The EnCase evidence file logical filename can be changed without affecting the verification of the acquired evidence.
Answer : B
In the FAT file system, the size of a deleted file can be found:
Answer : B
A sector on a floppy disk is the same size as a sector on a NTFS formatted hard drive.
Answer : A
A suspect typed a file on his computer and saved it to a floppy diskette. The filename was
MyNote.txt. You receive the floppy and the suspect computer. The suspect denies that the floppy disk belongs to him. You search the suspect computer and locate only the suspect? computer. The suspect denies that the floppy disk belongs to him. You search the suspect? computer and locate only the filename within a .LNK file. The .LNK file is located in the folder C:\Windows\Recent. How you would use the .LNK file to establish a connection between the file on the floppy diskette and the suspect computer? connection between the file on the floppy diskette and the suspect? computer?
Answer : A
Select the appropriate name for the highlighted area of the binary numbers.
Answer : B
The EnCase methodology dictates that the lab drive for evidence have a __________ prior to making an image.
Answer : C
In hexadecimal notation, one byte is represented by _____ character(s).
Answer : A
A personal data assistant was placed in a evidence locker until an examiner has time to examine it. Which of the following areas would require special attention?
Answer : B
When a non-compressed evidence file is reacquired with compression, the acquisition and verification hash values for the evidence will remain the same for both files.
Answer : A
To generate an MD5 hash value for a file, EnCase:
Answer : C
Which of the following is found in the FileSignatures.ini configuration file
Answer : B
During the power-up sequence, which of the following happens first?
Answer : B
A restored floppy diskette will have the same hash value as the original diskette.
Answer : B
A hard drive was imaged using EnCase. The original drive was placed into evidence. The restore feature was used to make a copy of the original hard drive. EnCase verifies the restored copy using:
Answer : A
To later verify the contents of an evidence file
7RODWHUYHULI\WKHFRQWHQWVRIDQHYLGHQFHILOH
Answer : A