EC-COUNCIL EC1-349 Exam Overview:
| Certification Vendor: | EC-Council |
|---|---|
| Exam Name: | Computer Hacking Forensic Investigator |
| Exam Number: | EC1-349 / EC0-349 / 312-49 |
| Exam Format: | Multiple Choice |
| Related Certifications: | EC-Council Certified Security Analyst (ECSA) Certified Ethical Hacker (CEH) |
| Passing Score: | 60%–85% (form-specific, average 70%) |
| Exam Price: | USD 500–550 |
| Real Exam Qty: | 150 |
| Exam Duration: | 240 minutes |
| Available Languages: | English |
| Certificate Validity Period: | 3 years |
| Recommended Training: | EC-Council CHFI Official Training CHFI Candidate Handbook |
| Exam Registration: | EC-Council Official Registration |
| Sample Questions: | EC-COUNCIL EC1-349 Sample Questions |
| Exam Way: | Online proctored via ECC Exam Portal or in-person at authorized EC-Council testing centers |
| Pre Condition: | Recommended: Official CHFI training. Without training: minimum 2 years of information security experience + EC-Council eligibility approval |
| Official Syllabus URL: | https://www.eccouncil.org/train-certify/computer-hacking-forensic-investigator-chfi/ |
EC-COUNCIL EC1-349 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Digital Forensics | 29% | - Memory and malware forensics - Cloud, mobile, and IoT forensics - Operating system forensics (Windows, macOS, Linux) - Database and dark web investigations - File system analysis - Network, email, and web application forensics |
| Topic 2: Forensic Science | 15% | - Investigation methodology - Fundamentals of computer forensics - Documentation and reporting basics - Crime scene management and triage |
| Topic 3: Digital Evidence | 18% | - Evidence identification and preservation - Chain of custody procedures - Hashing and integrity verification - Anti-forensics detection and countermeasures |
| Topic 4: Procedures and Methodology | 17% | - Timeline reconstruction - First responder guidelines - Forensic lab setup and best practices - Standard investigation workflows |
| Topic 5: Regulations, Policies, and Ethics | 10% | - Expert witness testimony - Code of ethics and professional conduct - Legal frameworks and admissibility - Privacy laws and warrants |
| Topic 6: Tools, Systems, and Programs | 11% | - Forensic acquisition and analysis tools - Reporting and case management tools - Imaging and duplication software |
EC-COUNCIL Computer Hacking Forensic Investigator Sample Questions:
Which of the following statements is incorrect related to acquiring electronic evidence at crime scene?
- A. Sample banners are used to record the system activities when used by the unauthorized user
- B. In warning banners, organizations give clear and unequivocal notice to intruders that by signing onto the system they are expressly consenting to such monitoring
- C. At the time of seizing process, you need to shut down the computer immediately
- D. The equipment is seized which is connected to the case, knowing the role of the computer which will indicate what should be taken
Correct Answer: C 🗳️
What is cold boot (hard boot)?
- A. It is the process of restarting a computer that is already in sleep mode
- B. It is the process of shutting down a computer from a powered-on or on state
- C. It is the process of restarting a computer that is already turned on through the operating system
- D. It is the process of starting a computer from a powered-down or off state
Correct Answer: D 🗳️
Wi-Fi Protected Access (WPA) is a data encryption method for WLANs based on 802.11 standards. Temporal Key Integrity Protocol (TKIP) enhances WEP by adding a rekeying mechanism to provide fresh encryption and integrity keys. Temporal keys are changed for every____________.
- A. 5,000 packets
- B. 15,000 packets
- C. 20.000 packets
- D. 10.000 packets
Correct Answer: D 🗳️
Data is striped at a byte level across multiple drives and parity information is distributed among all member drives.
What RAID level is represented here?
- A. RAID Level 3
- B. RAID Level0
- C. RAID Level 5
- D. RAID Level 1
Correct Answer: C 🗳️
When collecting electronic evidence at the crime scene, the collection should proceed from the most volatile to the least volatile
- A. True
- B. False
Correct Answer: A 🗳️

We're so confident of our products that we provide no hassle product exchange.


By Moore


