ENCE TEST QUESTIONS AND ANSWERS
EnCase Evidence File - ANSWER A Bit stream image of evidence written to a
file.
Contains Case Data - ANSWER Cannot be changed after evidence file is
created
Evidence file Contains - ANSWER Case Number; Examiner Name; Evidence
Number; Unique Description; Date/time of computer system clock; Acquisition
notes; serial number of physical hard drive
Evidence File Verification - ANSWER Cyclical Redundancy Check; 32-bit
CRC (by default) for 64 sectors (32kb) of data. Calculated when evidence file is
added to a case and rechecked every time the data block is accessed.
Verification hash - ANSWER MD5--128-bit/32 characters; SHA1 - 160 bit;
can choose MD5 and SHA1, MD5 or SHA1, or neither
Evidence File Characteristics - ANSWER Logical file that can be renamed and
moved; can be broken into multiple segments with a maximum segment size
dependent on the file system to which the evidence file is written; can be
password protected or encrypted and can be reacquired to remove or change
password/encryption; can be compressed during acquisition and/or reacquired
with compression for archival without changing the hash value; individual
segments can be verified by the CRCs when compression is not used (if
compression is used, the decompression algorithm is used); error granularity is
often used to adjust the writing of data to an evidence file, when a read error of
the subject media occurs (standard - size of data blocks, exhaustive - sector-by-
sector)
Evidence file verification - ANSWER Data is verified by verification hash
compared to the acquisition hash value of the original evidence; data in each
block is verified by a CRC when no compression is used; both the MD5 and/or
,SHA1 hash and CRCs must match for the evidence file to be verified (if any
compression is used, the algorithm is used to verify data blocks)
Case file extension - ANSWER .case
Compound File - ANSWER Pointers to the locations of evidence files on
forensic workstation; results of the file signature and hash analysis; bookmarks;
investigators notes
Case File, how many hard drives? - ANSWER Can contain any number of hard
drives or removable media
What to include in case file? - ANSWER Should be archived with the evidence
cache and evidence files as it contains all of the investigators notes work work
product; use the "Create Package" feature
configuration .ini files - ANSWER Contain global options used for all cases
FileTypes.ini - ANSWER organizes files into groups by extension, determines
which viewer to use
Local.ini - ANSWER Global configuration settings
Viewers.ini - ANSWER Installed viewers associated to EnCase
EnCase Methodology - ANSWER Use large capacity high rpm hard drives
with single partition; wipe the drive to eliminate any claims or arguments of
cross contamination; give the HD a unique label prior to acquisitions to
differentiate your drives from that of the suspect.
EnCase Folders - ANSWER Separate folders for each case; use unique
directory names; each case requires export, temp, and evidencecache folder
EvidenceCache - ANSWER Storing cache files and containers for processed
evidence
Export Folder - ANSWER Default folder for exporting evidence
, Temp Folder - ANSWER Default temporary folder for file viewing
Evidence Processor - ANSWER After adding evidence run the enCase
evidence processor; lets you run in a single session power analytic tools against
case data; unattended; can Recover folders and files that have been deleted or
corrupted on FAT and NTFS volumes; Hash analysis - can generate MD5 or
SHA1 hash values and compare against hash library; can create image
thumbnails
Expand Compound Files - ANSWER Expand compound and compressed files,
such as ZIP, RAR, and GZ
Find Email - ANSWER Extract individual messages from email archive files,
PST, NSF, DBX, EDB, AOL, MBOX, and EMLX
Find internet artifacts - ANSWER collect internet-related artifacts such as
browser histories and cached web pages; options to search unallocated space for
the artifacts
Search for keywords - ANSWER search raw text for specific keywords
index text - ANSWER create and index for when you need to search for
keywords in compound files and across large amounts of data; adjust
parameters for index creation such as minimum word length
File signature analysis - ANSWER determine if extension of a file has been
altered, whether or not the extension matches the file type as specified by the
files headers
protected file analysis - ANSWER Identify encrypted and password protected
files
Search index - ANSWER Case index created with processor; instantly search
for terms; adjust parameters for index creation such as minimum word length or
noise file use; search transcript output of file; guidance recommends always
indexing.
