Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 41 pages
Exam (elaborations)

ENCE PRACTICE TEST QUESTIONS & ANSWERS

Document preview thumbnail
Preview 4 out of 41 pages

ENCE PRACTICE TEST QUESTIONS & ANSWERS

Content preview

ENCE PRACTICE TEST QUESTIONS & ANSWERS

You are a computer forensic examiner tasked with determining what evidence is on a
seized computer. On what part of the computer system will you find data of evidentiary
value?

A. Microprocessor or CPU
B. USB controller
C. Hard drive
D. PCI Expansions - Answer -C. Hard drive

You are a computer forensic examiner explaining how computers store and access the
data you recovered as evidence during your examination. The evidence is a log file and
was recovered as an artifact of user activity on the ________, which was stored on the
_____________, contained within a _____________ on the media.

A. Partition, operating system, file system
B. Operating system, file system, partition
C. File system, operating system, hard drive
D. Operating system, partition, file system - Answer -B. Operating system, file system,
partition

You are a computer forensic examiner investigating a seized computer. You recovered
a document containing potential evidence. EnCase reports the file system on the
forensic image of the hard drive is File Allocation Table (FAT). What information about
the document file can be found in the FAT on the media? (Choose all that apply.)

A. Name of the file
B. Date and time stamps of the file
C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file - Answer -C and D

You are a computer forensic examiner at a scene and are authorized to seize only
media that can be determined to have evidence related to the investigation. What
options do you have to determine whether evidence is present before seizure and a full
forensic examination? (Choose all that apply.)

A. Use a DOS boot floppy or CD to boot the machine, and browse through the directory
for evidence.
B. Use a forensically sound Linux boot CD to boot the machine into Linux, and use
LinEn to preview the hard drive through a crossover cable with EnCase for Windows.
C. Remove the subject's hard drive from the machine, and preview the hard drive in
EnCase for Windows with a hardware write blocker such as FastBloc/Tableau.

,D. Boot the computer into Windows and use Explorer search utility to find the finds
being sought. - Answer -B and C

You are a computer forensic examiner at a scene and have determined you will need to
image a hard drive in a workstation while on-site. What are your options for creating a
forensically sound image of the hard drive? (Choose all that apply.)

A. Use a regular DOS boot floppy or CD to boot the machine, and use EnCase for DOS
to image the subject hard drive to a second hard drive attached to the machine.
B. Use a forensically sound Linux boot CD to boot the machine into Linux, and use
LinEn to image the subject hard drive to a second hard drive attached to the machine.
C. Remove the subject hard drive from the machine, and image the hard drive in
EnCase for Windows with a hardware write blocker such as FastBloc/Tableau.
D. Use a forensically sound Linux boot CD to boot the machine into Linux, and use
LinEn to image the hard drive through a crossover cable with EnCase for Windows. -
Answer -B, C and D

You are a computer forensic examiner and have imaged a hard drive on site. Before
you leave the scene, you want to ensure the image completely verifies as an exact
forensic duplicate of the original. To verify the EnCase evidence file containing the
image, you should do which of the following?

A. Use a hex editor to compare a sample of sectors in the EnCase evidence file with
that of the original.
B. Load the EnCase evidence files into EnCase for Windows, and after the verification
is more than halfway completed, cancel the verification and spot-check the results for
errors.
C. Load the EnCase evidence files into EnCase for DOS, and verify the hash of those
files.
D. Load the EnCase evidence files into EnCase for Windows, allow the verification
process to finish, and then check the results for complete verification. - Answer -D.
Load the EnCase evidence files into EnCase for Windows, allow the verification process
to finish, and then check the results for complete verification.

You are a computer forensic examiner and need to verify the integrity of an EnCase
evidence file. To completely verify the file's integrity, which of the following must be
true?

A. The MD5 hash value must verify.
B. The CRC values and the MD5 hash value both must verify.
C. Either CRC or MD5 hash values must verify.
D. The CRC values must verify. - Answer -B. The CRC values and the MD5 hash
values both must verify

You are a computer forensic examiner investigating media on a seized computer. You
recovered a document containing potential evidence. EnCase reports the file system on

,the forensic image of the hard drive is New Technology File System (NTFS). What
information about the document file can be found in the NTFS master file table on the
media? (Choose all that apply.)

A. Name of the file
B. Date and time stamps of the file
C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file - Answer -A, B, C, D and E

You are preparing to lead a team to serve a search warrant on a business suspected of
committing large-scale consumer fraud. Ideally, you would assign which tasks to search
team members? (Choose all that apply.)

A. Photographer
B. Search and seizure specialists
C. Recorder
D. Digital evidence search and seizure specialists - Answer -A, B, C and D

You are a computer forensic examiner at a scene and have determined you will seize a
Linux server, which, according to your source of information, contains the database
records for the company under investigation for fraud. What is the best practice for
"taking down" the server for collection?

A. Photograph the screen and note any running programs or messages, capture volatile
data, and so on, and use the normal shutdown procedure.
B. Photograph the screen and note any running programs or messages, capture volatile
data, and so on, and pull the plug from the wall.
C. Photograph the screen and note any running programs or messages, capture volatile
data, and so on, and pull the plug from the rear of the computer.
D. Photograph the screen and note any running programs or messages, capture volatile
data, and so on, and ask the user at the scene to shut down the server. - Answer -A.
Photograph the screen and note any running programs or messages, capture volatile
data, and so on, and use the normal shutdown procedure.

You are a computer forensic examiner and need to determine what files are contained
within a folder called Business documents. What EnCase pane will you use to view the
names of the files in the folder?

A. Tree pane
B. Table pane
C. View pane
D. EnScripts pane - Answer -B. Table pane

, You are a computer forensic examiner and need to view the contents of a file contained
within a folder called Business documents. What EnCase pane will you use to view the
contents of the file?

A. Tree pane
B. Table pane
C. View pane
D. EnScripts pane - Answer -C. View pane

You are a computer forensic examiner and are viewing a file in an EnCase evidence
file. With your cursor, you have selected one character in the file. What binary term is
used for the amount of data that represents a single character?

A. A bit
B. A nibble
C. A byte
D. A word - Answer -C. A byte

You are a computer forensic examiner and need to search for the name of a suspect in
an EnCase evidence file. You enter the name of the suspect into the EnCase keyword
interface as John Doe. What search hits will be found with this search term with the
default settings? (Choose all that apply.)'

A. John Doe
B. John D.
C. john doe
D. John.Doe - Answer -A and C

You are a computer forensic examiner and need to determine whether any Microsoft
Office documents have been renamed with image extensions to obscure their presence.
What EnCase process would you use to find such files?

A. File signature analysis
B. Recover Folders feature
C. File content search
D. File hash analysis - Answer -A. File signature analysis

You are a computer forensic examiner and want to reduce the number of files required
for examination by identifying and filtering out known good or system files. What
EnCase process would you use to identify such files?

A. File signature analysis
B. Recover Folders feature
C. File content search
D. File hash analysis - Answer -D. File hash analysis

Document information

Uploaded on
September 17, 2025
Number of pages
41
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$17.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
GEEKA
3.8
(363)
Sold
2148
Followers
1448
Items
59491
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions