Select the appropriate name for the highlighted area of the binary numbers.
The following GREP expression was typed in exactly as shown. Choose the answer(s) that would result. 800[) \-]+555-1212
What files are reconfigured or deleted by EnCase during the creation of an EnCase boot disk?
By default, what color does EnCase use for the contents of a logical file
Select the appropriate name for the highlighted area of the binary numbers.
Select the appropriate name for the highlighted area of the binary numbers.
RAM is used by the computer to:
You are an investigator and have encountered a computer that is running at the home of a suspect. The computer does not appear to be a part of a network. The operating system is Windows XP Home. No programs are visibly running. You should:
An EnCase evidence file of a hard drive ________ be restored to another hard drive of equal or greater size.
A hash set would most accurately be described as:
To later verify the contents of an evidence file 7RODWHUYHULI\WKHFRQWHQWVRIDQHYLGHQFHILOH
Pressing the power button on a computer that is running could have which of the following results?
The default export folder remains the same for all cases.
The following GREP expression was typed in exactly as shown. Choose the answer(s) that would result. Bob@ [a-z]+.com
Assume that MyNote.txt was allocated to clusters 5, 9, and 11. Cluster 6, 7, and 8 belong to MyResume.doc. Both files have been deleted and the directory entry in the FAT file system for MyResume.doc has been overwritten. What clusters would EnCase use to undelete MyNote.txt?
Which is the proper formula for determining the size in bytes of a hard drive that uses cylinders (C), heads (H), and sectors (S) geometry?
You are conducting an investigation and have encountered a computer that is running in the field. The operating system is Windows XP. A software program is currently running and is visible on the screen. You should:
EnCase can build a hash set of a selected group of files.
A SCSI host adapter would most likely perform which of the following tasks?
In Windows 98 and ME, Internet based e-mail, such as Hotmail, will most likely be recovered in the _____________________ folder.
When a file is deleted in the FAT or NTFS file systems, what happens to the data on the hard drive?
The boot partition table found at the beginning of a hard drive is located in what sector?
In Unicode, one printed character is composed of ____ bytes of data.
If cluster number 10 in the FAT contains the number 55, this means:
You are examining a hard drive that has Windows XP installed as the operating system. You see a file that has a date and time in the deleted column. Where does that date and time come from?
How are the results of a signature analysis examined?