored in the Recycle Bin in its physical location are renamed as Dxy.ext, where "x" represents the ___________________.

A.
Drive name
A.
Drive name
Answers
B.
Original file name's extension
B.
Original file name's extension
Answers
C.
Sequential number
C.
Sequential number
Answers
D.
Original file name
D.
Original file name
Answers
Suggested answer: A

Which of the following is an iOS Jailbreaking tool?

A.
Kingo Android ROOT
A.
Kingo Android ROOT
Answers
B.
Towelroot
B.
Towelroot
Answers
C.
One Click Root
C.
One Click Root
Answers
D.
Redsn0w
D.
Redsn0w
Answers
Suggested answer: D

Which of the following Registry components include offsets to other cells as well as the LastWrite time for the key?

A.
Value list cell
A.
Value list cell
Answers
B.
Value cell
B.
Value cell
Answers
C.
Key cell
C.
Key cell
Answers
D.
Security descriptor cell
D.
Security descriptor cell
Answers
Suggested answer: C

What is the default IIS log location?

A.
SystemDrive\inetpub\LogFiles
A.
SystemDrive\inetpub\LogFiles
Answers
B.
%SystemDrive%\inetpub\logs\LogFiles
B.
%SystemDrive%\inetpub\logs\LogFiles
Answers
C.
%SystemDrive\logs\LogFiles
C.
%SystemDrive\logs\LogFiles
Answers
D.
SystemDrive\logs\LogFiles
D.
SystemDrive\logs\LogFiles
Answers
Suggested answer: B

Charles has accidentally deleted an important file while working on his Mac computer. He wants to recover the deleted file as it contains some of his crucial business secrets. Which of the following tool will help Charles?

A.
Xplico
A.
Xplico
Answers
B.
Colasoft's Capsa
B.
Colasoft's Capsa
Answers
C.
FileSalvage
C.
FileSalvage
Answers
D.
DriveSpy
D.
DriveSpy
Answers
Suggested answer: C

Which file is a sequence of bytes organized into blocks understandable by the system's linker?

A.
executable file
A.
executable file
Answers
B.
source file
B.
source file
Answers
C.
Object file
C.
Object file
Answers
D.
None of these
D.
None of these
Answers
Suggested answer: C

Smith, a forensic examiner, was analyzing a hard disk image to find and acquire deleted sensitive files. He stumbled upon a $Recycle.Bin folder in the root directory of the disk. Identify the operating system in use.

A.
Windows 98
A.
Windows 98
Answers
B.
Linux
B.
Linux
Answers
C.
Windows 8.1
C.
Windows 8.1
Answers
D.
Windows XP
D.
Windows XP
Answers
Suggested answer: D

Jason discovered a file named $RIYG6VR.doc in the C:\$Recycle.Bin\\ while analyzing a hard disk image for the deleted dat a. What inferences can he make from the file name?

A.
It is a doc file deleted in seventh sequential order
A.
It is a doc file deleted in seventh sequential order
Answers
B.
RIYG6VR.doc is the name of the doc file deleted from the system
B.
RIYG6VR.doc is the name of the doc file deleted from the system
Answers
C.
It is file deleted from R drive
C.
It is file deleted from R drive
Answers
D.
It is a deleted doc file
D.
It is a deleted doc file
Answers
Suggested answer: D
Total 704 questions
Go to page: of 71