ExamGecko
Home Home / ECCouncil / 312-49v10

ECCouncil 312-49v10 Practice Test - Questions Answers, Page 47

Question list
Search
Search

List of questions

Search

Related questions











In a Linux-based system, what does the command "Last -F" display?

A.
Login and logout times and dates of the system
A.
Login and logout times and dates of the system
Answers
B.
Last run processes
B.
Last run processes
Answers
C.
Last functions performed
C.
Last functions performed
Answers
D.
Recently opened files
D.
Recently opened files
Answers
Suggested answer: A

Which of the following examinations refers to the process of providing the opposing side in a trial the opportunity to question a witness?

A.
Cross Examination
A.
Cross Examination
Answers
B.
Direct Examination
B.
Direct Examination
Answers
C.
Indirect Examination
C.
Indirect Examination
Answers
D.
Witness Examination
D.
Witness Examination
Answers
Suggested answer: A

Pick the statement which does not belong to the Rule 804. Hearsay Exceptions; Declarant Unavailable.

A.
Statement of personal or family history
A.
Statement of personal or family history
Answers
B.
Prior statement by witness
B.
Prior statement by witness
Answers
C.
Statement against interest
C.
Statement against interest
Answers
D.
Statement under belief of impending death
D.
Statement under belief of impending death
Answers
Suggested answer: D

Which of the following is a responsibility of the first responder?

A.
Determine the severity of the incident
A.
Determine the severity of the incident
Answers
B.
Collect as much information about the incident as possible
B.
Collect as much information about the incident as possible
Answers
C.
Share the collected information to determine the root cause
C.
Share the collected information to determine the root cause
Answers
D.
Document the findings
D.
Document the findings
Answers
Suggested answer: B

NTFS sets a flag for the file once you encrypt it and creates an EFS attribute where it stores Data Decryption Field (DDF) and Data Recovery Field (DDR). Which of the following is not a part of DDF?

A.
Encrypted FEK
A.
Encrypted FEK
Answers
B.
Checksum
B.
Checksum
Answers
C.
EFS Certificate Hash
C.
EFS Certificate Hash
Answers
D.
Container Name
D.
Container Name
Answers
Suggested answer: B

If the partition size is 4 GB, each cluster will be 32 K. Even if a file needs only 10 K, the entire 32 K will be allocated, resulting in 22 K of ________.

A.
Slack space
A.
Slack space
Answers
B.
Deleted space
B.
Deleted space
Answers
C.
Sector space
C.
Sector space
Answers
D.
Cluster space
D.
Cluster space
Answers
Suggested answer: A

After suspecting a change in MS-Exchange Server storage archive, the investigator has analyzed it.

Which of the following components is not an actual part of the archive?

A.
PRIV.STM
A.
PRIV.STM
Answers
B.
PUB.EDB
B.
PUB.EDB
Answers
C.
PRIV.EDB
C.
PRIV.EDB
Answers
D.
PUB.STM
D.
PUB.STM
Answers
Suggested answer: D

Which of the following is a non-zero data that an application allocates on a hard disk cluster in systems running on Windows OS?

A.
Sparse File
A.
Sparse File
Answers
B.
Master File Table
B.
Master File Table
Answers
C.
Meta Block Group
C.
Meta Block Group
Answers
D.
Slack Space
D.
Slack Space
Answers
Suggested answer: B

Which of the following is a tool to reset Windows admin password?

A.
R-Studio
A.
R-Studio
Answers
B.
Windows Password Recovery Bootdisk
B.
Windows Password Recovery Bootdisk
Answers
C.
Windows Data Recovery Software
C.
Windows Data Recovery Software
Answers
D.
TestDisk for Windows
D.
TestDisk for Windows
Answers
Suggested answer: B

Ron, a computer forensics expert, is investigating a case involving corporate espionage. He has recovered several mobile computing devices from the crime scene. One of the evidence that Ron possesses is a mobile phone from Nokia that was left in ON condition. Ron needs to recover the IMEI number of the device to establish the identity of the device owner. Which of the following key combinations can he use to recover the IMEI number?

A.
#*06*#
A.
#*06*#
Answers
B.
*#06#
B.
*#06#
Answers
C.
#06#*
C.
#06#*
Answers
D.
*IMEI#
D.
*IMEI#
Answers
Suggested answer: A
Total 704 questions
Go to page: of 71