312-49v9 Dumps

312-49v9 Free Practice Test

EC-Council 312-49v9: ECCouncil Computer Hacking Forensic Investigator (V9)

QUESTION 101

- (Topic 3)
James is testing the ability of his routers to withstand DoS attacks. James sends ICMP ECHO requests to the broadcast address of his network. What type of DoS attack is James testing against his network?

Correct Answer: B
The Fraggle attack is like a smurf attack, but uses UDP packets and not ICMP.

QUESTION 102

- (Topic 1)
What is the goal of forensic science?

Correct Answer: A

QUESTION 103

- (Topic 3)
Which Intrusion Detection System (IDS) usually produces the most false alarms due to the unpredictable behaviors of users and networks?

Correct Answer: BC
NIDS and HIDS are types of IDS systems, Host or Network, and addresses placement of the probe. Anomaly detection is based on behavior analysis, and if you read the question, the question says “behavior” and if the behavior is unporedictable, then the IDS won’t know what is normal and what is bad.

QUESTION 104

- (Topic 3)
An Expert witness gives an opinion if:

Correct Answer: A

QUESTION 105

- (Topic 3)
Before you are called to testify as an expert, what must an attorney do first?

Correct Answer: D