EC0-349 Investigation Practice Questions
The free EC0-349: ECCouncil Computer Hacking Forensic Investigator questions that deal with investigation, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.
Question #1
What is the first step in the computer forensic investigation process?
Correct answer: C
Explanation
The first step is identification, which involves determining what data needs to be collected.
Question #2
In a forensic investigation, what is the primary purpose of creating a forensic image?
Correct answer: C
Explanation
Creating a forensic image preserves the original data, ensuring that it remains unaltered during investigations.
Question #5
During an investigation, which of the following data types is least likely to be relevant?
Correct answer: D
Explanation
Non-volatile memory is typically not directly relevant, as it does not contain user-generated data.
Question #8
Which protocol is commonly used to capture live network data during an investigation?
Correct answer: A
Explanation
TCP/IP is the foundational protocol for network data transmission and is essential for live captures.
Continue with EC0-349: ECCouncil Computer Hacking Forensic Investigator
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in EC0-349: ECCouncil Computer Hacking Forensic Investigator, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
All EC0-349: ECCouncil Computer Hacking Forensic Investigator practice questions →
