EnCE Practice Test Questions with Detailed Verified
Answers (100% Correct Answers) /Already Graded A+
You are a computer forensic examiner tasked with determining what evidence
is on a seized computer. On what part of the computer system will you find
data of evidentiary value?
A. Microprocessor or CPU
B. USB controller
C. Hard drive
D. PCI Expansions
Ans: C. Hard drive
You are a computer forensic examiner explaining how computers store and
access the data you recovered as evidence during your examination. The
evidence is a log file and was recovered as an artifact of user activity on the
________, which was stored on the _____________, contained within a
_____________ on the media.
A. Partition, operating system, file system
B. Operating system, file system, partition
C. File system, operating system, hard drive
D. Operating system, partition, file system
Ans: B. Operating system, file system, partition
You are a computer forensic examiner investigating a seized computer. You
recovered a document containing potential evidence. EnCase reports the file
system on the forensic image of the hard drive is File Allocation Table (FAT).
What information about the document file can be found in the FAT on the
media? (Choose all that apply.)
A. Name of the file
Approved By:
vPretest - Stuvia US
,2
B. Date and time stamps of the file
C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file
Ans: C and D
You are a computer forensic examiner investigating media on a seized
computer. You recovered a document containing potential evidence. EnCase
reports the file system on the forensic image of the hard drive is New
Technology File System (NTFS). What information about the document file can
be found in the NTFS master file table on the media? (Choose all that apply.)
A. Name of the file
B. Date and time stamps of the file
C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file
Ans: A, B, C, D and E
You are preparing to lead a team to serve a search warrant on a business
suspected of committing large-scale consumer fraud. Ideally, you would assign
which tasks to search team members? (Choose all that apply.)
A. Photographer
B. Search and seizure specialists
C. Recorder
D. Digital evidence search and seizure specialists
Ans: A, B, C and D
You are a computer forensic examiner at a scene and have determined you
will seize a Linux server, which, according to your source of information,
Approved By:
vPretest - Stuvia US
,3
contains the database records for the company under investigation for fraud.
What is the best practice for "taking down" the server for collection?
A. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and use the normal shutdown procedure.
B. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and pull the plug from the wall.
C. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and pull the plug from the rear of the computer.
D. Photograph the screen and note any running programs or messages,
capture volatile data, and so on, and ask the user at the scene to shut down
the server.
Ans: A. Photograph the screen and note any running programs or messages,
capture volatile data, and so on, and use the normal shutdown procedure.
You are a computer forensic examiner at a scene and are authorized to seize
only media that can be determined to have evidence related to the
investigation. What options do you have to determine whether evidence is
present before seizure and a full forensic examination? (Choose all that apply.)
A. Use a DOS boot floppy or CD to boot the machine, and browse through
the directory for evidence.
B. Use a forensically sound Linux boot CD to boot the machine into Linux, and
use LinEn to preview the hard drive through a crossover cable with EnCase for
Windows.
C. Remove the subject's hard drive from the machine, and preview the hard
drive in EnCase for Windows with a hardware write blocker such as
FastBloc/Tableau.
D. Boot the computer into Windows and use Explorer search utility to find
the finds being sought.
Ans: B and C
You are a computer forensic examiner at a scene and have determined you
will need to image a hard drive in a workstation while on-site. What are your
Approved By:
vPretest - Stuvia US
, 4
options for creating a forensically sound image of the hard drive? (Choose all
that apply.)
A. Use a regular DOS boot floppy or CD to boot the machine, and use EnCase
for DOS to image the subject hard drive to a second hard drive attached to
the machine.
B. Use a forensically sound Linux boot CD to boot the machine into Linux, and
use LinEn to image the subject hard drive to a second hard drive attached to
the machine.
C. Remove the subject hard drive from the machine, and image the hard drive
in EnCase for Windows with a hardware write blocker such as
FastBloc/Tableau.
D. Use a forensically sound Linux boot CD to boot the machine into Linux,
and use LinEn to image the hard drive through a crossover cable with EnCase
for Windows.
Ans: B, C and D
You are a computer forensic examiner and have imaged a hard drive on site.
Before you leave the scene, you want to ensure the image completely verifies
as an exact forensic duplicate of the original. To verify the EnCase evidence file
containing the image, you should do which of the following?
A. Use a hex editor to compare a sample of sectors in the EnCase evidence file
with that of the original.
B. Load the EnCase evidence files into EnCase for Windows, and after the
verification is more than halfway completed, cancel the verification and spot-
check the results for errors.
C. Load the EnCase evidence files into EnCase for DOS, and verify the hash of
those files.
D. Load the EnCase evidence files into EnCase for Windows, allow the
verification process to finish, and then check the results for complete
verification.
Approved By:
vPretest - Stuvia US