最新的EC-COUNCIL Computer Hacking Forensic Investigator - EC1-349免費考試真題
Data files from original evidence should be used for forensics analysis
正確答案: A
During the seizure of digital evidence, the suspect can be allowed touch the computer system.
正確答案: A
At the time of evidence transfer, both sender and receiver need to give the information about date and time of transfer in the chain of custody record.
正確答案: B
SMTP (Simple Mail Transfer protocol) receives outgoing mail from clients and validates source and destination addresses, and also sends and receives emails to and from other SMTP servers.
正確答案: B
Volatile information can be easily modified or lost when the system is shut down or rebooted. It helps to determine a logical timeline of the security incident and the users who would be responsible.
正確答案: B
What is the goal of forensic science?
正確答案: A
Hard disk data addressing is a method of allotting addresses to each ___________of data on a hard disk
正確答案: D
First responder is a person who arrives first at the crime scene and accesses the victim's computer system after the incident. He or She is responsible for protecting, integrating, and preserving the evidence obtained from the crime scene.
Which of the following is not a role of first responder?
Which of the following is not a role of first responder?
正確答案: B
Which of the following is not a part of data acquisition forensics Investigation?
正確答案: C
Buffer Overflow occurs when an application writes more data to a block of memory, or buffer, than the buffer is allocated to hold. Buffer overflow attacks allow an attacker to modify the _______________in order to control the process execution, crash the process and modify internal variables.
正確答案: C