ENCE 325 EXAM 4 PRACTICE TEST 2026 FULL
SOLUTIONS REVIEW PACK
◉ You are a computer forensic examiner explaining how computers
store and access the data you recovered as evidence during your
examination. The evidence is a log file and was recovered as an
artifact of user activity on the ________, which was stored on the
_____________, contained within a _____________ on the media.
A. Partition, operating system, file system
B. Operating system, file system, partition
C. File system, operating system, hard drive
D. Operating system, partition, file system.
Answer: B. Operating system, file system, partition
◉ You are a computer forensic examiner investigating a seized
computer. You recovered a document containing potential evidence.
EnCase reports the file system on the forensic image of the hard
drive is File Allocation Table (FAT). What information about the
document file can be found in the FAT on the media? (Choose all that
apply.)
A. Name of the file
B. Date and time stamps of the file
,C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file.
Answer: C and D
◉ You are a computer forensic examiner investigating media on a
seized computer. You recovered a document containing potential
evidence. EnCase reports the file system on the forensic image of the
hard drive is New Technology File System (NTFS). What information
about the document file can be found in the NTFS master file table
on the media? (Choose all that apply.)
A. Name of the file
B. Date and time stamps of the file
C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file.
Answer: A, B, C, D and E
◉ You are preparing to lead a team to serve a search warrant on a
business suspected of committing large-scale consumer fraud.
Ideally, you would assign which tasks to search team members?
(Choose all that apply.)
,A. Photographer
B. Search and seizure specialists
C. Recorder
D. Digital evidence search and seizure specialists.
Answer: A, B, C and D
◉ You are a computer forensic examiner at a scene and have
determined you will seize a Linux server, which, according to your
source of information, contains the database records for the
company under investigation for fraud. What is the best practice for
"taking down" the server for collection?
A. Photograph the screen and note any running programs or
messages, capture volatile data, and so on, and use the normal
shutdown procedure.
B. Photograph the screen and note any running programs or
messages, capture volatile data, and so on, and pull the plug from the
wall.
C. Photograph the screen and note any running programs or
messages, capture volatile data, and so on, and pull the plug from the
rear of the computer.
D. Photograph the screen and note any running programs or
messages, capture volatile data, and so on, and ask the user at the
scene to shut down the server..
, Answer: A. Photograph the screen and note any running programs
or messages, capture volatile data, and so on, and use the normal
shutdown procedure.
◉ You are a computer forensic examiner at a scene and are
authorized to seize only media that can be determined to have
evidence related to the investigation. What options do you have to
determine whether evidence is present before seizure and a full
forensic examination? (Choose all that apply.)
A. Use a DOS boot floppy or CD to boot the machine, and browse
through the directory for evidence.
B. Use a forensically sound Linux boot CD to boot the machine into
Linux, and use LinEn to preview the hard drive through a crossover
cable with EnCase for Windows.
C. Remove the subject's hard drive from the machine, and preview
the hard drive in EnCase for Windows with a hardware write blocker
such as FastBloc/Tableau.
D. Boot the computer into Windows and use Explorer search utility
to find the finds being sought..
Answer: B and C
◉ You are a computer forensic examiner at a scene and have
determined you will need to image a hard drive in a workstation
while on-site. What are your options for creating a forensically
sound image of the hard drive? (Choose all that apply.)
SOLUTIONS REVIEW PACK
◉ You are a computer forensic examiner explaining how computers
store and access the data you recovered as evidence during your
examination. The evidence is a log file and was recovered as an
artifact of user activity on the ________, which was stored on the
_____________, contained within a _____________ on the media.
A. Partition, operating system, file system
B. Operating system, file system, partition
C. File system, operating system, hard drive
D. Operating system, partition, file system.
Answer: B. Operating system, file system, partition
◉ You are a computer forensic examiner investigating a seized
computer. You recovered a document containing potential evidence.
EnCase reports the file system on the forensic image of the hard
drive is File Allocation Table (FAT). What information about the
document file can be found in the FAT on the media? (Choose all that
apply.)
A. Name of the file
B. Date and time stamps of the file
,C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file.
Answer: C and D
◉ You are a computer forensic examiner investigating media on a
seized computer. You recovered a document containing potential
evidence. EnCase reports the file system on the forensic image of the
hard drive is New Technology File System (NTFS). What information
about the document file can be found in the NTFS master file table
on the media? (Choose all that apply.)
A. Name of the file
B. Date and time stamps of the file
C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file.
Answer: A, B, C, D and E
◉ You are preparing to lead a team to serve a search warrant on a
business suspected of committing large-scale consumer fraud.
Ideally, you would assign which tasks to search team members?
(Choose all that apply.)
,A. Photographer
B. Search and seizure specialists
C. Recorder
D. Digital evidence search and seizure specialists.
Answer: A, B, C and D
◉ You are a computer forensic examiner at a scene and have
determined you will seize a Linux server, which, according to your
source of information, contains the database records for the
company under investigation for fraud. What is the best practice for
"taking down" the server for collection?
A. Photograph the screen and note any running programs or
messages, capture volatile data, and so on, and use the normal
shutdown procedure.
B. Photograph the screen and note any running programs or
messages, capture volatile data, and so on, and pull the plug from the
wall.
C. Photograph the screen and note any running programs or
messages, capture volatile data, and so on, and pull the plug from the
rear of the computer.
D. Photograph the screen and note any running programs or
messages, capture volatile data, and so on, and ask the user at the
scene to shut down the server..
, Answer: A. Photograph the screen and note any running programs
or messages, capture volatile data, and so on, and use the normal
shutdown procedure.
◉ You are a computer forensic examiner at a scene and are
authorized to seize only media that can be determined to have
evidence related to the investigation. What options do you have to
determine whether evidence is present before seizure and a full
forensic examination? (Choose all that apply.)
A. Use a DOS boot floppy or CD to boot the machine, and browse
through the directory for evidence.
B. Use a forensically sound Linux boot CD to boot the machine into
Linux, and use LinEn to preview the hard drive through a crossover
cable with EnCase for Windows.
C. Remove the subject's hard drive from the machine, and preview
the hard drive in EnCase for Windows with a hardware write blocker
such as FastBloc/Tableau.
D. Boot the computer into Windows and use Explorer search utility
to find the finds being sought..
Answer: B and C
◉ You are a computer forensic examiner at a scene and have
determined you will need to image a hard drive in a workstation
while on-site. What are your options for creating a forensically
sound image of the hard drive? (Choose all that apply.)