Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 69 pages
Exam (elaborations)

EnCE Practice Test Questions with Detailed Verified Answers (100% Correct Answers) /Already Graded A+

Document preview thumbnail
Preview 4 out of 69 pages

You are a computer forensic examiner tasked with determining what evidence is on a seized computer. On what part of the computer system will you find data of evidentiary value? A. Microprocessor or CPU B. USB controller C. Hard drive D. PCI Expansions Ans: C. Hard drive You are a computer forensic examiner explaining how computers store and access the data you recovered as evidence during your examination. The evidence is a log file and was recovered as an artifact of user activity on the ________, which was stored on the _____________, contained within a _____________ on the media. A. Partition, operating system, file system B. Operating system, file system, partition C. File system, operating system, hard drive D. Operating system, partition, file system Ans: B. Operating system, file system, partition You are a computer forensic examiner investigating a seized computer. You recovered a document containing potential evidence. EnCase reports the file system on the forensic image of the hard drive is File Allocation Table (FAT). What information about the document file can be found in the FAT on the media? (Choose all that apply.) A. Name of the file 2 Approved By: vPretest - Stuvia US B. Date and time stamps of the file C. Starting cluster of the file D. Fragmentation of the file E. Ownership of the file Ans: C and D You are a computer forensic examiner investigating media on a seized computer. You recovered a document containing potential evidence. EnCase reports the file system on the forensic image of the hard drive is New Technology File System (NTFS). What information about the document file can be found in the NTFS master file table on the media? (Choose all that apply.) A. Name of the file B. Date and time stamps of the file C. Starting cluster of the file D. Fragmentation of the file E. Ownership of the file Ans: A, B, C, D and E You are preparing to lead a team to serve a search warrant on a business suspected of committing large-scale consumer fraud. Ideally, you would assign which tasks to search team members? (Choose all that apply.) A. Photographer B. Search and seizure specialists C. Recorder D. Digital evidence search and seizure specialists Ans: A, B, C and D You are a computer forensic examiner at a scene and have determined you will seize a Linux server, which, according to your source of information, 3

Content preview

1



EnCE Practice Test Questions with Detailed Verified
Answers (100% Correct Answers) /Already Graded A+
You are a computer forensic examiner tasked with determining what evidence
is on a seized computer. On what part of the computer system will you find
data of evidentiary value?


A. Microprocessor or CPU
B. USB controller
C. Hard drive
D. PCI Expansions
Ans: C. Hard drive

You are a computer forensic examiner explaining how computers store and
access the data you recovered as evidence during your examination. The
evidence is a log file and was recovered as an artifact of user activity on the
________, which was stored on the _____________, contained within a
_____________ on the media.


A. Partition, operating system, file system
B. Operating system, file system, partition
C. File system, operating system, hard drive
D. Operating system, partition, file system
Ans: B. Operating system, file system, partition

You are a computer forensic examiner investigating a seized computer. You
recovered a document containing potential evidence. EnCase reports the file
system on the forensic image of the hard drive is File Allocation Table (FAT).
What information about the document file can be found in the FAT on the
media? (Choose all that apply.)


A. Name of the file


Approved By:
vPretest - Stuvia US

,2

B. Date and time stamps of the file
C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file
Ans: C and D

You are a computer forensic examiner investigating media on a seized
computer. You recovered a document containing potential evidence. EnCase
reports the file system on the forensic image of the hard drive is New
Technology File System (NTFS). What information about the document file can
be found in the NTFS master file table on the media? (Choose all that apply.)


A. Name of the file
B. Date and time stamps of the file
C. Starting cluster of the file
D. Fragmentation of the file
E. Ownership of the file
Ans: A, B, C, D and E

You are preparing to lead a team to serve a search warrant on a business
suspected of committing large-scale consumer fraud. Ideally, you would assign
which tasks to search team members? (Choose all that apply.)


A. Photographer
B. Search and seizure specialists
C. Recorder
D. Digital evidence search and seizure specialists
Ans: A, B, C and D

You are a computer forensic examiner at a scene and have determined you
will seize a Linux server, which, according to your source of information,


Approved By:
vPretest - Stuvia US

,3

contains the database records for the company under investigation for fraud.
What is the best practice for "taking down" the server for collection?


A. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and use the normal shutdown procedure.
B. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and pull the plug from the wall.
C. Photograph the screen and note any running programs or messages, capture
volatile data, and so on, and pull the plug from the rear of the computer.
D. Photograph the screen and note any running programs or messages,
capture volatile data, and so on, and ask the user at the scene to shut down
the server.
Ans: A. Photograph the screen and note any running programs or messages,
capture volatile data, and so on, and use the normal shutdown procedure.

You are a computer forensic examiner at a scene and are authorized to seize
only media that can be determined to have evidence related to the
investigation. What options do you have to determine whether evidence is
present before seizure and a full forensic examination? (Choose all that apply.)


A. Use a DOS boot floppy or CD to boot the machine, and browse through
the directory for evidence.
B. Use a forensically sound Linux boot CD to boot the machine into Linux, and
use LinEn to preview the hard drive through a crossover cable with EnCase for
Windows.
C. Remove the subject's hard drive from the machine, and preview the hard
drive in EnCase for Windows with a hardware write blocker such as
FastBloc/Tableau.
D. Boot the computer into Windows and use Explorer search utility to find
the finds being sought.
Ans: B and C

You are a computer forensic examiner at a scene and have determined you
will need to image a hard drive in a workstation while on-site. What are your

Approved By:
vPretest - Stuvia US

, 4

options for creating a forensically sound image of the hard drive? (Choose all
that apply.)


A. Use a regular DOS boot floppy or CD to boot the machine, and use EnCase
for DOS to image the subject hard drive to a second hard drive attached to
the machine.
B. Use a forensically sound Linux boot CD to boot the machine into Linux, and
use LinEn to image the subject hard drive to a second hard drive attached to
the machine.
C. Remove the subject hard drive from the machine, and image the hard drive
in EnCase for Windows with a hardware write blocker such as
FastBloc/Tableau.
D. Use a forensically sound Linux boot CD to boot the machine into Linux,
and use LinEn to image the hard drive through a crossover cable with EnCase
for Windows.
Ans: B, C and D

You are a computer forensic examiner and have imaged a hard drive on site.
Before you leave the scene, you want to ensure the image completely verifies
as an exact forensic duplicate of the original. To verify the EnCase evidence file
containing the image, you should do which of the following?


A. Use a hex editor to compare a sample of sectors in the EnCase evidence file
with that of the original.
B. Load the EnCase evidence files into EnCase for Windows, and after the
verification is more than halfway completed, cancel the verification and spot-
check the results for errors.
C. Load the EnCase evidence files into EnCase for DOS, and verify the hash of
those files.
D. Load the EnCase evidence files into EnCase for Windows, allow the
verification process to finish, and then check the results for complete
verification.




Approved By:
vPretest - Stuvia US

Document information

Uploaded on
April 9, 2025
Number of pages
69
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$14.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
UniTests
4.0
(2)
Sold
18
Followers
0
Items
5177
Last sold
1 month ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions