Official Bank 0/1170

Computer Hacking Forensic Investigator (CHFI) v9 (312-49v9) - EC Council Actual Exam Questions

Last updated on May 13, 2026

97% Exam Compliance
1170 Total Questions
1
Question

Which program uses different techniques to conceal a malware's code, thereby making it difficult for security mechanisms to detect or remove it?

Options
A

Dropper

B

Packer

C

Injector

D

Obfuscator

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

The ____________________ refers to handing over the results of private investigations to the authorities because of indications of criminal activity.

Options
A

Locard Exchange Principle

B

Clark Standard

C

Kelly Policy

D

Silver-Platter Doctrine

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

Which one of the following is not a first response procedure?

Options
A

Preserve volatile data

B

Fill forms

C

Crack passwords

D

Take photos

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

CAN-SPAM act requires that you:

Options
A

Don’t use deceptive subject lines

B

Don’t tell the recipients where you are located

C

Don’t identify the message as an ad

D

Don’t use true header information

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

Smith, a network administrator with a large MNC, was the first to arrive at a suspected crime scene involving criminal use of compromised computers. What should be his first response while maintaining the integrity of evidence?

Options
A

Record the system state by taking photographs of physical system and the display

B

Perform data acquisition without disturbing the state of the systems

C

Open the systems, remove the hard disk and secure it

D

Switch off the systems and carry them to the laboratory

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.