ExamGecko
Home Home / ECCouncil / 312-49v10

ECCouncil 312-49v10 Practice Test - Questions Answers, Page 41

Question list
Search
Search

List of questions

Search

Related questions











Which tool does the investigator use to extract artifacts left by Google Drive on the system?

A.
PEBrowse Professional
A.
PEBrowse Professional
Answers
B.
RegScanner
B.
RegScanner
Answers
C.
RAM Capturer
C.
RAM Capturer
Answers
D.
Dependency Walker
D.
Dependency Walker
Answers
Suggested answer: C

Explanation:

Topic 3, Exam Pool C

Explanation:

BMP (Bitmap) is a standard file format for computers running the Windows operating system. BMP images can range from black and white (1 bit per pixel) up to 24 bit color (16.7 million colors). Each bitmap file contains a header, the RGBQUAD array, information header, and image dat a. Which of the following element specifies the dimensions, compression type, and color format for the bitmap?

A.
Information header
A.
Information header
Answers
B.
Image data
B.
Image data
Answers
C.
The RGBQUAD array
C.
The RGBQUAD array
Answers
D.
Header
D.
Header
Answers
Suggested answer: A

Identify the file system that uses $BitMap file to keep track of all used and unused clusters on a volume.

A.
NTFS
A.
NTFS
Answers
B.
FAT
B.
FAT
Answers
C.
EXT
C.
EXT
Answers
D.
FAT32
D.
FAT32
Answers
Suggested answer: A

An investigator has acquired packed software and needed to analyze it for the presence of malice.

Which of the following tools can help in finding the packaging software used?

A.
SysAnalyzer
A.
SysAnalyzer
Answers
B.
PEiD
B.
PEiD
Answers
C.
Comodo Programs Manager
C.
Comodo Programs Manager
Answers
D.
Dependency Walker
D.
Dependency Walker
Answers
Suggested answer: B

Korey, a data mining specialist in a knowledge processing firm DataHub.com, reported his CISO that he has lost certain sensitive data stored on his laptop. The CISO wants his forensics investigation team to find if the data loss was accident or intentional. In which of the following category this case will fall?

A.
Civil Investigation
A.
Civil Investigation
Answers
B.
Administrative Investigation
B.
Administrative Investigation
Answers
C.
Both Civil and Criminal Investigations
C.
Both Civil and Criminal Investigations
Answers
D.
Criminal Investigation
D.
Criminal Investigation
Answers
Suggested answer: B

Which of the following Windows-based tool displays who is logged onto a computer, either locally or remotely?

A.
Tokenmon
A.
Tokenmon
Answers
B.
PSLoggedon
B.
PSLoggedon
Answers
C.
TCPView
C.
TCPView
Answers
D.
Process Monitor
D.
Process Monitor
Answers
Suggested answer: B

A forensic examiner is examining a Windows system seized from a crime scene. During the examination of a suspect file, he discovered that the file is password protected. He tried guessing the password using the suspect's available information but without any success. Which of the following tool can help the investigator to solve this issue?

A.
Cain & Abel
A.
Cain & Abel
Answers
B.
Xplico
B.
Xplico
Answers
C.
Recuva
C.
Recuva
Answers
D.
Colasoft's Capsa
D.
Colasoft's Capsa
Answers
Suggested answer: A

Which of the following Android libraries are used to render 2D (SGL) or 3D (OpenGL/ES) graphics content to the screen?

A.
OpenGL/ES and SGL
A.
OpenGL/ES and SGL
Answers
B.
Surface Manager
B.
Surface Manager
Answers
C.
Media framework
C.
Media framework
Answers
D.
WebKit
D.
WebKit
Answers
Suggested answer: A

Report writing is a crucial stage in the outcome of an investigation. Which information should not be included in the report section?

A.
Speculation or opinion as to the cause of the incident
A.
Speculation or opinion as to the cause of the incident
Answers
B.
Purpose of the report
B.
Purpose of the report
Answers
C.
Author of the report
C.
Author of the report
Answers
D.
Incident summary
D.
Incident summary
Answers
Suggested answer: A

You are assigned a task to examine the log files pertaining to MyISAM storage engine. While examining, you are asked to perform a recovery operation on a MyISAM log file. Which among the following MySQL Utilities allow you to do so?

A.
mysqldump
A.
mysqldump
Answers
B.
myisamaccess
B.
myisamaccess
Answers
C.
myisamlog
C.
myisamlog
Answers
D.
myisamchk
D.
myisamchk
Answers
Suggested answer: C
Total 704 questions
Go to page: of 71