Get New 2026 Valid Practice Certified Ethical Hacker 312-49 Q&A - Testing Engine
312-49 Dumps PDF - 100% Passing Guarantee
Career Prospects
One of the most rewarding benefits of earning any IT certification is the opportunity to explore various career prospects. The professionals with the CHFI certificate have numerous career paths to explore. Of course, it all depends on their area of interest and where they would like to create their career niche. Some of the sectors that the certified individuals can explore include law enforcement, military, defense, and police. They can also build a career in legal professions, banking, insurance, government agencies, and e-Business security, among others.
NEW QUESTION # 320
On Linux/Unix based Web servers, what privilege should the daemon service be run under?
- A. Something other than root
- B. Guest
- C. Root
- D. You cannot determine what privilege runs the daemon service
Answer: A
NEW QUESTION # 321
Item 2If you come across a sheepdip machine at your client site, what would you infer?
- A. A sheepdip coordinates several honeypots
- B. A sheepdip computer defers a denial of service attack
- C. A sheepdip computer is used only for virus-checking.
- D. A sheepdip computer is another name for a honeypot
Answer: C
NEW QUESTION # 322
Which is a standard procedure to perform during all computer forensics investigations?
- A. With the hard drive removed from the suspect PC, check the date and time in the system CMOSWith the hard drive removed from the suspect PC, check the date and time in the system? CMOS
- B. With the hard drive removed from the suspect PC, check the date and time in the system RAMWith the hard drive removed from the suspect PC, check the date and time in the system? RAM
- C. With the hard drive in the suspect PC, check the date and time in the File Allocation
Table - D. With the hard drive in the suspect PC, check the date and time in the system CMOSWith the hard drive in the suspect PC, check the date and time in the system? CMOS
Answer: A
NEW QUESTION # 323
What technique is used by JPEGs for compression?
- A. ZIP
- B. TIFF-8
- C. TCD
- D. DCT
Answer: D
NEW QUESTION # 324
At what layer does a cross site scripting attack occur on?
- A. Application
- B. Data Link
- C. Presentation
- D. Session
Answer: A
NEW QUESTION # 325
In Windows Security Event Log, what does an event id of 530 imply?
- A. Logon Failure - Unknown user name or bad password
- B. Logon Failure - Account currently disabled
- C. Logon Failure - User not allowed to logon at this computer
- D. Logon Failure - Account logon time restriction violation
Answer: D
NEW QUESTION # 326
You are called in to assist the police in an investigation involving a suspected drug dealer.
The police searched the suspect house after aYou are called in to assist the police in an investigation involving a suspected drug dealer. The police searched the suspect? house after a warrant was obtained and they located a floppy disk in the suspect bedroom. The disk contains several files, but they appear to be passwordwarrant was obtained and they located a floppy disk in the suspect? bedroom. The disk contains several files, but they appear to be password protected. What are two common methods used by password cracking software that you could use to obtain the password?
- A. Brute force and dictionary attack
- B. Minimum force and appendix attack
- C. Maximum force and thesaurus attack
- D. Limited force and library attack
Answer: A
NEW QUESTION # 327
NTFS sets a flag for the file once you encrypt it and creates an EFS attribute where it stores Data Decryption Field (DDF) and Data Recovery Field (DDR). Which of the following is not a part of DDF?
- A. Checksum
- B. Container Name
- C. EFS Certificate Hash
- D. Encrypted FEK
Answer: A
NEW QUESTION # 328
Richard is extracting volatile data from a system and uses the command doskey/history. What is he trying to extract?
- A. Previously typed commands
- B. Passwords used across the system
- C. History of the browser
- D. Events history
Answer: A
NEW QUESTION # 329
Ron, a computer forensics expert, is investigating a case involving corporate espionage. He has recovered several mobile computing devices from the crime scene. One of the evidence that Ron possesses is a mobile phone from Nokia that was left in ON condition. Ron needs to recover the IMEI number of the device to establish the identity of the device owner. Which of the following key combinations can he use to recover the IMEI number?
- A. *#06#
- B. #*06*#
- C. #06#*
- D. *IMEI#
Answer: B
NEW QUESTION # 330
You are employed directly by an attorney to help investigate an alleged sexual harassment case at a large pharmaceutical manufacturer. While at the corporate office of the company, the CEO demands to know the status of the investigation. What prevents you from discussing the case with the CEO?
