This question addresses the EnCase for Windows search process. If a target word is within a logical file, and it begins in cluster 10 and ends in cluster 15 (the word is fragmented), the search:
Which of the following selections would be used to keep track of a fragmented file in the FAT file system?
Pressing the power button on a computer that is running could have which of the following results?
If an evidence file has been added to a case and completely verified, what happens if the data area within the evidence file is later changed?
How does EnCase verify that the case information (Case Number, Evidence Number, Investigator Name, etc) in an evidence file has not been damaged or changed, after the evidence file has been written?
Assume that MyNote.txt has been deleted. The FAT file system directory entry for that file has been overwritten. The data for MyNote.txt is now:
You are working in a computer forensic lab. A law enforcement investigator brings you a computer and a valid search warrant. You have legal authority to search the computer. The investigator hands you a piece of paper that has three printed checks on it. All three checks have the same check and account number. You image the suspect's computer and open the evidence file with EnCase. You perform a text search for the account number and check number. Nothing returns on the search results. You perform a text search for all other information found on the printed checks and there is still nothing returned in the search results. You run a signature analysis and check the gallery. You cannot locate any graphical copies of the printed checks in the gallery. At this point, is it safe to say that the checks are not located on the suspect computer?
What files are reconfigured or deleted by EnCase during the creation of an EnCase boot disk?
For an EnCase evidence file acquired with a hash value to pass verification, which of the following must be true?
A signature analysis has been run on a case. The result ?*JPEG ?in the signature column means:
Consider the following path in a FAT file system: C:\My Documents\My Pictures\Bikes. Where does the directory bikes receive its name?
Select the appropriate name for the highlighted area of the binary numbers.
To undelete a file in the FAT file system, EnCase obtains the starting extent from the: