EC-COUNCIL Computer Hacking Forensic Investigator (CHFI-v10) - 312-49v10 Exam Practice Test
In which implementation of RAID will the image of a Hardware RAID volume be different from the image taken separately from the disks?
Correct Answer: D
When a file is deleted by Windows Explorer or through the MS-DOS delete command, the operating system inserts _______________ in the first letter position of the filename in the FAT database.
Correct Answer: A
What TCP/UDP port does the toolkit program netstat use?
Correct Answer: B
Which tool does the investigator use to extract artifacts left by Google Drive on the system?
Correct Answer: D
____________________ is simply the application of Computer Investigation and analysis techniques in the interests of determining potential legal evidence.
Correct Answer: D
At what layer does a cross site scripting attack occur on?
Correct Answer: D
Which of the following commands shows you all of the network services running on Windows-based servers?
Correct Answer: B
Which of the following standard represents a legal precedent set in 1993 by the Supreme Court of the United States regarding the admissibility of expert witnesses' testimony during federal legal proceedings?
Correct Answer: D
To preserve digital evidence, an investigator should ____________________.
Correct Answer: B
What is the location of the binary files required for the functioning of the OS in a Linux system?
Correct Answer: C
According to RFC 3227, which of the following is considered as the most volatile item on a typical system?
Correct Answer: C