ECCouncil 312-49v8 - ECCouncil Computer Hacking Forensic Investigator (V8) Exam
Page: 3 / 36
Total 180 questions
Question #11 (Topic: )
FAT32 is a 32-bit version of FAT file system using smaller clusters and results in efficient
storage capacity. What is the maximum drive size supported?
storage capacity. What is the maximum drive size supported?
A. 1 terabytes
B. 2 terabytes
C. 3 terabytes
D. 4 terabytes
Answer: B
Question #12 (Topic: )
In which step of the computer forensics investigation methodology would you run MD5
checksum on the evidence?
checksum on the evidence?
A. Obtain search warrant
B. Evaluate and secure the scene
C. Collect the evidence
D. Acquire the data
Answer: D
Question #13 (Topic: )
Network forensics allows Investigators 10 inspect network traffic and logs to identify and
locate the attack system
Network forensics can reveal: (Select three answers)
locate the attack system
Network forensics can reveal: (Select three answers)
A. Source of security incidents’ and network attacks
B. Path of the attack
C. Intrusion techniques used by attackers
D. Hardware configuration of the attacker's system
Answer: A,B,C
Question #14 (Topic: )
Determine the message length from following hex viewer record:
A. 6E2F
B. 13
C. 27
D. 810D
Answer: D
Question #15 (Topic: )
TCP/IP (Transmission Control Protocol/Internet Protocol) is a communication protocol used
to connect different hosts in the Internet. It contains four layers, namely the network
interface layer. Internet layer, transport layer, and application layer.
Which of the following protocols works under the transport layer of TCP/IP?
to connect different hosts in the Internet. It contains four layers, namely the network
interface layer. Internet layer, transport layer, and application layer.
Which of the following protocols works under the transport layer of TCP/IP?
A. UDP
B. HTTP
C. FTP
D. SNMP
Answer: A