Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 51 pages
Exam (elaborations)

ENCE PRACTICE EXAM QUESTIONS WITH CORRECT ANSWERS

Document preview thumbnail
Preview 4 out of 51 pages

ENCE PRACTICE EXAM QUESTIONS WITH CORRECT ANSWERS...

Content preview

ENCE PRACTICE EXAM QUESTIONS WITH
CORRECT ANSWERS



You are a computer forensic examiner tasked with determining what evidence is
on a seized computer. On what part of the computer system will you find data of
evidentiary value?

A. Microprocessor or CPU
B. USB controller
C. Hard drive
D. PCI Expansions - ANSWER C. Hard drive

You are a computer forensic examiner explaining how computers store and
access the data you recovered as evidence during your examination. The
evidence is a log file and was recovered as an artifact of user activity on the
________, which was stored on the _____________, contained within a
_____________ on the media.

A. Partition, operating system, file system
B. Operating system, file system, partition
C. File system, operating system, hard drive
D. Operating system, partition, file system - ANSWER B. Operating system,
file system, partition

You are a computer forensic examiner investigating a seized computer. You
recovered a document containing potential evidence. EnCase reports the file
system on the forensic image of the hard drive is File Allocation Table (FAT).
What information about the document file can be found in the FAT on the
media? (Choose all that apply.)

A. Name of the file
B. Date and time stamps of the file
C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file - ANSWER C and D

,You are a computer forensic examiner investigating media on a seized
computer. You recovered a document containing potential evidence. EnCase
reports the file system on the forensic image of the hard drive is New
Technology File System (NTFS). What information about the document file can
be found in the NTFS master file table on the media? (Choose all that apply.)

A. Name of the file
B. Date and time stamps of the file
C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file - ANSWER A, B, C, D and E

You are preparing to lead a team to serve a search warrant on a business
suspected of committing large-scale consumer fraud. Ideally, you would assign
which tasks to search team members? (Choose all that apply.)

A. Photographer
B. Search and seizure specialists
C. Recorder
D. Digital evidence search and seizure specialists - ANSWER A, B, C and D

You are a computer forensic examiner at a scene and have determined you will
seize a Linux server, which, according to your source of information, contains
the database records for the company under investigation for fraud. What is the
best practice for "taking down" the server for collection?

A. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and use the normal shutdown procedure.
B. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and pull the plug from the wall.
C. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and pull the plug from the rear of the computer.
D. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and ask the user at the scene to shut down the server. -
ANSWER A. Photograph the screen and note any running programs or
messages, capture volatile data, and so on, and use the normal shutdown
procedure.

,You are a computer forensic examiner at a scene and are authorized to seize
only media that can be determined to have evidence related to the investigation.
What options do you have to determine whether evidence is present before
seizure and a full forensic examination? (Choose all that apply.)

A. Use a DOS boot floppy or CD to boot the machine, and browse through the
directory for evidence.
B. Use a forensically sound Linux boot CD to boot the machine into Linux, and
use LinEn to preview the hard drive through a crossover cable with EnCase for
Windows.
C. Remove the subject's hard drive from the machine, and preview the hard
drive in EnCase for Windows with a hardware write blocker such as
FastBloc/Tableau.
D. Boot the computer into Windows and use Explorer search utility to find the
finds being sought. - ANSWER B and C

You are a computer forensic examiner at a scene and have determined you will
need to image a hard drive in a workstation while on-site. What are your options
for creating a forensically sound image of the hard drive? (Choose all that
apply.)

A. Use a regular DOS boot floppy or CD to boot the machine, and use EnCase
for DOS to image the subject hard drive to a second hard drive attached to the
machine.
B. Use a forensically sound Linux boot CD to boot the machine into Linux, and
use LinEn to image the subject hard drive to a second hard drive attached to the
machine.
C. Remove the subject hard drive from the machine, and image the hard drive in
EnCase for Windows with a hardware write blocker such as FastBloc/Tableau.
D. Use a forensically sound Linux boot CD to boot the machine into Linux, and
use LinEn to image the hard drive through a crossover cable with EnCase for
Windows. - ANSWER B, C and D

You are a computer forensic examiner and have imaged a hard drive on site.
Before you leave the scene, you want to ensure the image completely verifies as
an exact forensic duplicate of the original. To verify the EnCase evidence file
containing the image, you should do which of the following?

, A. Use a hex editor to compare a sample of sectors in the EnCase evidence file
with that of the original.
B. Load the EnCase evidence files into EnCase for Windows, and after the
verification is more than halfway completed, cancel the verification and spot-
check the results for errors.
C. Load the EnCase evidence files into EnCase for DOS, and verify the hash of
those files.
D. Load the EnCase evidence files into EnCase for Windows, allow the
verification process to finish, and then check the results for complete
verification. - ANSWER D. Load the EnCase evidence files into EnCase for
Windows, allow the verification process to finish, and then check the results for
complete verification.

You are a computer forensic examiner and need to verify the integrity of an
EnCase evidence file. To completely verify the file's integrity, which of the
following must be true?

A. The MD5 hash value must verify.
B. The CRC values and the MD5 hash value both must verify.
C. Either CRC or MD5 hash values must verify.
D. The CRC values must verify. - ANSWER B. The CRC values and the MD5
hash values both must verify

You are a computer forensic examiner and need to determine what files are
contained within a folder called Business documents. What EnCase pane will
you use to view the names of the files in the folder?

A. Tree pane
B. Table pane
C. View pane
D. EnScripts pane - ANSWER B. Table pane

You are a computer forensic examiner and need to view the contents of a file
contained within a folder called Business documents. What EnCase pane will
you use to view the contents of the file?

A. Tree pane

Document information

Uploaded on
April 3, 2025
Number of pages
51
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$17.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
luzlinkuz
3.8
(328)
Sold
1596
Followers
852
Items
32252
Last sold
11 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions