Free 112-57 Practice Test Questions and Answers (2026) | Cert Empire Practice Questions
Free preview: 20 questions.
Eccouncil 112 57.pdf
Q: 1
Alice and John are close college friends. Alice frequently sends emails to John attaching her pics with
friends. One day, Alice sent an email to John describing all the details related to the final year project
without specifying the actual purpose. John missed the message as he frequently receives emails
from her and did not arrive for a project seminar.
Which of the following email fields could Alice have used in the above scenario to highlight the
importance of the email?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
Which of the following layers of the TCP/IP model includes protocols such as Frame Relay, SMDS, Fast
Ethernet, SLIP, PPP, FDDI, ATM, Ethernet, and ARP to enable a machine to deliver the desired data to
other hosts in the same network?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
Which of the following techniques is defined as the art of hiding data “behind” other data without
the target’s knowledge, thereby hiding the existence of the message itself?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
Which of the following commands can an investigator use to parse GPTs of both types of hard disks,
including those formatted with either UEFI or MBR?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
Which of the following MAC forensic data components saves file information and related events
using a token with a binary structure?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
Which of the following Tor relay nodes in the Tor circuit is designed to transfer data in an encrypted
format?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
Which of the following network protocols creates secure tunneling through which content
obfuscation can be achieved?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
Which of the following tools helps forensic experts analyze user activity in the Microsoft Edge
browser?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
Which of the following measures is defined as the time to move read or write disc heads from one
point to another on the disk?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
A disk drive has 16,384 cylinders, 80 heads, and 63 sectors per track, and each sector can store 512
bytes of data.
What is the total size of the disk?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
An organization decided to strengthen the security of its network by studying and analyzing the
behavior of attackers. For this purpose, Steven, a security analyst, was instructed to deploy a device
to bait attackers. Steven selected a solution that appears to contain very useful information to lure
attackers and find their locations and techniques.
Identify the type of device deployed by Steven in the above scenario.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
Below is the syntax of a command-line utility that displays active TCP connections and ports on which
the computer is listening.
netstat [-a] [-e] [-n] [-o] [-p Protocol] [-r] [-s] [Interval]
Identify the netstat parameter that displays active TCP connections and includes the process ID (PID)
for each connection.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
Sam, a digital forensic expert, is working on a case related to file tampering in a system at the
administrative department of an organization. In this process, Sam started performing the following
steps to analyze the acquired data to draw conclusions related to the case.
1.Analyze the file content for data usage.
2.Analyze the date and time of file creation and modification.
3.Find the users associated with file creation, access, and file modification.
4.Determine the physical storage location of the file.
5.Generate a timeline.
6.Identify the root cause of the incident.
Identify the type of analysis performed by Sam in the above scenario.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
Wesley, a professional hacker, deleted a confidential file in a compromised system using the
“/bin/rm/” command to deny access to forensic specialists.
Identify the operating system on which Don has performed the file carving act.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
Which of the following hives in the Windows Registry hierarchical database is volatile in nature and
contains file-extension association information and programmatic identifier (ProgID), Class ID
(CLSID), and Interface ID (IID) data?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20