Free 312-49v10: Computer Hacking Forensic Investigator Exam Questions and Answers
Computer Hacking Forensic Investigator is exam 312-49v10, part of EC-Council certification. EC-Council codes run three digits, a hyphen and two more, where the prefix marks the family — 212 for technician level, 312 for the main practitioner range including CEH, 712 for the executive CCISO — and the version is appended to the code rather than changing it. Formats differ sharply: some are four-hour multiple-choice papers, while CPENT is a 24-hour hands-on exam with a written report due within seven days.
The first 10 questions on this page are free to read, answers included — no account and no card. A plan opens the rest of the bank, the full timed practice test and your weak-topic reporting.
Last updated: September 19, 2026
- Exam code
- 312-49v10
- Provider
- ECCouncil
- Questions in our bank
- 1000+
- Free to read
- First 10, with answers
- Official page
- Official Exam website
- Our test mode duration & pass mark
- 130 mins · 70%
Recommended: Switch to Test Mode to start a practice test that simulates the real exam experience.
Question #1
Frank is working on a vulnerability assessment for a company on the West coast. The company hired Frank to assess its network security through scanning, pen tests, and vulnerability assessments. After discovering numerous known vulnerabilities detected by a temporary IDS he set up, he notices a number of items that show up as unknown but Questionable in the logs. He looks up the behavior on the Internet, but cannot find anything related. What organization should Frank submit the log to find out if it is a new vulnerability or not?
Please select an optionIncorrectCorrect answer: C
CVE is the public catalogue where newly discovered vulnerabilities are registered and disclosed, so unexplained suspicious activity should be reported there to see whether it is a new vulnerability.
Was this answer correct?Question #2
What will the following URL produce in an unpatched IIS Web Server? http://www.thetargetsite.com/scripts/..% co%af../..%co%af../windows/system32/cmd.exe?/c+dir+c:\
Please select an optionIncorrectCorrect answer: A
The double-encoded traversal bypasses IIS filtering and invokes cmd.exe with 'dir c:\', so the server returns a directory listing of the C: drive, not of the system32 folder.
Was this answer correct?Question #3
Law enforcement officers are conducting a legal search for which a valid warrant was obtained. While conducting the search, officers observe an item of evidence for an unrelated crime that was not included in the warrant. The item was clearly visible to the officers and immediately identified as evidence. What is the term used to describe how this evidence is admissible?
Please select an optionIncorrectCorrect answer: A
The plain view doctrine lets officers seize evidence of another crime that they lawfully observe in plain sight while executing a valid warrant, without needing a separate warrant.
Was this answer correct?Question #4
You have completed a forensic investigation case. You would like to destroy the data contained in various disks at the forensics lab due to sensitivity of the case. How would you permanently erase the data on the hard disk?
Please select an optionIncorrectCorrect answer: A
Physically destroying the platters by incineration guarantees the data can never be recovered, whereas overwriting with junk data or repeated formatting leaves remnants that forensic tools can still recover.
Was this answer correct?Question #5
The objective of this act was to protect consumers’ personal financial information held by financial institutions and their service providers.
Please select an optionIncorrectCorrect answer: A
The Gramm-Leach-Bliley Act requires financial institutions to protect the privacy and security of consumers' personal financial information, including data held by their service providers.
Was this answer correct?Question #6
Jason is the security administrator of ACMA metal Corporation. One day he notices the company's Oracle database server has been compromised and the customer information along with financial data has been stolen. The financial loss will be in millions of dollars if the database gets into the hands of the competitors. Jason wants to report this crime to the law enforcement agencies immediately. Which organization coordinates computer crimes investigations throughout the United States?
Please select an optionIncorrectCorrect answer: B
The local or national office of the U.S. Secret Service helps coordinate computer crime investigations throughout the United States, so the theft should be reported there.
Was this answer correct?Question #7
Area density refers to:
Please select an optionIncorrectCorrect answer: C
Area density measures how much data can be stored per square inch of disk media. Amount per disk, per partition, or per platter describes capacity, not density.
