Official Bank 0/589

ECCouncil Computer Hacking Forensic Investigator (V9) (312-49v9) - EC-Council Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
589 Total Questions
1
Question
When examining a hard disk without a write-blocker, you should not start windows because

Windows will write data to the:
Options
A Recycle Bin
B Case files
C BIOS
D MSDOS.sys
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Company ABC has employed a firewall, IDS, Antivirus, Domain Controller, and SIEM. The company’s domain controller goes down. From which system would you begin your investigation?
Options
A Domain Controller
B IDS
C Firewall
D SIEM
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Which of the following techniques delete the files permanently?
Options
A Steganography
B Trail obfuscation
C Data Hiding
D Artifact Wiping
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
What do you call the process of studying the changes that have taken place across a system or a machine after a series of actions or incidents?
Options
A Windows Services Monitoring
B Host integrity Monitoring
C Start-up Programs Monitoring
D System Baselining
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Daryl, a computer forensics investigator, has just arrived at the house of an alleged computer hacker. Daryl takes pictures and tags all computer and peripheral equipment found in the house. Daryl packs all the items found in his van and takes them back to his lab for further examination. At his lab, Michael his assistant helps him with the investigation. Since Michael is still in training, Daryl supervises all of his work very carefully. Michael is not quite sure about the procedures to copy all the data off the computer and peripheral devices. How many data acquisition tools should Michael use when creating copies of the evidence for the investigation?
Options
A Two
B Four
C Three
D One
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.