ENCE Questions with Detailed Verified Answers (100%
Correct Answers) /Already Graded A+
EnCase Evidence File
Ans: A Bit stream image of evidence written to a file.
Contains Case Data
Ans: Cannot be changed after evidence file is created
Evidence file Contains
Ans: Case Number; Examiner Name; Evidence Number; Unique Description;
Date/time of computer system clock; Acquisition notes; serial number of
physical hard drive
Evidence File Verification
Ans: Cyclical Redundancy Check; 32-bit CRC (by default) for 64 sectors
(32kb) of data. Calculated when evidence file is added to a case and rechecked
every time the data block is accessed.
Verification hash
Ans: MD5--128-bit/32 characters; SHA1 - 160 bit; can choose MD5 and
SHA1, MD5 or SHA1, or neither
Evidence File Characteristics
Ans: Logical file that can be renamed and moved; can be broken into multiple
segments with a maximum segment size dependent on the file system to which
the evidence file is written; can be password protected or encrypted and can
be reacquired to remove or change password/encryption; can be compressed
during acquisition and/or reacquired with compression for archival without
changing the hash value; individual segments can be verified by the CRCs when
compression is not used (if compression is used, the decompression algorithm
is used); error granularity is often used to adjust the writing of data to an
evidence file, when a read error of the subject media occurs (standard - size of
data blocks, exhaustive - sector-by-sector)
Approved By:
vPretest - Stuvia US
,2
Evidence file verification
Ans: Data is verified by verification hash compared to the acquisition hash
value of the original evidence; data in each block is verified by a CRC when no
compression is used; both the MD5 and/or SHA1 hash and CRCs must match
for the evidence file to be verified (if any compression is used, the algorithm is
used to verify data blocks)
Case file extension
Ans: .case
Compound File
Ans: Pointers to the locations of evidence files on forensic workstation;
results of the file signature and hash analysis; bookmarks; investigators notes
Case File, how many hard drives?
Ans: Can contain any number of hard drives or removable media
What to include in case file?
Ans: Should be archived with the evidence cache and evidence files as it
contains all of the investigators notes work work product; use the "Create
Package" feature
configuration .ini files
Ans: Contain global options used for all cases
FileTypes.ini
Ans: organizes files into groups by extension, determines which viewer to use
Local.ini
Ans: Global configuration settings
Viewers.ini
Approved By:
vPretest - Stuvia US
,3
Ans: Installed viewers associated to EnCase
EnCase Methodology
Ans: Use large capacity high rpm hard drives with single partition; wipe the
drive to eliminate any claims or arguments of cross contamination; give the HD
a unique label prior to acquisitions to differentiate your drives from that of the
suspect.
EnCase Folders
Ans: Separate folders for each case; use unique directory names; each case
requires export, temp, and evidencecache folder
EvidenceCache
Ans: Storing cache files and containers for processed evidence
Export Folder
Ans: Default folder for exporting evidence
Temp Folder
Ans: Default temporary folder for file viewing
Evidence Processor
Ans: After adding evidence run the enCase evidence processor; lets you run
in a single session power analytic tools against case data; unattended; can
Recover folders and files that have been deleted or corrupted on FAT and
NTFS volumes; Hash analysis - can generate MD5 or SHA1 hash values and
compare against hash library; can create image thumbnails
Expand Compound Files
Ans: Expand compound and compressed files, such as ZIP, RAR, and GZ
Find Email
Approved By:
vPretest - Stuvia US
, 4
Ans: Extract individual messages from email archive files, PST, NSF, DBX,
EDB, AOL, MBOX, and EMLX
Find internet artifacts
Ans: collect internet-related artifacts such as browser histories and cached
web pages; options to search unallocated space for the artifacts
Search for keywords
Ans: search raw text for specific keywords
index text
Ans: create and index for when you need to search for keywords in
compound files and across large amounts of data; adjust parameters for index
creation such as minimum word length
File signature analysis
Ans: determine if extension of a file has been altered, whether or not the
extension matches the file type as specified by the files headers
protected file analysis
Ans: Identify encrypted and password protected files
Search index
Ans: Case index created with processor; instantly search for terms; adjust
parameters for index creation such as minimum word length or noise file use;
search transcript output of file; guidance recommends always indexing.
Create a unified search
Ans: go to view menu and select index items; in index window enter index
query term or index search queries along with a logic operator; dynamic list is
displayed on right side of window showing terms in the index and number of
occurrence; click run or play button to run.
Raw Keyword - windows
Approved By:
vPretest - Stuvia US