| Exam Code/Number: | EC0-349Join the discussion |
| Exam Name: | Computer Hacking Forensic Investigator |
| Certification: | EC-COUNCIL |
| Question Number: | 490 |
| Publish Date: | Aug 30, 2026 |
|
Rating
100%
|
|
You are a computer forensics investigator working with local police department and you are called to assist in an investigation of threatening emails. The complainant has printed out 27 email messages from the suspect and gives the printouts to you. You inform her that you will need to examine her computer because you need access to the _________________________ in order to track the emails back to the suspect.
Physical security recommendations: There should be only one entrance to a forensics lab
Volatile Memory is one of the leading problems for forensics. Worms such as code Red are memory resident and do not write themselves to the hard drive, if you turn the system off they disappear. In a lab environment, which of the following options would you suggest as the most appropriate to overcome the problem of capturing volatile memory?
Which of the following would you consider an aspect of organizational security, especially focusing on IT security?
You are the network administrator for a small bank in Dallas, Texas. To ensure network security, you enact a security policy that requires all users to have 14 character passwords. After giving your users 2 weeks notice, you change the Group Policy to force 14 character passwords. A week later you dump the SAM database from the standalone server and run a password-cracking tool against it. Over 99% of the passwords are broken within an hour.
Why were these passwords cracked so Quickly?