Was this answer correct?Question #8
The following excerpt is taken from a honeypot log. The log captures activities across three days. There are several intrusion attempts; however, a few are successful. (Note: The objective of this question is to test whether the student can read basic information from log entries and interpret the nature of attack.) Apr 24 14:46:46 [4663]: spp_portscan: portscan detected from 194.222.156.169 Apr 24 14:46:46 [4663]: IDS27/FIN Scan: 194.222.156.169:56693 -> 172.16.1.107:482 Apr 24 18:01:05 [4663]: IDS/DNS-version-query: 212.244.97.121:3485 -> 172.16.1.107:53 Apr 24 19:04:01 [4663]: IDS213/ftp-passwd-retrieval: 194.222.156.169:1425 -> 172.16.1.107:21 Apr 25 08:02:41 [5875]: spp_portscan: PORTSCAN DETECTED from 24.9.255.53 Apr 25 02:08:07 [5875]: IDS277/DNS-version-query: 63.226.81.13:4499 -> 172.16.1.107:53 Apr 25 02:08:07 [5875]: IDS277/DNS-version-query: 63.226.81.13:4630 -> 172.16.1.101:53 Apr 25 02:38:17 [5875]: IDS/RPC-rpcinfo-query: 212.251.1.94:642 -> 172.16.1.107:111 Apr 25 19:37:32 [5875]: IDS230/web-cgi-space-wildcard: 198.173.35.164:4221 -> 172.16.1.107:80 Apr 26 05:45:12 [6283]: IDS212/dns-zone-transfer: 38.31.107.87:2291 -> 172.16.1.101:53 Apr 26 06:43:05 [6283]: IDS181/nops-x86: 63.226.81.13:1351 -> 172.16.1.107:53 Apr 26 06:44:25 victim7 PAM_pwdb[12509]: (login) session opened for user simple by (uid=0) Apr 26 06:44:36 victim7 PAM_pwdb[12521]: (su) session opened for user simon by simple(uid=506) Apr 26 06:45:34 [6283]: IDS175/socks-probe: 24.112.167.35:20 -> 172.16.1.107:1080 Apr 26 06:52:10 [6283]: IDS127/telnet-login-incorrect: 172.16.1.107:23 -> 213.28.22.189:4558 From the options given below choose the one which best interprets the following entry: Apr 26 06:43:05 [6283]: IDS181/nops-x86: 63.226.81.13:1351 -> 172.16.1.107:53
Please select an optionIncorrectCorrect answer: B
The nops-x86 signature flags a long run of no-operation instructions, the classic sled used to land a buffer overflow exploit. It is not an evasion technique, a DNS zone transfer, or a file retrieval.
Was this answer correct?Question #9
An employee is attempting to wipe out data stored on a couple of compact discs (CDs) and digital video discs (DVDs) by using a large magnet. You inform him that this method will not be effective in wiping out the data because CDs and DVDs are media used to store large amounts of data and are not affected by the magnet.
Please select an optionIncorrectCorrect answer: D
CDs and DVDs store data optically as pits read by a laser, so magnetism has no effect on them; only magnetic media can be wiped with a magnet.
Was this answer correct?Question #10
A packet is sent to a router that does not have the packet destination address in its route table. How will the packet get to its proper destination?
Please select an optionIncorrectCorrect answer: C
When no route matches the destination address, the router forwards the packet to its gateway of last resort, the default route, which carries it toward the proper destination.
Was this answer correct?
Continue with 312-49v10: Computer Hacking Forensic Investigator
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in 312-49v10: Computer Hacking Forensic Investigator, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Other ECCouncil certifications
- 312-50v11: Certified Ethical Hacker v11 Exam (opens in a new tab)
- 312-50v12: Certified Ethical Hacker v12 Exam (opens in a new tab)
- 712-50: EC-Council Certified CISO (opens in a new tab)
- 312-50: CEH Certified Ethical Hacker (312-50v9) (opens in a new tab)
- 312-50v13: Certified Ethical Hacker v13 (opens in a new tab)
- 212-89: EC-Council Certified Incident Handler (opens in a new tab)
Reviews
★★★★★
This platform is a lifesaver. The practice questions and explanations are so detailed. It’s the best study tool I’ve ever used.
