Want to pass your ECCouncil Computer Hacking Forensic Investigator (V9) 312-49 exam in the very first attempt? Try Pass2lead! It is equally effective for both starters and IT professionals.
VCE
An investigator is searching through the firewall logs of a company and notices ICMP packets that are larger than 65,536 bytes. What type of activity is the investigator seeing?
A. Smurf
B. Ping of death
C. Fraggle
D. Nmap scan
After suspecting a change in MS-Exchange Server storage archive, the investigator has analyzed it. Which of the following components is not an actual part of the archive?
A. PRIV.STM
B. PUB.EDB
C. PRIV.EDB
D. PUB.STM
In which registry does the system store the Microsoft security IDs?
A. HKEY_CLASSES_ROOT (HKCR)
B. HKEY_CURRENT_CONFIG (HKCC)
C. HKEY_CURRENT_USER (HKCU)
D. HKEY_LOCAL_MACHINE (HKLM)