ENCE PRACTICE EXAM QUESTIONS WITH
CORRECT ANSWERS
You are a computer forensic examiner tasked with determining what evidence is
on a seized computer. On what part of the computer system will you find data of
evidentiary value?
A. Microprocessor or CPU
B. USB controller
C. Hard drive
D. PCI Expansions - ANSWER C. Hard drive
You are a computer forensic examiner explaining how computers store and
access the data you recovered as evidence during your examination. The
evidence is a log file and was recovered as an artifact of user activity on the
________, which was stored on the _____________, contained within a
_____________ on the media.
A. Partition, operating system, file system
B. Operating system, file system, partition
C. File system, operating system, hard drive
D. Operating system, partition, file system - ANSWER B. Operating system,
file system, partition
You are a computer forensic examiner investigating a seized computer. You
recovered a document containing potential evidence. EnCase reports the file
system on the forensic image of the hard drive is File Allocation Table (FAT).
What information about the document file can be found in the FAT on the
media? (Choose all that apply.)
A. Name of the file
B. Date and time stamps of the file
C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file - ANSWER C and D
,You are a computer forensic examiner investigating media on a seized
computer. You recovered a document containing potential evidence. EnCase
reports the file system on the forensic image of the hard drive is New
Technology File System (NTFS). What information about the document file can
be found in the NTFS master file table on the media? (Choose all that apply.)
A. Name of the file
B. Date and time stamps of the file
C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file - ANSWER A, B, C, D and E
You are preparing to lead a team to serve a search warrant on a business
suspected of committing large-scale consumer fraud. Ideally, you would assign
which tasks to search team members? (Choose all that apply.)
A. Photographer
B. Search and seizure specialists
C. Recorder
D. Digital evidence search and seizure specialists - ANSWER A, B, C and D
You are a computer forensic examiner at a scene and have determined you will
seize a Linux server, which, according to your source of information, contains
the database records for the company under investigation for fraud. What is the
best practice for "taking down" the server for collection?
A. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and use the normal shutdown procedure.
B. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and pull the plug from the wall.
C. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and pull the plug from the rear of the computer.
D. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and ask the user at the scene to shut down the server. -
ANSWER A. Photograph the screen and note any running programs or
messages, capture volatile data, and so on, and use the normal shutdown
procedure.
,You are a computer forensic examiner at a scene and are authorized to seize
only media that can be determined to have evidence related to the investigation.
What options do you have to determine whether evidence is present before
seizure and a full forensic examination? (Choose all that apply.)
A. Use a DOS boot floppy or CD to boot the machine, and browse through the
directory for evidence.
B. Use a forensically sound Linux boot CD to boot the machine into Linux, and
use LinEn to preview the hard drive through a crossover cable with EnCase for
Windows.
C. Remove the subject's hard drive from the machine, and preview the hard
drive in EnCase for Windows with a hardware write blocker such as
FastBloc/Tableau.
D. Boot the computer into Windows and use Explorer search utility to find the
finds being sought. - ANSWER B and C
You are a computer forensic examiner at a scene and have determined you will
need to image a hard drive in a workstation while on-site. What are your options
for creating a forensically sound image of the hard drive? (Choose all that
apply.)
A. Use a regular DOS boot floppy or CD to boot the machine, and use EnCase
for DOS to image the subject hard drive to a second hard drive attached to the
machine.
B. Use a forensically sound Linux boot CD to boot the machine into Linux, and
use LinEn to image the subject hard drive to a second hard drive attached to the
machine.
C. Remove the subject hard drive from the machine, and image the hard drive in
EnCase for Windows with a hardware write blocker such as FastBloc/Tableau.
D. Use a forensically sound Linux boot CD to boot the machine into Linux, and
use LinEn to image the hard drive through a crossover cable with EnCase for
Windows. - ANSWER B, C and D
You are a computer forensic examiner and have imaged a hard drive on site.
Before you leave the scene, you want to ensure the image completely verifies as
an exact forensic duplicate of the original. To verify the EnCase evidence file
containing the image, you should do which of the following?
, A. Use a hex editor to compare a sample of sectors in the EnCase evidence file
with that of the original.
B. Load the EnCase evidence files into EnCase for Windows, and after the
verification is more than halfway completed, cancel the verification and spot-
check the results for errors.
C. Load the EnCase evidence files into EnCase for DOS, and verify the hash of
those files.
D. Load the EnCase evidence files into EnCase for Windows, allow the
verification process to finish, and then check the results for complete
verification. - ANSWER D. Load the EnCase evidence files into EnCase for
Windows, allow the verification process to finish, and then check the results for
complete verification.
You are a computer forensic examiner and need to verify the integrity of an
EnCase evidence file. To completely verify the file's integrity, which of the
following must be true?
A. The MD5 hash value must verify.
B. The CRC values and the MD5 hash value both must verify.
C. Either CRC or MD5 hash values must verify.
D. The CRC values must verify. - ANSWER B. The CRC values and the MD5
hash values both must verify
You are a computer forensic examiner and need to determine what files are
contained within a folder called Business documents. What EnCase pane will
you use to view the names of the files in the folder?
A. Tree pane
B. Table pane
C. View pane
D. EnScripts pane - ANSWER B. Table pane
You are a computer forensic examiner and need to view the contents of a file
contained within a folder called Business documents. What EnCase pane will
you use to view the contents of the file?
