The 312-49 test measures an individual’s ability to identify an intruder’s footprints and to properly gather the necessary evidence to prosecute. Before taking the 312-49 test, you should practice the following:
- Understand Internet laws of different countries.
- Review first responder procedure and CSIRT.
- Know the functions of file system, hard disk, and digital media devices.
- Understand Windows, Linux and Macintosh boot process.
- Practice Windows forensic tools.
- Identify commands and different kits of Linux forensics.
- Identify software and hardware tools for data acquisition and duplication.
- Identify partition recovery tools and methods.
- Understand different attacks and tools of steganography.
- Know about the password cracking tools and attacks.
- Understand wireless and Web attacks.