최신EC-COUNCIL Computer Hacking Forensic Investigator - EC0-349무료샘플문제
Harold is finishing up a report on a case of network intrusion, corporate spying, and embezzlement that he has been working on for over six months. He is trying to find the right term to use in his report to describe network-enabled spying. What term should Harold use?
The rule of thumb when shutting down a system is to pull the power plug. However, it has certain drawbacks. Which of the following would that be?
An attack vector is a path or means by which an attacker can gain access to computer or network resources in order to deliver an attack payload or cause a malicious outcome.
Which of the following should a computer forensics lab used for investigations have?
Windows Security Event Log contains records of login/logout activity or other security- related events specified by the system's audit policy. What does event ID 531 in Windows Security Event Log indicates?
Buffer Overflow occurs when an application writes more data to a block of memory, or buffer, than the buffer is allocated to hold. Buffer overflow attacks allow an attacker to modify the
_______________in order to control the process execution, crash the process and modify internal variables.
Printing under a Windows Computer normally requires which one of the following files types to be created?
In an echo data hiding technique, the secret message is embedded into a __________as an echo.
Volatile Memory is one of the leading problems for forensics. Worms such as code Red are memory resident and do not write themselves to the hard drive, if you turn the system off they disappear. In a lab environment, which of the following options would you suggest as the most appropriate to overcome the problem of capturing volatile memory?
When the operating system marks cluster as used, but does not allocate them to any file, such clusters are known as ___________.
Email spoofing refers to:
When should an MD5 hash check be performed when processing evidence?