EnCase Evidence File - ANSWER A Bit stream image of evidence written to a
file.
Contains Case Data - ANSWER Cannot be changed after evidence file is
created
Evidence file Contains - ANSWER Case Number; Examiner Name; Evidence
Number; Unique Description; Date/time of computer system clock; Acquisition
notes; serial number of physical hard drive
Evidence File Verification - ANSWER Cyclical Redundancy Check; 32-bit
CRC (by default) for 64 sectors (32kb) of data. Calculated when evidence file is
added to a case and rechecked every time the data block is accessed.
Verification hash - ANSWER MD5--128-bit/32 characters; SHA1 - 160 bit;
can choose MD5 and SHA1, MD5 or SHA1, or neither
Evidence File Characteristics - ANSWER Logical file that can be renamed and
moved; can be broken into multiple segments with a maximum segment size
dependent on the file system to which the evidence file is written; can be
password protected or encrypted and can be reacquired to remove or change
password/encryption; can be compressed during acquisition and/or reacquired
with compression for archival without changing the hash value; individual
segments can be verified by the CRCs when compression is not used (if
compression is used, the decompression algorithm is used); error granularity is
often used to adjust the writing of data to an evidence file, when a read error of
the subject media occurs (standard - size of data blocks, exhaustive - sector-by-
sector)
Evidence file verification - ANSWER Data is verified by verification hash
compared to the acquisition hash value of the original evidence; data in each
block is verified by a CRC when no compression is used; both the MD5 and/or
,SHA1 hash and CRCs must match for the evidence file to be verified (if any
compression is used, the algorithm is used to verify data blocks)
Case file extension - ANSWER .case
Compound File - ANSWER Pointers to the locations of evidence files on
forensic workstation; results of the file signature and hash analysis; bookmarks;
investigators notes
Case File, how many hard drives? - ANSWER Can contain any number of hard
drives or removable media
What to include in case file? - ANSWER Should be archived with the evidence
cache and evidence files as it contains all of the investigators notes work work
product; use the "Create Package" feature
configuration .ini files - ANSWER Contain global options used for all cases
FileTypes.ini - ANSWER organizes files into groups by extension, determines
which viewer to use
Local.ini - ANSWER Global configuration settings
Viewers.ini - ANSWER Installed viewers associated to EnCase
EnCase Methodology - ANSWER Use large capacity high rpm hard drives
with single partition; wipe the drive to eliminate any claims or arguments of
cross contamination; give the HD a unique label prior to acquisitions to
differentiate your drives from that of the suspect.
EnCase Folders - ANSWER Separate folders for each case; use unique
directory names; each case requires export, temp, and evidencecache folder
EvidenceCache - ANSWER Storing cache files and containers for processed
evidence
Export Folder - ANSWER Default folder for exporting evidence
, Temp Folder - ANSWER Default temporary folder for file viewing
Evidence Processor - ANSWER After adding evidence run the enCase
evidence processor; lets you run in a single session power analytic tools against
case data; unattended; can Recover folders and files that have been deleted or
corrupted on FAT and NTFS volumes; Hash analysis - can generate MD5 or
SHA1 hash values and compare against hash library; can create image
thumbnails
Expand Compound Files - ANSWER Expand compound and compressed files,
such as ZIP, RAR, and GZ
Find Email - ANSWER Extract individual messages from email archive files,
PST, NSF, DBX, EDB, AOL, MBOX, and EMLX
Find internet artifacts - ANSWER collect internet-related artifacts such as
browser histories and cached web pages; options to search unallocated space for
the artifacts
Search for keywords - ANSWER search raw text for specific keywords
index text - ANSWER create and index for when you need to search for
keywords in compound files and across large amounts of data; adjust
parameters for index creation such as minimum word length
File signature analysis - ANSWER determine if extension of a file has been
altered, whether or not the extension matches the file type as specified by the
files headers
protected file analysis - ANSWER Identify encrypted and password protected
files
Search index - ANSWER Case index created with processor; instantly search
for terms; adjust parameters for index creation such as minimum word length or
noise file use; search transcript output of file; guidance recommends always
indexing.