Hannah Smith
USA
★★★★★
I highly recommend Exam Practice. The feedback after each test helped me improve significantly, and I passed my exams easily.
Oscar Nyström
Sweden
★★★★★
Exam Practice is worth every penny. The mock exams are realistic, and the feedback helped me focus on key areas.
Amit Sharma
India
FAQ
Learn More: https://cert.eccouncil.org/
- Q1: What is the 312-49v10: Computer Hacking Forensic Investigator exam?
- A: 312-49v10: Computer Hacking Forensic Investigator is a ECCouncil certification exam. Judging by the questions in our bank, it concentrates on investigator, computer, extension, imei and forensics.
- Q2: What topics does the 312-49v10: Computer Hacking Forensic Investigator exam cover?
- A: Questions in our 312-49v10: Computer Hacking Forensic Investigator bank cluster around investigator, computer, extension, imei, forensics, windows, wireless and registry. Working through the full set is the quickest way to find which of these you are weakest on.
- Q3: How should I prepare for 312-49v10: Computer Hacking Forensic Investigator?
- A: Work through the 312-49v10: Computer Hacking Forensic Investigator practice questions here, checking your answer on each one, then sit the practice test to rehearse the exam under timed conditions before the real thing.
- Q4: Are these real 312-49v10: Computer Hacking Forensic Investigator exam questions?
- A: They are drawn from officially released past questions and from community members who have sat 312-49v10: Computer Hacking Forensic Investigator. Answers are verified and updated weekly.
- Q5: Where do I register for the 312-49v10: Computer Hacking Forensic Investigator exam?
- A: Register through ECCouncil directly at https://cert.eccouncil.org/. Exampractice is not affiliated with ECCouncil and does not administer the exam.
- Q6: Is there a free 312-49v10: Computer Hacking Forensic Investigator sample?
- A: Yes. Every 312-49v10: Computer Hacking Forensic Investigator page shows a free sample of real questions. Upgrading opens the full bank and the practice test.
- Q7: What are EC-Council Certification Exams?
- A: EC-Council Certification Exams validate your expertise in various aspects of cybersecurity, including ethical hacking, network security, and forensic investigation. These certifications demonstrate your proficiency in identifying, preventing, and mitigating cyber threats.
- Q8: Why should I pursue EC-Council Certification?
- A: EC-Council Certification enhances your professional credibility, showcasing your skills and knowledge in cybersecurity. This can lead to better job opportunities, higher salaries, and career advancement in the IT and cybersecurity industries.
- Q9: What are the benefits of EC-Council Certification?
- A: Benefits include recognition as a certified cybersecurity professional, improved job performance, access to exclusive resources, continuing education opportunities, and staying current with the latest cybersecurity trends and best practices.
- Q10: Who should take EC-Council Certification Exams?
- A: IT professionals, security analysts, ethical hackers, network administrators, and anyone involved in protecting and securing information systems should consider these certifications to validate their expertise and advance their careers.
- Q11: What types of EC-Council Certification Exams are available?
- A: EC-Council offers various certification paths, including:
- Q12: How do I prepare for EC-Council Certification Exams?
- A: Preparation can include official EC-Council training courses, study guides, practice exams, online tutorials, and hands-on experience in cybersecurity practices.
- Q13: Where can I take EC-Council Certification Exams?
- A: EC-Council Certification Exams can be taken at authorized Pearson VUE testing centers worldwide or online, providing flexibility to fit your schedule and location.
- Q14: How do EC-Council Certifications impact my career?
- A: EC-Council Certifications significantly boost your career by demonstrating your expertise to employers, making you a more competitive candidate for advanced roles and promotions in cybersecurity and IT.
- Q15: Are there any prerequisites for EC-Council Certification Exams?
- A: Some exams may have prerequisites, such as foundational knowledge or prior certifications. Check the specific requirements for each certification path on the EC-Council website.
- Q16: How often do I need to recertify for EC-Council Certifications?
- A: EC-Council Certifications typically require recertification every three years to ensure that certified professionals stay updated with the latest cybersecurity technologies and industry practices.



