Pass the Guidance Software EnCE GD0-110 Questions and answers with CertsForce

Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions
Questions # 31:

Search terms are stored in what .ini configuration file?

Options:

A.

FileTypes.ini


B.

FileSignatures.ini


C.

Keywords.ini


D.

TextStyle.ini


Expert Solution
Questions # 32:

The term signature and header as they relate to a signature analysis are:

Options:

A.

Areas compared with each other to verify the correct file type.


B.

Synonymous.


C.

The signature is the file extension. The header is a standard pattern normally found at the beginning of a file.


D.

None of the above


Expert Solution
Questions # 33:

A standard Windows 98 boot disk is acceptable for booting a suspect drive.

Options:

A.

True


B.

False


Expert Solution
Questions # 34:

You are investigating a case involving fraud. You seized a computer from a suspect who stated that the computer is not used by anyone other than himself. The computer has Windows 98 installed on the hard drive. You find the filename C:\downloads\check01.jpg that EnCase shows as being moved. The starting extent is 0C4057. You find another filename :\downloads\chk1.dll with the starting extent 0C4057, which EnCase also shows as being moved. In the C:\Windows\System folder you find an allocated file named chk1.dll with the starting extent 0C4057. The chk1.dll file is a JPEG image of a counterfeit check. What can be deduced from your findings?

Options:

A.

The presence and location of the files is strong evidence the suspect committed the crime.


B.

The presence and location of the files is not strong evidence the suspect committed the crime.


Expert Solution
Questions # 35:

A signature analysis has been run on a case. The result !Bad Signature means:

Options:

A.

The file signature is known and the file extension is known.


B.

The file signature is known and does not match a known file extension.


C.

The file signature is unknown and the file extension is known.


D.

The file signature is known and does not match a known file header.


Expert Solution
Questions # 36:

What does the acronym BIOS stand for?

Options:

A.

Basic Integrated Operating System


B.

Basic Input/Output System


C.

Binary Integrated Operating System


D.

Binary Input/Output System


Expert Solution
Questions # 37:

Searches and bookmarks are stored in the evidence file.

Options:

A.

True


B.

False


Expert Solution
Questions # 38:

A restored floppy diskette will have the same hash value as the original diskette.

Options:

A.

True


B.

False


Expert Solution
Questions # 39:

The case number in an evidence file can be changed without causing the verification feature to report an error, if:

Options:

A.

The user utilizes the case information editor within EnCase.


B.

The evidence file is reacquired.


C.

The user utilizes a text editor.


D.

The case information cannot be changed in an evidence file, without causing the verification feature to report an error.


Expert Solution
Questions # 40:

To undelete a file in the FAT file system, EnCase obtains the starting extent from the:

Options:

A.

FAT


B.

File header


C.

Operating system


D.

Directory entry


Expert Solution
Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions