Latest [Jul 01, 2026] 312-49v11 Exam with Accurate Computer Hacking Forensic Investigator (CHFI-v11) PDF Questions [Q89-Q108]

Share

Latest [Jul 01, 2026] 312-49v11 Exam with Accurate Computer Hacking Forensic Investigator (CHFI-v11) PDF Questions

Take a Leap Forward in Your Career by Earning EC-COUNCIL 152 Questions


EC-COUNCIL 312-49v11 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Network Forensics: This domain covers network incident investigation through traffic and log analysis, event correlation, indicators of compromise identification, SIEM usage, and wireless network attack detection and examination.
Topic 2
  • Dark Web Forensics: This domain addresses dark web investigation focusing on Tor browser artifact identification, memory dump analysis, and extracting evidence of dark web activities.
Topic 3
  • Mobile Forensics: This domain covers Android and iOS forensics including device architecture, forensics processes, cellular data investigation, file system acquisition, lock bypassing, rooting
  • jailbreaking, and mobile application analysis.
Topic 4
  • Linux and Mac Forensics: This domain addresses forensic methodologies for Linux and macOS systems including data collection, memory forensics, log analysis, APFS examination, and platform-specific investigation tools.
Topic 5
  • Cloud Forensics: This domain covers cloud platform forensics (AWS, Azure, Google Cloud) including data storage, logging, forensic acquisition of virtual machines, and investigation of cloud security incidents.
Topic 6
  • Computer Forensics in Today's World: This domain covers fundamentals of computer forensics including cybercrime types, investigation procedures, digital evidence handling, forensic readiness, investigator roles and responsibilities, industry standards, and legal compliance requirements.
Topic 7
  • Malware Forensics: This domain addresses malware investigation including controlled lab setup, static analysis, system and network behavior analysis, suspicious document examination, and ransomware investigation techniques.

 

NEW QUESTION # 89
An investigator is conducting a forensic analysis on a Windows machine suspected of accessing the Dark Web. The investigator has found Tor browser artifacts, but the Tor browser has been uninstalled. Which of the following steps should the investigator take next to obtain more information on the user's activities?

  • A. Use the netstat -ano command to check the active network connections
  • B. Check the prefetch files using a tool such as WinPrefetchView
  • C. Examine the registry key: HKEY_USERS\\SOFTWARE\Mozilla\Firefox\Launcher for path information
  • D. Look for the 'State' file in the \Tor Browser\Browser\TorBrowser\Data\Tor\ directory

Answer: B


NEW QUESTION # 90
Which of the following is NOT a graphics file?

  • A. Picture2.bmp
  • B. Picture1.tga
  • C. Picture3.nfo
  • D. Picture4.psd

Answer: C


NEW QUESTION # 91
Brian needs to acquire data from RAID storage. Which of the following acquisition methods is recommended to retrieve only the data relevant to the investigation?

  • A. Bit-by-bit Acquisition
  • B. Static Acquisition
  • C. Sparse or Logical Acquisition
  • D. Bit-stream disk-to-disk Acquisition

Answer: C


NEW QUESTION # 92
As a digital forensic investigator, you're tasked with analyzing disk data to uncover evidence of deleted files and other relevant information. Hex editors are essential tools for examining the physical contents of a disk and searching for remnants of deleted files.
Which area of a hex editor displays theASCII representation of each byteshown in the hexadecimal area?

  • A. Hexadecimal area
  • B. Character area
  • C. Footer area
  • D. Address area

Answer: B

Explanation:
According to theCHFI v11 Computer Forensics FundamentalsandFile Analysismodules, ahex editoris a critical forensic tool used to view and analyze raw disk data at the byte level. Hex editors typically present data in three main columns or areas: theaddress (offset) area, thehexadecimal area, and thecharacter (ASCII) area.
Thecharacter areadisplays theASCII interpretation of each byteshown in the hexadecimal area. This allows investigators to visually identifyreadable text strings, file headers, metadata, embedded scripts, usernames, URLs, file signatures, and fragments of deleted files that may still reside in unallocated space or slack space. Printable characters are shown as readable text, while non-printable bytes are usually represented by dots (.).
Theaddress areashows the offset or location of the data within the file or disk. Thehexadecimal areadisplays the raw byte values in hexadecimal format, which is essential for precise byte-level analysis. Afooter areais not a standard component of hex editor layouts as defined in CHFI v11.
CHFI v11 emphasizes correlating thehexadecimal values with their ASCII representationsto accurately interpret raw data and identify meaningful forensic artifacts. Therefore, the area that displays the ASCII representation of each byte is theCharacter area, makingOption Dthe correct and CHFI v11-verified answer.


NEW QUESTION # 93
A CHFI professional is investigating a data breach in a Windows 10 system. The initial analysis revealed some alterations in the system event logs. As part of the investigation, the professional uses the 'wevtutil' command-line tool. The command 'wevtutil gl Security' was executed, but the results seemed abnormal. Which of the following could be a plausible reason for this outcome?

  • A. The 'wevtutil' command cannot retrieve data from XML-based EVTX file format
  • B. The EVTX file storing the Security log was corrupted or tampered with
  • C. The command 'wevtutil gl Security' does not exist in the 'wevtutil' command set
  • D. The Event Log service was temporarily unresponsive or down

Answer: B


NEW QUESTION # 94
A honey pot deployed with the IP 172.16.1.108 was compromised by an attacker . Given below is an excerpt from a Snort binary capture of the attack. Decipher the activity carried out by the attacker by studying the log. Please note that you are required to infer only what is explicit in the excerpt.
(Note: The student is being tested on concepts learnt during passive OS fingerprinting, basic TCP/IP connection concepts and the ability to read packet signatures from a sniff dump.) TOS:0x0 ID:29726 IpLen:20 DgmLen:52 DF
***A**** Seq: 0x9B6338C5 Ack: 0x5820ADD0 Win: 0x7D78 TcpLen: 32
TCP Options (3) => NOP NOP TS: 23678634 2878772
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
+=
03/15-20:21:24.452051 211.185.125.124:789 -> 172.16.1.103:111
UDP TTL:43 TOS:0x0 ID:29733 IpLen:20 DgmLen:84
Len: 64
01 0A 8A 0A 00 00 00 00 00 00 00 02 00 01 86 A0 ................
00 00 00 02 00 00 00 03 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 01 86 B8 00 00 00 01 ................
00 00 00 11 00 00 00 00 ........
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
+=
03/15-20:21:24.730436 211.185.125.124:790 -> 172.16.1.103:32773
UDP TTL:43 TOS:0x0 ID:29781 IpLen:20 DgmLen:1104
Len: 1084
47 F7 9F 63 00 00 00 00 00 00 00 02 00 01 86 B8 G..c............
00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 20 ...............
3A B1 5E E5 00 00 00 09 6C 6F 63 61 6C 68 6F 73 :.^.....localhost
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
+=+=+
03/15-20:21:36.539731 211.185.125.124:4450 -> 172.16.1.108:39168
TCP TTL:43 TOS:0x0 ID:31660 IpLen:20 DgmLen:71 DF
***AP*** Seq: 0x9C6D2BFF Ack: 0x59606333 Win: 0x7D78 TcpLen: 32
TCP Options (3) => NOP NOP TS: 23679878 2880015
63 64 20 2F 3B 20 75 6E 61 6D 65 20 2D 61 3B 20 cd /; uname -a;
69 64 3B id;

  • A. The attacker has installed a backdoor
  • B. The attacker has conducted a network sweep on port 111
  • C. The attacker has used a Trojan on port 32773
  • D. The attacker has scanned and exploited the system using Buffer Overflow

Answer: B


NEW QUESTION # 95
As a forensic investigator, you are asked to identify whether the Dropbox application was installed on a suspect's computer running Windows 10. The request is made by an attorney. You are considering different tools and approaches for your investigation. What would be the most appropriate next step in the forensic investigation process?

  • A. Immediately start examining the suspect's computer with any readily available digital forensic tool
  • B. Formulate a hypothesis and design an experiment to test the hypothesis on a similar system before examining the suspect's machine
  • C. Rely on your past experience and intuition to confirm or disprove the installation of Dropbox without formulating any hypothesis
  • D. Use the most expensive commercial tool to guarantee a thorough investigation and reliable findings

Answer: B


NEW QUESTION # 96
Where is the default location for Apache access logs on a Linux computer?

  • A. usr/local/apache/logs/access_log
  • B. usr/logs/access_log
  • C. logs/usr/apache/access_log
  • D. bin/local/home/apache/logs/access_log

Answer: A


NEW QUESTION # 97
Stella, a forensic investigator, is analyzing logs from a cloud environment to determine if a password leak has led to the disabling of a user account. She suspects that a change in the login settings may have triggered the account to be locked due to multiple failed login attempts. To verify her hypothesis, she applies various filters to examine the cloud audit logs.
Which of the following filters would help Stella identify if a password leak has disabled a user account?

  • A. logName="organizations/ORGANIZATION_ID/logs/cloudaudit.googleapis.com%2Factivity"
  • B. protopayload.resource.labels.service="admin.googleapis.com"
  • C. protopayload.metadata.event.parameter.value=DOMAIN_NAME
  • D. protopayload.resource.labels.service="login.googleapis.com"

Answer: D

Explanation:
This question aligns with CHFI v11 objectives underCloud Forensics, particularlyGoogle Cloud audit log analysis and authentication event investigation. In Google Cloud Platform (GCP), authentication-related events-such as login attempts, failed authentications, suspicious access behavior, and account lockouts-are handled by theGoogle Login API service. CHFI v11 emphasizes that when investigators are examining suspected credential compromise or password leaks, they must focus onauthentication and identity-related logsrather than general administrative or configuration logs.
The filter
protopayload.resource.labels.service="login.googleapis.com"
targets audit log entries generated by the login service, which records successful and failed login attempts, abnormal authentication behavior, and security enforcement actions such as temporary account lockouts caused by repeated failed logins. These events are critical indicators when determining whether a password leak resulted in account disabling.
The other options are less suitable: admin.googleapis.com focuses on administrative actions, the activity log name is broad and not specific to authentication failures, and metadata parameter filters do not directly isolate login-related events. Therefore, consistent with CHFI v11 cloud forensic methodology, filtering logs by the login.googleapis.comservice is the most effective way to identify whether a password leak caused a user account to be disabled.


NEW QUESTION # 98
Consistency in the investigative report is more important than the exact format in the report to eliminate uncertainty and confusion.

  • A. True
  • B. False

Answer: A


NEW QUESTION # 99
While looking through the IIS log file of a web server, you find the following entries:

What is evident from this log file?

  • A. Web bugs
  • B. SQL injection is possible
  • C. Cross site scripting
  • D. Hidden fields

Answer: B


NEW QUESTION # 100
In a Linux-based system, what does the command "Last -F" display?

  • A. Login and logout times and dates of the system
  • B. Last functions performed
  • C. Recently opened files
  • D. Last run processes

Answer: A


NEW QUESTION # 101
Identify the location of Recycle Bin on a Windows 7 machine that uses NTFS file system to store and retrieve files on the hard disk.

  • A. DriveARECYCLER
  • B. C:\RECYCLED
  • C. DriveARECYCLED
  • D. Drive:\$Recycle.Bin

Answer: D


NEW QUESTION # 102
If you plan to startup a suspect's computer, you must modify the ___________ to ensure that you do not contaminate or alter data on the suspect's hard drive by booting to the hard drive.

  • A. CMOS
  • B. boot.ini
  • C. Scandisk utility
  • D. Boot.sys
  • E. deltree command

Answer: B

Explanation:
The OS isn't specified, but if this was a Windows OS, then this would be boot.ini The answer is CMOS. The startup of a computer is the boot sequence, and the boot sequence is defined in the CMOS. The common occurrence is to boot off a floppy, and you need to see that the floppy (usually the A drive) is first in the sequence. If you don't, and the hard drive is first, then booting the system wil boot the hard drive and alter the evidence.


NEW QUESTION # 103
Which of the following is not a part of data acquisition forensics Investigation?

  • A. Protect the evidence from extremes in temperature
  • B. Disable all remote access to the system
  • C. Permit only authorized personnel to access
  • D. Work on the original storage medium not on the duplicated copy

Answer: D


NEW QUESTION # 104
While investigating a potential SQL Injection Attack on a Windows-based server, a CHFI has found the following IIS log entry:
"2023-05-14 15:05:02 10.10.10.55 GET /products.php id=ORD-001%27%20or%201=l;-- 80 bob
10.10.10.12 HTTP/1.1
Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:67.0)+Gecko/20100101+Firefox/67.0
http://www.luxurytreats.com/products.php 200 0 0 510"
Based on this log entry, which of the following is a correct assertion?

