EC-COUNCIL Computer Hacking Forensic Investigator (EC1-349) Free Practice Test
Question 1
The IIS log file format is a fixed (cannot be customized) ASCII text-based format. The IIS format includes basic items, such as client IP address, user name, date and time, service and instance, server name and IP address, request type, target of operation, etc. Identify the service status code from the following IIS log.
192.168.100.150, -, 03/6/11, 8:45:30, W3SVC2, SERVER, 172.15.10.30, 4210, 125, 3524, 100, 0, GET, /dollerlogo.gif,
192.168.100.150, -, 03/6/11, 8:45:30, W3SVC2, SERVER, 172.15.10.30, 4210, 125, 3524, 100, 0, GET, /dollerlogo.gif,
Correct Answer: A
Question 2
What document does the screenshot represent?


Correct Answer: C
Question 3
Operating System logs are most beneficial for Identifying or Investigating suspicious activities involving a particular host. Which of the following Operating System logs contains information about operational actions performed by OS components?
Correct Answer: B
Question 4
Which of the following standard is based on a legal precedent regarding the admissibility of scientific examinations or experiments in legal cases?
Correct Answer: C
Question 5
According to US federal rules, to present a testimony in a court of law, an expert witness needs to furnish certain information to prove his eligibility. Jason, a qualified computer forensic expert who has started practicing two years back, was denied an expert testimony in a computer crime case by the US Court of Appeals for the Fourth Circuit in Richmond, Virginia. Considering the US federal rules, what could be the most appropriate reason for the court to reject Jason's eligibility as an expert witness?
Correct Answer: D
Question 6
Event correlation is a procedure that is assigned with a new meaning for a set of events that occur in a predefined interval of time.
Which type of correlation will you use if your organization wants to use different OS and network hardware platforms throughout the network?
Which type of correlation will you use if your organization wants to use different OS and network hardware platforms throughout the network?
Correct Answer: C
Question 7
Which of the following file in Novel GroupWise stores information about user accounts?
Correct Answer: A
Question 8
Which of the following reports are delivered under oath to a board of directors/managers/panel of jury?
Correct Answer: C
Question 9
Under no circumstances should anyone, with the exception of qualified computer forensics personnel, make any attempts to restore or recover information from a computer system or device that holds electronic information.
Correct Answer: B
Question 10
Who is responsible for the following tasks?
-Secure the scene and ensure that it is maintained In a secure state until the Forensic Team
advises -Make notes about the scene that will eventually be handed over to the Forensic Team
-Secure the scene and ensure that it is maintained In a secure state until the Forensic Team
advises -Make notes about the scene that will eventually be handed over to the Forensic Team
Correct Answer: D
Question 11
JPEG is a commonly used method of compressing photographic Images. It uses a compression algorithm to minimize the size of the natural image, without affecting the quality of the image. The JPEG lossy algorithm divides the image in separate blocks of____________.
Correct Answer: B
Question 12
Which of the following is not an example of a cyber-crime?
Correct Answer: C
Question 13
Which of the following approaches checks and compares all the fields systematically and intentionally for positive and negative correlation with each other to determine the correlation across one or multiple fields?
Correct Answer: C
Question 14
Smith, an employee of a reputed forensic Investigation firm, has been hired by a private organization to investigate a laptop that is suspected to be involved in hacking of organization DC server. Smith wants to find all the values typed into the Run box in the Start menu. Which of the following registry key Smith will check to find the above information?
Correct Answer: A