A suspect typed a file on his computer and saved it to a floppy diskette. The filename was MyNote.txt. You receive the floppy and the suspect's computer. The suspect denies that the floppy disk belongs to him. You search the suspect's computer and locate only the filename within a .LNK file. The .LNK file is located in the folder C:\Windows\Recent. How you would use the .LNK file to establish a connection between the file on the floppy diskette and the suspect computer?
The boot partition table found at the beginning of a hard drive is located in what sector?
Search terms are stored in what .ini configuration file?
You are at an incident scene and determine that a computer contains evidence as described in the search warrant. When you seize the computer, you should:
Which of the following selections is NOT found in the case file?
Which of the following statements is more accurate?
How are the results of a signature analysis examined?
A CPU is:
This question addresses the EnCase for Windows search process. If a target word is located in the unallocated space, and the word is fragmented between clusters 10 and 15, the search:
When an EnCase user double-clicks on a valid .jpg file, that file is:
When Unicode is selected for a search keyword, EnCase:
The following GREP expression was typed in exactly as shown. Choose the answer(s) that would result. Jan 1 st , 2?0?00
Before utilizing an analysis technique on computer evidence, the investigator should:
How many clusters can a FAT 16 system address?
A SCSI drive is pinned as a master when it is:
4 bits allows what number of possibilities?
In Windows, the file MyNote.txt is deleted from C Drive and is automatically sent to the recycle Bin. The long filename was MyNote.txt and the short filename was MYNOTE.TXT. When viewing the recycle Bin with EnCase, how will the long filename and short filename appear?
The end of a logical file to the end of the cluster that the file ends in is called:
The default export folder remains the same for all cases.
Select the appropriate name for the highlighted area of the binary numbers.
A physical file size is:
Which of the following aspects of the EnCase evidence file can be changed during a reacquire of the evidence file?
If an evidence file has been added to a case and completely verified, what happens if the data area within the evidence file is later changed?
All investigators using EnCase should run tests on the evidence file acquisition and verification process to:
Search terms are case sensitive by default.
The following keyword was typed in exactly as shown. Choose the answer(s) that would result. All search criteria have default settings. Speed and Meth