  • A. The attacker was unsuccessful, as the HTTP 200 status code indicated
  • B. The attacker could execute a stored procedure on the MS SQL server
  • C. The attacker tried to bypass authentication using a Linux machine
  • D. The attacker tried to manipulate the user login functionality of the website

Answer: C


NEW QUESTION # 105
A CHFI is analyzing suspicious activity on a company's AWS account. She suspects an unauthorized user accessed and deleted a crucial bucket object. To trace the potential perpetrator, she should primarily rely on the following:

  • A. AWS CloudTrail logs to determine when and where the specific API calls were made
  • B. Amazon CloudWatch logs to monitor system and application log data in real time
  • C. Amazon VPC Flow Logs to scrutinize the IP traffic entering and leaving the specific VPC
  • D. S3 Server Access logs to understand actions performed on a bucket object

Answer: A


NEW QUESTION # 106
Following a cybercrime incident, a forensic investigator is conducting a detailed examination of a suspect's digital device. The investigator needs to preserve and analyze the disk images without being restricted by various image file formats tied to commercial software, which may limit the investigator's ability to work with a range of analysis platforms. The investigator chooses a simple, straightforward, and uncompressed format that can be easily accessed and analyzed using a wide range of forensic tools and platforms, without the need for specialized software. Which data acquisition format should the investigator use in this case?

  • A. Employ the advanced forensics format for storing metadata and disk images.
  • B. Choose the AFF4 format, which offers advanced features for comprehensive analysis.
  • C. Use a proprietary format that is compatible with specific commercial software.
  • D. Adopt the raw format that is commonly used in digital evidence investigations.

Answer: D

Explanation:
This question maps directly to CHFI v11 objectives underData Acquisition and DuplicationandData Acquisition Formats. CHFI v11 clearly explains that theRAW (dd) image formatis the most widely used and universally supported forensic image format. RAW images are exact bit-by-bit copies of storage media and do not rely on proprietary structures, compression, or vendor-specific software. This makes them ideal when investigators require maximum compatibility across multiple forensic tools and platforms.
The RAW format is simple, uncompressed, and transparent, allowing it to be analyzed by nearly all forensic suites such as Autopsy, FTK, EnCase, and The Sleuth Kit. CHFI v11 emphasizes that RAW images are preferred when long-term accessibility, court admissibility, and tool independence are critical requirements.
AFF and AFF4 formats provide advanced features such as metadata storage and compression, but they require specific tool support and are not as universally accessible. Proprietary formats are discouraged because they limit interoperability and may introduce legal or technical constraints. Therefore, adopting the RAW format best satisfies the requirement for simplicity, broad compatibility, and forensic soundness as defined in CHFI v11 standards.


NEW QUESTION # 107
Lucas, a forensic investigator, is working on an investigation involving a compromised hard drive. To analyze the disk image and extract relevant forensic data, he decides to use a tool that integrates the powerful capabilities of Sleuth Kit with Python scripting. Lucas wants to automate the process of analyzing disk structures, file systems, and file recovery using Python scripts. Which of the following tools can help Lucas leverage Sleuth Kit's capabilities while using Python to perform these analysis tasks efficiently?

  • A. PySpark
  • B. PyTorch
  • C. PyTSK
  • D. NumPy

Answer: C

Explanation:
According to CHFI v11 objectives underComputer Forensics FundamentalsandDigital Forensics using Python, investigators are encouraged to automate forensic analysis tasks to improve efficiency, accuracy, and repeatability. The Sleuth Kit (TSK) is a widely used open-source forensic toolkit for analyzing disk images, file systems, and recovering deleted files. To extend these capabilities using Python, CHFI v11 highlights the use of Python bindings specifically designed for forensic purposes.
PyTSK (also known as pytsk3) is the official Python binding for The Sleuth Kit. It allows forensic investigators to programmatically access disk images, partitions, file systems, directories, and file metadata directly from Python scripts. This enables automation of tasks such as file enumeration, timeline creation, deleted file recovery, and artifact extraction-core activities in disk and file system forensics.
The other options are not suitable in this context. NumPy is designed for numerical computation, PyTorch is used for machine learning, and PySpark is intended for big data processing. None of these tools integrate with Sleuth Kit or provide native disk forensic analysis capabilities. Therefore, PyTSK is the correct and CHFI- aligned choice for Python-based Sleuth Kit forensic automation.


NEW QUESTION # 108
......

Authentic Best resources for 312-49v11 Online Practice Exam: https://freecert.test4sure.com/312-49v11-exam-materials.html