EC-COUNCIL · 312-49v11 CHFI v11

EC-Council 312-49v11 CHFI v11 Exam Practice Questions

452 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 452 questions in this pack

Question 1

A suspect is accused of violating the acceptable use of computing resources, as he has visited adult websites and downloaded images. The investigator wants to demonstrate that the suspect did indeed visit these sites. However, the suspect has cleared the search history and emptied the cookie cache. Moreover, he has removed any images he might have downloaded. What can the investigator do to prove the violation?

  1. Image the disk and try to recover deleted files
  2. Seek the help of co-workers who are eye-witnesses
  3. Check the Windows registry for connection data (you may or may not recover)
  4. Approach the website's administrator for evidence
Show answer and explanation

Correct answer: A. Image the disk and try to recover deleted files

Clearing history, cookies and deleting downloaded images only removes the file references, so the underlying data stays on the disk until it is overwritten. Creating a forensic image of the drive and carving unallocated space and slack space allows the investigator to recover the deleted images, browser cache remnants and index files. That recovered content is direct evidence that the suspect visited the sites and downloaded the material.

Why the other options are wrong

  • B. Co-worker statements depend on memory and availability and cannot establish which sites were visited or what was downloaded, so they do not substitute for forensic artifacts on the machine.
  • C. Registry artifacts such as typed URLs may hint at activity but they are incomplete and do not recover the downloaded images themselves.
  • D. Website administrators may not retain logs, are often outside the investigator's jurisdiction, and obtaining their records requires a legal process, while the suspect's own disk holds the evidence.

Question 2

You have been asked to investigate the possibility of computer fraud in the finance department of a company. It is suspected that a staff member has been committing finance fraud by printing cheques that have not been authorized. You have exhaustively searched all data files on a bitmap image of the target computer, but have found no evidence. You suspect the files may not have been saved. What should you examine next in this case?

  1. The registry
  2. The swap file
  3. The recycle bin
  4. The metadata
Show answer and explanation

Correct answer: B. The swap file

When searching data files yields no evidence of unauthorized cheques, the next logical location is the swap file (also called virtual memory or page file). The swap file contains data that was in RAM but not yet saved to disk, including active documents and files being edited. If the suspect was composing or printing cheques without saving them to permanent storage, traces of this activity would exist in the swap file.

Why the other options are wrong

  • A. The registry stores configuration and system settings, not typically the content of unsaved documents.
  • C. The recycle bin contains deleted files that were saved; this investigation already found no evidence in saved files.
  • D. Metadata describes file properties but does not contain the actual content of unsaved documents.

Question 3

Which of the following are small pieces of data sent from a website and stored on the user’s computer by the user’s web browser to track, validate, and maintain specific user information?

  1. Temporary Files
  2. Open files
  3. Cookies
  4. Web Browser Cache
Show answer and explanation

Correct answer: C. Cookies

Cookies are small text files created by websites and stored on the user's computer by the web browser. They are designed to track user activity, maintain session information, validate credentials, and store user preferences. Cookies persist across browser sessions and are a key forensic artifact for demonstrating web browsing activity.

Why the other options are wrong

  • A. Temporary files are cache files but are broader in scope and not specifically designed for tracking and user validation.
  • B. Open files refers to files currently accessed by running processes, not stored data from websites.
  • D. Web browser cache stores downloaded web page content and images but is not used for user tracking and validation in the same way cookies are.

See all 10 free questions Get the full pack, US$39

452 practice questions for EC-Council Computer Hacking Forensic Investigator v11 (CHFI), exam 312-49, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 452 questions mapped to the CHFI v11 exam blueprint
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A 312-49 attempt costs US$650. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 452 questions

What makes the CHFI hard

CHFI v11 is the current version and it is a long exam: 150 questions over four hours, with a passing score set per exam form somewhere between 60% and 85%. The v11 update brought in dark web investigations, IoT and OT forensics, fileless malware and AI-assisted forensics, so a v9 or v10 bank leaves gaps exactly where the newest questions sit.

Digital Forensics is the biggest domain at 29%: Windows, Linux and macOS artefacts, file systems including NTFS MFT records, slack space and carving, memory forensics, network forensics, malware forensics, and cloud, mobile, IoT, OT and dark web evidence.

Digital Evidence at 18% covers acquisition, imaging, hashing, chain of custody and anti-forensics, and Procedures and Methodology at 17% is the investigation process end to end. Forensic Science, Tools, Systems and Programs, and Regulations, Policies and Ethics make up the rest. The questions are scenario heavy, so knowing which artefact answers which question matters more than memorising tool menus.

About the exam

312-49 v11 (Computer Hacking Forensic Investigator) earns the EC-Council CHFI certification. It covers forensic science, regulations and ethics, digital evidence, investigation procedures and methodology, digital forensics across operating systems, networks, malware, cloud, mobile, IoT and OT, and forensic tools. There are no prerequisites with official training; self-study candidates need two years of information security experience and an eligibility application.

Exam domains

  • Forensic Science: 15%
  • Regulations, Policies, and Ethics: 10%
  • Digital Evidence: 18%
  • Procedures and Methodology: 17%
  • Digital Forensics: 29%
  • Tools, Systems, and Programs: 11%

150 multiple choice questions, 240 minutes, passing score 60% to 85% depending on the exam form, US$650 per attempt, ECC Exam Center, Pearson VUE or remote proctoring, certification valid for three years with EC-Council continuing education.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the EC-Council 312-49v11 CHFI v11 pack?

452 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.