Eccouncil 312-49v10 practice test

Computer Hacking Forensic Investigator (CHFI-v10) Exam


Question 1

Which tool allows dumping the contents of process memory without stopping the process?
A. psdump.exe
B. pmdump.exe
C. processdump.exe
D. pdump.exe

Answer:

B
191/191

Discussions

Question 2

Which of the following files store the MySQL database data permanently, including the data that had
been deleted, helping the forensic investigator in examining the case and finding the culprit?

  • A. mysql-bin
  • B. mysql-log
  • C. iblog
  • D. ibdata1
Answer:

D

Discussions

Question 3

MAC filtering is a security access control methodology, where a ___________ is assigned to each
network card to determine access to the network.

  • A. 48-bit address 190/191 Questions & Answers PDF P-
  • B. 24-bit address
  • C. 16-bit address
  • D. 32-bit address
Answer:

A

Discussions

Question 4

Which Event Correlation approach assumes and predicts what an attacker can do next after the
attack by studying statistics and probability?

  • A. Profile/Fingerprint-Based Approach
  • B. Bayesian Correlation
  • C. Time (Clock Time) or Role-Based Approach
  • D. Automated Field Correlation
Answer:

B

Discussions

Question 5

Which of the following stand true for BIOS Parameter Block?

  • A. The BIOS Partition Block describes the physical layout of a data storage volume
  • B. The BIOS Partition Block is the first sector of a data storage device
  • C. The length of BIOS Partition Block remains the same across all the file systems
  • D. The BIOS Partition Block always refers to the 512-byte boot sector
Answer:

A

Discussions

Question 6

James is dealing with a case regarding a cybercrime that has taken place in Arizona, US

  • A. First Amendment of the U.S. Constitution
  • B. Fourth Amendment of the U.S. Constitution
  • C. Third Amendment of the U.S. Constitution
  • D. Fifth Amendment of the U.S. Constitution
Answer:

D

Discussions

Question 7

You are asked to build a forensic lab and your manager has specifically informed you to use copper
for lining the walls, ceilings, and floor. What is the main purpose of lining the walls, ceilings, and floor
with copper?

  • A. To control the room temperature
  • B. To strengthen the walls, ceilings, and floor 189/191 Questions & Answers PDF P-
  • C. To avoid electromagnetic emanations
  • D. To make the lab sound proof
Answer:

D

Discussions

Question 8

What document does the screenshot represent?

  • A. Expert witness form
  • B. Search warrant form
  • C. Chain of custody form
  • D. Evidence collection form
Answer:

D

Discussions

Question 9

What does the Rule 101 of Federal Rules of Evidence states?

  • A. Scope of the Rules, where they can be applied
  • B. Purpose of the Rules
  • C. Limited Admissibility of the Evidence
  • D. Rulings on Evidence
Answer:

A

Discussions

Question 10

What does the bytes 0x0B-0x53 represent in the boot sector of NTFS volume on Windows 2000?
A. Jump instruction and the OEM ID
B. BIOS Parameter Block (BPB) and the OEM ID
C. BIOS Parameter Block (BPB) and the extended BPB
D. Bootstrap code and the end of the sector marker

Answer:

C
188/191
Questions & Answers PDF
P-

Discussions
To page 2