ExamGecko
Home Home / ECCouncil / 312-49v10

ECCouncil 312-49v10 Practice Test - Questions Answers, Page 44

Question list
Search
Search

List of questions

Search

Related questions











Rusty, a computer forensics apprentice, uses the command nbtstat -c while analyzing the network information in a suspect system. What information is he looking for?

A.
Contents of the network routing table
A.
Contents of the network routing table
Answers
B.
Status of the network carrier
B.
Status of the network carrier
Answers
C.
Contents of the NetBIOS name cache
C.
Contents of the NetBIOS name cache
Answers
D.
Network connections
D.
Network connections
Answers
Suggested answer: C

Gary, a computer technician, is facing allegations of abusing children online by befriending them and sending them illicit adult images from his office computer. What type of investigation does this case require?

A.
Administrative Investigation
A.
Administrative Investigation
Answers
B.
Criminal Investigation
B.
Criminal Investigation
Answers
C.
Both Criminal and Administrative Investigation
C.
Both Criminal and Administrative Investigation
Answers
D.
Civil Investigation
D.
Civil Investigation
Answers
Suggested answer: B

The Apache server saves diagnostic information and error messages that it encounters while processing requests. The default path of this file is usr/local/apache/logs/error.log in Linux. Identify the Apache error log from the following logs.

A.
http://victim.com/scripts/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+dir+C:\Winnt\system32\Logfiles\W3SVC1
A.
http://victim.com/scripts/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+dir+C:\Winnt\system32\Logfiles\W3SVC1
Answers
B.
[Wed Oct 11 14:32:52 2000] [error] [client 127.0.0.1] client denied by server configuration:/export/home/live/ap/htdocs/test
B.
[Wed Oct 11 14:32:52 2000] [error] [client 127.0.0.1] client denied by server configuration:/export/home/live/ap/htdocs/test
Answers
C.
127.0.0.1 - frank [10/Oct/2000:13:55:36 -0700]"GET /apache_pb.gif HTTP/1.0" 200 2326
C.
127.0.0.1 - frank [10/Oct/2000:13:55:36 -0700]"GET /apache_pb.gif HTTP/1.0" 200 2326
Answers
D.
127.0.0.1 - - [10/Apr/2007:10:39:11 +0300] ] [error] "GET /apache_pb.gif HTTP/1.0" 200 2326
D.
127.0.0.1 - - [10/Apr/2007:10:39:11 +0300] ] [error] "GET /apache_pb.gif HTTP/1.0" 200 2326
Answers
Suggested answer: B

Tasklist command displays a list of applications and services with their Process ID (PID) for all tasks running on either a local or a remote computer. Which of the following tasklist commands provides information about the listed processes, including the image name, PID, name, and number of the session for the process?

A.
tasklist /p
A.
tasklist /p
Answers
B.
tasklist /v
B.
tasklist /v
Answers
C.
tasklist /u
C.
tasklist /u
Answers
D.
tasklist /s
D.
tasklist /s
Answers
Suggested answer: B

Which part of Metasploit framework helps users to hide the data related to a previously deleted file or currently unused by the allocated file.

A.
Waffen FS
A.
Waffen FS
Answers
B.
RuneFS
B.
RuneFS
Answers
C.
FragFS
C.
FragFS
Answers
D.
Slacker
D.
Slacker
Answers
Suggested answer: D

Which one of the following is not a first response procedure?

A.
Preserve volatile data
A.
Preserve volatile data
Answers
B.
Fill forms
B.
Fill forms
Answers
C.
Crack passwords
C.
Crack passwords
Answers
D.
Take photos
D.
Take photos
Answers
Suggested answer: C

Graphics Interchange Format (GIF) is a ____ RGB bitmap image format for images with up to 256 distinct colors per frame.

A.
8-bit
A.
8-bit
Answers
B.
32-bit
B.
32-bit
Answers
C.
16-bit
C.
16-bit
Answers
D.
24-bit
D.
24-bit
Answers
Suggested answer: A

Hard disk data addressing is a method of allotting addresses to each _______ of data on a hard disk.

A.
Physical block
A.
Physical block
Answers
B.
Operating system block
B.
Operating system block
Answers
C.
Hard disk block
C.
Hard disk block
Answers
D.
Logical block
D.
Logical block
Answers
Suggested answer: A

Which of the following standard represents a legal precedent regarding the admissibility of scientific examinations or experiments in legal cases?

A.
SWGDE & SWGIT
A.
SWGDE & SWGIT
Answers
B.
Daubert
B.
Daubert
Answers
C.
Frye
C.
Frye
Answers
D.
IOCE
D.
IOCE
Answers
Suggested answer: C

Event correlation is the process of finding relevance between the events that produce a final result.

What type of correlation will help an organization to correlate events across a set of servers, systems, routers and network?

A.
Same-platform correlation
A.
Same-platform correlation
Answers
B.
Network-platform correlation
B.
Network-platform correlation
Answers
C.
Cross-platform correlation
C.
Cross-platform correlation
Answers
D.
Multiple-platform correlation
D.
Multiple-platform correlation
Answers
Suggested answer: C
Total 704 questions
Go to page: of 71