Eccouncil Computer Hacking Forensic Investigator V10 312-49 Exam Questions

Page: 1 / 14
Total 704 questions
Question 1

In the context of file deletion process, which of the following statement holds true?



Answer : C


Question 2

What will the following Linux command accomplish?

dd if=/dev/mem of=/home/sam/mem.bin bs=1024



Answer : C


Question 3

Which of the following file contains the traces of the applications installed, run, or uninstalled from a system?



Answer : A


Question 4

A Linux system is undergoing investigation. In which directory should the investigators look for its current state data if the system is in powered on state?



Answer : B


Question 5

Area density refers to:



Answer : A


Question 6

Which of the following is a MAC-based File Recovery Tool?



Answer : C


Question 7

Which Linux command when executed displays kernel ring buffers or information about device drivers loaded into the kernel?



Answer : B


Page:    1 / 14   
Total 704 questions