3 Months Free Update
3 Months Free Update
3 Months Free Update
Two allocated files can occupy one cluster, as long as they can both fit within the allotted number of bytes.
The case file should be archived with the evidence files at the termination of a case.
You are at an incident scene and determine that a computer contains evidence as described in the search warrant. When you seize the computer, you should:
To undelete a file in the FAT file system, EnCase obtains the starting extent from the:
You are an investigator and have encountered a computer that is running at the home of a suspect. The computer does not appear to be a part of a network. The operating system is Windows XP Home. No programs are visibly running. You should:
The spool files that are created during a print job are __________ after the print job is completed.
The EnCase methodology dictates that the lab drive for evidence have a __________ prior to making an image.
How many copies of the FAT are located on a FAT 32, Windows 98-formatted partition?
How many partitions can be found in the boot partition table found at the beginning of the drive?
When a drive letter is assigned to a logical volume, that information is temporarily written the volume boot record on the hard drive.
The end of a logical file to the end of the cluster that the file ends in is called:
A hard drive has been formatted as NTFS and Windows XP was installed. The user used fdisk to remove all partitions from that drive. Nothing else was done. You have imaged the drive and have opened the evidence file with EnCase. What would be the best way to examine this hard drive?