The 312-49 test measures an individual’s ability to identify an intruder’s footprints and to properly gather the necessary evidence to prosecute. Before taking the 312-49 test, you should practice the following:
- Understand Internet laws of different countries.
- Review first responder procedure and CSIRT.
- Know the functions of file system, hard disk, and digital media devices.
- Understand Windows, Linux and Macintosh boot process.
- Practice Windows forensic tools.
- Identify commands and different kits of Linux forensics.
- Identify software and hardware tools for data acquisition and duplication.
- Identify partition recovery tools and methods.
- Understand different attacks and tools of steganography.
- Know about the password cracking tools and attacks.
- Understand wireless and Web attacks.
- Use different types of DoS attacks.
- Recognize email sending-receiving System.
- Identify corporate espionage.
- Understand laws of Copyright and Trademark.
- Understand laws on sexual harassment.
- Understand laws of child pornography.
- Study features and tools for PDA forensics.
- Study features and tools for ipod forensics.
- Study working and functions of Blackberry.
- Create investigative and evidence reports.
- Recognize privacy issue involved in investigations.
- Understand forensic process and collecting evidences.