Free 312-49v11 Practice Test Questions and Answers (2026) | Cert Empire Practice Questions
Free preview: 20 questions.
Eccouncil 312 49v11
Q: 1
Sarah, a forensic investigator, is conducting a post-compromise investigation on a company’s server
that contains sensitive dat
a. To ensure the deleted files do not fall into the wrong hands, she follows a media sanitization
procedure. The process involves overwriting the deleted data 6 times with alternating sequences of
0x00 and 0xFF, followed by a final overwrite using the pattern 0xAA.
Which of the following media sanitization standards has Sarah followed in this scenario?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
During a forensic investigation on an iOS device, you are tasked with retrieving geolocation data for
various applications and system services. After examining the device, you come across several files.
Which of the following files contains the geolocation data of applications and system services on iOS
devices?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
An investigator is reviewing an NTFS file system for evidence of file activity during a cybercrime
investigation. The investigator uses The Sleuth Kit’s fls and mactime tools to extract and analyze
timestamps related to file actions. These timestamps can provide critical insights into the sequence
of events leading up to and during the incident. What kind of file information is the investigator likely
focusing on to reconstruct the timeline?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
Alex, a system administrator, is tasked with converting an existing EXT2 file system to an EXT3 file
system on a Linux machine. The EXT2 file system is currently in use, and Alex needs to enable
journaling to convert it to EXT3. Which of the following commands should Alex use to achieve this
conversion?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
As a forensic investigator specializing in cybersecurity, you've been assigned to analyze a suspicious
PDF document named “infected.pdf.” This document was discovered on a company server and is
suspected to contain malicious scripts that could pose a threat to the organization's systems and
network. As part of your investigation into the PDF document, what initial step would you take to
identify potential malicious components within the file?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
During a network security audit, an investigator is tasked with assessing the security of nearby
wireless networks. The investigator needs to gather real-time information about nearby wireless
access points (APs) and display this data using diagnostic views and charts. The tool should allow
them to visualize details such as signal strength, AP names, and other relevant characteristics of the
networks in the are
a. Which of the following tools would be most appropriate for this task?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
During a security audit of a web application, suspicious activity indicative of a directory traversal
attack is detected in the server logs. The attack appears to exploit vulnerabilities to gain
unauthorized access to sensitive files and directories.
In digital forensics, what is the primary objective of investigating a directory traversal attack?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
During a forensic investigation into suspicious activities within an organization's AWS environment,
the investigator uses Amazon CloudWatch to adjust the storage duration of specific log data sets. This
action is crucial for managing the lifespan of logs and ensuring that critical logs are preserved for
further analysis during the investigation. Which feature of Amazon CloudWatch is the investigator
using in this scenario?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
Sarah, a commuter, relies on her mobile device for entertainment during her daily train ride. She
prefers streaming high-definition videos to pass the time. With her need for seamless and high-
speed data transfer, she benefits greatly from cellular network technology that ensures smooth
streaming without buffering interruptions.
Which cellular network technology would be most suitable for Sarah for her mobile device?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
In a country where the government tightly controls internet access, a cybersecurity analyst suspects
that sensitive communications are being monitored. To circumvent this surveillance, the analyst
decides to use the Tor network. However, accessing the Tor network directly is impossible due to
government restrictions. How can the cybersecurity analyst overcome government surveillance and
access the Tor network in this scenario?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
During a digital forensics investigation, an investigator is tasked with collecting data from servers and
shared drives within an organization's infrastructure. The investigator accesses and retrieves relevant
electronic evidence from these central storage locations to assist in the investigation. This data
collection includes files, user logs, and other system artifacts necessary for understanding the scope
of the incident. Which eDiscovery collection methodology is the investigator employing in this
scenario?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
Sophia, a network security analyst, is reviewing the logs from a Cisco router in an attempt to identify
suspicious traffic patterns. She encounters a log entry that matches the criteria for an access control
list (ACL) filter, showing that a TCP or UDP packet was detected based on the applied rules. Based on
the log entry description, which of the following is the correct mnemonic for this log message?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
Alice, a seasoned iOS developer, dives into her latest project, an immersive gaming app. She delves
into utilizing cutting-edge technologies like OpenGL ES, OpenAL, and AV Foundation. As the lines of
code intertwine with her creativity, she inches closer to realizing her dream of delivering an app that
mesmerizes users on every level. Which layer of the iOS architecture is Alice primarily focusing on for
implementing functionalities?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
In a digital forensics investigation, persistent malware is discovered on a compromised system
despite repeated attempts to remove it. The malware reinstalls itself upon system reboot, indicating
sophisticated persistence mechanisms.
In digital forensics, why is identifying malware persistence important?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
During a forensic investigation involving an Android device, the investigator needs to establish
communication between the device and a computer running the Android Software Developer Kit
(SDK). This communication will allow the investigator to access system files, logs, and other relevant
data for analysis. To facilitate this, the investigator enables a specific Android developer feature on
the device.
Which feature must be enabled to allow the device to communicate with the workstation running
the Android SDK?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
Forensic investigators respond to a smart home burglary. They identify, collect, and preserve IoT
devices, then analyze data from cloud services and synced smartphones. A detailed report is
prepared for court presentation, outlining the investigation process and the evidence collected.
Which stage of the IoT forensic process ensures that evidence integrity is maintained by preventing
alteration before collection?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
In a financial institution's computer forensic investigation, suspicious activity reveals unauthorized access to GLBA (Gramm-Leach-Bliley Act)-protected customer data, raising concerns for customer safety. However, identifying the breach's source and extent poses significant challenges, complicating compliance with GLBA guidelines. What steps should be taken in a GLBA-covered computer forensic investigation when unauthorized access to sensitive customer data is discovered?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
A digital forensic investigator is tasked with analyzing an NTFS image file extracted from a pen drive.
They leverage The Sleuth Kit (TSK) for this task, specifically utilizing the fsstat command-line tool. By
employing fsstat, they delve into the file system’s intricate details, such as metadata, inode numbers,
and block or cluster information, thereby facilitating a comprehensive examination.
How can an investigator use TSK to analyze disk images?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
You're a digital forensic analyst tasked with analyzing a Portable Document Format (PDF) file to
extract information about its structure and contents. Understanding the PDF file structure is essential
for conducting a thorough analysis. What is the component of a PDF file that enables random access
to objects, includes links to all objects within the file, and aids in tracking updates made to the PDF
file?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
Forming a specialized cybercrime investigation team for a multinational corporation. Roles assigned
include photographer, incident responder, evidence examiner, and attorney. External support is
enlisted for complex cases. The goal is to identify perpetrators, gather evidence, and ensure justice.
What is a crucial step in forming a specialized cybercrime investigation team?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20