Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

By default, what color does EnCase use for the contents of a logical file

A.

Red

B.

Red on black

C.

Black

D.

Black on red

In Windows, the file MyNote.txt is deleted from C Drive and is automatically sent to the Recycle Bin. The long filename was MyNote.txt and the short filename was MYNOTE.TXT. When viewing the Recycle Bin with EnCase, how will the long filename and MyNote.txt and the short filename was MYNOTE.TXT?

A.

MyNote.txt, CD0.txt

B.

MyNote.txt, DC0.txt

C.

MyNote.del, DC1.del

D.

MyNote.del, DC0.del

The acronym ASCII stands for:

A.

American Standard Communication Information Index

B.

American Standard Code for Information Interchange

C.

Accepted Standard Code for Information Interchange

D.

Accepted Standard Communication Information Index

Select the appropriate name for the highlighted area of the binary numbers.

A.

Bit

B.

Nibble

C.

Word

D.

Dword

E.

Byte

If cluster #3552 entry in the FAT table contains a value of ?? this would mean:

A.

The cluster is unallocated

B.

The cluster is the end of a file

C.

The cluster is allocated

D.

The cluster is marked bad

Will EnCase allow a user to write data into an acquired evidence file

A.

Yes, but only bookmarks.

B.

Yes, but only to resize the partitions.

C.

No. Data cannot be added to the evidence file after the acquisition is made.

D.

Yes, but only case information.

E.

No, unless the user established a writing privilege when the evidence was acquired.

Search results are found in which of the following files? Select all that apply.

A.

The evidence file

B.

The configuration Searches.ini file

C.

The case file

Searches and bookmarks are stored in the evidence file.

A.

False

B.

True

How many partitions can be found in the boot partition table found at the beginning of the drive?

A.

8

B.

4

C.

6

D.

2

A hard drive was imaged using EnCase. The original drive was placed into evidence. The restore feature was used to make a copy of the original hard drive. EnCase verifies the restored copy using:

A.

An MD5 hash

B.

A 32 bit CRC

C.

Nothing. Restored volumes are not verified.

D.

A running log