A. Tree pane
CORRECT ANSWERS
You are a computer forensic examiner tasked with determining what evidence is
on a seized computer. On what part of the computer system will you find data of
evidentiary value?
A. Microprocessor or CPU
B. USB controller
C. Hard drive
D. PCI Expansions - ANSWER C. Hard drive
You are a computer forensic examiner explaining how computers store and
access the data you recovered as evidence during your examination. The
evidence is a log file and was recovered as an artifact of user activity on the
________, which was stored on the _____________, contained within a
_____________ on the media.
A. Partition, operating system, file system
B. Operating system, file system, partition
C. File system, operating system, hard drive
D. Operating system, partition, file system - ANSWER B. Operating system,
file system, partition
You are a computer forensic examiner investigating a seized computer. You
recovered a document containing potential evidence. EnCase reports the file
system on the forensic image of the hard drive is File Allocation Table (FAT).
What information about the document file can be found in the FAT on the
media? (Choose all that apply.)
A. Name of the file
B. Date and time stamps of the file
C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file - ANSWER C and D
,You are a computer forensic examiner investigating media on a seized
computer. You recovered a document containing potential evidence. EnCase
reports the file system on the forensic image of the hard drive is New
Technology File System (NTFS). What information about the document file can
be found in the NTFS master file table on the media? (Choose all that apply.)
A. Name of the file
B. Date and time stamps of the file
C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file - ANSWER A, B, C, D and E
You are preparing to lead a team to serve a search warrant on a business
suspected of committing large-scale consumer fraud. Ideally, you would assign
which tasks to search team members? (Choose all that apply.)
A. Photographer
B. Search and seizure specialists
C. Recorder
D. Digital evidence search and seizure specialists - ANSWER A, B, C and D
You are a computer forensic examiner at a scene and have determined you will
seize a Linux server, which, according to your source of information, contains
the database records for the company under investigation for fraud. What is the
best practice for "taking down" the server for collection?
A. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and use the normal shutdown procedure.
B. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and pull the plug from the wall.
C. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and pull the plug from the rear of the computer.
D. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and ask the user at the scene to shut down the server. -
ANSWER A. Photograph the screen and note any running programs or
messages, capture volatile data, and so on, and use the normal shutdown
procedure.
,You are a computer forensic examiner at a scene and are authorized to seize
only media that can be determined to have evidence related to the investigation.
What options do you have to determine whether evidence is present before
seizure and a full forensic examination? (Choose all that apply.)
A. Use a DOS boot floppy or CD to boot the machine, and browse through the
directory for evidence.
B. Use a forensically sound Linux boot CD to boot the machine into Linux, and
use LinEn to preview the hard drive through a crossover cable with EnCase for
Windows.
C. Remove the subject's hard drive from the machine, and preview the hard
drive in EnCase for Windows with a hardware write blocker such as
FastBloc/Tableau.
D. Boot the computer into Windows and use Explorer search utility to find the
finds being sought. - ANSWER B and C
You are a computer forensic examiner at a scene and have determined you will
need to image a hard drive in a workstation while on-site. What are your options
for creating a forensically sound image of the hard drive? (Choose all that
apply.)
A. Use a regular DOS boot floppy or CD to boot the machine, and use EnCase
for DOS to image the subject hard drive to a second hard drive attached to the
machine.
B. Use a forensically sound Linux boot CD to boot the machine into Linux, and
use LinEn to image the subject hard drive to a second hard drive attached to the
machine.
C. Remove the subject hard drive from the machine, and image the hard drive in
EnCase for Windows with a hardware write blocker such as FastBloc/Tableau.
D. Use a forensically sound Linux boot CD to boot the machine into Linux, and
use LinEn to image the hard drive through a crossover cable with EnCase for
Windows. - ANSWER B, C and D
You are a computer forensic examiner and have imaged a hard drive on site.
Before you leave the scene, you want to ensure the image completely verifies as
an exact forensic duplicate of the original. To verify the EnCase evidence file
containing the image, you should do which of the following?
, A. Use a hex editor to compare a sample of sectors in the EnCase evidence file
with that of the original.
B. Load the EnCase evidence files into EnCase for Windows, and after the
verification is more than halfway completed, cancel the verification and spot-
check the results for errors.
C. Load the EnCase evidence files into EnCase for DOS, and verify the hash of
those files.
D. Load the EnCase evidence files into EnCase for Windows, allow the
verification process to finish, and then check the results for complete
verification. - ANSWER D. Load the EnCase evidence files into EnCase for
Windows, allow the verification process to finish, and then check the results for
complete verification.
You are a computer forensic examiner and need to verify the integrity of an
EnCase evidence file. To completely verify the file's integrity, which of the
following must be true?
A. The MD5 hash value must verify.
B. The CRC values and the MD5 hash value both must verify.
C. Either CRC or MD5 hash values must verify.
D. The CRC values must verify. - ANSWER B. The CRC values and the MD5
hash values both must verify
You are a computer forensic examiner and need to determine what files are
contained within a folder called Business documents. What EnCase pane will
you use to view the names of the files in the folder?
A. Tree pane
B. Table pane
C. View pane
D. EnScripts pane - ANSWER B. Table pane
You are a computer forensic examiner and need to view the contents of a file
contained within a folder called Business documents. What EnCase pane will
you use to view the contents of the file?
A. Tree pane