- A. ISO 17799
- B. Good manners
- C. The attorney-work-product rule
- D. Trade secrets
Answer: C
NEW QUESTION # 331
You are assigned to work in the computer forensics lab of a state police agency. While working on a high profile criminal case, you have followed every applicable procedure, however your boss is still concerned that the defense attorney might question whether evidence has been changed while at the lab. What can you do to prove that the evidence is the same as it was when it first entered the lab?
- A. make an MD5 hash of the evidence and compare it with the original MD5 hash that was taken when the evidence first entered the lab
- B. sign a statement attesting that the evidence is the same as it was when it entered the lab
- C. there is no reason to worry about this possible claim because state labs are certified
- D. make an MD5 hash of the evidence and compare it to the standard database developed by NIST
Answer: A
NEW QUESTION # 332
On an Active Directory network using NTLM authentication, where on the domain controllers are the passwords stored?
- A. AMS
- B. Password.conf
- C. SAM
- D. Shadow file
Answer: C
NEW QUESTION # 333
Which of the following is a MAC-based File Recovery Tool?
- A. GetDataBack
- B. Cisdem DataRecovery 3
- C. VirtualLab
- D. Smart Undeleter
Answer: B
NEW QUESTION # 334
What encryption technology is used on Blackberry devices?Password Keeper?
- A. Blowfish
- B. 3DES
- C. RC5
- D. AES
Answer: D
NEW QUESTION # 335
You are called by an author who is writing a book and he wants to know how long the copyright for his book will last after he has the book published?
- A. Copyrights last forever
- B. 70 years
- C. The life of the author plus 70 years
- D. The life of the author
Answer: C
NEW QUESTION # 336
Which of the following is NOT an anti-forensics technique?
- A. Steganography
- B. Encryption
- C. Data Deduplication
- D. Password Protection
Answer: C
NEW QUESTION # 337
Cylie is investigating a network breach at a state organization in Florida. She discovers that the intruders were able to gain access into the company firewalls by overloading them with
IP packets. Cylie then discovers through her investigation that the intruders hacked into thecompany? firewalls by overloading them with IP packets. Cylie then discovers through her investigation that the intruders hacked into the company phone system and used the hard drives on their PBX system to store shared music files. What would this attack on the companycompany? phone system and used the hard drives on their PBX system to store shared music files. What would this attack on the company? PBX system be called?
- A. Crunching
- B. Squatting
- C. Pretexting
- D. Phreaking
Answer: D
NEW QUESTION # 338
What is the CIDR from the following screenshot?
- A. /24A./24A./24
- B. /16 C./16 C./16
- C. /32 B./32 B./32
- D. /8D./8D./8
Answer: D
NEW QUESTION # 339
What is the target host IP in the following command?
c:\>firewalk -F 80 10.10.150.1 172.16.28.95 -p UDP
- A. 10.10.150.1
- B. 172.16.28.95
- C. Firewalk does not scan target hosts
- D. This command is using FIN packets, which cannot scan target hosts
Answer: B
NEW QUESTION # 340
What hashing method is used to password protect Blackberry devices?
- A. SHA-1
- B. RC5
- C. MD5
- D. AES
Answer: A
NEW QUESTION # 341
Which of the following acts as a network intrusion detection system as well as network intrusion prevention system?
- A. Accunetix
- B. Nikto
- C. Kismet
- D. Snort
Answer: D
NEW QUESTION # 342
You are assisting in the investigation of a possible Web Server Hack. The company who called you stated that customers reported to them that whenever they entered the web address of the company in their browser, what they received was a porno graphic web site. The company checked the web server and nothing appears wrong.
When you type in the IP address of the web site in your browser everything appears normal. What is the name of the attack that affects the DNS cache of the name resolution servers, resulting in those servers directing users to the wrong web site?
- A. DNS Poisoning
- B. HTTP redirect attack
- C. ARP Poisoning
- D. IP Spoofing
Answer: A
NEW QUESTION # 343
Where are files temporarily written in Unix when printing?
- A. /var/spool
- B. /var/print
- C. /spool
- D. /usr/spool
Answer: A
NEW QUESTION # 344
......
312-49 Braindumps Real Exam Updated on Jul 27, 2026 with 534 Questions: https://www.trainingquiz.com/312-49-practice-quiz.html

