Questions for the 312-49 were updated on : Jan 11 ,2025
What is the First Step required in preparing a computer for forensics investigation?
A
Network forensics can be defined as the sniffing, recording, acquisition and analysis of the network
traffic and event logs in order to investigate a network security incident.
A
Which of the following commands shows you the names of all open shared files on a server and
number of file locks on each file?
B
The Recycle Bin exists as a metaphor for throwing files away, but it also allows user to retrieve and
restore files. Once the file is moved to the recycle bin, a record is added to the log file that exists in
the Recycle Bin.
Which of the following files contains records that correspond to each deleted file in the Recycle Bin?
A
Email archiving is a systematic approach to save and protect the data contained in emails so that it
can be accessed fast at a later date. There are two main archive types, namely Local Archive and
Server Storage Archive. Which of the following statements is correct while dealing with local
archives?
A
Which of the following email headers specifies an address for mailer-generated errors, like "no such
user" bounce messages, to go to (instead of the sender's address)?
A
Which of the following commands shows you all of the network services running on Windows-based
servers?
A
Email archiving is a systematic approach to save and protect the data contained in emails so that it
can tie easily accessed at a later date.
A
Which of the following commands shows you the NetBIOS name table each?
A
Windows Security Accounts Manager (SAM) is a registry file which stores passwords in a hashed
format.
SAM file in Windows is located at:
A
FAT32 is a 32-bit version of FAT file system using smaller clusters and results in efficient storage
capacity. What is the maximum drive size supported?
B
In which step of the computer forensics investigation methodology would you run MD5 checksum on
the evidence?
D
Network forensics allows Investigators to inspect network traffic and logs to identify and locate the
attack system
Network forensics can reveal: (Select three answers)
A, B, C
Determine the message length from following hex viewer record:
D
TCP/IP (Transmission Control Protocol/Internet Protocol) is a communication protocol used to
connect different hosts in the Internet. It contains four layers, namely the network interface layer.
Internet layer, transport layer, and application layer.
Which of the following protocols works under the transport layer of TCP/IP?
A